-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 16:44:03 +0200 Source: inetutils Binary: inetutils-ftp inetutils-ftp-dbgsym inetutils-ftpd inetutils-ftpd-dbgsym inetutils-inetd inetutils-inetd-dbgsym inetutils-ping inetutils-ping-dbgsym inetutils-syslogd inetutils-syslogd-dbgsym inetutils-talk inetutils-talk-dbgsym inetutils-talkd inetutils-talkd-dbgsym inetutils-telnet inetutils-telnet-dbgsym inetutils-telnetd inetutils-telnetd-dbgsym inetutils-tools inetutils-tools-dbgsym inetutils-traceroute inetutils-traceroute-dbgsym Architecture: arm64 Version: 2:2.6-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-conova-03) Changed-By: Guillem Jover Description: inetutils-ftp - File Transfer Protocol client inetutils-ftpd - File Transfer Protocol server inetutils-inetd - internet super server inetutils-ping - ICMP echo tool inetutils-syslogd - system logging daemon inetutils-talk - talk to another user inetutils-talkd - remote user communication server inetutils-telnet - telnet client inetutils-telnetd - telnet server inetutils-tools - base networking utilities (experimental package) inetutils-traceroute - trace the IPv4 route to another host Closes: 1130741 1130742 Changes: inetutils (2:2.6-3+deb13u3) trixie-security; urgency=high . * Add patches from upstream: - Ignore all environment options from clients unless the variable was listed in the new --accept-env telnetd option. This mitigates privilege escalation using environment variables. This is the complete fix for CVE-2026-24061, with its own CVE pending. - Fix stack buffer overflow processing SLC suboption triplets. Reported by Adiel Sol, Arad Inbar, Erez Cohen, Nir Somech, Ben Grinberg, Daniel Lubel at DREAM Security Research Team. Fixes CVE-2026-32746. (Closes: #1130742) * Add the hashcode-string1 module from forky/sid gnulib, required by the --accept-env patch. * Adapt netkit-telnet patch to not leak unexported environment variables to telnetd. Reported by Justin Swartz . Fixes CVE-2026-32772. (Closes: #1130741) * Prevent user local privilege escalation using --debug, which was susceptible to symlink attacks, or leaking on-wire credentials to a user that had pre-created the file and kept it open. Fix by switching from /tmp/telnet.debug to /run/telnet/debug., and making the setup error checks fatal. Partially reported by Justin Swartz . * Update local telnetd man page to match new --debug behavior. Checksums-Sha1: d6d9b95f3054efe9785dc465f9e22999f5c6dfa8 163028 inetutils-ftp-dbgsym_2.6-3+deb13u3_arm64.deb 59d8370c3972bd547d02f32302a686064de35e4a 106064 