[Git][security-tracker-team/security-tracker][master] 6 commits: mark CVE-2026-64611 as postponed
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Sun Aug 2 18:23:37 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3727610d by Thorsten Alteholz at 2026-08-02T19:23:23+02:00
mark CVE-2026-64611 as postponed
- - - - -
cbfbb018 by Thorsten Alteholz at 2026-08-02T19:23:23+02:00
mark CVE-2026-64612 as postponed for Bullseye and Bookworm
- - - - -
70a26e5a by Thorsten Alteholz at 2026-08-02T19:23:24+02:00
add jbig2dec
- - - - -
1b7a9cd3 by Thorsten Alteholz at 2026-08-02T19:23:24+02:00
mark CVE-2026-60075 and CVE-2026-60074 as postponed for Bookworm and Bullseye
- - - - -
05898b61 by Thorsten Alteholz at 2026-08-02T19:23:24+02:00
add libnet-dns-perl
- - - - -
6af70faa by Thorsten Alteholz at 2026-08-02T19:23:24+02:00
add librest
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1467,11 +1467,15 @@ CVE-2024-25039 (IBM Engineering Requirements Management DOORS and DOORS Web Acce
CVE-2026-60075 (Date::Manip versions through 6.99 for Perl allow CPU exhaustion via qu ...)
- libdate-manip-perl 6.99-2 (bug #1143125)
[trixie] - libdate-manip-perl <no-dsa> (Minor issue)
+ [bookworm] - libdate-manip-perl <postponed> (Minor issue)
+ [bullseye] - libdate-manip-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42266599/
NOTE: https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60075-r1.patch
CVE-2026-60074 (Date::Manip versions through 6.99 for Perl return corrupted dates via ...)
- libdate-manip-perl 6.99-2 (bug #1143125)
[trixie] - libdate-manip-perl <no-dsa> (Minor issue)
+ [bookworm] - libdate-manip-perl <postponed> (Minor issue)
+ [bullseye] - libdate-manip-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42266594/
NOTE: https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch
CVE-2026-53587
@@ -8216,6 +8220,8 @@ CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image downl
NOT-FOR-US: Joomla
CVE-2026-64611 (A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ...)
- libcupsfilters <unfixed> (bug #1142686)
+ [bookworm] - libcupsfilters <postponed> (Minor issue)
+ [bullseye] - libcupsfilters <postponed> (Minor issue)
NOTE: https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4
NOTE: Fixed by: https://github.com/OpenPrinting/libcupsfilters/commit/4b343522823403df01f6753082df83f07d18c217
TODO: check use in embedded cups, cups-filters
@@ -12682,7 +12688,11 @@ CVE-2026-64620 (FreeRDP before 3.28.0 (affected <=3.27.1) contains a heap-based
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc
CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG image rea ...)
- libcupsfilters <unfixed> (bug #1142687)
+ [bookworm] - libcupsfilters <postponed> (Minor issue)
+ [bullseye] - libcupsfilters <postponed> (Minor issue)
- cups-filters <unfixed>
+ [bookworm] - cups-filters <postponed> (Minor issue)
+ [bullseye] - cups-filters <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502801
NOTE: https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-7mxj-cfq5-84ch (not public)
CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of Service via de ...)
=====================================
data/dla-needed.txt
=====================================
@@ -291,6 +291,9 @@ jackson-databind
NOTE: 20260709: CVE-2026-54512/54513/54514/54515 hit 2.12(bullseye)+2.14(bookworm);
NOTE: 20260709: 54516/54517/54518 (>=2.21) and 50193 (bookworm 2.14) not-affected.
--
+jbig2dec
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
jetty9
NOTE: 20260418: Added by Front-Desk. Fix CVE-2026-5795 maybe other (rouca)
--
@@ -367,6 +370,9 @@ libio-compress-perl
NOTE: 20260612: Added by Front-Desk (rouca)
NOTE: 20260612: MUST hold-back following the upper suites and wait for green light from security team (rouca/FD)
--
+libnet-dns-perl
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
libpgjava
NOTE: 20260613: Added by Front-Desk (rouca)
--
@@ -377,6 +383,9 @@ libreoffice/bullseye (santiago)
NOTE: 20260508: Added by Front-Desk (dleidert)
NOTE: 20260508: Follow DSA-6251-1 (dleidert/front-desk)
--
+librest
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
libreswan/bookworm
NOTE: 20230301: Added by Security Team (jmm)
NOTE: 20260611: bookworm LTS handover.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/da18b782745a71eb5d3a8962718f41db7f712737...6af70faa5476ef363dd428ad83ff17a324983f2c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/da18b782745a71eb5d3a8962718f41db7f712737...6af70faa5476ef363dd428ad83ff17a324983f2c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/86771e72/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list