[Git][security-tracker-team/security-tracker][helmutg/type-improvements] 251 commits: Correct source package association of CVE-2026-55995 to open-isns
Helmut Grohne (@helmutg)
helmutg at debian.org
Mon Aug 3 06:29:03 BST 2026
Helmut Grohne pushed to branch helmutg/type-improvements at Debian Security Tracker / security-tracker
Commits:
0c2059a8 by Salvatore Bonaccorso at 2026-07-30T06:36:25+02:00
Correct source package association of CVE-2026-55995 to open-isns
- - - - -
124c4f5e by Helmut Grohne at 2026-07-30T06:36:57+02:00
web tracker: delete broken unix socket server
The Service and WebService classes are utterly broken on Python 3.x,
because they mix and match str and bytes. As the rest of the code
evolved to use Python 3.x features, it has become evident that nobody
has used this code in probably a decade. Delete it.
- - - - -
01dd9028 by Salvatore Bonaccorso at 2026-07-30T06:42:18+02:00
Fix typo in GHSA reference for CVE-2026-54603
- - - - -
a7dbc68a by Salvatore Bonaccorso at 2026-07-30T07:22:21+02:00
Update status for CVE-2026-14957/libreswan
- - - - -
1b483935 by Salvatore Bonaccorso at 2026-07-30T07:32:51+02:00
Add upstream tag for CVE-2026-13346/pip
- - - - -
38f4d03a by Salvatore Bonaccorso at 2026-07-30T07:35:38+02:00
Add upstream reference for geary issue
- - - - -
e31f795c by Salvatore Bonaccorso at 2026-07-30T09:04:05+02:00
Add Debian bug references for reported issues
- - - - -
3c4eac01 by Salvatore Bonaccorso at 2026-07-30T09:07:53+02:00
Update status or CVE-2026-10722
- - - - -
96b20b60 by security tracker role at 2026-07-30T07:12:18+00:00
automatic update
- - - - -
ef6bcbdc by security tracker role at 2026-07-30T07:13:12+00:00
automatic NOT-FOR-US entries update
- - - - -
2505c6c7 by Salvatore Bonaccorso at 2026-07-30T09:17:37+02:00
Add new batch of chromium issues
- - - - -
7ddf581e by Salvatore Bonaccorso at 2026-07-30T09:19:14+02:00
Earlier batch of chromium issues already fixed in unstable
- - - - -
62fd926d by Salvatore Bonaccorso at 2026-07-30T09:43:13+02:00
Update status for node-ws issues
CVE-2026-62389 got rejected because it is a duplicate of CVE-2026-48779.
Merge useful tracking information from CVE-2026-62389 to CVE-2026-48779.
- - - - -
51756ce1 by Salvatore Bonaccorso at 2026-07-30T09:49:56+02:00
Remove notes from CVEs which got withdrawn by the assigning CNA
- - - - -
72e71350 by Salvatore Bonaccorso at 2026-07-30T10:10:50+02:00
Add CVE-2026-66066/rails
- - - - -
19f1549d by Salvatore Bonaccorso at 2026-07-30T10:18:31+02:00
Reference upstream commit for CVE-2026-66066
- - - - -
1b1e1c9c by Salvatore Bonaccorso at 2026-07-30T10:20:17+02:00
Add new imagemagick issues
- - - - -
ac0e238c by Salvatore Bonaccorso at 2026-07-30T10:21:43+02:00
Add Debian bug reference for CVE-2026-66066/rails
- - - - -
dc65c13e by Salvatore Bonaccorso at 2026-07-30T10:30:20+02:00
Process some NFUs
- - - - -
0ba85664 by Salvatore Bonaccorso at 2026-07-30T10:31:02+02:00
Add new pgvector issue
- - - - -
278f019d by Salvatore Bonaccorso at 2026-07-30T10:31:27+02:00
Add more node-undici issues
- - - - -
60c2e598 by Salvatore Bonaccorso at 2026-07-30T10:31:47+02:00
Add new batch of pcp issues
- - - - -
253566b8 by Aron Xu at 2026-07-30T16:34:55+08:00
DSA for expat
- - - - -
570a72ea by Aron Xu at 2026-07-30T16:37:49+08:00
Take nginx
- - - - -
b47e2cf5 by Salvatore Bonaccorso at 2026-07-30T11:21:46+02:00
Add new nodejs issues
- - - - -
910c3faa by Salvatore Bonaccorso at 2026-07-30T11:24:44+02:00
Remove no-dsa tagged entries for CVEs which got an update for expat
- - - - -
a28cba02 by Salvatore Bonaccorso at 2026-07-30T11:25:09+02:00
Add missing list of CVEs for DSA-6404-1/expat
- - - - -
04a824d6 by Henri Salo at 2026-07-30T14:13:27+03:00
NFU Apache Zeppelin
- - - - -
d15746ea by Henri Salo at 2026-07-30T14:14:55+03:00
NFU Apache Kyuubi
- - - - -
6d7aa3cf by Salvatore Bonaccorso at 2026-07-30T13:45:37+02:00
Merge Linux CVEs from kernel-sec
- - - - -
1f657782 by Salvatore Bonaccorso at 2026-07-30T14:08:12+02:00
Add reference for CVE-2026-53167
- - - - -
6c4575f1 by Salvatore Bonaccorso at 2026-07-30T14:16:28+02:00
Track fixed version for erlang issues
- - - - -
119f42e1 by Henri Salo at 2026-07-30T15:38:09+03:00
NFU Apache Superset
- - - - -
af9c37e0 by Salvatore Bonaccorso at 2026-07-30T15:10:36+02:00
Add two new swift issues
- - - - -
ce8cda3c by Salvatore Bonaccorso at 2026-07-30T15:15:21+02:00
Track fixed version for one node-body-parser issue
- - - - -
6bc3d666 by Salvatore Bonaccorso at 2026-07-30T15:18:21+02:00
Two node-ajv issues fixed via unstable
- - - - -
73926a5e by Abhijith PA at 2026-07-30T19:48:11+05:30
Add patch references for xrdp
- - - - -
76a63f84 by Salvatore Bonaccorso at 2026-07-30T16:38:54+02:00
Track fixed version for CVE-2026-54272 via unstable
- - - - -
c356ab03 by Salvatore Bonaccorso at 2026-07-30T16:45:40+02:00
Reference upstream tag for CVE-2026-15588/glib2.0
- - - - -
5287d833 by Salvatore Bonaccorso at 2026-07-30T16:54:28+02:00
Track node-undici fixes via unstable upload
- - - - -
0b8f365d by Salvatore Bonaccorso at 2026-07-30T17:00:06+02:00
Track as well rust-glib-0.18 source for RUSTSEC-2024-0429
- - - - -
7d9c1f83 by Salvatore Bonaccorso at 2026-07-30T17:19:04+02:00
Add new php issues
- - - - -
63caa1fa by Salvatore Bonaccorso at 2026-07-30T17:28:47+02:00
Add CVE-2026-62268/borgbackup
- - - - -
e201c0c8 by Salvatore Bonaccorso at 2026-07-30T17:32:08+02:00
