-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 16:44:03 +0200 Source: inetutils Binary: inetutils-ftp inetutils-ftp-dbgsym inetutils-ftpd inetutils-ftpd-dbgsym inetutils-inetd inetutils-inetd-dbgsym inetutils-ping inetutils-ping-dbgsym inetutils-syslogd inetutils-syslogd-dbgsym inetutils-talk inetutils-talk-dbgsym inetutils-talkd inetutils-talkd-dbgsym inetutils-telnet inetutils-telnet-dbgsym inetutils-telnetd inetutils-telnetd-dbgsym inetutils-tools inetutils-tools-dbgsym inetutils-traceroute inetutils-traceroute-dbgsym Architecture: ppc64el Version: 2:2.6-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: ppc64el Build Daemon (ppc64el-conova-02) Changed-By: Guillem Jover Description: inetutils-ftp - File Transfer Protocol client inetutils-ftpd - File Transfer Protocol server inetutils-inetd - internet super server inetutils-ping - ICMP echo tool inetutils-syslogd - system logging daemon inetutils-talk - talk to another user inetutils-talkd - remote user communication server inetutils-telnet - telnet client inetutils-telnetd - telnet server inetutils-tools - base networking utilities (experimental package) inetutils-traceroute - trace the IPv4 route to another host Closes: 1130741 1130742 Changes: inetutils (2:2.6-3+deb13u3) trixie-security; urgency=high . * Add patches from upstream: - Ignore all environment options from clients unless the variable was listed in the new --accept-env telnetd option. This mitigates privilege escalation using environment variables. This is the complete fix for CVE-2026-24061, with its own CVE pending. - Fix stack buffer overflow processing SLC suboption triplets. Reported by Adiel Sol, Arad Inbar, Erez Cohen, Nir Somech, Ben Grinberg, Daniel Lubel at DREAM Security Research Team. Fixes CVE-2026-32746. (Closes: #1130742) * Add the hashcode-string1 module from forky/sid gnulib, required by the --accept-env patch. * Adapt netkit-telnet patch to not leak unexported environment variables to telnetd. Reported by Justin Swartz . Fixes CVE-2026-32772. (Closes: #1130741) * Prevent user local privilege escalation using --debug, which was susceptible to symlink attacks, or leaking on-wire credentials to a user that had pre-created the file and kept it open. Fix by switching from /tmp/telnet.debug to /run/telnet/debug., and making the setup error checks fatal. Partially reported by Justin Swartz . * Update local telnetd man page to match new --debug behavior. Checksums-Sha1: 43b4eeaee151be8a0c67147e954976fa2ef5746d 167492 inetutils-ftp-dbgsym_2.6-3+deb13u3_ppc64el.deb 6f620cebe5fa53c40a122edb785896bc7bcd67bb 113668 