-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Mon, 30 Mar 2026 16:44:03 +0200 Source: inetutils Binary: inetutils-ftp inetutils-ftp-dbgsym inetutils-ftpd inetutils-ftpd-dbgsym inetutils-inetd inetutils-inetd-dbgsym inetutils-ping inetutils-ping-dbgsym inetutils-syslogd inetutils-syslogd-dbgsym inetutils-talk inetutils-talk-dbgsym inetutils-talkd inetutils-talkd-dbgsym inetutils-telnet inetutils-telnet-dbgsym inetutils-telnetd inetutils-telnetd-dbgsym inetutils-tools inetutils-tools-dbgsym inetutils-traceroute inetutils-traceroute-dbgsym Architecture: armel Version: 2:2.6-3+deb13u3 Distribution: trixie-security Urgency: high Maintainer: arm Build Daemon (arm-ubc-03) Changed-By: Guillem Jover Description: inetutils-ftp - File Transfer Protocol client inetutils-ftpd - File Transfer Protocol server inetutils-inetd - internet super server inetutils-ping - ICMP echo tool inetutils-syslogd - system logging daemon inetutils-talk - talk to another user inetutils-talkd - remote user communication server inetutils-telnet - telnet client inetutils-telnetd - telnet server inetutils-tools - base networking utilities (experimental package) inetutils-traceroute - trace the IPv4 route to another host Closes: 1130741 1130742 Changes: inetutils (2:2.6-3+deb13u3) trixie-security; urgency=high . * Add patches from upstream: - Ignore all environment options from clients unless the variable was listed in the new --accept-env telnetd option. This mitigates privilege escalation using environment variables. This is the complete fix for CVE-2026-24061, with its own CVE pending. - Fix stack buffer overflow processing SLC suboption triplets. Reported by Adiel Sol, Arad Inbar, Erez Cohen, Nir Somech, Ben Grinberg, Daniel Lubel at DREAM Security Research Team. Fixes CVE-2026-32746. (Closes: #1130742) * Add the hashcode-string1 module from forky/sid gnulib, required by the --accept-env patch. * Adapt netkit-telnet patch to not leak unexported environment variables to telnetd. Reported by Justin Swartz . Fixes CVE-2026-32772. (Closes: #1130741) * Prevent user local privilege escalation using --debug, which was susceptible to symlink attacks, or leaking on-wire credentials to a user that had pre-created the file and kept it open. Fix by switching from /tmp/telnet.debug to /run/telnet/debug., and making the setup error checks fatal. Partially reported by Justin Swartz . * Update local telnetd man page to match new --debug behavior. Checksums-Sha1: df2f2911cd651736d38f2820b9530bd3dc42c9cb 162596 inetutils-ftp-dbgsym_2.6-3+deb13u3_armel.deb f23af13e00b9d66bdd0853443e96d8705cc00b78 