Debian alert DLA-4286-2 (libcommons-lang3-java)
From: | Daniel Leidert <dleidert@debian.org> | |
To: | debian-lts-announce@lists.debian.org | |
Subject: | [SECURITY] [DLA 4286-2] libcommons-lang3-java regression update | |
Date: | Tue, 30 Sep 2025 22:14:02 +0200 | |
Message-ID: | <54da1e1efd4d38cb6a0fb127608a75c8731dccfc.camel@debian.org> |
------------------------------------------------------------------------- Debian LTS Advisory DLA-4286-2 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Daniel Leidert September 30, 2025 https://wiki.debian.org/LTS ------------------------------------------------------------------------- Package : libcommons-lang3-java Version : 3.11-1+deb11u2 CVE ID : CVE-2025-48924 A regression has been discovered in the latest release 3.11-1+deb11u1 of libcommons-lang3-java. The patch to fix CVE-2025-48924 had not been properly backported. For Debian 11 bullseye, this problem has been fixed in version 3.11-1+deb11u2. We recommend that you upgrade your libcommons-lang3-java packages. For the detailed security status of libcommons-lang3-java please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libcommons-la... Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS
Attachment: signature.asc (type=application/pgp-signature)
-----BEGIN PGP SIGNATURE----- iQIzBAABCgAdFiEEvu1N7VVEpMA+KD3HS80FZ8KW0F0FAmjcOgoACgkQS80FZ8KW 0F2PUQ//fGy67rxfPNB9S/rNyQ5G47grAY5cKd49QJgZ27Jkzbi7VExwZUkyE16H DHXys1MYivIGbN4beRBClOoiD+xGrOd+yGqeePwoLhSd7lJdU6FtPURkD7s0Bd2A HOqHO7JPopoC9Amg57eyLG7PUU4eReB/dHUiX731P/HOg6+lHdxROTWcMpwV5Cx6 +upDRW1iBBR3OE+euKAfIITsneN6ajA6Daa+RQJXi8OdZ/UBVe9qhaANFdRnaZmN YZIcG1XQNULbD//X0JET50p2dq7Rg0n5FuWoBEmIT4rEKFnaU7fKqR8og1KKcSzW 8ea3GLdVxYM0qnmjjstbNlGs+7m9ijLSwPQmbKiSMWR8+MV1iEITs1nE5fDRAjOa f8regn8ebJKwnCxSI7WAuhudC+T7crUKrhxY2SlE6C7Wf42ruHZOEFDrx4TQuhId mTI3FYVOOuzqAkGbFItUx1qxhSdYDSDiEFAYK5FRbRWIzMtc6lb4uT3ykmUPJ4OJ mWiEzRsyTxe6xa2Im8VgVOL+i+6pUWXyeRQtmC919gxrFX/SRa7iuHABq2t2K58q MuOgfSc0q/9Wsjd8UpKJZPq7z1Z/oyJKOMZaRuCKaH/JHXyiA7ALz9Gd0OK8xxVy DFzkHlePRrLExGg2AbZu51oye/D0RQ/QSE00BFoSVvLstybNMEA= =HfhT -----END PGP SIGNATURE-----