Update status for CVE-2026-12804/lemonldap-ng
- - - - -
0291f881 by Salvatore Bonaccorso at 2026-07-30T19:19:06+02:00
Add new set of libgit2 issues
- - - - -
72487167 by Salvatore Bonaccorso at 2026-07-30T19:34:28+02:00
Add reference for CVE-2026-53264
- - - - -
2b1fa6df by Abhijith PA at 2026-07-31T00:06:10+05:30
Reserve DLA-4706-1 for ruby-rack
- - - - -
7c9cf646 by Salvatore Bonaccorso at 2026-07-30T20:38:14+02:00
Add two new libdate-manip-perl issues
- - - - -
27534d5b by Salvatore Bonaccorso at 2026-07-30T20:46:31+02:00
Reference advisory for CVE-2026-18107/criu
- - - - -
ff76ce2c by Salvatore Bonaccorso at 2026-07-30T21:01:45+02:00
Add Debian bug reference for libdate-manip-perl issues
- - - - -
5236cba7 by Salvatore Bonaccorso at 2026-07-30T21:04:46+02:00
Add Debian bug reference for CVE-2026-60102/php-horde-vfs
- - - - -
cf67cf12 by security tracker role at 2026-07-30T19:13:27+00:00
automatic update
- - - - -
5236899e by security tracker role at 2026-07-30T19:14:20+00:00
automatic NOT-FOR-US entries update
- - - - -
280af689 by Salvatore Bonaccorso at 2026-07-30T21:20:38+02:00
Add Debian bug reference for CVE-2026-18022/pgvector
- - - - -
56183136 by Salvatore Bonaccorso at 2026-07-30T21:27:09+02:00
Add todo item for CVE-2026-6657 to reflect ongoing discussion to CNA
- - - - -
9226430a by Salvatore Bonaccorso at 2026-07-30T21:34:32+02:00
Add todo item for CVE-2026-5422 to reflect CNA action status
- - - - -
e0128950 by Salvatore Bonaccorso at 2026-07-30T21:42:06+02:00
Update status for CVE-2026-18022
- - - - -
27064b5a by Salvatore Bonaccorso at 2026-07-30T22:25:23+02:00
Process some NFUs
- - - - -
7b93209d by Salvatore Bonaccorso at 2026-07-30T22:26:31+02:00
Add CVE-2026-67351/serendipity
- - - - -
ca1308cd by Salvatore Bonaccorso at 2026-07-30T22:28:42+02:00
Add CVE-2026-59881/python-aiohttp
- - - - -
79275285 by Salvatore Bonaccorso at 2026-07-30T22:29:32+02:00
Add CVE-2026-57862/kanboard
- - - - -
4dba3389 by Salvatore Bonaccorso at 2026-07-30T22:31:06+02:00
Add CVE-2026-54522/ruby-msgpack
- - - - -
75f1c174 by Salvatore Bonaccorso at 2026-07-30T22:33:50+02:00
Add new jspwiki issues
- - - - -
a6d8f0de by Salvatore Bonaccorso at 2026-07-30T22:34:56+02:00
Add CVE-2026-18369/dogtag-pki
- - - - -
0934c403 by Salvatore Bonaccorso at 2026-07-30T22:35:58+02:00
Add CVE-2026-13379
- - - - -
0f9998b5 by Salvatore Bonaccorso at 2026-07-30T22:46:09+02:00
Track fixed version for libdate-manip-perl issues via unstable
- - - - -
8f8a84a9 by Daniel Leidert at 2026-07-31T03:42:13+02:00
lts/dla-needed: claim node-tar to upload the prepared OSPU
I
- - - - -
ecfe199b by Carlos Henrique Lima Melara at 2026-07-30T23:30:38-03:00
Reserve DLA-4707-1 for gsasl
- - - - -
36857b05 by Salvatore Bonaccorso at 2026-07-31T07:07:53+02:00
Add CVE-2026-9672/libgd2
- - - - -
2b3890c3 by Salvatore Bonaccorso at 2026-07-31T07:09:15+02:00
Add Debian bug reference for php issues
- - - - -
88e47b73 by Salvatore Bonaccorso at 2026-07-31T07:41:03+02:00
Add Debian bug references for various issues
- - - - -
fcb7a928 by security tracker role at 2026-07-31T07:12:28+00:00
automatic update
- - - - -
4775c20b by security tracker role at 2026-07-31T07:13:21+00:00
automatic NOT-FOR-US entries update
- - - - -
8759f54f by Salvatore Bonaccorso at 2026-07-31T09:23:01+02:00
Track fixed version for aom issues fixed via unstable upload
- - - - -
8a63279e by Salvatore Bonaccorso at 2026-07-31T09:25:48+02:00
Track fixed version for CVE-2026-9672/libgd2 via unstable
- - - - -
75195ecf by Salvatore Bonaccorso at 2026-07-31T09:48:06+02:00
Process some NFUs
- - - - -
db31447b by Salvatore Bonaccorso at 2026-07-31T09:51:43+02:00
Add two new node-re2 issues
- - - - -
c3355e5b by Salvatore Bonaccorso at 2026-07-31T09:53:54+02:00
Add two new tika issues
- - - - -
467ef2c0 by Salvatore Bonaccorso at 2026-07-31T09:54:54+02:00
Add new codeigniter issues
- - - - -
963de199 by Salvatore Bonaccorso at 2026-07-31T09:56:14+02:00
Add libgd2 and php8.4 to dsa-needed list
Maintainer (ondrej) preparing updates.
- - - - -
e8cc8a89 by Salvatore Bonaccorso at 2026-07-31T10:25:08+02:00
Process some NFUs
- - - - -
cedb3f42 by Salvatore Bonaccorso at 2026-07-31T10:26:23+02:00
Add new goaccess issues
- - - - -
673f90a0 by Salvatore Bonaccorso at 2026-07-31T10:27:33+02:00
Add CVE-2026-10031/sftpgo
- - - - -
0c1ecb16 by Salvatore Bonaccorso at 2026-07-31T11:42:03+02:00
Add new set of open62541 issues
- - - - -
465fc9e2 by Abhijith PA at 2026-07-31T15:13:58+05:30
Mark CVE-2025-58767 as ignored in bullseye. Minor issue
Intrusive to backport.
- - - - -
1f1c0104 by Salvatore Bonaccorso at 2026-07-31T11:48:11+02:00
Track fixed version for chromium issues via unstable
- - - - -
56ddca4c by Salvatore Bonaccorso at 2026-07-31T11:49:26+02:00
Update status for CVE-2026-42492/xen
Thanks: Hans van Kranenburg
- - - - -
0cd56cd1 by Henri Salo at 2026-07-31T14:33:32+03:00
NFU Apache Kyuubi
- - - - -
e1011bab by Salvatore Bonaccorso at 2026-07-31T14:07:38+02:00
Add Debian bug reference for node-re2 issues
- - - - -
a92c5e40 by Salvatore Bonaccorso at 2026-07-31T14:54:19+02:00
Add Debian bug references for goaccess issues
- - - - -
5b79c12f by Salvatore Bonaccorso at 2026-07-31T15:45:42+02:00
Add incus to dsa-needed list
- - - - -
08e1c52a by Salvatore Bonaccorso at 2026-07-31T15:50:46+02:00
Reserve DSA number for linux update
- - - - -
8d349775 by Abhijith PA at 2026-07-31T19:26:07+05:30
data/dla-needed.txt: Update ruby2.7 note.
