Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]
Groups > linux.debian.bugs.dist > #1269285 > unrolled thread
| Started by | Alex <alex@puer-robustus.eu> |
|---|---|
| First post | 2025-11-06 14:40 +0100 |
| Last post | 2025-11-09 17:20 +0100 |
| Articles | 6 — 5 participants |
Back to article view | Back to linux.debian.bugs.dist
Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 Alex <alex@puer-robustus.eu> - 2025-11-06 14:40 +0100
Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 "Adam D. Barratt" <adam@adam-barratt.org.uk> - 2025-11-06 20:20 +0100
Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Adam D Barratt <adam@adam-barratt.org.uk> - 2025-11-07 20:40 +0100
Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Paul Gevers <elbrus@debian.org> - 2025-11-09 12:00 +0100
Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Adrian Bunk <bunk@debian.org> - 2025-11-09 14:20 +0100
Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance Paul Gevers <elbrus@debian.org> - 2025-11-09 17:20 +0100
| From | Alex <alex@puer-robustus.eu> |
|---|---|
| Date | 2025-11-06 14:40 +0100 |
| Subject | Bug#1120262: trixie-pu: package curl/8.14.1-2+deb13u1 |
| Message-ID | <LO8nv-aVFX-3@gated-at.bofh.it> |
[Multipart message — attachments visible in raw view] — view raw
Package: release.debian.org Severity: normal Tags: trixie X-Debbugs-Cc: curl@packages.debian.org Control: affects -1 + src:curl User: release.debian.org@packages.debian.org Usertags: pu [ Reason ] The curl package version in Debian Trixie suffers from three minor CVEs: [1]: https://security-tracker.debian.org/tracker/CVE-2025-9086 [2]: https://security-tracker.debian.org/tracker/CVE-2025-10148 [3]: https://security-tracker.debian.org/tracker/CVE-2025-11563 The updated package version contains the backported upstream patches to close those vulnerabilities and also two bug fixes for wcurl: a man page fix and a fix to allow overriding the output file name with --curl-options. [ Impact ] If the update is not approved, all curl installations on Debian Trixie machines will remain vulnerable to the exploits: - CVE-2025-9086 allows for an out-of-bound read for cookie path - A fixed mask pattern discovered in CVE-2025-10148 allows a malicious server to induce traffic between the two communicating parties that could be interpreted by an involved proxy (configured or transparent) as genuine, real, HTTP traffic with content and thereby poison its cache. That cached poisoned content could then be served to all users of that proxy. - CVE-2025-11563 is a path traversal vulnerability where users might end up with the downloaded files placed in a folder outside of the current working directory unintentionally. Regarding the additional wcurl fixes: - The manpage fix is for an example invocation where the user wants downloads to be resumed, it's an important use case and was reported by a user. - The fix for overriding the output filename with --curl-options is not that important, given users will use --output directly, but the fix is extremely straightforward. [ Tests ] All upstream tests run successfully. Samuel Henrique <samueloph> has also run the reproducer for CVE-2025-9086 manually and confirmed that the patch fixes the issue. [ Risks ] Errors in backporting the patches which either don't close the vulnerabilities or introduce regressions which are not caught by the upstream tests. The cookie handling patch with the fix for CVE-2025-9086 could be carried over as is from upstream: https://salsa.debian.org/debian/curl/-/commit/700cf2ca7aa6b461c37f28f4f2634850dbf3b971 The websocket patch for CVE-2025-10148 required some backporting to make the expected return types match: https://salsa.debian.org/debian/curl/-/commit/98f245da1dee1f4c549cd3b826a8bcc49cb03d71 The wcurl patches only required minimal backporting changes: https://salsa.debian.org/debian/curl/-/commit/a50e1fa30dd7a58af13d4ce029352520b4e20dd1 https://salsa.debian.org/debian/curl/-/commit/84b76ed84665be069b70b14b0a857a6440708d9b https://salsa.debian.org/debian/curl/-/commit/84e8794b04007dbc07db29ea3b3ab66873339986 [ Checklist ] [x] *all* changes are documented in the d/changelog [x] I reviewed all changes and I approve them [x] attach debdiff against the package in (old)stable [x] the issue is verified as fixed in unstable [ Changes ] * Backported patch to not drop leading slash in cookie path if that is its only component. * Backported patch which ensures the use of a new, random mask for each outgoing frame on websockets. * Backported wcurl patches for the CVE, manpage fix, and output filename overriding fix. * salsa-ci.yml: Disable arm builds, they are currently broken. [ Other info ] Nothing that I am aware of.
