Debian Package Tracker
Register | Log in
Subscribe

lexbor

Choose email to subscribe with

general
  • source: lexbor (main)
  • version: 2.6.0-2
  • maintainer: Karsten Schöke (DMD) (DM)
  • arch: any
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • testing: 2.6.0-2
  • unstable: 2.6.0-2
versioned links
  • 2.6.0-2: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • liblexbor-dev
  • liblexbor2
action needed
A new upstream version is available: 2.7.0 high
A new upstream version 2.7.0 is available, you should consider packaging it.
Created: 2026-03-14 Last update: 2026-03-17 03:02
2 security issues in sid high

There are 2 open security issues in sid.

2 important issues:
  • CVE-2026-29078: Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary size variable between iterations. The statement ctx->buffer_used -= size with a stale size = 3 causes an integer underflow that wraps to SIZE_MAX. Afterwards, memcpy is called with a negative length, leading to an out‑of‑bounds read from the stack and an out‑of‑bounds write to the heap. The source data is partially controllable via the contents of the DOM tree. This vulnerability is fixed in 2.7.0.
  • CVE-2026-29079: Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the qualified_name field. That corrupted value is later used as a pointer and dereferenced near the zero page. This vulnerability is fixed in 2.7.0.
Created: 2026-03-14 Last update: 2026-03-14 21:00
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-29078: Lexbor is a web browser engine library. Prior to 2.7.0, the ISO‑2022‑JP encoder in Lexbor fails to reset the temporary size variable between iterations. The statement ctx->buffer_used -= size with a stale size = 3 causes an integer underflow that wraps to SIZE_MAX. Afterwards, memcpy is called with a negative length, leading to an out‑of‑bounds read from the stack and an out‑of‑bounds write to the heap. The source data is partially controllable via the contents of the DOM tree. This vulnerability is fixed in 2.7.0.
  • CVE-2026-29079: Lexbor is a web browser engine library. Prior to 2.7.0, a type‑confusion vulnerability exists in Lexbor’s HTML fragment parser. When ns = UNDEF, a comment is created using the “unknown element” constructor. The comment’s data are written into the element’s fields via an unsafe cast, corrupting the qualified_name field. That corrupted value is later used as a pointer and dereferenced near the zero page. This vulnerability is fixed in 2.7.0.
Created: 2026-03-14 Last update: 2026-03-14 21:00
lintian reports 7 errors high
Lintian reports 7 errors about this package. You should make the package lintian clean getting rid of them.
Created: 2026-03-03 Last update: 2026-03-03 19:31
news
[rss feed]
  • [2026-03-04] lexbor 2.6.0-2 MIGRATED to testing (Debian testing watch)
  • [2026-03-02] Accepted lexbor 2.6.0-2 (source) into unstable (Karsten Schöke)
  • [2026-02-01] lexbor 2.6.0-1 MIGRATED to testing (Debian testing watch)
  • [2026-01-29] Accepted lexbor 2.6.0-1 (source amd64) into unstable (Debian FTP Masters) (signed by: Carsten Schoenert)
bugs [bug history graph]
  • all: 1
  • RC: 1
  • I&N: 0
  • M&W: 0
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (7, 0)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • edit tags
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2.6.0-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing