Your message dated Sun, 13 Sep 2026 03:33:46 +0000
with message-id <[email protected]>
and subject line Bug#1139180: fixed in logback 1:1.6.3-1
has caused the Debian Bug report #1139180,
regarding logback: CVE-2026-10532
to be marked as done.
This means that you claim that the problem has been dealt with.
If this is not the case it is now your responsibility to reopen the
Bug report if necessary, and/or fix the problem forthwith.
(NB: If you are a system administrator and have no idea what this
message is talking about, this may indicate a serious mail system
misconfiguration somewhere. Please contact [email protected]
immediately.)
--
1139180: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1139180
Debian Bug Tracking System
Contact [email protected] with problems
--- Begin Message ---
Source: logback
Version: 1:1.2.11-3
Severity: important
Tags: security upstream
X-Debbugs-Cc: [email protected], Debian Security Team <[email protected]>
Hi,
The following vulnerability was published for logback.
CVE-2026-10532[0]:
| Deserialization of untrusted data vulnerability in QOS.CH Sarl
| logback logback-core (HardenedObjectInputStream (logback-core)
| modules) allows Object Injection, albeit heavily restricted. More
| precisely, an attacker able to influence serialized data sent to
| SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy
| objects. Although deserialization is heavily restricted by
| HardenedObjectInputStream and no practical way to achieve remote
| code execution or significant privilege escalation has been
| identified, this issue constitutes a bypass of the intended
| security restrictions. This issue affects logback: through 1.5.33
| inclusive.
If you fix the vulnerability please also make sure to include the
CVE (Common Vulnerabilities & Exposures) id in your changelog entry.
For further information see:
[0] https://security-tracker.debian.org/tracker/CVE-2026-10532
https://www.cve.org/CVERecord?id=CVE-2026-10532
[1] https://logback.qos.ch/news.html#1.5.34
Regards,
Salvatore
--- End Message ---
--- Begin Message ---
Source: logback
Source-Version: 1:1.6.3-1
Done: Jérôme Charaoui <[email protected]>
We believe that the bug you reported is fixed in the latest version of
logback, which is due to be installed in the Debian FTP archive.
A summary of the changes between this version and the previous one is
attached.
Thank you for reporting the bug, which will now be closed. If you
have further comments please address them to [email protected],
and the maintainer will reopen the bug report if appropriate.
Debian distribution maintenance software
pp.
Jérôme Charaoui <[email protected]> (supplier of updated logback package)
(This message was generated automatically at their request; if you
believe that there is a problem with it please contact the archive
administrators by mailing [email protected])
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA512
Format: 1.8
Date: Sat, 12 Sep 2026 21:01:00 -0400
Source: logback
Architecture: source
Version: 1:1.6.3-1
Distribution: unstable
Urgency: medium
Maintainer: Debian Java Maintainers
<[email protected]>
Changed-By: Jérôme Charaoui <[email protected]>
Closes: 1091319 1091320 1126748 1138632 1139180 1140922 1146719
Changes:
logback (1:1.6.3-1) unstable; urgency=medium
.
* Team upload.
* New upstream version 1.6.3, fixes CVE-2026-19880, CVE-2026-13006,
CVE-2026-10532, CVE-2026-9828, CVE-2026-1225, CVE-2025-11226,
CVE-2026-1225, CVE-2024-12801, CVE-2024-12798 (Closes: #1146719, #1140922,
#1139180, #1138632, #1126748, #1091320, #1091319)
- The logback-access module is no longer part of the upstream project, and
will instead available via the new logback-access source package, see ITP
#1146286.
* update poms
* refresh maven rules
* drop obsolete lintian overrides
* d/control: build with headless jdk
* d/control: update build dependencies
* d/control: add liblogback-access-java to Suggests
* d/copyright: drop obsolete Files-Excluded stanza
* d/copyright: refresh upstream copyright per LICENSE.txt
* d/copyright: upstream switch to EPL-2.0
* d/NEWS: add entry about logback-access split
* d/patches: drop obsolete patches
* d/patches: new patch to use older jansi package
* d/upstream: add metadata
* d/watch: update to v5 format
* Remove redundant Priority: optional from source stanza.
* Removed Rules-Requires-Root
* Update standards version to 4.7.4, no changes needed.
Checksums-Sha1:
3fcdbfe728bd4b854e424cc8af739b5774b81570 1501 logback_1.6.3-1.dsc
a33cdcd844ad78821a0fe2a9d0b7ae842e3aeb5e 581848 logback_1.6.3.orig.tar.xz
ef7c277792396a74709751c119ee002b7dda1f63 11664 logback_1.6.3-1.debian.tar.xz
a81c70cc5c219903aed85221e95e2db959029903 10967 logback_1.6.3-1_amd64.buildinfo
Checksums-Sha256:
62c2dd5927e15e8531300cdd24f592192457d9d22d285ecdc27685efaa401796 1501
logback_1.6.3-1.dsc
9c971ebb0dd62936a671677868dc1845cd4a1596f360fcf08732886941eec1db 581848
logback_1.6.3.orig.tar.xz
7907eccc8216dcfff25dcdf97dd8943cc7f364f2b69daa4c0d9444a2c48bac22 11664
logback_1.6.3-1.debian.tar.xz
dd182d59f783b2aba5821265ba752504fbc89ab7af14d696089f95882507a335 10967
logback_1.6.3-1_amd64.buildinfo
Files:
f3a509ced2a453ac51e8c2f3f5e972b1 1501 java optional logback_1.6.3-1.dsc
945ffe907d4a89388ddf02875c54ca68 581848 java optional logback_1.6.3.orig.tar.xz
e9bef2aee264173c75036c5275081a8e 11664 java optional
logback_1.6.3-1.debian.tar.xz
ece5d76203c866ebb8c5a733785a8790 10967 java optional
logback_1.6.3-1_amd64.buildinfo
-----BEGIN PGP SIGNATURE-----
iHUEARYKAB0WIQTAq04Rv2xblqv/eu5pxS9ljpiFQgUCaqYXFgAKCRBpxS9ljpiF
QrshAP9a6EQ5kXGAwx0T8wyJ6CjpK//whEVihp69zxb/4/NIewD/Z0vcQbAXGJOY
ADZga36BTG4F2Y31wjr4II8SG2WJDAk=
=zSSw
-----END PGP SIGNATURE-----
pgpp2Nethh8yZ.pgp
Description: PGP signature
--- End Message ---
__
This is the maintainer address of Debian's Java team
<https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/pkg-java-maintainers>.
Please use
[email protected] for discussions and questions.