[toc] | [next] | [standalone]
| From | "Adam D. Barratt" <adam@adam-barratt.org.uk> |
|---|---|
| Date | 2025-11-06 20:20 +0100 |
| Message-ID | <LOdGx-aZdX-1@gated-at.bofh.it> |
| In reply to | #1269285 |
Control: tags -1 + confirmed On Thu, 2025-11-06 at 14:30 +0100, Alex wrote: > The curl package version in Debian Trixie suffers from three minor > CVEs: > > [1]: https://security-tracker.debian.org/tracker/CVE-2025-9086 > [2]: https://security-tracker.debian.org/tracker/CVE-2025-10148 > [3]: https://security-tracker.debian.org/tracker/CVE-2025-11563 > > The updated package version contains the backported upstream patches > to close those vulnerabilities and also two bug fixes for wcurl: a > man page fix and a fix to allow overriding the output file name with > --curl-options. Please go ahead. Regards, Adam
[toc] | [prev] | [next] | [standalone]
| From | Adam D Barratt <adam@adam-barratt.org.uk> |
|---|---|
| Date | 2025-11-07 20:40 +0100 |
| Subject | Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance |
| Message-ID | <LOAtr-beIs-7@gated-at.bofh.it> |
| In reply to | #1269285 |
package release.debian.org tags 1120262 = trixie pending thanks Hi, The upload referenced by this bug report has been flagged for acceptance into the proposed-updates queue for Debian trixie. Thanks for your contribution! Upload details ============== Package: curl Version: 8.14.1-2+deb13u1 Explanation: fix buffer over-read issue [CVE-2025-9086]; fix cache poisoning issue [CVE-2025-10148]; fix path traversal issue [CVE-2025-10148]; allow --output to be overridden by --curl-options; fix manpage example for "continue-at"
[toc] | [prev] | [next] | [standalone]
| From | Paul Gevers <elbrus@debian.org> |
|---|---|
| Date | 2025-11-09 12:00 +0100 |
| Subject | Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance |
| Message-ID | <LPbjj-bDsB-1@gated-at.bofh.it> |
| In reply to | #1269453 |
[Multipart message — attachments visible in raw view] — view raw
Hi, On 11/7/25 20:36, Adam D Barratt wrote: > Package: curl > Version: 8.14.1-2+deb13u1 > > Explanation: fix buffer over-read issue [CVE-2025-9086]; fix cache poisoning issue [CVE-2025-10148]; fix path traversal issue [CVE-2025-10148]; allow --output to be overridden by --curl-options; fix manpage example for "continue-at" https://release.debian.org/proposed-updates/stable.html shows a regression (4 tries, the test doesn't seem to have a flaky history) in mpd on s390x. Now I'm not really worried that people use mpd on s390x, but it might indicate a subtle issue with curl on s390x. Care to have a look? I've CC'd the mpd maintainers as they might be able to tell what failure they are observing in their test. I also CC'd the s390x porters as they might care about curl behavior on s390x. Paul PS: the other "regressions" will go away when the page is refreshed as they all passed on retry or are flaky tests.
[toc] | [prev] | [next] | [standalone]
| From | Adrian Bunk <bunk@debian.org> |
|---|---|
| Date | 2025-11-09 14:20 +0100 |
| Subject | Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance |
| Message-ID | <LPduN-bF7o-3@gated-at.bofh.it> |
| In reply to | #1269629 |
On Sun, Nov 09, 2025 at 11:56:19AM +0100, Paul Gevers wrote: > Hi, > > On 11/7/25 20:36, Adam D Barratt wrote: > > Package: curl > > Version: 8.14.1-2+deb13u1 > > > > Explanation: fix buffer over-read issue [CVE-2025-9086]; fix cache poisoning issue [CVE-2025-10148]; fix path traversal issue [CVE-2025-10148]; allow --output to be overridden by --curl-options; fix manpage example for "continue-at" > > > https://release.debian.org/proposed-updates/stable.html shows a regression > (4 tries, the test doesn't seem to have a flaky history) in mpd on s390x. > Now I'm not really worried that people use mpd on s390x, but it might > indicate a subtle issue with curl on s390x. Care to have a look? I've CC'd > the mpd maintainers as they might be able to tell what failure they are > observing in their test. I also CC'd the s390x porters as they might care > about curl behavior on s390x. Migration references are not retried for pu->stable, and when I did so manually it also failed: https://ci.debian.net/packages/m/mpd/stable/s390x/ But this reference failure is in a different test... Failure also previously happened in testing last month: https://ci.debian.net/packages/m/mpd/testing/s390x/ After a manual retry mpd reference tests also fail in testing and bookworm. In unstable it failed on 3rd attempt. The latter indicates that mpd/s390x is flaky. > Paul >... cu Adrian
[toc] | [prev] | [next] | [standalone]
| From | Paul Gevers <elbrus@debian.org> |
|---|---|
| Date | 2025-11-09 17:20 +0100 |
| Subject | Bug#1120262: curl 8.14.1-2+deb13u1 flagged for acceptance |
| Message-ID | <LPgiZ-bHiy-13@gated-at.bofh.it> |
| In reply to | #1269637 |
[Multipart message — attachments visible in raw view] — view raw
Hi Adrian On 11/9/25 14:08, Adrian Bunk wrote: > On Sun, Nov 09, 2025 at 11:56:19AM +0100, Paul Gevers wrote: >> https://release.debian.org/proposed-updates/stable.html shows a regression >> (4 tries, the test doesn't seem to have a flaky history) in mpd on s390x. >> Now I'm not really worried that people use mpd on s390x, but it might >> indicate a subtle issue with curl on s390x. Care to have a look? I've CC'd >> the mpd maintainers as they might be able to tell what failure they are >> observing in their test. I also CC'd the s390x porters as they might care >> about curl behavior on s390x. > > Migration references are not retried for pu->stable, Depends on what you mean here. Britney2 for pu->stable is configure to retry in a similar way as unstable->testing. As stable doesn't change that much references are valid for 15 day while in testing validity is 7 days. > and when I did so > manually it also failed: > https://ci.debian.net/packages/m/mpd/stable/s390x/ The last reference ran on 31 October and the history of the package was very good, hence it didn't occur to me to retry. Thanks. > Failure also previously happened in testing last month: > https://ci.debian.net/packages/m/mpd/testing/s390x/ But this was a single incident and on retry that passed. > After a manual retry mpd reference tests also fail in testing > and bookworm. In unstable it failed on 3rd attempt. > > The latter indicates that mpd/s390x is flaky. The older history in s390x doesn't suggest that though. So this looks like fresh flakiness. Sorry for not considering that option. Paul
[toc] | [prev] | [standalone]
Back to top | Article view | linux.debian.bugs.dist
csiph-web