Skip to content

[Deepin Integration]~[v25-Release] fix: CVE-2026-34986 panic on KeyUnwrap of too-short slice by deepin-ci-robot@deepin-community/golang-gopkg-square-go-jose.v2 by deepin-community-ci-bot[bot] #13300

@deepin-bot

Description

@deepin-bot

Package information | 软件包信息

包名 版本
golang-gopkg-square-go-jose.v2 2.6.0-2deepin1

Package repository address | 软件包仓库地址

deb [trusted=yes] https://ci.deepin.com/repo/obs/deepin:/CI:/TestingIntegration:/test-integration-pr-4041/testing/ ./

Changelog | 更新信息

golang-gopkg-square-go-jose.v2 (2.6.0-2deepin1) unstable; urgency=medium

  • Fix CVE-2026-34986: panic on KeyUnwrap of too-short slice
    Backport fix from go-jose/go-jose v3.0.5 to add length validation
    in KeyUnwrap and nil recipient checks in decryptKey functions.

Metadata

Metadata

Labels

Type

No type
No fields configured for issues without a type.

Projects

Status

In progress

Milestone

Relationships

None yet

Development

No branches or pull requests

Issue actions