104036 inetutils-ftp_2.6-3+deb13u3_armel.deb 902fa01f69000742ac349cd6a8124614a8c0ab62 190568 inetutils-ftpd-dbgsym_2.6-3+deb13u3_armel.deb ef3a265033c6014a422935bc0d3c28de746f0a4b 105932 inetutils-ftpd_2.6-3+deb13u3_armel.deb 81c2c9e9d734031fcf5a6ad9bc5d2eea5bb24389 105676 inetutils-inetd-dbgsym_2.6-3+deb13u3_armel.deb cdc4959e9ff887eb69b68a107650778bf27bbd4b 80052 inetutils-inetd_2.6-3+deb13u3_armel.deb 8fe9713c3f5b70487da3bdfd1bd5d9255ba0d56f 187696 inetutils-ping-dbgsym_2.6-3+deb13u3_armel.deb f50a4828de94a7ca1ac3fa4c393047f161eaa619 84872 inetutils-ping_2.6-3+deb13u3_armel.deb 64b1835e206195a3993e0cdb5383abfc12a2a14b 123496 inetutils-syslogd-dbgsym_2.6-3+deb13u3_armel.deb ca9d6254292ff1c325a0e96777f6a12aa4cae92c 86276 inetutils-syslogd_2.6-3+deb13u3_armel.deb 83841cc3abd5cafc7f86ac4019213977678261f1 85436 inetutils-talk-dbgsym_2.6-3+deb13u3_armel.deb 0b56e453d6c750180aa7d8f4b060e718a5d5a3e0 68804 inetutils-talk_2.6-3+deb13u3_armel.deb 99d5f6ae7b6f0feb03d993ba9df4a922482a5534 112656 inetutils-talkd-dbgsym_2.6-3+deb13u3_armel.deb 8e862dd781c53a06878ded11ce7a006a1d17e08c 74024 inetutils-talkd_2.6-3+deb13u3_armel.deb 3b581e53724a01e51263d2a5dc8b3d6bd2dec792 222172 inetutils-telnet-dbgsym_2.6-3+deb13u3_armel.deb 532ed3c3f3da90e015b4cbe30c02e697045d8bbf 116676 inetutils-telnet_2.6-3+deb13u3_armel.deb bb111db0577d32a00d6660c473119eed49c421a6 182540 inetutils-telnetd-dbgsym_2.6-3+deb13u3_armel.deb 9ff451e7c0c6f9153247d3169afb3d0dfb70bd3c 101756 inetutils-telnetd_2.6-3+deb13u3_armel.deb 71fad7ae0aa5cc40f6b6f259602f3701928e48ba 332472 inetutils-tools-dbgsym_2.6-3+deb13u3_armel.deb f4ec3f566442ecb90efa59bd27126eafbd03e438 92772 inetutils-tools_2.6-3+deb13u3_armel.deb f859be5d4b86cb993cdcc4bc72c0e8a38e9a0196 88000 inetutils-traceroute-dbgsym_2.6-3+deb13u3_armel.deb d18324f1d5e5cb0515e846e867d3fa4b7f107759 67720 inetutils-traceroute_2.6-3+deb13u3_armel.deb dd83d4ae1eb9ded2182db86b8255865d3dcd6b14 12821 inetutils_2.6-3+deb13u3_armel-buildd.buildinfo Checksums-Sha256: 6e47bc355d0236a62cee4b0729eb2f086f59d4e7a2537106682f77bf42399024 162596 inetutils-ftp-dbgsym_2.6-3+deb13u3_armel.deb ce9f4f33122537f82e426ab1550dc182d761b9ff40141ddb657323f188da3cbd 104036 inetutils-ftp_2.6-3+deb13u3_armel.deb 6d86898e4829da85969052318f50721689c5bdbddcd980f0e6522f2deb9dd852 190568 inetutils-ftpd-dbgsym_2.6-3+deb13u3_armel.deb 50dbaacead7cf650e396386b12a560836fac3a987bbff877395c7f43862889f3 105932 inetutils-ftpd_2.6-3+deb13u3_armel.deb ee6f447628c3106ff659af45f4afd4cfa182f9ca65a706fbaca86c4f556bffb8 105676 inetutils-inetd-dbgsym_2.6-3+deb13u3_armel.deb