-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 16:44:03 +0200 Source: inetutils Binary: inetutils-ftp inetutils-ftp-dbgsym inetutils-ftpd inetutils-ftpd-dbgsym inetutils-inetd inetutils-inetd-dbgsym inetutils-ping inetutils-ping-dbgsym inetutils-syslogd inetutils-syslogd-dbgsym inetutils-talk inetutils-talk-dbgsym inetutils-talkd inetutils-talkd-dbgsym inetutils-telnet inetutils-telnet-dbgsym inetutils-telnetd inetutils-telnetd-dbgsym inetutils-tools inetutils-tools-dbgsym inetutils-traceroute inetutils-traceroute-dbgsym Architecture: s390x Version: 2:2.6-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: s390x Build Daemon (zandonai) Changed-By: Guillem Jover Description: inetutils-ftp - File Transfer Protocol client inetutils-ftpd - File Transfer Protocol server inetutils-inetd - internet super server inetutils-ping - ICMP echo tool inetutils-syslogd - system logging daemon inetutils-talk - talk to another user inetutils-talkd - remote user communication server inetutils-telnet - telnet client inetutils-telnetd - telnet server inetutils-tools - base networking utilities (experimental package) inetutils-traceroute - trace the IPv4 route to another host Closes: 1130741 1130742 Changes: inetutils (2:2.6-3+deb13u3) trixie-security; urgency=high . * Add patches from upstream: - Ignore all environment options from clients unless the variable was listed in the new --accept-env telnetd option. This mitigates privilege escalation using environment variables. This is the complete fix for CVE-2026-24061, with its own CVE pending. - Fix stack buffer overflow processing SLC suboption triplets. Reported by Adiel Sol, Arad Inbar, Erez Cohen, Nir Somech, Ben Grinberg, Daniel Lubel at DREAM Security Research Team. Fixes CVE-2026-32746. (Closes: #1130742) * Add the hashcode-string1 module from forky/sid gnulib, required by the --accept-env patch. * Adapt netkit-telnet patch to not leak unexported environment variables to telnetd. Reported by Justin Swartz . Fixes CVE-2026-32772. (Closes: #1130741) * Prevent user local privilege escalation using --debug, which was susceptible to symlink attacks, or leaking on-wire credentials to a user that had pre-created the file and kept it open. Fix by switching from /tmp/telnet.debug to /run/telnet/debug., and making the setup error checks fatal. Partially reported by Justin Swartz . * Update local telnetd man page to match new --debug behavior. Checksums-Sha1: a47775bf8ba6af9575f4abd9f8eeb22b9a474092 162980 inetutils-ftp-dbgsym_2.6-3+deb13u3_s390x.deb 3712e0d0f02bc59d3c3fe5dad61cae2f02023e9b 