Source: bison
Version: 2:3.8.2+dfsg-1
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>

Hi,

The following vulnerabilities were published for bison.

CVE-2026-56389[0]:
| GNU Bison allows for an execution of an arbitrary program during
| HTML report generation due to improper handling of grammar-defined
| configuration variables. A grammar file can override the executable
| used for the XML‑to‑HTML transformation step via %define
| tool.xsltproc, which is accepted without restriction and passed
| directly to execvp().   When running bison --html on a attacker-
| provided grammar, this behavior allows execution of an arbitrary
| program with the privileges of the Bison process.   Maintainers of
| this project were notified about this vulnerability, and fixed the
| issue in commit 3169c1e7a2c6acc4c59dfcf8b089896d6881925b. However,
| they did not provide vulnerable version range. Version 3.8.2 was
| tested and confirmed as vulnerable, other versions were not tested
| but might also be vulnerable.


CVE-2026-56390[1]:
| GNU Bison improperly handles grammar‑defined output paths. Grammar
| directives such as %output and %header allow specifying file paths,
| which are accepted without restriction and override caller‑supplied
| output options.  When processing attacker-supplied grammar, this
| behavior allows directing generated files to arbitrary writable
| locations on the filesystem, potentially overwriting existing files
| accessible to the Bison process.  Maintainers of this project were
| notified about this vulnerability, and fixed the issue in
| commit 8d101c19d4d9aaedf83a448c925513742d4efcf0. However, they did
| not provide vulnerable version range. Version 3.8.2 was tested and
| confirmed as vulnerable, other versions were not tested but might
| also be vulnerable.


If you fix the vulnerabilities please also make sure to include the
CVE (Common Vulnerabilities & Exposures) ids in your changelog entry.

For further information see:

[0] https://security-tracker.debian.org/tracker/CVE-2026-56389
    https://www.cve.org/CVERecord?id=CVE-2026-56389
[1] https://security-tracker.debian.org/tracker/CVE-2026-56390
    https://www.cve.org/CVERecord?id=CVE-2026-56390

Please adjust the affected versions in the BTS as needed.

Regards,
Salvatore

Reply via email to