[Git][security-tracker-team/security-tracker][master] 3 commits: add libmodbus

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sat Aug 1 16:40:07 BST 2026



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b611cc33 by Thorsten Alteholz at 2026-08-01T17:39:52+02:00
add libmodbus

- - - - -
37fa6e48 by Thorsten Alteholz at 2026-08-01T17:39:52+02:00
add sslh

- - - - -
8fafbc1c by Thorsten Alteholz at 2026-08-01T17:39:54+02:00
Reserve DLA-4713-1 for sslh

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -197068,7 +197068,6 @@ CVE-2025-52936 (Improper Link Resolution Before File Access ('Link Following') v
 	{DLA-4238-1}
 	- sslh 2.3.1-1 (bug #1108284)
 	[trixie] - sslh <no-dsa> (Minor issue)
-	[bookworm] - sslh <no-dsa> (Minor issue)
 	NOTE: https://github.com/yrutschle/sslh/pull/494
 	NOTE: Fixed by: https://github.com/yrutschle/sslh/commit/0fe9bd5a956a123342ff12352b25bff8025dac69 (v2.2.2)
 CVE-2025-52935 (Integer Overflow or Wraparound vulnerability in dragonflydb dragonfly  ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[01 Aug 2026] DLA-4713-1 sslh - security update
+	{CVE-2025-52936}
+	[bookworm] - sslh 1.20-1+deb12u1
 [01 Aug 2026] DLA-4712-1 node-tar - security update
 	{CVE-2024-28863 CVE-2026-23745 CVE-2026-26960 CVE-2026-29786}
 	[bookworm] - node-tar 6.1.13+~cs7.0.5-1+deb12u1


=====================================
data/dla-needed.txt
=====================================
@@ -357,6 +357,9 @@ libio-compress-perl
   NOTE: 20260612: Added by Front-Desk (rouca)
   NOTE: 20260612: MUST hold-back following the upper suites and wait for green light from security team (rouca/FD)
 --
+libmodbus (Thorsten Alteholz)
+  NOTE: 20260801: Added by Front-Desk (ta)
+--
 libpgjava
   NOTE: 20260613: Added by Front-Desk (rouca)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/bc1b63000e3a05e884d081491723663c7820b17d...8fafbc1cc27bcb67d545108e1b64dd04d70e95f0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/bc1b63000e3a05e884d081491723663c7820b17d...8fafbc1cc27bcb67d545108e1b64dd04d70e95f0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/e062ad4b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list