[Git][security-tracker-team/security-tracker][master] 2 commits: nginx spu/ospu
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Aug 29 19:00:52 BST 2025
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
76b5fac5 by Moritz Mühlenhoff at 2025-08-29T19:59:35+02:00
nginx spu/ospu
- - - - -
5d519ec1 by Moritz Mühlenhoff at 2025-08-29T20:00:13+02:00
nodejs DSA
- - - - -
5 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
- data/next-oldstable-point-update.txt
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -5244,6 +5244,8 @@ CVE-2024-10219 (An issue has been discovered in GitLab CE/EE affecting all versi
CVE-2025-53859 (NGINX Open Source and NGINX Plus have a vulnerability in the ngx_mail_ ...)
[experimental] - nginx 1.28.0-2
- nginx 1.28.0-3 (bug #1111138)
+ [trixie] - nginx <no-dsa> (Minor issue, will be fixed via point update)
+ [bookworm] - nginx <no-dsa> (Minor issue, will be fixed via point update)
NOTE: https://www.openwall.com/lists/oss-security/2025/08/13/5
NOTE: https://nginx.org/download/patch.2025.smtp.txt
CVE-2025-54472 (Unlimited memory allocation in redis protocol parser in Apache bRPC (a ...)
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[29 Aug 2025] DSA-5991-1 nodejs - security update
+ {CVE-2023-46809 CVE-2024-21892 CVE-2024-22019 CVE-2024-22020 CVE-2024-22025 CVE-2024-27982 CVE-2024-27983 CVE-2025-47153}
+ [bookworm] - nodejs 18.20.4+dfsg-1~deb12u1
[29 Aug 2025] DSA-5990-1 libxml2 - security update
{CVE-2025-7425}
[bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u4
=====================================
data/dsa-needed.txt
=====================================
@@ -48,9 +48,6 @@ mbedtls/oldstable
--
netty
--
-nodejs/oldstable (jmm)
- Bastien Roucaries (rouca) showed interest to prepare an update and is working on it
---
opennds/oldstable
pinged maintainer, but no reply yet. should most probably be bumped to 10.x
--
=====================================
data/next-oldstable-point-update.txt
=====================================
@@ -368,3 +368,5 @@ CVE-2023-31484
[bookworm] - perl 5.36.0-7+deb12u3
CVE-2025-40909
[bookworm] - perl 5.36.0-7+deb12u3
+CVE-2025-53859
+ [bookworm] - nginx 1.22.1-9+deb12u3
=====================================
data/next-point-update.txt
=====================================
@@ -57,3 +57,6 @@ CVE-2024-31031
CVE-2025-XXXX [OSSN-0094]
[trixie] - nova 2:31.0.0-6+deb13u1
[trixie] - watcher 14.0.0-1+deb13u1
+CVE-2025-53859
+ [trixie] - nginx 1.26.3-3+deb13u1
+
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/31ea5b6e4d4d154a69fc9913af634f40054ddd8b...5d519ec1989806abe27e1bfaa3a44490bd1f35d0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/31ea5b6e4d4d154a69fc9913af634f40054ddd8b...5d519ec1989806abe27e1bfaa3a44490bd1f35d0
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250829/dac76438/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list