- - - - -
8586e226 by Salvatore Bonaccorso at 2026-07-31T16:19:22+02:00
Add CVE-2026-55707/neutron
- - - - -
b6e622c8 by Salvatore Bonaccorso at 2026-07-31T16:38:48+02:00
Add initial tracking for incus issues
- - - - -
5b0be83e by Salvatore Bonaccorso at 2026-07-31T16:42:33+02:00
Two incus issues do not affect trixie, vulnerable code not present in 6.0 series
- - - - -
082a8650 by Salvatore Bonaccorso at 2026-07-31T16:45:18+02:00
Track fixed version for php8.4 issues
- - - - -
6e75f57d by Andrej Shadura at 2026-07-31T17:20:41+02:00
Claim DLA-4708-1
- - - - -
7456d6f0 by Andrej Shadura at 2026-07-31T17:43:47+02:00
Mark bookworm python-authlib fixed versions
- - - - -
ecb2f041 by Salvatore Bonaccorso at 2026-07-31T19:16:32+02:00
Track fixed version for two open-iscsi issues
- - - - -
e270b87b by Thorsten Alteholz at 2026-07-31T19:23:55+02:00
mark CVE-2026-14957 as EOL for Bullseye
- - - - -
bb0a0c33 by Thorsten Alteholz at 2026-07-31T19:23:57+02:00
mark CVE-2026-6879 as EOL for Bullseye
- - - - -
4332ed3b by Thorsten Alteholz at 2026-07-31T19:23:59+02:00
mark CVE-2026-67214 and CVE-2026-67213 as postponed for Bullseye
- - - - -
5535473d by Thorsten Alteholz at 2026-07-31T19:24:00+02:00
add libgd2
- - - - -
0883e9c5 by Thorsten Alteholz at 2026-07-31T19:24:00+02:00
add librabbitmq
- - - - -
179287bc by Thorsten Alteholz at 2026-07-31T19:27:48+02:00
add libssh
- - - - -
0dd47110 by Thorsten Alteholz at 2026-07-31T19:31:25+02:00
add libyaml-syck-perl
- - - - -
93e28a48 by Thorsten Alteholz at 2026-07-31T19:37:24+02:00
add opensc
- - - - -
5bde46ed by Thorsten Alteholz at 2026-07-31T19:40:13+02:00
libxmltok needs to be fixed in bookworm as well
- - - - -
7eaf748f by Salvatore Bonaccorso at 2026-07-31T20:26:32+02:00
auto-nfu: Add two more products for the VMware CNA rule
- - - - -
ebf9d319 by Salvatore Bonaccorso at 2026-07-31T20:26:35+02:00
Process some NFUs
- - - - -
cc4076c3 by Abhijith PA at 2026-08-01T00:19:59+05:30
Mark CVE-2026-35512 CVE-2026-42218 as not-affected for both
bullseye and bookworm. Mark CVE-2026-55626 as not bullseye.
CVE-2026-35512, EGFX (graphics dynamic virtual channel) function
implemented in version v0.10.0-ard-macos.
CVE-2026-42218 CVE-2026-55626 sesman/sesexec functions mentioned
in the patches not present in version 0.9.21.1.
- - - - -
7f80df2f by Abhijith PA at 2026-08-01T00:42:13+05:30
data/dla-needed.txt: update note for xrdp
- - - - -
7f0e07b3 by security tracker role at 2026-07-31T19:18:26+00:00
automatic update
- - - - -
8342ea58 by security tracker role at 2026-07-31T19:19:14+00:00
automatic NOT-FOR-US entries update
- - - - -
d7ab54dc by Salvatore Bonaccorso at 2026-07-31T21:35:17+02:00
Add libyaml-syck-perl to dsa-needed list
- - - - -
bafda488 by Salvatore Bonaccorso at 2026-07-31T21:38:19+02:00
Cleanup several rejected CVEs
- - - - -
6650770c by Salvatore Bonaccorso at 2026-07-31T22:07:24+02:00
Process some NFUs
- - - - -
ea91b590 by Salvatore Bonaccorso at 2026-07-31T22:08:17+02:00
Add CVE-2026-67350/serendipity
- - - - -
ef92cceb by Salvatore Bonaccorso at 2026-07-31T22:10:20+02:00
Add new httpcomponents client issue, needs more triage
- - - - -
454bd3ce by Salvatore Bonaccorso at 2026-07-31T22:11:06+02:00
Add new set of thumbor issues
- - - - -
bfafec33 by Salvatore Bonaccorso at 2026-07-31T22:14:43+02:00
Add CVE-2026-18446/node-ajv (providing fast-uri)
- - - - -
1df34b7e by Salvatore Bonaccorso at 2026-07-31T22:19:28+02:00
Add CVE-2026-18358/gnome-remote-desktop
- - - - -
b740e825 by Salvatore Bonaccorso at 2026-07-31T22:20:36+02:00
Add CVE-2026-18321/ntpsec
- - - - -
5b360260 by Salvatore Bonaccorso at 2026-07-31T22:21:33+02:00
Add new keycloak issues
- - - - -
dc01bbbe by Salvatore Bonaccorso at 2026-07-31T22:22:33+02:00
Add new pgadmin4 issues, itp'ed
- - - - -
7eb618e7 by Salvatore Bonaccorso at 2026-07-31T22:23:47+02:00
Add two new 389-ds-base issues
- - - - -
82bcc568 by Salvatore Bonaccorso at 2026-07-31T22:25:01+02:00
Add CVE-2026-15227/ckeck-mk
- - - - -
3a2dfbd2 by Salvatore Bonaccorso at 2026-07-31T22:25:41+02:00
Add note for CVE-2026-16221
- - - - -
2b58b038 by Salvatore Bonaccorso at 2026-07-31T23:07:31+02:00
Track source-wise fix for CVE-2026-9672 in php
- - - - -
84f44d10 by Salvatore Bonaccorso at 2026-07-31T23:09:55+02:00
Reserve DSA number for php8.4 update
- - - - -
45ad2768 by Salvatore Bonaccorso at 2026-07-31T23:28:31+02:00
Reserve DSA number for incus update
- - - - -
56abc549 by Guilhem Moulin at 2026-07-31T23:40:09+02:00
Reserve DLA-4709-1 for poppler
- - - - -
65674499 by Andres Salomon at 2026-07-31T20:52:36-04:00
chromium dsa
- - - - -
cde45350 by Daniel Leidert at 2026-08-01T05:02:45+02:00
lts: mark CVE-2026-11771/openvpn as not affecting Bullseye
The vulnerable check was introduced with
https://github.com/OpenVPN/openvpn/commit/6e010d4824b7251d817cf1770e80f186000b99ae
The original check doesn't seem to be vulnerable.
- - - - -
4a24f9bb by Daniel Leidert at 2026-08-01T05:02:47+02:00
lts: mark CVE-2026-12996/openvpn as fixed in version 2.5.1-3+deb11u4
The code didnt exist originally in Bullseye. It got introduced by the upload of
2.5.1-3+deb11u3 and then fixed quickly with the upload of 2.5.1-3+deb11u4. So,
in theory, only 2.5.1-3+deb11u3 was briefly vulnerable.
