google / google/osv.dev

Debian unstable release not handled correctly

Open
#5,754 2 comments 0 reactions 0 assignees View on GitHub
fix-it 🔨 vulnfeeds
Dominant language
Go
Stars
2.9k
Forks
369
Avg merge
1d 17h
Merged PRs (30d)
149

Description

It appears data on osv.dev indicate that all versions of Debian 12 and 13 package 7zip are vulnerable:
Debian {12-13} / Affected versions / 26.*:
```
26.00+dfsg-1
26.00+dfsg-2
26.00+dfsg-3
26.00+dfsg-4
26.00+dfsg-5
26.00+dfsg1-1
26.00+dfsg1-2
26.00+dfsg1-3
26.01+dfsg-1
26.01+dfsg-2
26.01+dfsg-3
26.02+dfsg-1 <--- BUG
26.02+dfsg
```
Debian's [CVE tracker](https://security-tracker.debian.org/tracker/CVE-2026-14266) states affected versions are:

Bookworm (12) `22.01+really26.01+dfsg-0+deb12u1`
Trixie (13) `25.01+dfsg-1~deb13u2`
and fix is introduced in `26.02+dfsg-1`

Similarly, for package p7zip for Debian 12 data on osv.dev states affected version are:
```
16.02+dfsg-8
16.02+really25.01+dfsg-0+deb12u1
16.02+really26.01+dfsg-0+deb12u1
16.02+transitional.1 <--- BUG
```
While Debian states fixed version is `16.02+transitional.1`

Contributor guide

Open the contributing guide

Research direction

Start by comparing the Debian 12 and 13 7zip records on osv.dev with the linked Debian CVE tracker, then inspect the corresponding p7zip data. Done means the affected and fixed-version ranges agree with Debian's stated versions, including the Debian unstable release handling.

Written by the indexing model from the issue text.

Assessment

Tech stack
debian
Domain
databases, security
Issue type
Bug
Difficulty
3/5
Estimated time
1-2 days
Activity status
Quiet
Clarity
Mostly clear
Newbie friendliness
48/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.