Debian unstable release not handled correctly
- Dominant language
- Go
- Stars
- 2.9k
- Forks
- 369
- Avg merge
- 1d 17h
- Merged PRs (30d)
- 149
Description
It appears data on osv.dev indicate that all versions of Debian 12 and 13 package 7zip are vulnerable:
Debian {12-13} / Affected versions / 26.*:
```
26.00+dfsg-1
26.00+dfsg-2
26.00+dfsg-3
26.00+dfsg-4
26.00+dfsg-5
26.00+dfsg1-1
26.00+dfsg1-2
26.00+dfsg1-3
26.01+dfsg-1
26.01+dfsg-2
26.01+dfsg-3
26.02+dfsg-1 <--- BUG
26.02+dfsg
```
Debian's [CVE tracker](https://security-tracker.debian.org/tracker/CVE-2026-14266) states affected versions are:
Bookworm (12) `22.01+really26.01+dfsg-0+deb12u1`
Trixie (13) `25.01+dfsg-1~deb13u2`
and fix is introduced in `26.02+dfsg-1`
Similarly, for package p7zip for Debian 12 data on osv.dev states affected version are:
```
16.02+dfsg-8
16.02+really25.01+dfsg-0+deb12u1
16.02+really26.01+dfsg-0+deb12u1
16.02+transitional.1 <--- BUG
```
While Debian states fixed version is `16.02+transitional.1`
Contributor guide
Research direction
Start by comparing the Debian 12 and 13 7zip records on osv.dev with the linked Debian CVE tracker, then inspect the corresponding p7zip data. Done means the affected and fixed-version ranges agree with Debian's stated versions, including the Debian unstable release handling.
Written by the indexing model from the issue text.
Assessment
- Tech stack
- debian
- Domain
- databases, security
- Issue type
- Bug
- Difficulty
- 3/5
- Estimated time
- 1-2 days
- Activity status
- Quiet
- Clarity
- Mostly clear
- Newbie friendliness
- 48/100