[Git][security-tracker-team/security-tracker][master] Reserve DSA number for libssh update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 2 08:32:40 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
96a4f370 by Salvatore Bonaccorso at 2026-08-02T09:31:58+02:00
Reserve DSA number for libssh update

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -102385,7 +102385,6 @@ CVE-2026-3732 (A security vulnerability has been detected in Tenda F453 1.0.0.3.
 	NOT-FOR-US: Tenda
 CVE-2026-3731 (A weakness has been identified in libssh up to 0.11.3. The impacted el ...)
 	- libssh 0.12.0-1 (bug #1127693)
-	[trixie] - libssh <no-dsa> (Minor issue)
 	[bookworm] - libssh <no-dsa> (Minor issue)
 	[bullseye] - libssh <postponed> (Minor issue)
 	NOTE: https://www.libssh.org/security/advisories/libssh-2026-sftp-extensions.txt
@@ -113561,7 +113560,6 @@ CVE-2018-25157 (Phraseanet 4.0.3 contains a stored cross-site scripting vulnerab
 	NOT-FOR-US: Phraseanet
 CVE-2026-0968 (A flaw was found in libssh in which a malicious SFTP (SSH File Transfe ...)
 	- libssh 0.12.0-1 (bug #1127693)
-	[trixie] - libssh <no-dsa> (Minor issue)
 	[bookworm] - libssh <no-dsa> (Minor issue)
 	[bullseye] - libssh <postponed> (Minor issue)
 	NOTE: https://www.libssh.org/security/advisories/CVE-2026-0968.txt
@@ -113569,14 +113567,12 @@ CVE-2026-0968 (A flaw was found in libssh in which a malicious SFTP (SSH File Tr
 	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=796d85f786dff62bd4bcc4408d9b7bbc855841e9 (libssh-0.11.4)
 CVE-2026-0967 (A flaw was found in libssh. A remote attacker, by controlling client c ...)
 	- libssh 0.12.0-1 (bug #1127693)
-	[trixie] - libssh <no-dsa> (Minor issue)
 	[bookworm] - libssh <no-dsa> (Minor issue)
 	[bullseye] - libssh <postponed> (Minor issue)
 	NOTE: https://www.libssh.org/security/advisories/CVE-2026-0967.txt
 	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=6d74aa6138895b3662bade9bd578338b0c4f8a15 (libssh-0.11.4)
 CVE-2026-0966 (A flaw was found in libssh. The API function `ssh_get_hexa()` is vulne ...)
 	- libssh 0.12.0-1 (bug #1127693)
-	[trixie] - libssh <no-dsa> (Minor issue)
 	[bookworm] - libssh <no-dsa> (Minor issue)
 	[bullseye] - libssh <postponed> (Minor issue)
 	NOTE: https://www.libssh.org/security/advisories/CVE-2026-0966.txt
@@ -113585,14 +113581,12 @@ CVE-2026-0966 (A flaw was found in libssh. The API function `ssh_get_hexa()` is
 	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=6ba5ff1b7b1547a59f750fbc06b89737b7456117 (libssh-0.11.4)
 CVE-2026-0965 (A flaw was found in libssh where it can attempt to open arbitrary file ...)
 	- libssh 0.12.0-1 (bug #1127693)
-	[trixie] - libssh <no-dsa> (Minor issue)
 	[bookworm] - libssh <no-dsa> (Minor issue)
 	[bullseye] - libssh <postponed> (Minor issue)
 	NOTE: https://www.libssh.org/security/advisories/CVE-2026-0965.txt
 	NOTE: Fixed by: https://git.libssh.org/projects/libssh.git/commit/?id=bf390a042623e02abc8f421c4c5fadc0429a8a76 (libssh-0.11.4)
 CVE-2026-0964 (A malicious SCP server can send unexpected paths that could make the c ...)
 	- libssh 0.12.0-1 (bug #1127693)
-	[trixie] - libssh <no-dsa> (Minor issue)
 	[bookworm] - libssh <no-dsa> (Minor issue)
 	[bullseye] - libssh <postponed> (Minor issue)
 	NOTE: https://www.libssh.org/security/advisories/CVE-2026-0964.txt


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[02 Aug 2026] DSA-6410-1 libssh - security update
+	{CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-15370 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850}
+	[trixie] - libssh 0.11.5-0+deb13u1
 [01 Aug 2026] DSA-6409-1 libgd2 - security update
 	{CVE-2026-9672}
 	[trixie] - libgd2 2.3.3-14~deb13u1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/96a4f37088a52777b3469a9c0fda7e064a2d4b0b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/96a4f37088a52777b3469a9c0fda7e064a2d4b0b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/4f6e24bc/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list