Executive brief
Debusine is a platform used to build and manage Debian software distributions. A security flaw was found where the system incorrectly handled file paths in package manifest files. An attacker could exploit this to create unauthorized file links on the system, potentially allowing them to overwrite files that the background worker process has permission to access, which could disrupt operations or lead to unauthorized system changes.
Technical details
A path traversal vulnerability exists in Debusine's handling of Debian source packages (.dsc) and upload artifacts (.changes). The parser for these manifest files failed to validate filenames in the 'Files' and 'Checksums-*' sections, accepting arbitrary user-controlled paths including absolute paths and parent directory references (../). During the 'mergeuploads' task, the '_symlink_files' function uses these unverified names to compute 'merged_file_path'. An attacker can exploit this to create symbolic links at arbitrary locations with the permissions of the debusine-worker user. This can lead to a containment breach and the overwriting of sensitive files. The issue was addressed by enforcing that checksum filenames contain only a single path component.
Affected products
- Debian Debusine Prior to commit c24cdc49fb258714767546bdec5b09f8065d414e
Timeline
- 2026-05-31: other: Merge request initiated to fix the path sanitization issue.
- 2026-06-01: patched: Fix committed to the repository.
- 2026-06-10: disclosed: CVE-2026-11853 published.