fc41d120fd8ffda55f5c83ce3587f06a348b124c7ac27d2ae90ea21d5b44ad75 80052 inetutils-inetd_2.6-3+deb13u3_armel.deb c6cd9f06d48d4674bab63b61b54b25abeff7fb024d73f33f61f5a0993c89c1be 187696 inetutils-ping-dbgsym_2.6-3+deb13u3_armel.deb b2182af82a175201c65fcdf0ea167dff63183fa1ca0d8c3eedf6dbb01de6515f 84872 inetutils-ping_2.6-3+deb13u3_armel.deb d11f316381d6e6f4ed451dbbe6d6c6d77afdf10e63824a244c8e76a3a51e7d04 123496 inetutils-syslogd-dbgsym_2.6-3+deb13u3_armel.deb 6062bc3678c3db5fce74d974e3dfd0e53b4ba86de0b133633de43ff923874784 86276 inetutils-syslogd_2.6-3+deb13u3_armel.deb a3f5a43030a9e5c7a8c03bdafbac21a3b3d79d676e70a61388c80020f86ae93a 85436 inetutils-talk-dbgsym_2.6-3+deb13u3_armel.deb a7978a0fdcfecd5b2e3b8fd31d0a24ab6dc77176afdbb93931d53caf756c5ecd 68804 inetutils-talk_2.6-3+deb13u3_armel.deb 704ebc7b82052c90494cf50bac8afcedf01c86da56652ccced1ce468f812a070 112656 inetutils-talkd-dbgsym_2.6-3+deb13u3_armel.deb 1b97fde098d16082ef00240e44c267f76b11564cf445a1903524ae1d7bd51b56 74024 inetutils-talkd_2.6-3+deb13u3_armel.deb 0be678e78b227eba654bfabc8389007445d0605d8813fdd97ea497876f9a3e4c 222172 inetutils-telnet-dbgsym_2.6-3+deb13u3_armel.deb 00a19824c9f88be4532ab1fd438babfeef0e5e303d5578497bdcae3f81ec42f1 116676 inetutils-telnet_2.6-3+deb13u3_armel.deb c3e57af1a66daa759d0dace14d7075329cbe3a7505f4613255f0fab5ac960cfe 182540 inetutils-telnetd-dbgsym_2.6-3+deb13u3_armel.deb 0b7285226ed0a0cf8e82a903f3e1317e7e1ea6209bb81988ba1f5819eecb2005 101756 inetutils-telnetd_2.6-3+deb13u3_armel.deb b3cb1fab0f0cfa0990151fb9981914ab0867ddd8b69b991cb05dc110cc056218 332472 inetutils-tools-dbgsym_2.6-3+deb13u3_armel.deb e8d162cd5b22024ba9f79daf3f0ec07fffdded55ee1b9f9e67fae53e3aa65fdf 92772 inetutils-tools_2.6-3+deb13u3_armel.deb 21f96613e9d0e67fbbc4111d6831e89c524d49be66ec91af2fdc25faf6ebe551 88000 inetutils-traceroute-dbgsym_2.6-3+deb13u3_armel.deb b240ca5ea72c87e8610b8f9a02e8594b65a800239703fc4dd4b03bf2430d9ba2 67720 inetutils-traceroute_2.6-3+deb13u3_armel.deb c22ce547a507d4e51a36384e1a50b6e97d7a9c093f6effa8e0ac82ac5369a263 12821 inetutils_2.6-3+deb13u3_armel-buildd.buildinfo Files: bdb74808daa9d691f454a27d22356915 162596 debug optional inetutils-ftp-dbgsym_2.6-3+deb13u3_armel.deb eea53cbbcb0ee7518f0a27967bfce1c8 104036 net optional inetutils-ftp_2.6-3+deb13u3_armel.deb bf732f79e35f912ccbebed5ed8fdf5da 190568 debug optional inetutils-ftpd-dbgsym_2.6-3+deb13u3_armel.deb 5f78b7f2eac2b7d10740fd424f2627c4 105932 net optional inetutils-ftpd_2.6-3+deb13u3_armel.deb 64a4fddef9db4eb118ea66960bb0f4ab 105676 debug optional inetutils-inetd-dbgsym_2.6-3+deb13u3_armel.deb