[Git][security-tracker-team/security-tracker][master] 4 commits: mark CVE-2026-6390 as postponed for Bookworm and Bullseye
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Sun Aug 2 18:42:52 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eb79b731 by Thorsten Alteholz at 2026-08-02T19:42:34+02:00
mark CVE-2026-6390 as postponed for Bookworm and Bullseye
- - - - -
f1c95502 by Thorsten Alteholz at 2026-08-02T19:42:35+02:00
add open-iscsi
- - - - -
e50721c5 by Thorsten Alteholz at 2026-08-02T19:42:37+02:00
mark CVE-2026-13346 as postponed for Bookworm and Bullseye
- - - - -
4640d065 by Thorsten Alteholz at 2026-08-02T19:42:39+02:00
mark CVE-2026-15037 and CVE-2026-9499 as postponed for Bookworm and Bullseye
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -3785,6 +3785,8 @@ CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Store
CVE-2026-13346 (pip would incorrectly handle doubly-encoded package URLs from indexes ...)
- python-pip <unfixed> (bug #1143072)
[trixie] - python-pip <no-dsa> (Minor issue)
+ [bookworm] - python-pip <postponed> (Minor issue)
+ [bullseye] - python-pip <postponed> (Minor issue)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/
NOTE: https://github.com/pypa/pip/pull/14110
NOTE: Fixed by: https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679 (26.2)
@@ -8489,7 +8491,10 @@ CVE-2026-15348 (The Premium Packages \u2013 Sell Digital Products Securely plugi
NOT-FOR-US: WordPress plugin
CVE-2026-15037 (Improper output neutralization (XML injection) in QDom comment, CDATA, ...)
- qt6-base <unfixed>
+ [bookworm] - qt6-base <postponed> (Minor issue)
- qtbase-opensource-src <unfixed>
+ [bookworm] - qtbase-opensource-src <postponed> (Minor issue)
+ [bullseye] - qtbase-opensource-src <postponed> (Minor issue)
NOTE: https://codereview.qt-project.org/c/qt/qtbase/+/748323
CVE-2026-15017 (The MDJM Event Management plugin for WordPress is vulnerable to Privil ...)
NOT-FOR-US: WordPress plugin
@@ -8533,6 +8538,8 @@ CVE-2026-7120 (@fastify/static evaluates the allowedPath callback before normali
NOT-FOR-US: fastify/static
CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message handling. Wh ...)
- nano <unfixed>
+ [bookworm] - nano <postponed> (Minor issue)
+ [bullseye] - nano <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2458767
TODO: check upstream status
CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation vulnerab ...)
@@ -11733,7 +11740,10 @@ CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to 150.0
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in QText ...)
- qt6-5compat 6.10.2-4 (bug #1142690)
+ [bookworm] - qt6-5compat <postponed> (Minor issue)
- qtbase-opensource-src 5.15.19+dfsg-4 (bug #1142691)
+ [bookworm] - qtbase-opensource-src <postponed> (Minor issue)
+ [bullseye] - qtbase-opensource-src <postponed> (Minor issue)
NOTE: https://codereview.qt-project.org/c/qt/qt5compat/+/723911
NOTE: https://codereview.qt-project.org/c/qt/qt5compat/+/724348 (6.11 branch)
NOTE: https://codereview.qt-project.org/c/qt/qt5compat/+/724995 (6.10 branch)
=====================================
data/dla-needed.txt
=====================================
@@ -589,6 +589,9 @@ opam/bullseye
NOTE: 20260716: Added by Front-Desk (Beuc)
NOTE: 20260716: Follow DSA-6386-1 and DLA-4684-1 (1 CVE) (Beuc/front-desk)
--
+open-iscsi
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
openexr
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260713: Also add for bookworm (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1102a144f0855d642ede2257302cdff80bfcefd1...4640d065e6651a27dcdc3702e8f30e8013fdda57
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1102a144f0855d642ede2257302cdff80bfcefd1...4640d065e6651a27dcdc3702e8f30e8013fdda57
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/a24a1285/attachment.htm>
More information about the debian-security-tracker-commits
mailing list