CVE-2025-67859

NameCVE-2025-67859
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)
Debian Bugs1125019

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
tlp (PTS)bullseye1.3.1-2fixed
bookworm1.5.0-2fixed
trixie1.8.0-1fixed
forky1.8.0-1vulnerable
sid1.9.1-1fixed

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
tlpsourcebullseye(not affected)
tlpsourcebookworm(not affected)
tlpsourcetrixie(not affected)
tlpsource(unstable)1.9.1-11125019

Notes

[trixie] - tlp <not-affected> (Vulnerable code not yet present)
[bookworm] - tlp <not-affected> (Vulnerable code not yet present)
[bullseye] - tlp <not-affected> (Vulnerable code not yet present)
https://www.openwall.com/lists/oss-security/2026/01/07/8
Fixed by: https://github.com/linrunner/TLP/commit/08aa9cdb135b3563b2fb6eb4e0ecb638df5e7c09 (1.9.1)

Search for package or bug name: Reporting problems