- - - - -
f329f1e2 by Daniel Leidert at 2026-08-01T05:02:47+02:00
lts/dla-needed: giving back openvpn/bullseye with comments
- - - - -
6c34035c by Salvatore Bonaccorso at 2026-08-01T07:35:10+02:00
Track fixed version for two libarchive issues
- - - - -
efe3eb99 by Salvatore Bonaccorso at 2026-08-01T07:37:03+02:00
Track fix for CVE-2026-42533 via unstable upload
- - - - -
cd54edc1 by Salvatore Bonaccorso at 2026-08-01T07:39:21+02:00
Track fixed version for CVE-2026-15588 via unstable
- - - - -
8c17e22f by Salvatore Bonaccorso at 2026-08-01T08:45:19+02:00
Add CVE-2026-56818/netty
- - - - -
61c448c5 by security tracker role at 2026-08-01T07:12:34+00:00
automatic update
- - - - -
355418ac by security tracker role at 2026-08-01T07:13:25+00:00
automatic NOT-FOR-US entries update
- - - - -
14be3e65 by Salvatore Bonaccorso at 2026-08-01T09:25:34+02:00
Add references for CVE-2026-66066/rails
- - - - -
638c01c3 by Thorsten Alteholz at 2026-08-01T09:30:53+02:00
add adminer
- - - - -
03894892 by Thorsten Alteholz at 2026-08-01T09:30:56+02:00
mark CVE-2026-56390 and CVE-2026-56389 as postponed for Bookworm and Bullseye
- - - - -
78689b9c by Thorsten Alteholz at 2026-08-01T09:30:58+02:00
mark CVE-2026-62268 as postponed for Bookworm and Bullseye
- - - - -
e43f37b1 by Thorsten Alteholz at 2026-08-01T09:31:00+02:00
mark CVE-2026-47143 as postponed for Bookworm and Bullseye
- - - - -
62dfb093 by Thorsten Alteholz at 2026-08-01T09:39:25+02:00
add gawk
- - - - -
0cca93cc by Thorsten Alteholz at 2026-08-01T09:42:57+02:00
add cjson
- - - - -
0bb307b1 by Thorsten Alteholz at 2026-08-01T09:47:39+02:00
add pcp
- - - - -
cb3f2e5f by Salvatore Bonaccorso at 2026-08-01T10:03:23+02:00
Process some NFUs
- - - - -
728dd6e0 by Salvatore Bonaccorso at 2026-08-01T10:08:01+02:00
Add two coturn issues
- - - - -
639b67f5 by Salvatore Bonaccorso at 2026-08-01T10:11:34+02:00
Add CVE-2026-54909/pion-stun
- - - - -
03ad8de1 by Salvatore Bonaccorso at 2026-08-01T10:12:11+02:00
Add CVE-2026-54787/sigstore-go
- - - - -
c46b297c by Emilio Pozuelo Monfort at 2026-08-01T10:36:49+02:00
Reserve DLA-4710-1 for chromium
- - - - -
99bace2d by Salvatore Bonaccorso at 2026-08-01T11:20:02+02:00
Reserve DSA number for libgd2 update
- - - - -
afbabb2f by Guilhem Moulin at 2026-08-01T14:49:45+02:00
CVE-2025-43718/poppler: Reference commit introducing the issue
- - - - -
703ef968 by Guilhem Moulin at 2026-08-01T15:23:17+02:00
CVE-2025-52885/poppler: Reference commit introducing the issue
- - - - -
49f4d495 by Salvatore Bonaccorso at 2026-08-01T16:04:37+02:00
Track proposed update for proftpd-dfsg via trixie-pu
- - - - -
91249437 by Salvatore Bonaccorso at 2026-08-01T16:14:31+02:00
Add CVE-2026-18536/libdata-entropy-perl
- - - - -
7f7edaad by Salvatore Bonaccorso at 2026-08-01T16:19:03+02:00
Track fixed version for CVE-2026-55995/open-isns via unstable
- - - - -
909ad1ea by Salvatore Bonaccorso at 2026-08-01T16:23:08+02:00
Track trixie-pu update for open-isns
- - - - -
9be3db14 by Salvatore Bonaccorso at 2026-08-01T16:28:55+02:00
Track fixed version for CVE-2026-54908 via unstable upload
- - - - -
f12448b6 by Salvatore Bonaccorso at 2026-08-01T16:55:09+02:00
Update status for CVE-2026-54388
- - - - -
482ec894 by Thorsten Alteholz at 2026-08-01T17:00:19+02:00
claim libyaml-syck-perl for carnil
- - - - -
650c9e75 by Daniel Leidert at 2026-08-01T17:04:48+02:00
Reserve DLA-4711-1 for starlette
- - - - -
6c130286 by Daniel Leidert at 2026-08-01T17:15:28+02:00
Reserve DLA-4712-1 for node-tar
- - - - -
8458e9bc by Salvatore Bonaccorso at 2026-08-01T17:17:43+02:00
Add fixing commit for CVE-2026-50019
- - - - -
ec6c0b18 by Salvatore Bonaccorso at 2026-08-01T17:19:23+02:00
Update status for CVE-2026-46600 for trixie
- - - - -
bc1b6300 by Salvatore Bonaccorso at 2026-08-01T17:38:08+02:00
Some MINA SSHD issues were miss-assigned to src:mina2, correct to libmina-sshd-java
Thanks: Utkarsh Gupta for spotting the problem.
- - - - -
b611cc33 by Thorsten Alteholz at 2026-08-01T17:39:52+02:00
add libmodbus
- - - - -
37fa6e48 by Thorsten Alteholz at 2026-08-01T17:39:52+02:00
add sslh
- - - - -
8fafbc1c by Thorsten Alteholz at 2026-08-01T17:39:54+02:00
Reserve DLA-4713-1 for sslh
- - - - -
2632c5ea by Thorsten Alteholz at 2026-08-01T18:43:56+02:00
Reserve DLA-4714-1 for libmodbus
- - - - -
eae59fd5 by Thorsten Alteholz at 2026-08-01T19:12:22+02:00
add jline3
- - - - -
c144d662 by Thorsten Alteholz at 2026-08-01T19:17:51+02:00
mark CVE-2026-39155 as postponed for Bullseye and Bookworm
- - - - -
0a5737c5 by Thorsten Alteholz at 2026-08-01T19:22:24+02:00
mark CVE-2026-15813, CVE-2026-15812 and CVE-2026-15811 as postponed for Bullseye and Bookworm
- - - - -
225088f9 by Thorsten Alteholz at 2026-08-01T19:28:19+02:00
add libdvi-perl
- - - - -
8db68edf by Thorsten Alteholz at 2026-08-01T19:36:49+02:00
add libgit2
- - - - -
413ff2fe by Salvatore Bonaccorso at 2026-08-01T20:23:46+02:00
Reassign CVE-2026-48827 to libmina-sshd-java
- - - - -
a8e7c9e6 by Salvatore Bonaccorso at 2026-08-01T20:23:48+02:00
Triage libmina-sshd-java issues for trixie
- - - - -
8be2805f by Salvatore Bonaccorso at 2026-08-01T20:38:38+02:00
Add Debian bug reference for CVE-2026-18536/libdata-entropy-perl
- - - - -
ee75319f by security tracker role at 2026-08-01T19:13:49+00:00
automatic update
- - - - -
e0993811 by security tracker role at 2026-08-01T19:14:43+00:00
automatic NOT-FOR-US entries update
- - - - -
12dbaf3d by Salvatore Bonaccorso at 2026-08-01T21:28:57+02:00
Add new guzzle issues
- - - - -
ebe8c36c by Salvatore Bonaccorso at 2026-08-01T22:00:14+02:00
Process some NFUs
- - - - -
5f9bd977 by Salvatore Bonaccorso at 2026-08-01T22:17:20+02:00
Add CVE-2026-67338/jupyterlab
- - - - -
0bd2687e by Salvatore Bonaccorso at 2026-08-01T22:18:10+02:00
Add new python-git issues
- - - - -
eab77ccf by Salvatore Bonaccorso at 2026-08-01T22:19:39+02:00
Add new node-axios issues
- - - - -
b6d3392c by Salvatore Bonaccorso at 2026-08-01T22:20:26+02:00
Add CVE-2026-67309/traefik
