jellyfin: miscellaneous security fixes from 12.0

These go directly to 26.05 because master is on 12.0 which has all the
fixes. Jellyfin team is not going to release another 10.11.x version.
Hence these backports.

Only one patch is marked with a GHSA marker, and none are currently
listed in their official roster. Which doesn't mean much since the
project practices a 14-day delay for disclosures.

https://github.com/jellyfin/jellyfin/security#post-disclosure-process

Two fixed scenarios require an authenticated user (one bug allows to
SSRF or DoS with a SVG file; another allows a user to read others'
private playlists). Another patch fixes max limit for login attempts,
which was broken in 10.11.11.

Not-cherry-picked-because: master is on 12.0 and has the fixes.
This commit is contained in:
Ihar Hrachyshka
2026-09-12 16:30:17 -04:00
parent 6eb0f007b6
commit 599cbfe8cc
2 changed files with 55 additions and 0 deletions

View File

@@ -0,0 +1,26 @@
From 5f13afa1cecfae398ff7d84ed89fc45b14b71c61 Mon Sep 17 00:00:00 2001
From: Shadowghost <Ghost_of_Stone@web.de>
Date: Thu, 4 Jun 2026 19:00:03 +0200
Subject: [PATCH] Fix playlist visibility
---
MediaBrowser.Controller/Entities/Folder.cs | 5 ++++-
1 file changed, 4 insertions(+), 1 deletion(-)
diff --git a/MediaBrowser.Controller/Entities/Folder.cs b/MediaBrowser.Controller/Entities/Folder.cs
--- a/MediaBrowser.Controller/Entities/Folder.cs
+++ b/MediaBrowser.Controller/Entities/Folder.cs
@@ -811,7 +811,10 @@ namespace MediaBrowser.Controller.Entities
private bool RequiresPostFiltering2(InternalItemsQuery query)
{
- if (query.IncludeItemTypes.Length == 1 && query.IncludeItemTypes[0] == BaseItemKind.BoxSet)
+ // BoxSets and Playlists can have per-user visibility (shares/open access) that is stored in the
+ // serialized item data and cannot be evaluated by the database query, so filter them in memory.
+ if (query.IncludeItemTypes.Length > 0
+ && query.IncludeItemTypes.All(t => t == BaseItemKind.BoxSet || t == BaseItemKind.Playlist))
{
Logger.LogDebug("Query requires post-filtering due to BoxSet query");
return true;
--
2.51.0

View File

@@ -1,6 +1,7 @@
{
lib,
fetchFromGitHub,
fetchpatch,
nixosTests,
dotnetCorePackages,
buildDotnetModule,
@@ -23,6 +24,34 @@ buildDotnetModule (finalAttrs: {
hash = "sha256-HCs4ZsutVoVH+bBZANjpPeMyV8e63Yemjg9DSr0R9zg=";
};
patches = [
# Prevent SSRF, local file disclosure and DoS via external references in SVG rendering.
# (No public PR.)
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/cefa78fc1de2410e5c5c6da5062c98fe98b22d17.patch";
hash = "sha256-TxGo+sLLG+C9omxrwvO6byzw+iRqONVLXrQKwkrY22s=";
})
# Fix MaxLoginAttempts not honored.
# https://github.com/jellyfin/jellyfin/pull/17274
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/8b826d981bcfec22063d6008e38016f4b77790d0.patch";
hash = "sha256-Nav05TcpjBJABybU0BVyJ0UyxKi+6nDNBQ6tjY0DPT8=";
})
# GHSA-9x85-gx46-6522
# Reject user impersonation when retrieving private playlist items.
# (No public PR.)
(fetchpatch {
url = "https://github.com/jellyfin/jellyfin/commit/911ac3769cdcce50a8f6e0b3c0739d509bd9a23f.patch";
hash = "sha256-MwaTwqhuBc7yWW3cL6htlyDQ9O1wt5iFCOM/oVTi6P0=";
})
# Don't let unauthorized users to list other's private playlists.
# https://github.com/jellyfin/jellyfin/pull/17025
./fix-playlist-visibility.patch
];
propagatedBuildInputs = [ sqlite ];
projectFile = "Jellyfin.Server/Jellyfin.Server.csproj";