{
  "document": {
    "aggregate_severity": {
      "text": "Important"
    },
    "category": "csaf_security_advisory",
    "csaf_version": "2.0",
    "distribution": {
      "text": "TuxCare License Agreement",
      "tlp": {
        "label": "WHITE",
        "url": "https://www.first.org/tlp/"
      }
    },
    "lang": "en",
    "notes": [
      {
        "category": "legal_disclaimer",
        "text": "This content is licensed under the Creative Commons Attribution 4.0 International License (https://creativecommons.org/licenses/by/4.0/). If you distribute this content, or a modified version of it, you must provide attribution to Cloud Linux Inc. and provide a link to the original.",
        "title": "Terms of Use"
      },
      {
        "category": "details",
        "text": "* SECURITY UPDATE: --dump-bin could overwrite an arbitrary existing file\n     - debian/patches/CVE-2023-30630.patch: write the dump file in a single\n       pass and create it with O_EXCL so an existing file is never clobbered\n     - CVE-2023-30630\n   * Build on armel\n     - debian/control: add armel to Architecture on dmidecode and\n       dmidecode-udeb. The debian11-els platform builds amd64, arm64 and\n       armel, and with armel absent from the list dh produced no binary\n       artifacts there, so every build of this package failed that target\n       with \"dpkg-genbuildinfo: error: binary build with no binary artifacts\n       found\" - the pristine vendor import fails the same way\n     - the omission is an artefact of Debian's opt-in architecture list, not\n       a portability limit: armhf and arm64 were each added on request\n       (#715139, #767965) and armel was simply never asked for. dmidecode has\n       no inline assembly and no VFP dependency (its only float use is printf\n       formatting of voltages, which soft-float handles), its arch-conditional\n       code is confined to __ia64__, __aarch64__ and an x86-only entry-point\n       fallback - none of which armel enters - and the primary path reads\n       /sys/firmware/dmi/tables/smbios_entry_point, which is arch-neutral",
        "title": "Details"
      }
    ],
    "publisher": {
      "category": "vendor",
      "contact_details": "https://tuxcare.com/contact/",
      "name": "TuxCare",
      "namespace": "https://tuxcare.com/"
    },
    "references": [
      {
        "category": "self",
        "summary": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789574775",
        "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789574775"
      },
      {
        "category": "self",
        "summary": "Canonical URL",
        "url": "https://security.tuxcare.com/csaf/v2/els_os/debian11els/advisories/2026/clsa-2026_1789574775.json"
      }
    ],
    "tracking": {
      "current_release_date": "2026-09-16T16:06:44Z",
      "generator": {
        "date": "2026-09-16T16:06:44Z",
        "engine": {
          "name": "pyCSAF"
        }
      },
      "id": "CLSA-2026:1789574775",
      "initial_release_date": "2026-09-16T16:06:44Z",
      "revision_history": [
        {
          "date": "2026-09-16T16:06:44Z",
          "number": "1",
          "summary": "Initial version"
        }
      ],
      "status": "final",
      "version": "1"
    },
    "title": "Fix CVE(s): CVE-2023-30630"
  },
  "product_tree": {
    "branches": [
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_name",
                "name": "Debian 11",
                "product": {
                  "name": "Debian 11",
                  "product_id": "Debian-11",
                  "product_identification_helper": {
                    "cpe": "cpe:2.3:o:debian:debian_linux:11:*:*:*:*:*:*:*"
                  }
                }
              }
            ],
            "category": "product_family",
            "name": "Debian"
          }
        ],
        "category": "vendor",
        "name": "Software in the Public Interest, Inc."
