[Git][security-tracker-team/security-tracker][master] 3 commits: add unzip

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sun Aug 2 09:44:08 BST 2026



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4aa72bc8 by Thorsten Alteholz at 2026-08-02T10:25:56+02:00
add unzip

- - - - -
3fe0a30d by Thorsten Alteholz at 2026-08-02T10:29:40+02:00
add pyasn1

- - - - -
f328a047 by Thorsten Alteholz at 2026-08-02T10:35:50+02:00
mark CVE-2026-17572, CVE-2026-17573 and CVE-2026-17572 as postponed for Bullseye and Bookworm

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -5376,14 +5376,20 @@ CVE-2026-17612 (Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prio
 	NOT-FOR-US: Honeywell
 CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability. Processing a c ...)
 	- hdf5 <unfixed> (bug #1143001)
+	[bookworm] - hdf5 <postponed> (Minor issue)
+	[bullseye] - hdf5 <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc (2.2.0-rc1)
 CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library. Proces ...)
 	- hdf5 <unfixed> (bug #1143000)
+	[bookworm] - hdf5 <postponed> (Minor issue)
+	[bullseye] - hdf5 <postponed> (Minor issue)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/6124
 	NOTE: https://github.com/HDFGroup/hdf5/pull/6160
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/dd3080a58cc6bb86f3b34284399915da9e513262 (2.1.0)
 CVE-2026-17572 (Heap-based buffer overflow in the SOHM list-index deserialization code ...)
 	- hdf5 <unfixed> (bug #1142999)
+	[bookworm] - hdf5 <postponed> (Minor issue)
+	[bullseye] - hdf5 <postponed> (Minor issue)
 	NOTE: https://github.com/HDFGroup/hdf5/issues/6501
 	NOTE: https://github.com/HDFGroup/hdf5/pull/6499
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/20f0b9564bc46154e60f8d35578720a599d41552 (2.2.0-rc1)


=====================================
data/dla-needed.txt
=====================================
@@ -677,6 +677,9 @@ py7zr
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: CVE-2026-23879 (GHSA range <=1.1.2); Debian 0.11.3 in range.
 --
+pyasn1
+  NOTE: 20260802: Added by Front-Desk (ta)
+--
 pypdf2/bullseye (dleidert)
   NOTE: 20260328: Added by Front-Desk (Beuc)
   NOTE: 20260328: 6 new CVEs, and lots of postponed issues piled-up (Beuc/front-desk)
@@ -915,6 +918,9 @@ unbound
   NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
   NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
 --
+unzip
+  NOTE: 20260802: Added by Front-Desk (ta)
+--
 uriparser/bullseye
   NOTE: 20260519: Added by Front-Desk (Beuc)
   NOTE: 20260519: Many postponed CVEs piled-up (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96a4f37088a52777b3469a9c0fda7e064a2d4b0b...f328a0470b8695958f90fecf46360429e294ea83

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96a4f37088a52777b3469a9c0fda7e064a2d4b0b...f328a0470b8695958f90fecf46360429e294ea83
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/5d1b82a8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list