- - - - -
d0f971a6 by Salvatore Bonaccorso at 2026-08-01T22:20:48+02:00
Note prepared update for libyaml-syck-perl
- - - - -
1afaaa17 by Salvatore Bonaccorso at 2026-08-01T22:30:34+02:00
Add new batch of freerdp3 issues
- - - - -
5df4ee53 by Salvatore Bonaccorso at 2026-08-02T07:22:00+02:00
Track fixed version for CVE-2026-66066/rails
- - - - -
b48d401c by Salvatore Bonaccorso at 2026-08-02T07:39:05+02:00
Add references bugs for various issues
- - - - -
e535077d by Salvatore Bonaccorso at 2026-08-02T07:40:38+02:00
Track fix via unstable for CVE-2026-50813/sqlite3
- - - - -
c5017ed8 by Salvatore Bonaccorso at 2026-08-02T09:08:02+02:00
Add reference for CVE-2026-66755/tika
- - - - -
61efaabf by Salvatore Bonaccorso at 2026-08-02T09:09:42+02:00
Update status for CVE-2026-67320/node-axios
- - - - -
b875c773 by security tracker role at 2026-08-02T07:13:17+00:00
automatic update
- - - - -
ef0702c9 by security tracker role at 2026-08-02T07:14:03+00:00
automatic NOT-FOR-US entries update
- - - - -
8a93129d by Salvatore Bonaccorso at 2026-08-02T09:15:31+02:00
Add references for reported Debian bugs for various issues
- - - - -
f8187166 by Salvatore Bonaccorso at 2026-08-02T09:21:01+02:00
Add CVE-2026-9335/keras
- - - - -
0e2b01e7 by Salvatore Bonaccorso at 2026-08-02T09:21:55+02:00
Add new batch of keycloak issues, itp'ed
- - - - -
8c071347 by Salvatore Bonaccorso at 2026-08-02T09:25:24+02:00
Process one more NFU
- - - - -
159f2df1 by Salvatore Bonaccorso at 2026-08-02T09:27:38+02:00
Update status for CVE-2026-17523
- - - - -
96a4f370 by Salvatore Bonaccorso at 2026-08-02T09:31:58+02:00
Reserve DSA number for libssh update
- - - - -
4aa72bc8 by Thorsten Alteholz at 2026-08-02T10:25:56+02:00
add unzip
- - - - -
3fe0a30d by Thorsten Alteholz at 2026-08-02T10:29:40+02:00
add pyasn1
- - - - -
f328a047 by Thorsten Alteholz at 2026-08-02T10:35:50+02:00
mark CVE-2026-17572, CVE-2026-17573 and CVE-2026-17572 as postponed for Bullseye and Bookworm
- - - - -
947fec14 by Thorsten Alteholz at 2026-08-02T11:02:41+02:00
add urwid
- - - - -
bbaf24ac by Thorsten Alteholz at 2026-08-02T11:08:19+02:00
mark CVE-2026-11703 and CVE-2026-11999 as postponed for Bullseye
- - - - -
39603967 by Thorsten Alteholz at 2026-08-02T11:11:04+02:00
mark CVE-2026-11310, CVE-2026-10592, CVE-2026-10512, CVE-2026-10098 and CVE-2026-10097 as EOL for Bookworm and postponed for Bullseye
- - - - -
ff7da5e5 by Thorsten Alteholz at 2026-08-02T13:52:26+02:00
Reserve DLA-4715-1 for kissfft
- - - - -
7a85708c by Salvatore Bonaccorso at 2026-08-02T18:34:16+02:00
Track fixed version for ocker-registry issues
- - - - -
a074ff6d by Salvatore Bonaccorso at 2026-08-02T18:50:31+02:00
Add two new freerdp3 issues
- - - - -
80049a37 by Salvatore Bonaccorso at 2026-08-02T19:01:32+02:00
Track proposed update for python-aiohttp issues via trixie-pu
- - - - -
a2d97171 by Salvatore Bonaccorso at 2026-08-02T19:13:14+02:00
Track proposed update for avahi via trixie-pu
- - - - -
b4e21ba2 by Salvatore Bonaccorso at 2026-08-02T19:15:40+02:00
Track proposed update for libraw via trixie-pu
- - - - -
d35edc0f by Salvatore Bonaccorso at 2026-08-02T19:18:51+02:00
Track spice-vdagent issues via trixie-pu
- - - - -
da18b782 by Salvatore Bonaccorso at 2026-08-02T19:22:45+02:00
Track alternative for wolfssl via trixie-pu
- - - - -
3727610d by Thorsten Alteholz at 2026-08-02T19:23:23+02:00
mark CVE-2026-64611 as postponed
- - - - -
cbfbb018 by Thorsten Alteholz at 2026-08-02T19:23:23+02:00
mark CVE-2026-64612 as postponed for Bullseye and Bookworm
- - - - -
70a26e5a by Thorsten Alteholz at 2026-08-02T19:23:24+02:00
add jbig2dec
- - - - -
1b7a9cd3 by Thorsten Alteholz at 2026-08-02T19:23:24+02:00
mark CVE-2026-60075 and CVE-2026-60074 as postponed for Bookworm and Bullseye
- - - - -
05898b61 by Thorsten Alteholz at 2026-08-02T19:23:24+02:00
add libnet-dns-perl
- - - - -
6af70faa by Thorsten Alteholz at 2026-08-02T19:23:24+02:00
add librest
- - - - -
c9256588 by Salvatore Bonaccorso at 2026-08-02T19:32:48+02:00
Track proposed update for cyrus-imapd via trixie-pu
- - - - -
f7e96b3c by Salvatore Bonaccorso at 2026-08-02T19:37:54+02:00
Track proposed update for bettercap via trixie-pu
- - - - -
1102a144 by Salvatore Bonaccorso at 2026-08-02T19:39:39+02:00
Track proposed update for dhcpcd via trixie-pu
- - - - -
eb79b731 by Thorsten Alteholz at 2026-08-02T19:42:34+02:00
mark CVE-2026-6390 as postponed for Bookworm and Bullseye
- - - - -
f1c95502 by Thorsten Alteholz at 2026-08-02T19:42:35+02:00
add open-iscsi
- - - - -
e50721c5 by Thorsten Alteholz at 2026-08-02T19:42:37+02:00
mark CVE-2026-13346 as postponed for Bookworm and Bullseye
- - - - -
4640d065 by Thorsten Alteholz at 2026-08-02T19:42:39+02:00
mark CVE-2026-15037 and CVE-2026-9499 as postponed for Bookworm and Bullseye
- - - - -
8d8321ca by Thorsten Alteholz at 2026-08-02T19:52:43+02:00
mark CVE-2026-16461 and CVE-2026-16277 as postponed for Bookworm and Bullseye
- - - - -
2ecfacbe by Salvatore Bonaccorso at 2026-08-02T19:57:46+02:00
Merge branch 'helmutg/delete-dead-webservice' into 'master'
web tracker: delete broken unix socket server
See merge request security-tracker-team/security-tracker!313
- - - - -
0e5b6c77 by Salvatore Bonaccorso at 2026-08-02T21:09:19+02:00
Mark wolfssl issues as no-dsa for trixie
- - - - -
f19ed518 by security tracker role at 2026-08-02T19:12:53+00:00
automatic update
- - - - -
162fd10e by security tracker role at 2026-08-02T19:13:45+00:00
automatic NOT-FOR-US entries update
- - - - -
77d695b8 by Salvatore Bonaccorso at 2026-08-02T21:20:02+02:00
Process some NFUs
- - - - -
8395a56c by Salvatore Bonaccorso at 2026-08-02T21:23:04+02:00
Fix typos in TODO items
- - - - -
21d64579 by Helmut Grohne at 2026-08-03T07:25:10+02:00
lib: change internUrgency not to return None
A number of callers of internUrgency are not prepared to handle its None
return value. Rather than fix all the callers, make it raise an
exception and adapt the one place that wants to handle it.
