DEBIAN-CVE-2026-46607

Source
https://security-tracker.debian.org/tracker/CVE-2026-46607
Import Source
https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46607.json
JSON Data
https://api.test.osv.dev/v1/vulns/DEBIAN-CVE-2026-46607
Upstream
Published
2026-06-25T19:16:37.527Z
Modified
2026-06-26T23:00:28.290551890Z
Severity
  • 7.8 (High) CVSS_V3 - CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
[none]
Details

Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, glances/outdated.py uses pickle.load() to read a version-check cache file stored at a predictable, world-accessible path (~/.cache/glances/glances-version.db or $XDGCACHEHOME/glances/glances-version.db). No integrity check, signature verification, or format validation is performed before deserialization. An attacker with write access to that path — through any of several realistic local or container-level scenarios — can plant a malicious pickle file and achieve arbitrary code execution as the OS user running Glances the next time it starts with version checking enabled (the default). This vulnerability is fixed in 4.5.5.

References

Affected packages

Debian:12 / glances

Package

Name
glances
Purl
pkg:deb/debian/glances?arch=source&distro=bookworm

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

3.*
3.3.1.1+dfsg-1
3.4.0.3+dfsg-1
4.*
4.0.5+dfsg-1
4.1.2.1+dfsg-1
4.2.1+dfsg-1
4.3.0.8+dfsg-1
4.3.1+dfsg-1
4.3.3+dfsg-1
4.5.1+dfsg-1
4.5.2+dfsg-1
4.5.3.2+dfsg-1
4.5.4+dfsg-1
4.5.5+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46607.json"

Debian:13 / glances

Package

Name
glances
Purl
pkg:deb/debian/glances?arch=source&distro=trixie

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected

Affected versions

4.*
4.3.1+dfsg-1
4.3.3+dfsg-1
4.5.1+dfsg-1
4.5.2+dfsg-1
4.5.3.2+dfsg-1
4.5.4+dfsg-1
4.5.5+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46607.json"

Debian:14 / glances

Package

Name
glances
Purl
pkg:deb/debian/glances?arch=source&distro=forky

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Fixed
4.5.5+dfsg-1

Affected versions

4.*
4.3.1+dfsg-1
4.3.3+dfsg-1
4.5.1+dfsg-1
4.5.2+dfsg-1
4.5.3.2+dfsg-1
4.5.4+dfsg-1

Ecosystem specific

{
    "urgency": "not yet assigned"
}

Database specific

source
"https://storage.googleapis.com/osv-test-debian-osv/debian-cve-osv/DEBIAN-CVE-2026-46607.json"