Debian Package Tracker
Register | Log in
Subscribe

yara

Pattern matching swiss knife for malware researchers

Choose email to subscribe with

general
  • source: yara (main)
  • version: 4.5.8-1
  • maintainer: Debian Security Tools (DMD)
  • uploaders: Hilko Bengen [DMD]
  • arch: all any
  • std-ver: 4.7.3
  • VCS: Git (Browse, QA)
versions [more versions can be listed by madison] [old versions available from snapshot.debian.org]
[pool directory]
  • o-o-stable: 4.0.5-1
  • oldstable: 4.2.3-4
  • old-bpo: 4.5.2-1~bpo12+1
  • stable: 4.5.2-1
  • testing: 4.5.8-1
  • unstable: 4.5.8-1
versioned links
  • 4.0.5-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.2.3-4: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.5.2-1~bpo12+1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.5.2-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
  • 4.5.8-1: [.dsc, use dget on this link to retrieve source package] [changelog] [copyright] [rules] [control]
binaries
  • libyara-dev
  • libyara10
  • yara
  • yara-doc
action needed
2 security issues in sid high

There are 2 open security issues in sid.

2 important issues:
  • CVE-2026-88340: An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.
  • CVE-2026-88341: A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate.
Created: 2026-09-23 Last update: 2026-09-25 15:00
2 security issues in forky high

There are 2 open security issues in forky.

2 important issues:
  • CVE-2026-88340: An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.
  • CVE-2026-88341: A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate.
Created: 2026-09-23 Last update: 2026-09-25 15:00
2 security issues in bookworm high

There are 2 open security issues in bookworm.

2 important issues:
  • CVE-2026-88340: An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.
  • CVE-2026-88341: A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate.
Created: 2026-09-23 Last update: 2026-09-25 15:00
2 low-priority security issues in trixie low

There are 2 open security issues in trixie.

2 issues left for the package maintainer to handle:
  • CVE-2026-88340: (needs triaging) An invalid pointer release vulnerability exists in YARA 4.5.8 during deserialization of compiled .yrc rule files. The vulnerability is caused by insufficient validation of external-variable pointers, which may lead to invalid free in yr_rules_destroy() or wild pointer access in yr_object_create(). An attacker can provide a specially crafted .yrc file that causes memory corruption and application crash.
  • CVE-2026-88341: (needs triaging) A reachable assertion vulnerability exists in YARA 4.5.8 when loading crafted .yrc compiled rule files. An attacker can provide a malicious file with an invalid arena configuration (num_buffers=0) that triggers an assertion failure in yr_arena_get_ptr(), causing the application to terminate.

You can find information about how to handle these issues in the security team's documentation.

Created: 2026-09-23 Last update: 2026-09-25 15:00
Standards version of the package is outdated. wishlist
The package should be updated to follow the last version of Debian Policy (Standards-Version 4.7.4 instead of 4.7.3).
Created: 2026-03-31 Last update: 2026-07-29 06:00
testing migrations
  • This package will soon be part of the auto-openssl transition. You might want to ensure that your package is ready for it. You can probably find supplementary information in the debian-release archives or in the corresponding release.debian.org bug.
news
[rss feed]
  • [2026-08-03] yara 4.5.8-1 MIGRATED to testing (Debian testing watch)
  • [2026-07-28] Accepted yara 4.5.8-1 (source) into unstable (Hilko Bengen)
  • [2026-06-27] yara 4.5.7-1 MIGRATED to testing (Debian testing watch)
  • [2026-06-21] Accepted yara 4.5.7-1 (source) into unstable (Hilko Bengen)
  • [2026-06-07] yara 4.5.6-1 MIGRATED to testing (Debian testing watch)
  • [2026-05-31] Accepted yara 4.5.6-1 (source) into unstable (Hilko Bengen)
  • [2026-02-21] yara 4.5.5-1 MIGRATED to testing (Debian testing watch)
  • [2026-02-08] Accepted yara 4.5.5-1 (source) into unstable (Hilko Bengen)
  • [2025-08-13] yara 4.5.4-1 MIGRATED to testing (Debian testing watch)
  • [2025-07-29] Accepted yara 4.5.4-1 (source) into unstable (Hilko Bengen)
  • [2025-05-25] Accepted yara 4.5.3-1 (source) into unstable (Hilko Bengen)
  • [2024-09-20] Accepted yara 4.5.2-1~bpo12+1 (source) into stable-backports (Hilko Bengen)
  • [2024-09-16] yara 4.5.2-1 MIGRATED to testing (Debian testing watch)
  • [2024-09-10] Accepted yara 4.5.2-1 (source) into unstable (Hilko Bengen)
  • [2024-05-31] yara 4.5.1-1 MIGRATED to testing (Debian testing watch)
  • [2024-05-26] Accepted yara 4.5.1-1~bpo12+1 (source) into stable-backports (Hilko Bengen)
  • [2024-05-26] Accepted yara 4.5.1-1 (source) into unstable (Hilko Bengen)
  • [2024-05-15] Accepted yara 4.5.0-1~bpo12+1 (source amd64 all) into stable-backports (Debian FTP Masters) (signed by: Hilko Bengen)
  • [2024-02-19] yara 4.5.0-1 MIGRATED to testing (Debian testing watch)
  • [2024-02-13] Accepted yara 4.5.0-1 (source) into unstable (Hilko Bengen)
  • [2023-09-22] yara 4.4.0-1 MIGRATED to testing (Debian testing watch)
  • [2023-09-16] Accepted yara 4.4.0-1 (source) into unstable (Hilko Bengen)
  • [2023-06-20] yara 4.3.2-1 MIGRATED to testing (Debian testing watch)
  • [2023-06-12] Accepted yara 4.3.2-1 (source) into unstable (Hilko Bengen)
  • [2023-03-24] Accepted yara 4.3.0-1 (source amd64 all) into experimental (Debian FTP Masters) (signed by: Hilko Bengen)
  • [2023-01-25] yara 4.2.3-4 MIGRATED to testing (Debian testing watch)
  • [2023-01-23] Accepted yara 4.2.3-4 (source) into unstable (Hilko Bengen)
  • [2023-01-02] yara 4.2.3-3 MIGRATED to testing (Debian testing watch)
  • [2022-12-28] Accepted yara 4.2.3-3 (source) into unstable (Hilko Bengen)
  • [2022-12-27] Accepted yara 4.2.3-2 (source) into unstable (Hilko Bengen)
  • 1
  • 2
bugs [bug history graph]
  • all: 2
  • RC: 0
  • I&N: 1
  • M&W: 1
  • F&P: 0
  • patch: 0
links
  • homepage
  • lintian
  • buildd: logs, reproducibility, cross
  • popcon
  • browse source code
  • other distros
  • security tracker
ubuntu Ubuntu logo [Information about Ubuntu for Debian Developers]
  • version: 4.5.8-1

Debian Package Tracker — Copyright 2013-2025 The Distro Tracker Developers
Report problems to the tracker.debian.org pseudo-package in the Debian BTS.
Documentation — Bugs — Git Repository — Contributing