inetutils-ftp_2.6-3+deb13u3_arm64.deb 80b6c6d9a49fa7e5cdc3c92a1d28302ced6e03fb 191400 inetutils-ftpd-dbgsym_2.6-3+deb13u3_arm64.deb 9f194a636a857710c4b737d3ec853deaf3893304 107104 inetutils-ftpd_2.6-3+deb13u3_arm64.deb c6626b416dcf10a19d07c4cb23c3f29a3fe07e02 107092 inetutils-inetd-dbgsym_2.6-3+deb13u3_arm64.deb 86cc9b82a146b73d3267ef7953d95515a301566e 83144 inetutils-inetd_2.6-3+deb13u3_arm64.deb 037b3f6f1ef01389a797a0c45eee3ed99bfe135d 202384 inetutils-ping-dbgsym_2.6-3+deb13u3_arm64.deb 2da8bb78b9ca49c539195a51c10cc5c84ae6dc4e 87376 inetutils-ping_2.6-3+deb13u3_arm64.deb f90fb5127105cc94cca4233c155d25baffffdb13 124648 inetutils-syslogd-dbgsym_2.6-3+deb13u3_arm64.deb 71833fd115b20477911c5d6c89599b46345a14d7 89028 inetutils-syslogd_2.6-3+deb13u3_arm64.deb 05f15eb3295988c80030b49f44e90eee8f23dea4 85936 inetutils-talk-dbgsym_2.6-3+deb13u3_arm64.deb fc75ec08be2685b2c7fdda73c51630273a2decef 70760 inetutils-talk_2.6-3+deb13u3_arm64.deb 31a473f800f37e9b98fb703e42e228f8ec9ce748 113992 inetutils-talkd-dbgsym_2.6-3+deb13u3_arm64.deb 4000262c1d41d23d7d6e23c5ee90048fd12d57f2 77120 inetutils-talkd_2.6-3+deb13u3_arm64.deb 7388b941ef6c2688b1c9338452dff182ce191f10 233220 inetutils-telnet-dbgsym_2.6-3+deb13u3_arm64.deb 69cdfd74e381a17079def1ae7be177f3cb8f446b 125480 inetutils-telnet_2.6-3+deb13u3_arm64.deb 3b3954a13aa366cf6dfd80903cee1a09db68c6a3 183424 inetutils-telnetd-dbgsym_2.6-3+deb13u3_arm64.deb 193b47d521343bf2e72b1aefdb1c5e08cb1ecf14 106380 inetutils-telnetd_2.6-3+deb13u3_arm64.deb a5e1cb8cb49c6027668936e40bcbc69b4d61d792 362628 inetutils-tools-dbgsym_2.6-3+deb13u3_arm64.deb bb65153500ca59ab72a83cac455dfadb56b98427 101104 inetutils-tools_2.6-3+deb13u3_arm64.deb cfc66fc11d0cd19aedbc26e824a2b090294e2c25 88660 inetutils-traceroute-dbgsym_2.6-3+deb13u3_arm64.deb 9f47cebffc2a57214c09c8815499752f45019277 68588 inetutils-traceroute_2.6-3+deb13u3_arm64.deb e6941964bafb74a7339e0347e749ee525cf8562c 12959 inetutils_2.6-3+deb13u3_arm64-buildd.buildinfo Checksums-Sha256: 33ba56bc15c55e1a8e5cae166172dd58ce7cbb3ec92ba460dc97bd21d48ee0a6 163028 inetutils-ftp-dbgsym_2.6-3+deb13u3_arm64.deb 936fd15ab913f4827f16a280e47513784c18c66316aec3c489ae12a86466bcfb 106064 inetutils-ftp_2.6-3+deb13u3_arm64.deb 57989b444f0f6f92b82457a0b505746f326a283d1c297dce84feaf7501dfe746 191400 inetutils-ftpd-dbgsym_2.6-3+deb13u3_arm64.deb ac580ec8fdbc88cecb442b53331941028b733061905b68bc322bfcb43ce50d7d 107104 inetutils-ftpd_2.6-3+deb13u3_arm64.deb aeef57a87a5a5a8061ec0a53d2e2f72b1233ae3a6f7c793f4e1a2429b043c70e 107092 inetutils-inetd-dbgsym_2.6-3+deb13u3_arm64.deb 