[Git][security-tracker-team/security-tracker][master] Reserve DSA number for libssh update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 2 08:32:40 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
96a4f370 by Salvatore Bonaccorso at 2026-08-02T09:31:58+02:00
Reserve DSA number for libssh update
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -102385,7 +102385,6 @@ CVE-2026-3732 (A security vulnerability has been detected in Tenda F453 1.0.0.3.
NOT-FOR-US: Tenda
CVE-2026-3731 (A weakness has been identified in libssh up to 0.11.3. The impacted el ...)
- libssh 0.12.0-1 (bug #1127693)
- [trixie] - libssh <no-dsa> (Minor issue)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt
@@ -113561,7 +113560,6 @@ CVE-2018-25157 (Phraseanet 4.0.3 contains a stored cross-site scripting vulnerab
NOT-FOR-US: Phraseanet
CVE-2026-0968 (A flaw was found in libssh in which a malicious SFTP (SSH File Transfe ...)
- libssh 0.12.0-1 (bug #1127693)
- [trixie] - libssh <no-dsa> (Minor issue)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0968.txt
@@ -113569,14 +113567,12 @@ CVE-2026-0968 (A flaw was found in libssh in which a malicious SFTP (SSH File Tr
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=796d85f786dff62bd4bcc4408d9b7bbc855841e9 (libssh-0.11.4)
CVE-2026-0967 (A flaw was found in libssh. A remote attacker, by controlling client c ...)
- libssh 0.12.0-1 (bug #1127693)
- [trixie] - libssh <no-dsa> (Minor issue)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0967.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=6d74aa6138895b3662bade9bd578338b0c4f8a15 (libssh-0.11.4)
CVE-2026-0966 (A flaw was found in libssh. The API function `ssh_get_hexa()` is vulne ...)
- libssh 0.12.0-1 (bug #1127693)
- [trixie] - libssh <no-dsa> (Minor issue)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0966.txt
@@ -113585,14 +113581,12 @@ CVE-2026-0966 (A flaw was found in libssh. The API function `ssh_get_hexa()` is
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=6ba5ff1b7b1547a59f750fbc06b89737b7456117 (libssh-0.11.4)
CVE-2026-0965 (A flaw was found in libssh where it can attempt to open arbitrary file ...)
- libssh 0.12.0-1 (bug #1127693)
- [trixie] - libssh <no-dsa> (Minor issue)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0965.txt
NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=bf390a042623e02abc8f421c4c5fadc0429a8a76 (libssh-0.11.4)
CVE-2026-0964 (A malicious SCP server can send unexpected paths that could make the c ...)
- libssh 0.12.0-1 (bug #1127693)
- [trixie] - libssh <no-dsa> (Minor issue)
[bookworm] - libssh <no-dsa> (Minor issue)
[bullseye] - libssh <postponed> (Minor issue)
NOTE: https://www.libssh.org/security/advisories/CVE-2026-0964.txt
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[02 Aug 2026] DSA-6410-1 libssh - security update
+ {CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-15370 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850}
+ [trixie] - libssh 0.11.5-0+deb13u1
[01 Aug 2026] DSA-6409-1 libgd2 - security update
{CVE-2026-9672}
[trixie] - libgd2 2.3.3-14~deb13u1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/96a4f37088a52777b3469a9c0fda7e064a2d4b0b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/96a4f37088a52777b3469a9c0fda7e064a2d4b0b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/4f6e24bc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list