inetutils-ftp_2.6-3+deb13u3_ppc64el.deb 13a99590dacb8fd5e2069f6e3fef0f3ffa901b4b 200320 inetutils-ftpd-dbgsym_2.6-3+deb13u3_ppc64el.deb 6b7d51eeea4549917fb5a5af1e527cc14701378f 117564 inetutils-ftpd_2.6-3+deb13u3_ppc64el.deb d35350db7782d0571812ce76b4d9d0f2eedd98a5 110504 inetutils-inetd-dbgsym_2.6-3+deb13u3_ppc64el.deb 0a48715b25174ea47bce2973c6a5f3075c356994 89456 inetutils-inetd_2.6-3+deb13u3_ppc64el.deb 629c4da34d9dec2c4876c81a8a508c98650ae37a 194088 inetutils-ping-dbgsym_2.6-3+deb13u3_ppc64el.deb 6001735edebec29c8cb47ca2241f1df1548a2d31 93004 inetutils-ping_2.6-3+deb13u3_ppc64el.deb ff3b82b0c75f0ba2b53a32658215b517ebe330b8 128900 inetutils-syslogd-dbgsym_2.6-3+deb13u3_ppc64el.deb ba33fb3813dc20aba13d891f4cc27aa3942b1422 96124 inetutils-syslogd_2.6-3+deb13u3_ppc64el.deb f0440b9e3d037b20f4f32f64a723f7cb40a7b604 88352 inetutils-talk-dbgsym_2.6-3+deb13u3_ppc64el.deb 9f289f7792526e76d5775810c1bb90e2f5c96a95 75356 inetutils-talk_2.6-3+deb13u3_ppc64el.deb c5b5d5b4661ae62b1b4c3c982492af9a3ca4c255 118348 inetutils-talkd-dbgsym_2.6-3+deb13u3_ppc64el.deb 337bd9470628e79f5f4a50c0da7ddf9fdf65e9a1 84184 inetutils-talkd_2.6-3+deb13u3_ppc64el.deb 831e59cd99a6b523b24c7f858deed801bfa34280 237512 inetutils-telnet-dbgsym_2.6-3+deb13u3_ppc64el.deb b952c6e621f9ef276037709b6c9c01828c9ce976 135424 inetutils-telnet_2.6-3+deb13u3_ppc64el.deb f1a563202dcf925f616f67214e5adc97cd1cf203 189344 inetutils-telnetd-dbgsym_2.6-3+deb13u3_ppc64el.deb e2f23af6547f82272f51519bb89540d11fd0393b 116220 inetutils-telnetd_2.6-3+deb13u3_ppc64el.deb fee3e239dce25bd71c7cd59e02f8f5cc247d908c 349068 inetutils-tools-dbgsym_2.6-3+deb13u3_ppc64el.deb bb6de2a16ca01334e46eca6e5de6920ed9a8706f 110020 inetutils-tools_2.6-3+deb13u3_ppc64el.deb 78d781f1f9202866451b741e7be4adf6bba6e59a 91264 inetutils-traceroute-dbgsym_2.6-3+deb13u3_ppc64el.deb c6d774c0dc6f17737c00b56ae2c9c65c81601363 73396 inetutils-traceroute_2.6-3+deb13u3_ppc64el.deb 2350e2e8367ad458bc2c074294cfda1b3b5bfe69 13091 inetutils_2.6-3+deb13u3_ppc64el-buildd.buildinfo Checksums-Sha256: 967df342bfae66a99696567826b8e6a7df673d829a30d14caeee615933b7e861 167492 inetutils-ftp-dbgsym_2.6-3+deb13u3_ppc64el.deb 36ab899728d5d629ef5ec5757ec32bc9d4d2b62ce924ebe6a9ec69db0640d517 113668 inetutils-ftp_2.6-3+deb13u3_ppc64el.deb 695ce472673d84e5a8dcd49c878da7b13aef374821aec6cdb16b01c93c55b063 200320 inetutils-ftpd-dbgsym_2.6-3+deb13u3_ppc64el.deb 59beb65437f136c2fd7ded41f8d93d77e70850559855ca584a509267df44fcfd 117564 inetutils-ftpd_2.6-3+deb13u3_ppc64el.deb e83b06472ec254a350c3161472fc394e27d1eef138fa42dc713c4502ffc31f05 110504 inetutils-inetd-dbgsym_2.6-3+deb13u3_ppc64el.deb