[Git][security-tracker-team/security-tracker][master] 4 commits: mark CVE-2026-6390 as postponed for Bookworm and Bullseye

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sun Aug 2 18:42:52 BST 2026



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eb79b731 by Thorsten Alteholz at 2026-08-02T19:42:34+02:00
mark CVE-2026-6390 as postponed for Bookworm and Bullseye

- - - - -
f1c95502 by Thorsten Alteholz at 2026-08-02T19:42:35+02:00
add open-iscsi

- - - - -
e50721c5 by Thorsten Alteholz at 2026-08-02T19:42:37+02:00
mark CVE-2026-13346 as postponed for Bookworm and Bullseye

- - - - -
4640d065 by Thorsten Alteholz at 2026-08-02T19:42:39+02:00
mark CVE-2026-15037 and CVE-2026-9499 as postponed for Bookworm and Bullseye

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -3785,6 +3785,8 @@ CVE-2026-13425 (The Database for CF7 plugin for WordPress is vulnerable to Store
 CVE-2026-13346 (pip would incorrectly handle doubly-encoded package URLs from indexes  ...)
 	- python-pip <unfixed> (bug #1143072)
 	[trixie] - python-pip <no-dsa> (Minor issue)
+	[bookworm] - python-pip <postponed> (Minor issue)
+	[bullseye] - python-pip <postponed> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/L2BNQGGVQCEV7DROOORQ7WFKKFF2OOQX/
 	NOTE: https://github.com/pypa/pip/pull/14110
 	NOTE: Fixed by: https://github.com/pypa/pip/commit/10dfb6b9005484578b386f64b9f36982e3dc6679 (26.2)
@@ -8489,7 +8491,10 @@ CVE-2026-15348 (The Premium Packages \u2013 Sell Digital Products Securely plugi
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15037 (Improper output neutralization (XML injection) in QDom comment, CDATA, ...)
 	- qt6-base <unfixed>
+	[bookworm] - qt6-base <postponed> (Minor issue)
 	- qtbase-opensource-src <unfixed>
+	[bookworm] - qtbase-opensource-src <postponed> (Minor issue)
+	[bullseye] - qtbase-opensource-src <postponed> (Minor issue)
 	NOTE: https://codereview.qt-project.org/c/qt/qtbase/+/748323
 CVE-2026-15017 (The MDJM Event Management plugin for WordPress is vulnerable to Privil ...)
 	NOT-FOR-US: WordPress plugin
@@ -8533,6 +8538,8 @@ CVE-2026-7120 (@fastify/static evaluates the allowedPath callback before normali
 	NOT-FOR-US: fastify/static
 CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message handling. Wh ...)
 	- nano <unfixed>
+	[bookworm] - nano <postponed> (Minor issue)
+	[bullseye] - nano <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2458767
 	TODO: check upstream status
 CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation vulnerab ...)
@@ -11733,7 +11740,10 @@ CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to 150.0
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in QText ...)
 	- qt6-5compat 6.10.2-4 (bug #1142690)
+	[bookworm] - qt6-5compat <postponed> (Minor issue)
 	- qtbase-opensource-src 5.15.19+dfsg-4 (bug #1142691)
+	[bookworm] - qtbase-opensource-src <postponed> (Minor issue)
+	[bullseye] - qtbase-opensource-src <postponed> (Minor issue)
 	NOTE: https://codereview.qt-project.org/c/qt/qt5compat/+/723911
 	NOTE: https://codereview.qt-project.org/c/qt/qt5compat/+/724348 (6.11 branch)
 	NOTE: https://codereview.qt-project.org/c/qt/qt5compat/+/724995 (6.10 branch)


=====================================
data/dla-needed.txt
=====================================
@@ -589,6 +589,9 @@ opam/bullseye
   NOTE: 20260716: Added by Front-Desk (Beuc)
   NOTE: 20260716: Follow DSA-6386-1 and DLA-4684-1 (1 CVE) (Beuc/front-desk)
 --
+open-iscsi
+  NOTE: 20260802: Added by Front-Desk (ta)
+--
 openexr
   NOTE: 20260413: Added by Front-Desk (rouca)
   NOTE: 20260713: Also add for bookworm (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1102a144f0855d642ede2257302cdff80bfcefd1...4640d065e6651a27dcdc3702e8f30e8013fdda57

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1102a144f0855d642ede2257302cdff80bfcefd1...4640d065e6651a27dcdc3702e8f30e8013fdda57
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/a24a1285/attachment.htm>


More information about the debian-security-tracker-commits mailing list