[Git][security-tracker-team/security-tracker][master] LTS: mark CVE-2025-26519/musl as postponed (Minor issue) for bullseye, drop...
Roberto C. Sánchez (@roberto)
roberto at debian.org
Thu Jun 5 16:03:49 BST 2025
Roberto C. Sánchez pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cf8c3838 by Roberto C. Sánchez at 2025-06-05T11:02:51-04:00
LTS: mark CVE-2025-26519/musl as postponed (Minor issue) for bullseye, drop musl from dla-needed.txt
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -37145,6 +37145,7 @@ CVE-2025-26788 (StrongKey FIDO Server before 4.15.1 treats a non-discoverable (n
CVE-2025-26519 (musl libc 0.9.13 through 1.2.5 before 1.2.6 has an out-of-bounds write ...)
- musl 1.2.5-2 (bug #1098238)
[bookworm] - musl <no-dsa> (Minor issue)
+ [bullseye] - musl <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2025/02/13/2
NOTE: https://git.musl-libc.org/cgit/musl/commit/?id=e5adcd97b5196e29991b524237381a0202a60659 (master)
NOTE: https://git.musl-libc.org/cgit/musl/commit/?id=c47ad25ea3b484e10326f933e927c0bc8cded3da (master)
=====================================
data/dla-needed.txt
=====================================
@@ -211,15 +211,6 @@ mina2
NOTE: 20250114: Patches for CVE-2024-52046 https://github.com/apache/mina/commit/f9cc5ada6ebef4ee7cc51aac824e42e2e422310e (2.2.4) and ... (dleidert)
NOTE: 20250114: ... https://github.com/apache/mina/commit/cdb59eb6131696a440870ab89ad0e20804eb5ca7 (2.1.10) (dleidert)
--
-musl
- NOTE: 20250217: Added by Front-Desk (Beuc)
- NOTE: 20250218: Requested review. (lamby)
- NOTE: 20250219: Update delayed until CVE-2025-26519 fixed in unstable. (lamby)
- NOTE: 20250219: → See "Re: Please review musl 1.2.2-1+deb11u1 for bullseye LTS" on debian-lts at lists.debian.org. (lamby)
- NOTE: 20250323: the update is ready but not tests. rails and rack stable updates were more prio at the time.
- NOTE: 20250323: now that they're done, will complete the update this week and release. (utkarsh)
- NOTE: 20250407: this still needs a resolution. will reach out to bunk to see if he can help with a reproducer. (utkarsh)
---
nagvis
NOTE: 20250117: Added by Front-Desk (rouca)
NOTE: 20250119: Also check/fix https://bugs.debian.org/1061044
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf8c383859d41d468e0f3cb51489d40f492387e0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cf8c383859d41d468e0f3cb51489d40f492387e0
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20250605/0c4f05fe/attachment.htm>
More information about the debian-security-tracker-commits
mailing list