There are 2 open security issues in trixie.
2 issues left for the package maintainer to handle:
- CVE-2026-18739:
(needs triaging)
A flaw was found in popt, a command-line option parsing library. An off-by-one error in the poptStuffArgs function, when repeatedly called by a host application or through deep alias nesting, can lead to corruption of internal program data. This corruption could potentially enable a local attacker to execute arbitrary code if the host application then unsafely processes the altered data.
- CVE-2026-18839:
(needs triaging)
An integer underflow was found in the popt library when formatting help text for option tables that exceed the terminal width. A local user who can cause an application to print help under those conditions may cause that application to crash or fail to display help, resulting in a denial of service of the affected application.
You can find information about how to handle these issues in the security team's documentation.