- - - - -
4a8a298e by Helmut Grohne at 2026-08-03T07:25:10+02:00
lib: change internRelease not to return None
A number of callers of internRelease are not prepared to handle its None
return value. Rather than fix all the callers, make it raise an
exception.
- - - - -
6326d73c by Helmut Grohne at 2026-08-03T07:26:42+02:00
web tracker: delete method pre_dispatch
None of the implementations is non-trivial, but the more striking issue
is that their argument count varies. Rather than figure out, what is
right, dispose this unused mechanism.
- - - - -
f4e39d43 by Helmut Grohne at 2026-08-03T07:26:46+02:00
delete test of isKernOnly
Fixes: efd6f70f4aca ("Remove unused methods")
- - - - -
46ba4067 by Helmut Grohne at 2026-08-03T07:26:46+02:00
security_db.py: use sets
Some of this code predates the introduction of the set type to Python
and uses dicts with True values instead. We can now convert this to
proper sets. More importantly, this helps avoid variable type changes.
The list conversion can be deferred.
- - - - -
04611e8e by Helmut Grohne at 2026-08-03T07:26:46+02:00
tracker_service.py: pass a bool where a bool is expected
The getFakeBugs parameter vulnerability actually expects a bool. Pass it
as such.
- - - - -
54d6bcbb by Helmut Grohne at 2026-08-03T07:26:46+02:00
security_db.py: rewrite mergeLists using sets
Aside from being faster, this avoids changing the type of the result
variable.
- - - - -
3324817d by Helmut Grohne at 2026-08-03T07:26:46+02:00
python: avoid more variable type changes
If we ever want to head into type checking, the type of value stored in
a variable should not change. Thus rename affected assignments or elide
them entirely.
- - - - -
7dc46c85 by Helmut Grohne at 2026-08-03T07:26:46+02:00
tracker_service.py: narrow implied type of filters attribute
The lookup in params may return None in principle. This influences type
deduction and filters is assumed to be able to hold None, but the next
line changes that. In combining them, the deduced type of filters
becomes narrower.
- - - - -
ba900d6e by Helmut Grohne at 2026-08-03T07:27:10+02:00
tracker_service.py: don't pass None via body_attribs
While a None value might be acceptable there, it is discarded anyway.
Rather than supporting that use case, simply avoid passing it.
- - - - -
13a2bb96 by Helmut Grohne at 2026-08-03T07:27:16+02:00
tracker_service.py: explicitly cast hide_check to bool
When we pass it to getTODOs a real bool is expected, so convert the
thing that might be a list early.
- - - - -
12 changed files:
- bin/tracker_service.py
- data/CVE/list
- data/DLA/list
- data/DSA/list
- data/dla-needed.txt
- data/dsa-needed.txt
- data/next-point-update.txt
- data/packages/nfu.yaml
- lib/python/bugs.py
- lib/python/debian_support.py
- lib/python/security_db.py
- lib/python/web_support.py
Changes:
=====================================
bin/tracker_service.py
=====================================
@@ -2,7 +2,6 @@
import os.path
import sys
-import time
import setup_paths # noqa
import bugs
@@ -12,23 +11,14 @@ import security_db
from web_support import *
if __name__ == "__main__":
- if len(sys.argv) not in (3, 5):
- print("usage: python tracker_service.py SOCKET-PATH DATABASE-PATH")
- print(" python tracker_service.py URL HOST PORT DATABASE-PATH")
+ if len(sys.argv) != 5:
+ print("usage: python tracker_service.py URL HOST PORT DATABASE-PATH")
sys.exit(1)
- if len(sys.argv) == 3:
- socket_name = sys.argv[1]
- db_name = sys.argv[2]
- webservice_base_class = WebService
- else:
- server_base_url = sys.argv[1]
- server_address = sys.argv[2]
- server_port = int(sys.argv[3])
- socket_name = (server_base_url, server_address, server_port)
- db_name = sys.argv[4]
- webservice_base_class = WebServiceHTTP
-else:
- webservice_base_class = WebServiceHTTP
+ server_base_url = sys.argv[1]
+ server_address = sys.argv[2]
+ server_port = int(sys.argv[3])
+ socket_name = (server_base_url, server_address, server_port)
+ db_name = sys.argv[4]
class BugFilter:
default_action_list = [('high_urgency', 'high', 'urgency'),
@@ -55,9 +45,9 @@ class BugFilter:
self.params = {}
for (prop, desc, field) in self.action_list:
self.params[prop] = int(params.get(prop, (0,))[0])
- self.filters=params.get('filter')
- if not self.filters:
- self.filters=['high_urgency', 'medium_urgency', 'low_urgency', 'unassigned_urgency']
+ self.filters = (
+ params.get('filter') or ['high_urgency', 'medium_urgency', 'low_urgency', 'unassigned_urgency']
+ )
def actions(self, url):
"""Returns a HTML snippet which can be used to change the filter."""
@@ -108,7 +98,7 @@ class BugFilter:
"""Returns True for postponedissues if filtered."""
return no_dsa_reason == 'postponed' and not self.params['nopostponed']
-class TrackerService(webservice_base_class):
+class TrackerService(WebServiceHTTP):
nvd_text = P('''If a "**" is included, the urgency field was automatically
assigned by the NVD (National Vulnerability Database). Note that this
rating is automatically derived from a set of known factors about the
@@ -118,7 +108,7 @@ class TrackerService(webservice_base_class):
from a fully automated formula.''')
def __init__(self, socket_name, db_name):
- webservice_base_class.__init__(self, socket_name)
+ WebServiceHTTP.__init__(self, socket_name)
self.db = security_db.DB(db_name)
self.stable_releases = config.get_supported_releases()
@@ -935,7 +925,7 @@ checker to find out why they have not entered testing yet."""),
"Remote", ""))])
def page_status_todo(self, path, params, url):
- hide_check = params.get('hide_check', False)
+ hide_check = bool(params.get('hide_check', False))
if hide_check:
flags = A(url.updateParamsDict({'hide_check' : None}),
'Show "check" TODOs')
@@ -1187,13 +1177,9 @@ not unimportant."""),
def gen():
for (rel, subrel, archive, sources, archs) \
in self.db.availableReleases():
- if sources:
- sources = 'yes'
- else:
- sources = 'no'
if 'source' in archs:
archs.remove('source')
- yield rel, subrel, archive, sources, make_list(archs)
+ yield rel, subrel, archive, "yes" if sources else "no" , make_list(archs)
return self.create_page(
url, "Available releases",
[P("""The security issue database is checked against
@@ -1247,8 +1233,8 @@ issue (or a bug has been created and is not recorded in this database).
In the second kind of names, there is a Debian bug for the issue, and the "''',
CODE("000000"), '''"part of the name is replaced with the
Debian bug number.'''),
- make_table(gen(1),title=H2('With unfixed issues'), caption=("Bug", "Description")),
- make_table(gen(0),title=H2('The rest'), caption=("Bug", "Description")),
+ make_table(gen(True),title=H2('With unfixed issues'), caption=("Bug", "Description")),
+ make_table(gen(False),title=H2('The rest'), caption=("Bug", "Description")),
])
def page_data_pts(self, path, params, url):
@@ -1299,17 +1285,16 @@ Debian bug number.'''),
"Source"),
" ", A(url.absolute("https://salsa.debian.org/security-tracker-team/security-tracker"), "(Git)"),
)))
+ body_attribs = {}
if search_in_page:
- on_load = "selectSearch()"
- else:
- on_load = None
+ body_attribs["onload"] = "selectSearch()"
head_contents = compose(
LINK(' ', href=url.scriptRelative("style.css")),
SCRIPT(' ', src=url.scriptRelative("script.js")),
).toHTML()
return HTMLResult(self.add_title(title, body,
head_contents=head_contents,
- body_attribs={'onload': on_load}),
+ body_attribs=body_attribs),
doctype=self.html_dtd(),
status=status)
@@ -1537,8 +1522,5 @@ Debian bug number.'''),
def make_dangerous(self, contents):
return SPAN(contents, _class="dangerous")
- def pre_dispatch(self):
- pass
-
if __name__ == "__main__":
TrackerService(socket_name, db_name).run()
=====================================
data/CVE/list
=====================================
The diff for this file was not included because it is too large.
