|
|
Log in / Subscribe / Register

Debian alert DLA-4714-1 (libmodbus)

From:  Thorsten Alteholz <debian@alteholz.de>
To:  debian-lts-announce@lists.debian.org
Subject:  [SECURITY] [DLA 4714-1] libmodbus security update
Date:  Sat, 01 Aug 2026 17:04:30 +0000
Message-ID:  <14d6f273-7a5a-c882-be54-802debff8d81@alteholz.de>

-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 - ------------------------------------------------------------------------- Debian LTS Advisory DLA-4714-1 debian-lts@lists.debian.org https://www.debian.org/lts/security/ Thorsten Alteholz August 01, 2026 https://wiki.debian.org/LTS - ------------------------------------------------------------------------- Package : libmodbus Version : 3.1.6-2.1+deb12u1 CVE ID : CVE-2024-10918 An issue has been found in libmodbus, a library for the Modbus protocol. The issue is related to a stack-based Buffer Overflow vulnerability, that allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length. For Debian 12 bookworm, this problem has been fixed in version 3.1.6-2.1+deb12u1. We recommend that you upgrade your libmodbus packages. For the detailed security status of libmodbus please refer to its security tracker page at: https://security-tracker.debian.org/tracker/libmodbus Further information about Debian LTS security advisories, how to apply these updates to your system and frequently asked questions can be found at: https://wiki.debian.org/LTS -----BEGIN PGP SIGNATURE----- iQKTBAEBCgB9FiEEYgH7/9u94Hgi6ruWlvysDTh7WEcFAmpuJx5fFIAAAAAALgAo aXNzdWVyLWZwckBub3RhdGlvbnMub3BlbnBncC5maWZ0aGhvcnNlbWFuLm5ldDYy MDFGQkZGREJCREUwNzgyMkVBQkI5Njk2RkNBQzBEMzg3QjU4NDcACgkQlvysDTh7 WEcPPxAAtLv1mERDUoba7ZasjUwSPZNrwwR241QJDpDsZFeS3W7MVB6Xl47Nr/G+ dFFiaMQpMbepGvDROoVxa+8GY+Di5TH0AdTlCiSr9IPpTZwpseqjCmR75VL22oK6 VV1sHqiWTvvhOic/AY1f3q8kPZcE6UjHABXhSm4P5FIP1eV2ndJR5lLi/1b+u2VH 4/P7USrUHeiAjIy28POr+w2nkjohlY2wN8ju5QXKaZnYgEoqurrPkSP2+qknNhW9 PAEBbIh4L8xMqyEIzeb7M5alZ8ykEy7jCruifRX53sW4pbypovRDgBukek+Zmyba DNO9N1RPKICAOgEEnn8dJqusFM7Ibxv1qDznqThJMq0tDHaCe7lo2GW3yLmmw1d+ w1YCiiLWlGNwNkQyR81ASIE1D+fWyMXC9U9NexcT115lzmDfNWsGc0VEavXwAB8q WlwEkrZkq1V7iMJ0ZWij5WbM3zKdg9Q0FKd5Ydm9Yy2IQX6PU3NOtNrTuGcDmrWZ Vs55j9iqDhMgWI/8gHb9rEeWN5wobIhynaDiXSCtI60cT97vzC/XH5rzQof4lHsK cH010NuVS75IJY03JC3o+3Dxbirf4C0ndBrdwOWpWCmQNu/OpiHZkJv1JRA3W/V/ zBXvzLQRghNsH/9rLhBFqWRjSiLSkBe1W0a34qIOyeC+FVkBFiQ= =V2WV -----END PGP SIGNATURE-----


to post comments


Copyright © 2026, Eklektix, Inc.
Comments and public postings are copyrighted by their creators.
Linux is a registered trademark of Linus Torvalds