[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2025-12058,CVE-2025-49655/keras: bullseye ignored

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Thu Nov 6 17:29:30 GMT 2025



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
04335d86 by Sylvain Beucler at 2025-11-06T18:29:16+01:00
CVE-2025-12058,CVE-2025-49655/keras: bullseye ignored

- - - - -
9dd605e7 by Sylvain Beucler at 2025-11-06T18:29:19+01:00
CVE-2025-12060/keras: bullseye postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1672,8 +1672,10 @@ CVE-2025-12515 (Systemic Internal Server Errors - HTTP 500 ResponseThis issue af
 	NOT-FOR-US: Azure Access Technology
 CVE-2025-12060 (The keras.utils.get_file API in Keras, when used with the extract=True ...)
 	- keras <removed>
+	[bullseye] - keras <postponed> (Minor issue, only use with trusted models)
 	NOTE: https://github.com/keras-team/keras/pull/21760
 	NOTE: https://github.com/keras-team/keras/security/advisories/GHSA-hjqc-jx6g-rwp9
+	NOTE: Code present in keras/utils/data_utils.py in v2.3.1/bullseye.
 CVE-2025-11998 (The following HP Card Readers B Models(X3D03B & Y7C05B) are potentiall ...)
 	NOT-FOR-US: HP
 CVE-2025-10348 (URVE Smart Office is vulnerable to Stored XSS in report problem functi ...)
@@ -2083,6 +2085,7 @@ CVE-2025-12142 (Buffer Copy without Checking Size of Input ('Classic Buffer Over
 	NOT-FOR-US: ABB group
 CVE-2025-12058 (The Keras.Model.load_model method, including when executed with the in ...)
 	- keras <removed>
+	[bullseye] - keras <ignored> (safe_mode introduced in v2.12, only use with trusted models)
 	NOTE: https://github.com/keras-team/keras/pull/21751
 CVE-2025-11632 (The Call Now Button \u2013 The #1 Click to Call Button for WordPress p ...)
 	NOT-FOR-US: WordPress plugin
@@ -5769,6 +5772,7 @@ CVE-2025-55085 (In NextX Duo before 6.4.4, in the HTTP client module, the networ
 	NOT-FOR-US: Eclipse
 CVE-2025-49655 (Deserialization of untrusted data can occur in versions of the Keras f ...)
 	- keras <removed>
+	[bullseye] - keras <ignored> (safe_mode introduced in v2.12, only use with trusted models)
 	NOTE: https://github.com/keras-team/keras/pull/21575
 CVE-2025-48087 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: WordPress plugin or theme



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b276559a2e39d29efcabe3fa8b61826d5ed0af69...9dd605e76db032a1a4ea0930136ff73ba14b3c14

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b276559a2e39d29efcabe3fa8b61826d5ed0af69...9dd605e76db032a1a4ea0930136ff73ba14b3c14
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251106/90a1ad83/attachment.htm>


More information about the debian-security-tracker-commits mailing list