3fa42380c940ae8d166e598f98b3b6024dbe2b023894e1e3b9d30662585e2f74 83144 inetutils-inetd_2.6-3+deb13u3_arm64.deb e50fb051d4f3c77e54d6c3cf48b9ada2ff8e0ff860a8f991b1cc39a47df1d1c6 202384 inetutils-ping-dbgsym_2.6-3+deb13u3_arm64.deb 9f6542418dcfb0da9da8e78fe62b164c2b0acf86356ba99b6779e307276efe78 87376 inetutils-ping_2.6-3+deb13u3_arm64.deb cd6b51e5ef411f0994fe433a64b9c38a9b3a610c576876bef920a75594b66410 124648 inetutils-syslogd-dbgsym_2.6-3+deb13u3_arm64.deb 315b079760cdbc420bddc02e4b69bc9d54f66a4dea6e2d422fc7d5571e897a8f 89028 inetutils-syslogd_2.6-3+deb13u3_arm64.deb ee02866974fe2b69fdf1852d6dbebc0ee4738af84c253f28c88480b8727549f8 85936 inetutils-talk-dbgsym_2.6-3+deb13u3_arm64.deb da6cf6675c236913bf840093f817cc32606ad759b9bfbdf45c8836015f4a719e 70760 inetutils-talk_2.6-3+deb13u3_arm64.deb eaa88690169369a1450b75137d2352973e1fa9ff945d8ad75162b96c4e74c7eb 113992 inetutils-talkd-dbgsym_2.6-3+deb13u3_arm64.deb ac7f320bd1fd46f6a1b93bcc8e3059594a10664fadfc088e51adcc70e1525e58 77120 inetutils-talkd_2.6-3+deb13u3_arm64.deb 3a59466828a4d04cd5ddb0db850b44e0914c0bda24074e386c69d96c24b9ce44 233220 inetutils-telnet-dbgsym_2.6-3+deb13u3_arm64.deb e5a96398f54b55f1aaed9ff143084580c8e08099046a1f21cd02cfc5bec79af2 125480 inetutils-telnet_2.6-3+deb13u3_arm64.deb 445c6b2498b112dff0b08653c6b2fc832489f9a12df61ed9fb0ba222d8073e71 183424 inetutils-telnetd-dbgsym_2.6-3+deb13u3_arm64.deb b7f538c992cfee0e2002657b338a4d022091bc2251887bc6d02dffb36c2046dd 106380 inetutils-telnetd_2.6-3+deb13u3_arm64.deb 44b51e1976b6a98b07deb62f024089b0b0aca0a200c3b2e2b7426f1c53c92e10 362628 inetutils-tools-dbgsym_2.6-3+deb13u3_arm64.deb 9d09f31a66ae526b6bde8df5e5d615cc01ba3ee07d150ae974c9c39b339fc4de 101104 inetutils-tools_2.6-3+deb13u3_arm64.deb 316a2ce3765990b38131fed7ad90055401680c518f39cf03401f1dd08f2d7f41 88660 inetutils-traceroute-dbgsym_2.6-3+deb13u3_arm64.deb 52507073bc3f6b89edb837947d5eef661096aee6022d950c75b0ec76a6d3ad45 68588 inetutils-traceroute_2.6-3+deb13u3_arm64.deb 15b3f886ff81901094b5644541c3db24f5ca68523e2841e687ef5463c2da1267 12959 inetutils_2.6-3+deb13u3_arm64-buildd.buildinfo Files: fe94f3549ac4dd3014b8465ffb1f4a63 163028 debug optional inetutils-ftp-dbgsym_2.6-3+deb13u3_arm64.deb c7fe860221970f78a9f317f55f4eafbd 106064 net optional inetutils-ftp_2.6-3+deb13u3_arm64.deb a0142c8f1fc9a2b1032f63072f4f032b 191400 debug optional inetutils-ftpd-dbgsym_2.6-3+deb13u3_arm64.deb fbbf06287d137280f6e4591a18313d1e 107104 net optional inetutils-ftpd_2.6-3+deb13u3_arm64.deb 7462703fa0d1235a9e50a6ce2df9e7cf 107092 debug optional inetutils-inetd-dbgsym_2.6-3+deb13u3_arm64.deb 