ac500cb24e59a96c00604550dea334450cd8d2138d4bc4ee40501ca85601b668 89456 inetutils-inetd_2.6-3+deb13u3_ppc64el.deb 39059a942759525b670bbc60b10019208653f9ee83fe822d518fde410b8ce56d 194088 inetutils-ping-dbgsym_2.6-3+deb13u3_ppc64el.deb 758b597fdf138f2bab1ef5595be46a385fe27085d8ea4ad060bffa67467b3cc4 93004 inetutils-ping_2.6-3+deb13u3_ppc64el.deb 31f8221409610a8c9ce592c811d2e44d45395953b5b103993b15c4966fcd6f8c 128900 inetutils-syslogd-dbgsym_2.6-3+deb13u3_ppc64el.deb c1e705640e26c8ba32b338b3d2652453a70afd4ed3d871292b4de00fcc3d9bec 96124 inetutils-syslogd_2.6-3+deb13u3_ppc64el.deb e98d8e9d3c3ec6bff6f4639d9e0f8c54fef1032067b4cca2dc5df466b3faf2c1 88352 inetutils-talk-dbgsym_2.6-3+deb13u3_ppc64el.deb be1969880e0b6f58a837a260c8fa98fdcbad4caeea7435939580b128d5e17433 75356 inetutils-talk_2.6-3+deb13u3_ppc64el.deb d26928e6751062362a573ff2868f600bffd72ba47b086c635a9870b27af21e02 118348 inetutils-talkd-dbgsym_2.6-3+deb13u3_ppc64el.deb 9a81665d324b6bf70bb084849328ae7c1ae4d17b7176ce122848b37fa11ed4d9 84184 inetutils-talkd_2.6-3+deb13u3_ppc64el.deb 6e346beecf4d5463b1be3d517c672fb3e760ae7b9931aee5d2eb82b5dca008c2 237512 inetutils-telnet-dbgsym_2.6-3+deb13u3_ppc64el.deb c8a8789695728606337890bcf6ddfd8f63ec512e9cdd4cc902bd47b3adefed5d 135424 inetutils-telnet_2.6-3+deb13u3_ppc64el.deb 085159d7376d7b0a247b54df5ecb0b3487e29d1bcfa44da7cab893b155ec4f59 189344 inetutils-telnetd-dbgsym_2.6-3+deb13u3_ppc64el.deb 8abfa8a94b6a5bee1da7cb2daf930c8271a710bae054b8924fe6cae71f92539c 116220 inetutils-telnetd_2.6-3+deb13u3_ppc64el.deb bae4d7e44f93c0eab93517803ac84cff3cffcb47ffbb248af3a2c764e512906f 349068 inetutils-tools-dbgsym_2.6-3+deb13u3_ppc64el.deb 81653002ab8dfe63d9f1ff724f5f65434264f371b58c9dc67d3ec28e62e564eb 110020 inetutils-tools_2.6-3+deb13u3_ppc64el.deb 4a5ac9364a14e87b0e69a65efb816c35d39d21d5de8102ec9858341db0ef8fa8 91264 inetutils-traceroute-dbgsym_2.6-3+deb13u3_ppc64el.deb ef380bba490290216bc327d859bfc85b4a1f781e20feb639bc809c122a423691 73396 inetutils-traceroute_2.6-3+deb13u3_ppc64el.deb 9bd37bef70526975275f3e251a1a7a0b3801549091591bd92ef921acf157dcf5 13091 inetutils_2.6-3+deb13u3_ppc64el-buildd.buildinfo Files: 45f1e4d3a2e43dec5c704a340c823add 167492 debug optional inetutils-ftp-dbgsym_2.6-3+deb13u3_ppc64el.deb c4177d0505473044700eb0270b5fcbab 113668 net optional inetutils-ftp_2.6-3+deb13u3_ppc64el.deb 113a8aacddeb2b5ba5882d915bb83337 200320 debug optional inetutils-ftpd-dbgsym_2.6-3+deb13u3_ppc64el.deb 7ecd8cb34087ac19f01457d36d347393 117564 net optional inetutils-ftpd_2.6-3+deb13u3_ppc64el.deb ae5e6b70553017c337a5cd44f9fc3aaf 110504 debug optional inetutils-inetd-dbgsym_2.6-3+deb13u3_ppc64el.deb