110924 inetutils-ftp_2.6-3+deb13u3_s390x.deb acb0eddb207d0db41da9fb0bfaa69abfe2618f7f 194828 inetutils-ftpd-dbgsym_2.6-3+deb13u3_s390x.deb 11c16a6a2dcbb711d37de4746380e2e0ac959abb 112772 inetutils-ftpd_2.6-3+deb13u3_s390x.deb 0d095246a48f5022017cfabfce6e3736cef647da 107736 inetutils-inetd-dbgsym_2.6-3+deb13u3_s390x.deb be6bf5a8c32a793f524e9d80913b3d9c08a9f512 85644 inetutils-inetd_2.6-3+deb13u3_s390x.deb ac5306e7cf81d40d4253036e2827f5ad1995879c 190752 inetutils-ping-dbgsym_2.6-3+deb13u3_s390x.deb 675803c68121ddeab07b5d21fd2c305d6803b735 90284 inetutils-ping_2.6-3+deb13u3_s390x.deb 9dd160b1753271eee76b4a7cdd532c2378eeef8d 126484 inetutils-syslogd-dbgsym_2.6-3+deb13u3_s390x.deb 1a3a8d3873885f224f1fec4815de317665dca3d9 92052 inetutils-syslogd_2.6-3+deb13u3_s390x.deb 880fabeb212a1fc9c74963f1617eef620051fa51 86368 inetutils-talk-dbgsym_2.6-3+deb13u3_s390x.deb 0edc76d88394baa85eb87462576fa655605779a5 73048 inetutils-talk_2.6-3+deb13u3_s390x.deb f58e9728ca5d34236fbe7093e36c3d0db5bf115e 115344 inetutils-talkd-dbgsym_2.6-3+deb13u3_s390x.deb a0ce3c4bd9feaffbc703a6faff3db1e7ec4710de 79980 inetutils-talkd_2.6-3+deb13u3_s390x.deb 4bcb0eef780029d05c6f79b762b94972fc2606e1 235948 inetutils-telnet-dbgsym_2.6-3+deb13u3_s390x.deb 4ae1017b1a2d39e4e4f43758ddec5ce5b1cd52ce 131420 inetutils-telnet_2.6-3+deb13u3_s390x.deb 4fcc33694f52b26dccd8ad5ea0cdf2042849d42a 186068 inetutils-telnetd-dbgsym_2.6-3+deb13u3_s390x.deb f8903eb1ad2191b72090944c91f49dc7824525a9 110904 inetutils-telnetd_2.6-3+deb13u3_s390x.deb 9e2f97646d9b5b4e4d453ae131b115f347221415 342336 inetutils-tools-dbgsym_2.6-3+deb13u3_s390x.deb b01c9d3ade34996b2cc35740572c36fb2107c08b 103408 inetutils-tools_2.6-3+deb13u3_s390x.deb ed516f80f90a5405984ee4cd89728c148e478ccf 89432 inetutils-traceroute-dbgsym_2.6-3+deb13u3_s390x.deb c21fbaa7e3993dc664e6201f6db350422887ca06 71176 inetutils-traceroute_2.6-3+deb13u3_s390x.deb 6dfe299acc7887dd701e2ae5f712b4b31acabb19 12834 inetutils_2.6-3+deb13u3_s390x-buildd.buildinfo Checksums-Sha256: 0606cd892dc1a5c1405ce8ce02979e11e7e30651675efb285b9e70e5e646ab9b 162980 inetutils-ftp-dbgsym_2.6-3+deb13u3_s390x.deb 2e4bbabfd5c42368f3a8b5b7f9f0df290e021a94f239899ba052892aa489a99e 110924 inetutils-ftp_2.6-3+deb13u3_s390x.deb df6bbcf110e8cd7be9a6ef084367e829da6e6b105726bbf6964212a9a4890283 194828 inetutils-ftpd-dbgsym_2.6-3+deb13u3_s390x.deb d05d1435ae4005c9e65b0e8e748deefe9953d861a0336b48dc5d2bd7e627efae 112772 inetutils-ftpd_2.6-3+deb13u3_s390x.deb 55e590fdb53386bf3d97ef734bce3f62344725e37757e96c005ebbfb9bdbd70b 107736 inetutils-inetd-dbgsym_2.6-3+deb13u3_s390x.deb