[Git][security-tracker-team/security-tracker][master] 4 commits: add adminer
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Sat Aug 1 08:31:13 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
638c01c3 by Thorsten Alteholz at 2026-08-01T09:30:53+02:00
add adminer
- - - - -
03894892 by Thorsten Alteholz at 2026-08-01T09:30:56+02:00
mark CVE-2026-56390 and CVE-2026-56389 as postponed for Bookworm and Bullseye
- - - - -
78689b9c by Thorsten Alteholz at 2026-08-01T09:30:58+02:00
mark CVE-2026-62268 as postponed for Bookworm and Bullseye
- - - - -
e43f37b1 by Thorsten Alteholz at 2026-08-01T09:31:00+02:00
mark CVE-2026-47143 as postponed for Bookworm and Bullseye
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1108,8 +1108,11 @@ CVE-2026-53583
CVE-2026-62268
- borgbackup2 2.0.0b22-1
[trixie] - borgbackup2 <no-dsa> (Minor issue)
+ [bookworm] - borgbackup2 <postponed> (Minor issue)
- borgbackup 1.4.5-1
[trixie] - borgbackup <no-dsa> (Minor issue)
+ [bookworm] - borgbackup <postponed> (Minor issue)
+ [bullseye] - borgbackup <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/2d632531028b09da8ab5d1450f89bebcc205d640 (2.0.0b22)
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/4f37fdfed10b50559a0dd333b0d5581c642af329 (2.0.0b22)
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/3e9ed6d1ad6d3531b39c07b8ef3ecf41fce4437f (1.4.5)
@@ -3217,11 +3220,15 @@ CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked messag
CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output paths. Gramma ...)
- bison <unfixed> (bug #1143158)
[trixie] - bison <no-dsa> (Minor issue)
+ [bookworm] - bison <postponed> (Minor issue)
+ [bullseye] - bison <postponed> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389/
NOTE: https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a448c925513742d4efcf0
CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program during HTML ...)
- bison <unfixed> (bug #1143158)
[trixie] - bison <no-dsa> (Minor issue)
+ [bookworm] - bison <postponed> (Minor issue)
+ [bullseye] - bison <postponed> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389
NOTE: https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b
CVE-2026-55995 (A Double Free vulnerability in open-iscsi allows anunauthenticatedMITM ...)
@@ -10857,6 +10864,8 @@ CVE-2026-47237 (Kubeflow Community Distribution helps users to install Kubeflow
NOT-FOR-US: Kubeflow
CVE-2026-47143 (Capstone is a disassembly framework. Versions prior to 6.0.0-Alpha8 an ...)
- capstone <unfixed> (bug #1142678)
+ [bookworm] - capstone <postponed> (Minor issue)
+ [bullseye] - capstone <postponed> (Minor issue)
NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-289w-cm54-fgrm
NOTE: https://github.com/capstone-engine/capstone/pull/2924
NOTE: Fixed by: https://github.com/capstone-engine/capstone/commit/fab595205fee206f5c21be6ed8ad2eaf9225f1c7 (5.0.8)
=====================================
data/dla-needed.txt
=====================================
@@ -40,6 +40,9 @@ activemq
NOTE: 20260715: Also add for bookworm
NOTE: 20260715: Upcoming DSA, though they may just bump version (Beuc/front-desk)
--
+adminer
+ NOTE: 20260801: Added by Front-Desk (ta)
+--
amd64-microcode
NOTE: 20250710: Added by Front-Desk (apo)
NOTE: 20250906: Reached out to maintainer, offering help.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/14be3e65da21e48878857e4efb40874205183bdf...e43f37b1c3adec42e7c839de582bd1d423dbedfe
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/14be3e65da21e48878857e4efb40874205183bdf...e43f37b1c3adec42e7c839de582bd1d423dbedfe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/032411d5/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list