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,37 @@
+[02 Aug 2026] DLA-4715-1 kissfft - security update
+ {CVE-2025-34297 CVE-2026-41445}
+ [bullseye] - kissfft 131.1.0-1+deb11u1
+[01 Aug 2026] DLA-4714-1 libmodbus - security update
+ {CVE-2024-10918}
+ [bookworm] - libmodbus 3.1.6-2.1+deb12u1
+[01 Aug 2026] DLA-4713-1 sslh - security update
+ {CVE-2025-52936}
+ [bookworm] - sslh 1.20-1+deb12u1
+[01 Aug 2026] DLA-4712-1 node-tar - security update
+ {CVE-2024-28863 CVE-2026-23745 CVE-2026-26960 CVE-2026-29786}
+ [bookworm] - node-tar 6.1.13+~cs7.0.5-1+deb12u1
+[01 Aug 2026] DLA-4711-1 starlette - security update
+ {CVE-2026-48817 CVE-2026-54282 CVE-2026-54283}
+ [bookworm] - starlette 0.26.1-1+deb12u2
+[01 Aug 2026] DLA-4710-1 chromium - security update
+ {CVE-2026-16804 CVE-2026-16805 CVE-2026-16806 CVE-2026-16807 CVE-2026-17650 CVE-2026-17651 CVE-2026-17652 CVE-2026-17653 CVE-2026-17654 CVE-2026-17655 CVE-2026-17656 CVE-2026-17657 CVE-2026-17658 CVE-2026-17659 CVE-2026-17660 CVE-2026-17661 CVE-2026-17662 CVE-2026-17663 CVE-2026-17664 CVE-2026-17665 CVE-2026-17666 CVE-2026-17667 CVE-2026-17668 CVE-2026-17669 CVE-2026-17670 CVE-2026-17671 CVE-2026-17672 CVE-2026-17673 CVE-2026-17674 CVE-2026-17675 CVE-2026-17676 CVE-2026-17677 CVE-2026-17678 CVE-2026-17679 CVE-2026-17680 CVE-2026-17681 CVE-2026-17682 CVE-2026-17683 CVE-2026-17684 CVE-2026-17685 CVE-2026-17686 CVE-2026-17687 CVE-2026-17688 CVE-2026-17689 CVE-2026-17690 CVE-2026-17691 CVE-2026-17692 CVE-2026-17693 CVE-2026-17694 CVE-2026-17695 CVE-2026-17696 CVE-2026-17697 CVE-2026-17698 CVE-2026-17699 CVE-2026-17700 CVE-2026-17701 CVE-2026-17702 CVE-2026-17703 CVE-2026-17704 CVE-2026-17705 CVE-2026-17706 CVE-2026-17707 CVE-2026-17708 CVE-2026-17709 CVE-2026-17710 CVE-2026-17711 CVE-2026-17712 CVE-2026-17713 CVE-2026-17714 CVE-2026-17715 CVE-2026-17716 CVE-2026-17717 CVE-2026-17718 CVE-2026-17719 CVE-2026-17720 CVE-2026-17721 CVE-2026-17722 CVE-2026-17723 CVE-2026-17724 CVE-2026-17725 CVE-2026-17726 CVE-2026-17727 CVE-2026-17728 CVE-2026-17729 CVE-2026-17730 CVE-2026-17731 CVE-2026-17732 CVE-2026-17733 CVE-2026-17734 CVE-2026-17735 CVE-2026-17736 CVE-2026-17737 CVE-2026-17738 CVE-2026-17739 CVE-2026-17740 CVE-2026-17741 CVE-2026-17742 CVE-2026-17743 CVE-2026-17744 CVE-2026-17745 CVE-2026-17746 CVE-2026-17747 CVE-2026-17748 CVE-2026-17749 CVE-2026-17750 CVE-2026-17751 CVE-2026-17752 CVE-2026-17753 CVE-2026-17754 CVE-2026-17755 CVE-2026-17756 CVE-2026-17757 CVE-2026-17758 CVE-2026-17759 CVE-2026-17760 CVE-2026-17761 CVE-2026-17762 CVE-2026-17763 CVE-2026-17764 CVE-2026-17765 CVE-2026-17766 CVE-2026-17767 CVE-2026-17768 CVE-2026-17769 CVE-2026-17770 CVE-2026-17771 CVE-2026-17772 CVE-2026-17773 CVE-2026-17774 CVE-2026-17775 CVE-2026-17776 CVE-2026-17777 CVE-2026-17778 CVE-2026-17779 CVE-2026-17780 CVE-2026-17781 CVE-2026-17782 CVE-2026-17783 CVE-2026-17784 CVE-2026-17785 CVE-2026-17786 CVE-2026-17787 CVE-2026-17788 CVE-2026-17789 CVE-2026-17790 CVE-2026-17791 CVE-2026-17792 CVE-2026-17793 CVE-2026-17794 CVE-2026-17795 CVE-2026-17796 CVE-2026-17797 CVE-2026-17798 CVE-2026-17799 CVE-2026-17800 CVE-2026-17801 CVE-2026-17802 CVE-2026-17803 CVE-2026-17804 CVE-2026-17805 CVE-2026-17806 CVE-2026-17807 CVE-2026-17808 CVE-2026-17809 CVE-2026-17810 CVE-2026-17811 CVE-2026-17812 CVE-2026-17813 CVE-2026-17814 CVE-2026-17815 CVE-2026-17816 CVE-2026-17817 CVE-2026-17818 CVE-2026-17819 CVE-2026-17820 CVE-2026-17821 CVE-2026-17822 CVE-2026-17823 CVE-2026-17824 CVE-2026-17825 CVE-2026-17826 CVE-2026-17827 CVE-2026-17828 CVE-2026-17829 CVE-2026-17830 CVE-2026-17831 CVE-2026-17832 CVE-2026-17833 CVE-2026-17834 CVE-2026-17835 CVE-2026-17836 CVE-2026-17837 CVE-2026-17838 CVE-2026-17839 CVE-2026-17840 CVE-2026-17841 CVE-2026-17842 CVE-2026-17843 CVE-2026-17844 CVE-2026-17845 CVE-2026-17846 CVE-2026-17847 CVE-2026-17848 CVE-2026-17849 CVE-2026-17850 CVE-2026-17851 CVE-2026-17852 CVE-2026-17853 CVE-2026-17854 CVE-2026-17855 CVE-2026-17856 CVE-2026-17857 CVE-2026-17858 CVE-2026-17859 CVE-2026-17860 CVE-2026-17861 CVE-2026-17862 CVE-2026-17863 CVE-2026-17864 CVE-2026-17865 CVE-2026-17866 CVE-2026-17867 CVE-2026-17868 CVE-2026-17869 CVE-2026-17870 CVE-2026-17871 CVE-2026-17872 CVE-2026-17873 CVE-2026-17874 CVE-2026-17875 CVE-2026-17876 CVE-2026-17877 CVE-2026-17878 CVE-2026-17879 CVE-2026-17880 CVE-2026-17881 CVE-2026-17882 CVE-2026-17883 CVE-2026-17884 CVE-2026-17885 CVE-2026-17886 CVE-2026-17887 CVE-2026-17888 CVE-2026-17889 CVE-2026-17890 CVE-2026-17891 CVE-2026-17892 CVE-2026-17893 CVE-2026-17894 CVE-2026-17895 