c81ffe3163f0a1d7c111ead5271a04cb 89456 net optional inetutils-inetd_2.6-3+deb13u3_ppc64el.deb dab5a5ff9c8d40dd8eb66716e2d903f1 194088 debug optional inetutils-ping-dbgsym_2.6-3+deb13u3_ppc64el.deb 4d9cc1a199cdfa2a7a863c5cc56c2a9f 93004 net optional inetutils-ping_2.6-3+deb13u3_ppc64el.deb 45c33682e3071b8aa7d8290b6a7a6280 128900 debug optional inetutils-syslogd-dbgsym_2.6-3+deb13u3_ppc64el.deb e9a9f9b6386f815fd838080da2d100ae 96124 net optional inetutils-syslogd_2.6-3+deb13u3_ppc64el.deb dfd5e0137f613949be0bf310d44d5c05 88352 debug optional inetutils-talk-dbgsym_2.6-3+deb13u3_ppc64el.deb a9eb3907bc92819a2158468e6bd11e43 75356 net optional inetutils-talk_2.6-3+deb13u3_ppc64el.deb b5c279334f1722a5c8452c8105661c08 118348 debug optional inetutils-talkd-dbgsym_2.6-3+deb13u3_ppc64el.deb 596d8682c786cfc0e4c5a84d4a2d2cdb 84184 net optional inetutils-talkd_2.6-3+deb13u3_ppc64el.deb 90f3c810f50e203574a3d20a0b232d19 237512 debug optional inetutils-telnet-dbgsym_2.6-3+deb13u3_ppc64el.deb 4b5c1a8ceec9f7f00c20b5e38bc2022e 135424 net standard inetutils-telnet_2.6-3+deb13u3_ppc64el.deb 9af9bc7781cafbea268eed9405f4271a 189344 debug optional inetutils-telnetd-dbgsym_2.6-3+deb13u3_ppc64el.deb ccfeb46bdc871918af29f51f2ace3f04 116220 net optional inetutils-telnetd_2.6-3+deb13u3_ppc64el.deb 60fa180b67df398db181f22ad6be0dc4 349068 debug optional inetutils-tools-dbgsym_2.6-3+deb13u3_ppc64el.deb b4dbdba3045a663e7a3084236cacc0b9 110020 net optional inetutils-tools_2.6-3+deb13u3_ppc64el.deb 0de5278a86e9e2ca1856f80cd282337a 91264 debug optional inetutils-traceroute-dbgsym_2.6-3+deb13u3_ppc64el.deb dd913438d3f727fbec9c48868cb4b317 73396 net optional inetutils-traceroute_2.6-3+deb13u3_ppc64el.deb e749e4991ea397df9cfb6ed5f3c93c04 13091 net optional inetutils_2.6-3+deb13u3_ppc64el-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEEySUEQfg5pZeb/U372FRWNm40e2YFAmnL3HoACgkQ2FRWNm40 e2balQ//UJJXpGF1QS+nDXFQZroAyh2xt4cd6x5ptv1RwhdVHFShnP50oTl2dzG0 du1D/BdMdnDfgd9sLHg5vZYXbcyrgWhLAm72tcwU9++j+CvIhkJ5rDOCvSRJeYSy 2OEqfMeCGcf+Iu61v8q+3PgM3CEgBvi2BRZ3DTesQHMQCmEI6+pMkyTa84Ygg0jd ch6NfaPVECCf7oId+8unCU8r94Hix55rD1DTTN/55dhsRDNkUpa2gPMHh7NgCSOO GXH06g4/7D6qskgrqj8R+zZU0kDl4WS/sGrlR4NiOKXo8YIE+Yd3ixo0kBOJMsaj +yGt4QCV4fDA4YXUpKyaZlWbn+bvV+plvYD7MqeMW8fmR/ZyWXSS3LFcvwmzqCUV vw5MRFG+VU8WscqLHauPkSou+NdWk8KpUGdCYHlolbLNq/NuuR8iGGqQoHNjA2ci e3Dw2h4FKnkGbHLxgvDusnjpbuZqjrrMdfP1PgwLfKhAU2u74UckeVXDn2jYZFZl 7872sjpvlUPS7niJ2yReKocWtkUxWK3ZpstFD6K7Ux2M1M2mvs38S+40bjgTxsCI l9d9z+E5wLvkrtGcbH9qFp/eJ9+ycPwLxw2Bay3ZRiL9/7n9H9uNN7W9jMvawUlj AkjDdYKVUzqpBhTtepVUyedWpGbZuvv/OlN9gW2mNiSRXUvHb1o= =kphD -----END PGP SIGNATURE-----