b76ef5125828083a3f602234a07c604d51d2babcffaca8ec65ab54cb016bbbfa 85644 inetutils-inetd_2.6-3+deb13u3_s390x.deb b03c8b99adae84a7aae336306792244637ea270719e91ab9b6ae4c4ab21960b1 190752 inetutils-ping-dbgsym_2.6-3+deb13u3_s390x.deb 058fc0948db564ac1e1ce5f10118d1a7d2ded26acef75f7ec6b07788e2fd208b 90284 inetutils-ping_2.6-3+deb13u3_s390x.deb 59f72fac7cf1e629e5d66f29941ba98407ad5528cd8364da796e694afed7b44c 126484 inetutils-syslogd-dbgsym_2.6-3+deb13u3_s390x.deb baf26559bb9aa51bd0d22b08ca9dfd795909293cc6d1646b05c0224fc1e4aea3 92052 inetutils-syslogd_2.6-3+deb13u3_s390x.deb 375bffcf8aa34a15a112c2ea96e3ec0d62e7c336f7dfba03b28421c383bbb15b 86368 inetutils-talk-dbgsym_2.6-3+deb13u3_s390x.deb 57563c86dc76fc7bcda4757f43190812eeec4e601189748f4ae19da272d9c461 73048 inetutils-talk_2.6-3+deb13u3_s390x.deb ad80b499bf372d5d029681f0bb7218ae99734efadaf24c25ee7325baffba1539 115344 inetutils-talkd-dbgsym_2.6-3+deb13u3_s390x.deb f92048bd1d80ce4a518634659fe8dc45161ba30314ee79ac91003a9c9bdccec8 79980 inetutils-talkd_2.6-3+deb13u3_s390x.deb 5d801d775959aee6e6be625706334806d271f090996788b95c999d38c03301c6 235948 inetutils-telnet-dbgsym_2.6-3+deb13u3_s390x.deb 0aa38db063bee4551d5397b49267c9b6dce9f5bf675115834c992c76026165b1 131420 inetutils-telnet_2.6-3+deb13u3_s390x.deb fb53bfa914c640f44d40745817830d4aefd8cc193d5308665d76a12a24853ea2 186068 inetutils-telnetd-dbgsym_2.6-3+deb13u3_s390x.deb d30e8add985da87048dd7e89b1485072bf9152e695c7719baa9a30e1213e01ad 110904 inetutils-telnetd_2.6-3+deb13u3_s390x.deb 55b5f5abbb1307d9820eacf88fad3be499d4dcfffcfa9cf261b5e47759a0fa6a 342336 inetutils-tools-dbgsym_2.6-3+deb13u3_s390x.deb 939f11032bab4264310e10553d86e1001eb8475648894bed62be0d4e8c616c45 103408 inetutils-tools_2.6-3+deb13u3_s390x.deb 9e9561534e1b4508ca9dfc941649cd52a2d4130ddcf3a6cdbaa68ada7ad8a632 89432 inetutils-traceroute-dbgsym_2.6-3+deb13u3_s390x.deb d02f2298e0afcdb568bea19e1ff5c4d881923ccd32f30f316710bfdfafc92cf1 71176 inetutils-traceroute_2.6-3+deb13u3_s390x.deb a3a620aee110da21b689be170a70eae93b546d849ffbbdc9238233c8ea3bb63c 12834 inetutils_2.6-3+deb13u3_s390x-buildd.buildinfo Files: 0271a35ddab8e7dd167657826c40de0a 162980 debug optional inetutils-ftp-dbgsym_2.6-3+deb13u3_s390x.deb b2a6b10252ffb766637b6e4512983da4 110924 net optional inetutils-ftp_2.6-3+deb13u3_s390x.deb 2d0060c28cc9cbbff3a64b499bd10d34 194828 debug optional inetutils-ftpd-dbgsym_2.6-3+deb13u3_s390x.deb fa66f5f2ba1b6f00c8de55509294e01c 112772 net optional inetutils-ftpd_2.6-3+deb13u3_s390x.deb 125e22db14ffd4c827a3e9aa3266c8ae 107736 debug optional inetutils-inetd-dbgsym_2.6-3+deb13u3_s390x.deb