[Git][security-tracker-team/security-tracker][master] 3 commits: add unzip
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Sun Aug 2 09:44:08 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4aa72bc8 by Thorsten Alteholz at 2026-08-02T10:25:56+02:00
add unzip
- - - - -
3fe0a30d by Thorsten Alteholz at 2026-08-02T10:29:40+02:00
add pyasn1
- - - - -
f328a047 by Thorsten Alteholz at 2026-08-02T10:35:50+02:00
mark CVE-2026-17572, CVE-2026-17573 and CVE-2026-17572 as postponed for Bullseye and Bookworm
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -5376,14 +5376,20 @@ CVE-2026-17612 (Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prio
NOT-FOR-US: Honeywell
CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability. Processing a c ...)
- hdf5 <unfixed> (bug #1143001)
+ [bookworm] - hdf5 <postponed> (Minor issue)
+ [bullseye] - hdf5 <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc (2.2.0-rc1)
CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library. Proces ...)
- hdf5 <unfixed> (bug #1143000)
+ [bookworm] - hdf5 <postponed> (Minor issue)
+ [bullseye] - hdf5 <postponed> (Minor issue)
NOTE: https://github.com/HDFGroup/hdf5/issues/6124
NOTE: https://github.com/HDFGroup/hdf5/pull/6160
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/dd3080a58cc6bb86f3b34284399915da9e513262 (2.1.0)
CVE-2026-17572 (Heap-based buffer overflow in the SOHM list-index deserialization code ...)
- hdf5 <unfixed> (bug #1142999)
+ [bookworm] - hdf5 <postponed> (Minor issue)
+ [bullseye] - hdf5 <postponed> (Minor issue)
NOTE: https://github.com/HDFGroup/hdf5/issues/6501
NOTE: https://github.com/HDFGroup/hdf5/pull/6499
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/20f0b9564bc46154e60f8d35578720a599d41552 (2.2.0-rc1)
=====================================
data/dla-needed.txt
=====================================
@@ -677,6 +677,9 @@ py7zr
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-23879 (GHSA range <=1.1.2); Debian 0.11.3 in range.
--
+pyasn1
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
pypdf2/bullseye (dleidert)
NOTE: 20260328: Added by Front-Desk (Beuc)
NOTE: 20260328: 6 new CVEs, and lots of postponed issues piled-up (Beuc/front-desk)
@@ -915,6 +918,9 @@ unbound
NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
--
+unzip
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
uriparser/bullseye
NOTE: 20260519: Added by Front-Desk (Beuc)
NOTE: 20260519: Many postponed CVEs piled-up (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96a4f37088a52777b3469a9c0fda7e064a2d4b0b...f328a0470b8695958f90fecf46360429e294ea83
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/96a4f37088a52777b3469a9c0fda7e064a2d4b0b...f328a0470b8695958f90fecf46360429e294ea83
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/5d1b82a8/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list