[Git][security-tracker-team/security-tracker][master] 5 commits: add jline3
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Sat Aug 1 18:38:45 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eae59fd5 by Thorsten Alteholz at 2026-08-01T19:12:22+02:00
add jline3
- - - - -
c144d662 by Thorsten Alteholz at 2026-08-01T19:17:51+02:00
mark CVE-2026-39155 as postponed for Bullseye and Bookworm
- - - - -
0a5737c5 by Thorsten Alteholz at 2026-08-01T19:22:24+02:00
mark CVE-2026-15813, CVE-2026-15812 and CVE-2026-15811 as postponed for Bullseye and Bookworm
- - - - -
225088f9 by Thorsten Alteholz at 2026-08-01T19:28:19+02:00
add libdvi-perl
- - - - -
8db68edf by Thorsten Alteholz at 2026-08-01T19:36:49+02:00
add libgit2
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -7330,6 +7330,8 @@ CVE-2026-40430 (Pronetiqs IntraVUE Versions 3.2.1a14 and prior have a plaintext
NOT-FOR-US: Pronetiqs IntraVUE
CVE-2026-39155 (Knot DNS before 3.4.10 and 3.5.x before 3.5.4 contains a vulnerability ...)
- knot 3.5.4-1
+ [bookworm] - knot <postponed> (Minor issue)
+ [bullseye] - knot <postponed> (Minor issue)
NOTE: https://www.knot-dns.cz/2026-04-01-version-3410.html
NOTE: https://www.knot-dns.cz/2026-04-02-version-354.html
CVE-2026-38764 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
@@ -12195,9 +12197,13 @@ CVE-2026-15927 (A flaw was found in Red Hat Quay's repository-level mirror confi
NOT-FOR-US: Quay
CVE-2026-15812 (A vulnerability was found in the internal Access Control List (ACL) su ...)
- kronosnet <unfixed> (bug #1142847)
+ [bookworm] - kronosnet <postponed> (Minor issue)
+ [bullseye] - kronosnet <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500851
CVE-2026-15811 (A vulnerability was found in kronosnet's (version <=1.34) cryptographi ...)
- kronosnet <unfixed> (bug #1142847)
+ [bookworm] - kronosnet <postponed> (Minor issue)
+ [bullseye] - kronosnet <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500849
CVE-2026-15788 (BuildKit's cache mount source= selector on Windows Container on Window ...)
- golang-github-moby-buildkit <itp> (bug #1094971)
@@ -12590,6 +12596,8 @@ CVE-2026-16242 (A flaw was found in the Konnectivity proxy-server configuration
NOT-FOR-US: Konnectivity proxy-server
CVE-2026-15813 (A vulnerability was found in the network packet de-fragmentation engin ...)
- kronosnet <unfixed> (bug #1142847)
+ [bookworm] - kronosnet <postponed> (Minor issue)
+ [bullseye] - kronosnet <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500854
CVE-2026-15588 (A denial-of-service and resource exhaustion vulnerability exists withi ...)
- glib2.0 2.88.3-1 (bug #1142835)
=====================================
data/dla-needed.txt
=====================================
@@ -294,6 +294,9 @@ jackson-databind
jetty9
NOTE: 20260418: Added by Front-Desk. Fix CVE-2026-5795 maybe other (rouca)
--
+jline3
+ NOTE: 20260801: Added by Front-Desk (ta)
+--
jpeg-xl/bookworm
NOTE: 20260619: Added by Front-Desk (charles)
NOTE: 20260619: Follow DSA-6342-1 (charles)
@@ -342,6 +345,9 @@ libcryptx-perl
NOTE: 20260725: tag Copy and CVE-2026-13758 memNE both present. Sponsored in
NOTE: 20260725: both suites. (utkarsh/front-desk)
--
+libdbi-perl
+ NOTE: 20260801: Added by Front-Desk (ta)
+--
libde265
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
@@ -350,6 +356,10 @@ libde265
libgd2
NOTE: 20260731: Added by Front-Desk (ta)
--
+libgit2
+ NOTE: 20260801: Added by Front-Desk (ta)
+ NOTE: 20260801: not sure whether Bullseye and Bookworm are really affected, please recheck (ta)
+--
libheif
NOTE: 20260612: Added by Front-Desk (rouca)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2632c5ea630978d67091868da5988acf1d8fdf52...8db68edf4d94e156534d1f6bdd7cf4f6106b0efc
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2632c5ea630978d67091868da5988acf1d8fdf52...8db68edf4d94e156534d1f6bdd7cf4f6106b0efc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260801/4b25dd96/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list