ac4dc9170aafb3ca52424f3fb742726d 85644 net optional inetutils-inetd_2.6-3+deb13u3_s390x.deb 5565f6d00115ce40856c62d1f64c937d 190752 debug optional inetutils-ping-dbgsym_2.6-3+deb13u3_s390x.deb 30ffb971981246d5a031e0716969fef9 90284 net optional inetutils-ping_2.6-3+deb13u3_s390x.deb f9b62ae582da9a9aa8ec390bb7c33ef8 126484 debug optional inetutils-syslogd-dbgsym_2.6-3+deb13u3_s390x.deb e67d0fead60c66736356c7bad98c28b7 92052 net optional inetutils-syslogd_2.6-3+deb13u3_s390x.deb 8da75e1be1d1993cd584cd187adeb494 86368 debug optional inetutils-talk-dbgsym_2.6-3+deb13u3_s390x.deb f1f421495ab81e6ade9d193810a1e319 73048 net optional inetutils-talk_2.6-3+deb13u3_s390x.deb a25bc43c538200a7e0fdd4c32b46a1ff 115344 debug optional inetutils-talkd-dbgsym_2.6-3+deb13u3_s390x.deb d9bcc4634d4edea3655ae4748862a74c 79980 net optional inetutils-talkd_2.6-3+deb13u3_s390x.deb 38eaabdb36f4d7ceac04dd7abd761a70 235948 debug optional inetutils-telnet-dbgsym_2.6-3+deb13u3_s390x.deb 09ed9ba374664d5dcff3fa5ad6330956 131420 net standard inetutils-telnet_2.6-3+deb13u3_s390x.deb be2437fe7c4b7597ec7f00e6998464dc 186068 debug optional inetutils-telnetd-dbgsym_2.6-3+deb13u3_s390x.deb 094c5bd375fe9e9c4bfb08ee908b2912 110904 net optional inetutils-telnetd_2.6-3+deb13u3_s390x.deb 84bff3dddbf01850be414b2639b0129e 342336 debug optional inetutils-tools-dbgsym_2.6-3+deb13u3_s390x.deb b045ad5ed8d9cdda80ed1a2716a4c016 103408 net optional inetutils-tools_2.6-3+deb13u3_s390x.deb 08486601ed5aafa91f57cbf17498acd9 89432 debug optional inetutils-traceroute-dbgsym_2.6-3+deb13u3_s390x.deb dfc8d9cda6ebb94f9d1f7467a0e71007 71176 net optional inetutils-traceroute_2.6-3+deb13u3_s390x.deb 9237c8a42b8f005577463f8c76617bd5 12834 net optional inetutils_2.6-3+deb13u3_s390x-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEENly2ANlpa4eeqnluvVOPI7pYNpgFAmnL26cACgkQvVOPI7pY NpgpnxAAoyiFrtUskH7QY4rwcu2YQcqkaC+k7nbaSJDSbsqjWhDWz7owmTXQ1rXh FMcRvvPv7GObakM3+hjUN1xQMqu/6VwcMqja6suhT1JBatUm13u/POQOqRgDBRFO YrPnQAYh3Z9oh8rzmZQzKymVO5RIj46ohvYoPPrdWK1bPPE9tFJtG/WuqryI3ozw EdBIRGFvpCqHyZrbQNH4Uyn+v+qH3k8RM7buneYk9GiPEqsmdVLNhkMz/gaMyG0R 7Z/pZie+ZMIsja4oZj6B+xQNDa9SI0CFS9ATdUJEMhA8DgZMhQiJFaAXq5a4Xe4a n51o3KMMkXgAcDDJeyIgT0LGklXhkQ3wEwi1cjm1e7U5j5ByNpvOF9Tktpz0cq/m GKMXFCyDctr+oE7vcRaXRk6qWqodyR6pN5jLtXDvurLVjO+f9EhyrtItH1J5DZU9 3DGi/pFY0z+gXtn4Eew4zpZtAhazbv20qHbtThQ7yn92klVYHMQgfM0ekx6XnBGo /7bNt/2QYBtwke50OvmsZ6MBdB6JA0Faz8RAl15pL1nC9yJxR1ZbEO4M1ho5lIKe Z21EPVhcpUwKHAgB+bw1XJ6InyqRTfvIU7iDk04eddPV4o0Ld9s4X6wpvgGDzOzS scF4dhJyd4QAr5/mr6Kejqpcg6Y9mRpYgYe7vVDEKUV+w7uonOg= =KmIF -----END PGP SIGNATURE-----