CVE-2025-11230

NameCVE-2025-11230
DescriptionBUG/CRITICAL: mjson: fix possible DoS when parsing numbers
SourceCVE (at NVD; CERT, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
ReferencesDSA-6017-1

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
haproxy (PTS)bullseye2.2.9-2+deb11u6fixed
bullseye (security)2.2.9-2+deb11u7fixed
bookworm2.6.12-1+deb12u2vulnerable
bookworm (security)2.6.12-1+deb12u3fixed
trixie3.0.11-1vulnerable
trixie (security)3.0.11-1+deb13u1fixed
forky3.2.5-1vulnerable
sid3.2.6-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
haproxysourcebullseye(not affected)
haproxysourcebookworm2.6.12-1+deb12u3DSA-6017-1
haproxysourcetrixie3.0.11-1+deb13u1DSA-6017-1
haproxysource(unstable)3.2.5-2

Notes

[bullseye] - haproxy <not-affected> (Vulnerable code introduced later)
Introduced with: https://github.com/haproxy/haproxy/commit/41007a6835fe29f865e01d8fbeb96114c0d01828 (v2.4-dev17)
Fixed by: https://git.haproxy.org/?p=haproxy-3.2.git;a=commit;h=6fd1287526eae1b31329997a2df29c9fb564a8e8 (v3.2.6)
Fixed by: https://github.com/haproxy/haproxy/commit/06675db4bf234ed17e14305f1d59259d2fe78b06 (v3.3-dev9)

Search for package or bug name: Reporting problems