9ee107856dd5b319229ac6255082ea02 83144 net optional inetutils-inetd_2.6-3+deb13u3_arm64.deb f97744a702d56667b4635554aa5b152d 202384 debug optional inetutils-ping-dbgsym_2.6-3+deb13u3_arm64.deb 58d29b657734250faa95f4049bbe78d7 87376 net optional inetutils-ping_2.6-3+deb13u3_arm64.deb 5629efd87e385f649e7a28215cba163a 124648 debug optional inetutils-syslogd-dbgsym_2.6-3+deb13u3_arm64.deb 4fc6c5f6857925f3b21c613126803e9d 89028 net optional inetutils-syslogd_2.6-3+deb13u3_arm64.deb 5414e473b0b2056547d7b262d457c3f8 85936 debug optional inetutils-talk-dbgsym_2.6-3+deb13u3_arm64.deb 741b311e5fff111b4ae47a2a4bab5752 70760 net optional inetutils-talk_2.6-3+deb13u3_arm64.deb 3d385e08c2df3b8e5f2fdd1362165b2b 113992 debug optional inetutils-talkd-dbgsym_2.6-3+deb13u3_arm64.deb cb131844eb7dda2ffb97556b97fe8dd9 77120 net optional inetutils-talkd_2.6-3+deb13u3_arm64.deb 539a174d73644cd3da7d7273499e4b76 233220 debug optional inetutils-telnet-dbgsym_2.6-3+deb13u3_arm64.deb fda360a935e01c253e03fcf705faf7a2 125480 net standard inetutils-telnet_2.6-3+deb13u3_arm64.deb 070c136a18e6993b4896c79e708014a3 183424 debug optional inetutils-telnetd-dbgsym_2.6-3+deb13u3_arm64.deb 0e1fd072d34502fd70154f091b9b62f1 106380 net optional inetutils-telnetd_2.6-3+deb13u3_arm64.deb 07febdffdef7935b8aa6220038c8a6bd 362628 debug optional inetutils-tools-dbgsym_2.6-3+deb13u3_arm64.deb aa5e6a694a745d81217f3cb682d6a34c 101104 net optional inetutils-tools_2.6-3+deb13u3_arm64.deb a342e568f221449456a4f3f56dbb73d2 88660 debug optional inetutils-traceroute-dbgsym_2.6-3+deb13u3_arm64.deb cd504b303d5a8dfd830adcb9f3ec9899 68588 net optional inetutils-traceroute_2.6-3+deb13u3_arm64.deb f41ebe9b210424fb099dee493f479430 12959 net optional inetutils_2.6-3+deb13u3_arm64-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEElFiH1oZRZh1t4FSiXVp1sEH/1mIFAmnL3IEACgkQXVp1sEH/ 1mJDQA/9FpTNry8AD/fP+1M4l+sDQJUVoiMTN3nvndomRtSVWkjJt0MV943vz7Oo c5d6bkB3AH55h4WmcrUTWfoA0qKCGUaE0OWnCnQkFTXxsW/0+TZpQ0X/4LrlZKBp F1XBOxOm5uPH6WdJzJGaO6MH3OBaX2NGKvjQg1MUgHmAYYNaIEFJjAFH3a3j8zqm w4QW9DCmVxpDIWWXZlUvejlBBOgypbQfekSgpIC5wqF6yjF07CUOzPILdcH0cNuD IFKla92BYrkWuNRBSIFSVlNXb118BM8FQJuLZ8pOIqQuU5Mm/iR7YCr5JtQToms3 SQA85h3roaPF53ktmdVPBkBqDDV6uHnHewf0ng+eKhs4RUf3OAzYvqVqRo8QLdx1 h4gyHm/j6ZbT14m/HjvGG6qZtmH/8Tl8n2A6BBQ4GACX6NIWlWC/5ueC/TjtMiiA pu1f7Q6+N60imPAUbO6DRX/rjzwhGk78rqNaqwjlKGDpsV/X4FkZq5OK0ubRUnA/ +v6LBAsOuLba3Z9o/OqygBe4jtq/W/zp5cfUMgfTUWfY1Kr7D4/1loB0nWMAc8ul 6h4JRX9Hk3+3QRGsb2UBfmX9sWwlYD7/S/JSB18vtzWnQftEZy3mlDZiEkjHFXiG IxrZt3Lu7mpLVHTS2hqPWILKDupE8azjrr68fzjl1fW56BUeqNI= =b5Ih -----END PGP SIGNATURE-----