Here is my monthly update covering what I have been doing in the free software world during September 2026 (previous month):
Debian LTS
This month I have worked 30 hours on Debian Long Term Support (LTS) and on its sister Extended LTS (ELTS) project.
-
Issued both DLA 4794-1 and ELA-1831-1 for the Redis key/value database to fix two different CVEs. Specifically:
-
CVE-2026-81934: Prevent a use-after-free vulnerability in the handling of pending TLS data. A remote, unauthenticated attacker may have been able to execute arbitrary commands with the privileges of the Redis server. -
CVE-2026-92925: Prevent an out-of-bounds vulnerability in the handling of cluster ping extensions. This could have allowed a remote attacker to craft a malicious packet, leading to an out-of-bounds read when the packet's payload was processed.
-
-
Issued DLA 4802-1 and ELA-1835-1 for the Django web development framework in order to address multiple vulnerabilities:
-
CVE-2026-48587: Potential exposure of private data via whitespace padding in theVaryheader.UpdateCacheMiddlewareincorrectly cached responses whoseVaryheader values contained leading or trailing whitespace. Becausehas_vary_headerfailed to strip that whitespace, a response with a "Vary: *" header (note the trailing space) was not recognized as containing the wildcard, causing it to be stored and potentially served from the cache when it should not have been. (stretch and buster only) -
CVE-2026-48588:UpdateCacheMiddlewareand the@cache_pagedecorator cached responses that vary on cookies when the incoming request carried unrelated cookies which allowed remote attackers to read private data from the shared cache. -
CVE-2026-53877:django.contrib.gis.gdal.GDALRasterover-read its in-memory buffer when constructed from a bytes object, which could disclose adjacent memory or cause service degradation via a potential segmentation fault when thevsi_bufferproperty is accessed. (bullseye only)
-
-
Frontdesk duties, responding to user/developer questions, reviewing others' packages, participating in mailing list discussions, etc.
-
Investigated and triaged
redis(CVE-2026-81934andCVE-2026-92925). -
Finally, I uploaded both
redisversion5:8.0.6-3andpython-djangoversion3:6.1.1-1to Debian unstable.
You can find out more about the Debian LTS project via the following video:
