CVE-2026-68496

NameCVE-2026-68496
DescriptionThe Smile parser in FasterXML jackson-dataformats-binary never invokes ...
SourceCVE (at NVD; CERT, ENISA, LWN, oss-sec, fulldisc, Debian ELTS, Red Hat, Ubuntu, Gentoo, SUSE bugzilla/CVE, GitHub advisories/code/issues, web search, more)

Vulnerable and fixed packages

The table below lists information on source packages.

Source PackageReleaseVersionStatus
jackson-dataformat-smile (PTS)bookworm, bookworm (security)2.7.8-5+deb12u1vulnerable
trixie (security), trixie2.7.8-5+deb13u1vulnerable
forky, sid2.7.8-6vulnerable

The information below is based on the following data on fixed versions.

PackageTypeReleaseFixed VersionUrgencyOriginDebian Bugs
jackson-dataformat-smilesource(unstable)(unfixed)

Notes

https://github.com/FasterXML/jackson-dataformats-binary/security/advisories/GHSA-3v8f-v6vx-fmrm
Fixed by: https://github.com/FasterXML/jackson-dataformats-binary/commit/8bbcac61fe35aedc71ae681915c99312f324eb65 (jackson-dataformats-binary-2.18.10)
check, might not affect our ancient version

Search for package or bug name: Reporting problems