| Release | Version |
|---|---|
| bullseye | 2:3.7.5+dfsg-1 |
| bookworm | 2:3.8.2+dfsg-1 |
| trixie | 2:3.8.2+dfsg-1 |
| forky | 2:3.8.2+dfsg-1 |
| sid | 2:3.8.2+dfsg-1 |
| Bug | bullseye | bookworm | trixie | forky | sid | Description |
|---|---|---|---|---|---|---|
| CVE-2026-56390 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | GNU Bison improperly handles grammar\u2011defined output paths. Gramma ... |
| CVE-2026-56389 | vulnerable (no DSA, postponed) | vulnerable (no DSA, postponed) | vulnerable (no DSA) | vulnerable | vulnerable | GNU Bison allows for an execution of an arbitrary program during HTML ... |
| Bug | Description |
|---|---|
| CVE-2020-24240 | GNU Bison before 3.7.1 has a use-after-free in _obstack_free in lib/ob ... |
| CVE-2020-14150 | GNU Bison before 3.5.4 allows attackers to cause a denial of service ( ... |