Debian Package Tracker
Register | Log in
Subscribe

bison

YACC-compatible parser generator

Choose email to subscribe with

general
  • source: bison (main)
  • version: 2:3.8.2+dfsg-1
  • maintainer: Chuan-kai Lin (DMD)
  • arch: any
  • std-ver: 4.6.0
  • VCS: unknown
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 2:3.7.5+dfsg-1
  • oldstable: 2:3.8.2+dfsg-1
  • stable: 2:3.8.2+dfsg-1
  • testing: 2:3.8.2+dfsg-1
  • unstable: 2:3.8.2+dfsg-1
versioned links
  • 2:3.7.5+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 2:3.8.2+dfsg-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • bison (5 bugs: 0, 4, 1, 0)
  • libbison-dev
action needed
Multiarch hinter reports 1 issue(s) high
There are issues with the multiarch metadata for this package.
  • libbison-dev conflicts on /usr/share/doc/libbison-dev/changelog.Debian.gz on loong64 <-> amd64, arm64, armhf and 4 more
Created: 2026-04-19 Last update: 2026-08-08 15:02
2 security issues in sid high

There are 2 open security issues in sid.

2 important issues:
  • CVE-2026-56389: GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
  • CVE-2026-56390: GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
Created: 2026-07-30 Last update: 2026-08-02 20:32
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-56389: GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
  • CVE-2026-56390: GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
Created: 2026-07-30 Last update: 2026-08-02 20:32
lintian reports 1 warning normal
Lintian reports 1 warning about this package. You should make the package lintian clean getting rid of them.
Created: 2024-10-17 Last update: 2024-10-17 00:00
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-56389: (needs triaging) GNU Bison allows for an execution of an arbitrary program during HTML report generation due to improper handling of grammar-defined configuration variables. A grammar file can override the executable used for the XML‑to‑HTML transformation step via %define tool.xsltproc, which is accepted without restriction and passed directly to execvp(). When running bison --html on a attacker-provided grammar, this behavior allows execution of an arbitrary program with the privileges of the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.
  • CVE-2026-56390: (needs triaging) GNU Bison improperly handles grammar‑defined output paths. Grammar directives such as %output and %header allow specifying file paths, which are accepted without restriction and override caller‑supplied output options. When processing attacker-supplied grammar, this behavior allows directing generated files to arbitrary writable locations on the filesystem, potentially overwriting existing files accessible to the Bison process. Maintainers of this project were notified about this vulnerability, and fixed the issue in commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did not provide vulnerable version range. Version 3.8.2 was tested and confirmed as vulnerable, other versions were not tested but might also be vulnerable.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-07-30 Last update: 2026-08-02 20:32
debian/patches: 1 patch to forward upstream low

Among the 2 debian patches available in version 2:3.8.2+dfsg-1 of the package, we noticed the following issues:

  • 1 patch where the metadata indicates that the patch has not yet been forwarded upstream. You should either forward the patch upstream or update the metadata to document its real status.
Created: 2023-02-26 Last update: 2023-02-27 20:59
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.6.0).
Created: 2022-05-11 Last update: 2026-03-31 15:01
news
[rss feed]
  • [2021-10-08] bison 2:3.8.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-10-03] Accepted bison 2:3.8.2+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2021-09-25] bison 2:3.8.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-09-20] Accepted bison 2:3.8.1+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2021-08-16] bison 2:3.7.6+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-05-06] Accepted bison 2:3.7.6+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2021-02-05] bison 2:3.7.5+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2021-01-30] Accepted bison 2:3.7.5+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2020-12-10] bison 2:3.7.4+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-12-04] Accepted bison 2:3.7.4+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2020-10-23] bison 2:3.7.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-10-18] Accepted bison 2:3.7.3+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2020-09-13] bison 2:3.7.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-09-07] Accepted bison 2:3.7.2+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2020-08-01] bison 2:3.7+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-07-25] Accepted bison 2:3.7+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2020-06-13] bison 2:3.6.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-06-08] Accepted bison 2:3.6.3+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2020-05-17] bison 2:3.6.1+dfsg-2 MIGRATED to testing (Debian testing watch)
  • [2020-05-11] Accepted bison 2:3.6.1+dfsg-2 (source) into unstable (Chuan-kai Lin)
  • [2020-05-10] Accepted bison 2:3.6.1+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2020-03-20] bison 2:3.5.3+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-03-15] Accepted bison 2:3.5.3+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2020-01-27] bison 2:3.5.1+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2020-01-22] Accepted bison 2:3.5.1+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2019-09-27] bison 2:3.4.2+dfsg-1 MIGRATED to testing (Debian testing watch)
  • [2019-09-22] Accepted bison 2:3.4.2+dfsg-1 (source) into unstable (Chuan-kai Lin)
  • [2019-08-20] bison 2:3.4.1+dfsg-4 MIGRATED to testing (Debian testing watch)
  • [2019-07-10] Accepted bison 2:3.4.1+dfsg-4 (source amd64) into unstable (Chuan-kai Lin)
  • [2019-07-07] Accepted bison 2:3.4.1+dfsg-3 (source amd64) into unstable (Chuan-kai Lin)
  • 1
  • 2
bugs [bug history graph]
  • all: 8
  • RC: 0
  • I&N: 5
  • M&W: 3
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian (0, 1)
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
  • l10n (-, 67)
  • debian patches
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 2:3.8.2+dfsg-1build4

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing