Debian Patches

Status for libcommons-lang3-java/3.17.0-2

Patch Description Author Forwarded Bugs Origin Last update
disable_testGetUserHome_test.diff Disable SystemUtilsTest#testGetUserHome as it depends on $HOME (which is not available on buildd). Damien Raude-Morvan <drazzib@debian.org> not-needed 2012-05-27
ignore-benchmarks.diff Ignore the JMH benchmarks Emmanuel Bourg <ebourg@apache.org> not-needed
CVE-2025-48924.diff Rewrite ClassUtils.getClass() without recursion to avoid StackOverflowError on very long inputs.

- This was found fuzz testing Apache Commons Text which relies on
ClassUtils.
- OssFuzz Issue 42522972:
apache-commons-text:StringSubstitutorInterpolatorFuzzer: Security
exception in org.apache.commons.lang3.ClassUtils.getClass
Gary Gregory <garydgregory@gmail.com> yes debian upstream https://github.com/apache/commons-lang/commit/b424803abdb2bec818e4fbcb251ce031c22aca53 2024-09-21

All known versions for source package 'libcommons-lang3-java'

Links