a6e96d63284e5f9f866dd0814d40f272 80052 net optional inetutils-inetd_2.6-3+deb13u3_armel.deb 2eb5a33c2a7d33cfafdb68eb080df88e 187696 debug optional inetutils-ping-dbgsym_2.6-3+deb13u3_armel.deb 24733efb724a684e9632f39d8ec11f23 84872 net optional inetutils-ping_2.6-3+deb13u3_armel.deb f5aa6f0b8f9c1d9d33308bcd8c4fd4e4 123496 debug optional inetutils-syslogd-dbgsym_2.6-3+deb13u3_armel.deb 5c27845d68a364c63d5ff2504be935ca 86276 net optional inetutils-syslogd_2.6-3+deb13u3_armel.deb 37e729dbbed34ddd378993fd2eb7038a 85436 debug optional inetutils-talk-dbgsym_2.6-3+deb13u3_armel.deb b3a4db407730acd1dadd3018bce342d4 68804 net optional inetutils-talk_2.6-3+deb13u3_armel.deb d7e2658cf01887955db8a832f858fc1a 112656 debug optional inetutils-talkd-dbgsym_2.6-3+deb13u3_armel.deb 9856ea9f55d8be9d3217622803e170b1 74024 net optional inetutils-talkd_2.6-3+deb13u3_armel.deb 51a26497d2ad516e789754977f6cb03f 222172 debug optional inetutils-telnet-dbgsym_2.6-3+deb13u3_armel.deb c6abdae8938f96e23754a47377e9a6a2 116676 net standard inetutils-telnet_2.6-3+deb13u3_armel.deb 82fca6ea838382fc28966d809a1ec283 182540 debug optional inetutils-telnetd-dbgsym_2.6-3+deb13u3_armel.deb 6581899d2579ee92f7759f300557dcac 101756 net optional inetutils-telnetd_2.6-3+deb13u3_armel.deb e55882e05dd7597c006dc35fcc4f94e6 332472 debug optional inetutils-tools-dbgsym_2.6-3+deb13u3_armel.deb 86c0da5ebb79c74325b82f17e74b447e 92772 net optional inetutils-tools_2.6-3+deb13u3_armel.deb 438e5e8de10269f77237f0a404c264a8 88000 debug optional inetutils-traceroute-dbgsym_2.6-3+deb13u3_armel.deb b37f52c0c3049f961dc099833a1be9b7 67720 net optional inetutils-traceroute_2.6-3+deb13u3_armel.deb c48b835325c3e91d8a92635b1ac6a5e3 12821 net optional inetutils_2.6-3+deb13u3_armel-buildd.buildinfo -----BEGIN PGP SIGNATURE----- iQIzBAEBCgAdFiEE2kd8oHy+LXk/nybqvzDqKQSGl8UFAmnL3X8ACgkQvzDqKQSG l8XogQ/+KbBKFrwkvlGRWBpwbmbImu537qEKUhtGLu4JsQUqbUIUkyrSd0RtIMHI 2/wMEzHFzi2HzwJ7w7chkLj2ml7P5QHSEVmZdC3r5I8fTOYh5tCRE3whDexT+XBE kbiaAOfp0y6+fjLxpoIymRh8gV3M9cIxM6hsTXfC3ixOANN8L9QcSA5OhbDqnLm9 fyri8MYoOnKhKtLts+UAjyjCaXx9ykXcGb5F9z2zYQZJHUI1o4Ur+vRlZhHqh9qX 35EeZ/lxGVA44BIKQhdoQ/sis/lljUzjHYQYkJh6JFM2IBvCQTzWCeUhREyRD0Ik LT51g4Lyw8aL17xbfcrYTYHdUluHkvtfxRYmB9huleB2O2hV08C5jW7gDv6tTM0R uqUyC1fo3yrYcgA/Bjx/aKp12OFKry7CxbKhu6BH7mdTAXsHRwLKnodJFNEjtl3M YexZ8607SZds7K0dvRJl11Ev1oASkeJEuGanMdCJPrxZDYrGCsjjH93q0SNk+iFj jlN+yv5ieG0acfsX0GDr/q9eX3G5BqL7ySOSZ/AKGmVpOHJGBRr2PmE722iBabt6 3EVNwudzFhfvUEkNAbhV/Wy47L2SjvB+bnXn7aQJHTRxBpcZp4Vav3ALc7sAjd6d X/gKRiqGIl6vE/gM5MyXfyGN6C53zWJEPKE1pDQH/vx/Per8kAA= =fVh2 -----END PGP SIGNATURE-----