      },
      {
        "branches": [
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dmidecode-0:3.3-2+tuxcare.els1.armel",
                "product": {
                  "name": "dmidecode-0:3.3-2+tuxcare.els1.armel",
                  "product_id": "dmidecode-0:3.3-2+tuxcare.els1.armel",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/dmidecode@3.3-2%2Btuxcare.els1?arch=armel"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "armel"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dmidecode-0:3.3-2+tuxcare.els1.arm64",
                "product": {
                  "name": "dmidecode-0:3.3-2+tuxcare.els1.arm64",
                  "product_id": "dmidecode-0:3.3-2+tuxcare.els1.arm64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/dmidecode@3.3-2%2Btuxcare.els1?arch=arm64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "arm64"
          },
          {
            "branches": [
              {
                "category": "product_version",
                "name": "dmidecode-0:3.3-2+tuxcare.els1.amd64",
                "product": {
                  "name": "dmidecode-0:3.3-2+tuxcare.els1.amd64",
                  "product_id": "dmidecode-0:3.3-2+tuxcare.els1.amd64",
                  "product_identification_helper": {
                    "purl": "pkg:deb/tuxcare/dmidecode@3.3-2%2Btuxcare.els1?arch=amd64"
                  }
                }
              }
            ],
            "category": "architecture",
            "name": "amd64"
          }
        ],
        "category": "vendor",
        "name": "TuxCare"
      }
    ],
    "relationships": [
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dmidecode-0:3.3-2+tuxcare.els1.armel as a component of Debian 11",
          "product_id": "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.armel"
        },
        "product_reference": "dmidecode-0:3.3-2+tuxcare.els1.armel",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dmidecode-0:3.3-2+tuxcare.els1.arm64 as a component of Debian 11",
          "product_id": "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.arm64"
        },
        "product_reference": "dmidecode-0:3.3-2+tuxcare.els1.arm64",
        "relates_to_product_reference": "Debian-11"
      },
      {
        "category": "default_component_of",
        "full_product_name": {
          "name": "dmidecode-0:3.3-2+tuxcare.els1.amd64 as a component of Debian 11",
          "product_id": "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.amd64"
        },
        "product_reference": "dmidecode-0:3.3-2+tuxcare.els1.amd64",
        "relates_to_product_reference": "Debian-11"
      }
    ]
  },
  "vulnerabilities": [
    {
      "cve": "CVE-2023-30630",
      "notes": [
        {
          "category": "description",
          "text": "Dmidecode before 3.5 allows -dump-bin to overwrite a local file. This has security relevance because, for example, execution of Dmidecode via Sudo is plausible. NOTE: Some third parties have indicated the fix in 3.5 does not adequately address the vulnerability. The argument is that the proposed patch prevents dmidecode from writing to an existing file. However, there are multiple attack vectors that would not require overwriting an existing file that would provide the same level of unauthorized privilege escalation (e.g. creating a new file in /etc/cron.hourly).",
          "title": "Vulnerability description"
        }
      ],
      "product_status": {
        "fixed": [
          "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.amd64",
          "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.arm64",
          "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.armel"
        ]
      },
      "references": [
        {
          "category": "self",
          "summary": "Canonical URL",
          "url": "https://cve.tuxcare.com/els/cve/CVE-2023-30630"
        },
        {
          "category": "external",
          "summary": "https://git.savannah.nongnu.org/cgit/dmidecode.git/commit/?id=6ca381c1247c81f74e1ca4e7706f70bdda72e6f2",
          "url": "https://git.savannah.nongnu.org/cgit/dmidecode.git/commit/?id=6ca381c1247c81f74e1ca4e7706f70bdda72e6f2"
        },
        {
          "category": "external",
          "summary": "https://git.savannah.nongnu.org/cgit/dmidecode.git/commit/?id=d8cfbc808f387e87091c25e7d5b8c2bb348bb206",
          "url": "https://git.savannah.nongnu.org/cgit/dmidecode.git/commit/?id=d8cfbc808f387e87091c25e7d5b8c2bb348bb206"
        },
        {
          "category": "external",
          "summary": "https://github.com/adamreiser/dmiwrite",
          "url": "https://github.com/adamreiser/dmiwrite"
        },
        {
          "category": "external",
          "summary": "https://lists.nongnu.org/archive/html/dmidecode-devel/2023-03/msg00003.html",
          "url": "https://lists.nongnu.org/archive/html/dmidecode-devel/2023-03/msg00003.html"
        }
      ],
      "release_date": "2023-04-13T16:15:00Z",
      "remediations": [
        {
          "category": "vendor_fix",
          "date": "2026-09-16T16:06:17.190066Z",
          "details": "Details on how to apply the fix are available at: https://cve.tuxcare.com/els/releases/CLSA-2026:1789574775",
          "product_ids": [
            "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.amd64",
            "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.arm64",
            "Debian-11:dmidecode-0:3.3-2+tuxcare.els1.armel"
          ],
          "url": "https://cve.tuxcare.com/els/releases/CLSA-2026:1789574775"
        }
      ],
      "threats": [
        {
          "category": "impact",
          "details": "Important"
        }
      ]
    }
  ]
}