CVE-2026-17896 CVE-2026-17897 CVE-2026-17898 CVE-2026-17899 CVE-2026-17900 CVE-2026-17901 CVE-2026-17902 CVE-2026-17903 CVE-2026-17904 CVE-2026-17905 CVE-2026-17906 CVE-2026-17907 CVE-2026-17908 CVE-2026-17909 CVE-2026-17910 CVE-2026-17911 CVE-2026-17912 CVE-2026-17913 CVE-2026-17914 CVE-2026-17915 CVE-2026-17916 CVE-2026-17917 CVE-2026-17918 CVE-2026-17919 CVE-2026-17920 CVE-2026-17921 CVE-2026-17922 CVE-2026-17923 CVE-2026-17924 CVE-2026-17925 CVE-2026-17926 CVE-2026-17927 CVE-2026-17928 CVE-2026-17929 CVE-2026-17930 CVE-2026-17931 CVE-2026-17932 CVE-2026-17933 CVE-2026-17934 CVE-2026-17935 CVE-2026-17936 CVE-2026-17937 CVE-2026-17938 CVE-2026-17939 CVE-2026-17940 CVE-2026-17941 CVE-2026-17942 CVE-2026-17943 CVE-2026-17944 CVE-2026-17945 CVE-2026-17946 CVE-2026-17947 CVE-2026-17948 CVE-2026-17949 CVE-2026-17950 CVE-2026-17951 CVE-2026-17952 CVE-2026-17953 CVE-2026-17954 CVE-2026-17955 CVE-2026-17956 CVE-2026-17957 CVE-2026-17958 CVE-2026-17959 CVE-2026-17960 CVE-2026-17961 CVE-2026-17962 CVE-2026-17963 CVE-2026-17964 CVE-2026-17965 CVE-2026-17966 CVE-2026-17967 CVE-2026-17968 CVE-2026-17969 CVE-2026-17970 CVE-2026-17971 CVE-2026-17972 CVE-2026-17973 CVE-2026-17974 CVE-2026-17975 CVE-2026-17976 CVE-2026-17977 CVE-2026-17978 CVE-2026-17979 CVE-2026-17980 CVE-2026-17981 CVE-2026-17982 CVE-2026-17983 CVE-2026-17984 CVE-2026-17985 CVE-2026-17986 CVE-2026-17987 CVE-2026-17988 CVE-2026-17989 CVE-2026-17990 CVE-2026-17991 CVE-2026-17992 CVE-2026-17993 CVE-2026-17994 CVE-2026-17995 CVE-2026-17996 CVE-2026-17997 CVE-2026-17998 CVE-2026-17999 CVE-2026-18000 CVE-2026-18001 CVE-2026-18002 CVE-2026-18003 CVE-2026-18004 CVE-2026-18005 CVE-2026-18006 CVE-2026-18007 CVE-2026-18008 CVE-2026-18009 CVE-2026-18010 CVE-2026-18011 CVE-2026-18012 CVE-2026-18013 CVE-2026-18014 CVE-2026-18015 CVE-2026-18016 CVE-2026-18017 CVE-2026-18018 CVE-2026-18019}
+ [bookworm] - chromium 151.0.7922.71-1~deb12u1
+[31 Jul 2026] DLA-4709-1 poppler - security update
+ {CVE-2025-43903 CVE-2025-50420 CVE-2025-52886}
+ [bullseye] - poppler 20.09.0-3.1+deb11u3
+ [bookworm] - poppler 22.12.0-2+deb12u3
+[31 Jul 2026] DLA-4708-1 python-authlib - security update
+ {CVE-2026-44681}
+ [bullseye] - python-authlib 0.15.4-1+deb11u4
+ [bookworm] - python-authlib 1.2.0-1+deb12u2
+[30 Jul 2026] DLA-4707-1 gsasl - security update
+ {CVE-2026-56968}
+ [bullseye] - gsasl 1.10.0-4+deb11u3
+ [bookworm] - gsasl 2.2.0-1+deb12u2
+[31 Jul 2026] DLA-4706-1 ruby-rack - security update
+ {CVE-2026-26961 CVE-2026-34230 CVE-2026-34763 CVE-2026-34785 CVE-2026-34786 CVE-2026-34826 CVE-2026-34829 CVE-2026-34830 CVE-2026-34831}
+ [bullseye] - ruby-rack 2.1.4-3+deb11u6
+ [bookworm] - ruby-rack 2.2.22-0+deb12u2
[29 Jul 2026] DLA-4705-1 calibre - security update
{CVE-2026-27810 CVE-2026-27824 CVE-2026-30853 CVE-2026-33205 CVE-2026-33206}
[bullseye] - calibre 5.12.0+dfsg-1+deb11u5
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,24 @@
+[02 Aug 2026] DSA-6410-1 libssh - security update
+ {CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-15370 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850}
+ [trixie] - libssh 0.11.5-0+deb13u1
+[01 Aug 2026] DSA-6409-1 libgd2 - security update
+ {CVE-2026-9672}
+ [trixie] - libgd2 2.3.3-14~deb13u1
+[31 Jul 2026] DSA-6408-1 chromium - security update
+ {CVE-2026-16804 CVE-2026-16805 CVE-2026-16806 CVE-2026-16807 CVE-2026-17650 CVE-2026-17651 CVE-2026-17652 CVE-2026-17653 CVE-2026-17654 CVE-2026-17655 CVE-2026-17656 CVE-2026-17657 CVE-2026-17658 CVE-2026-17659 CVE-2026-17660 CVE-2026-17661 CVE-2026-17662 CVE-2026-17663 CVE-2026-17664 CVE-2026-17665 CVE-2026-17666 CVE-2026-17667 CVE-2026-17668 CVE-2026-17669 CVE-2026-17670 CVE-2026-17671 CVE-2026-17672 CVE-2026-17673 CVE-2026-17674 CVE-2026-17675 CVE-2026-17676 CVE-2026-17677 CVE-2026-17678 CVE-2026-17679 CVE-2026-17680 CVE-2026-17681 CVE-2026-17682 CVE-2026-17683 CVE-2026-17684 CVE-2026-17685 CVE-2026-17686 CVE-2026-17687 CVE-2026-17688 CVE-2026-17689 CVE-2026-17690 CVE-2026-17691 CVE-2026-17692 CVE-2026-17693 CVE-2026-17694 CVE-2026-17695 CVE-2026-17696 CVE-2026-17697 CVE-2026-17698 CVE-2026-17699 CVE-2026-17700 CVE-2026-17701 CVE-2026-17702 CVE-2026-17703 CVE-2026-17704 CVE-2026-17705 CVE-2026-17706 CVE-2026-17707 CVE-2026-17708 CVE-2026-17709 CVE-2026-17710 CVE-2026-17711 CVE-2026-17712 CVE-2026-17713 CVE-2026-17714 CVE-2026-17715 CVE-2026-17716 CVE-2026-17717 CVE-2026-17718 CVE-2026-17719 CVE-2026-17720 CVE-2026-17721 CVE-2026-17722 CVE-2026-17723 CVE-2026-17724 CVE-2026-17725 CVE-2026-17726 CVE-2026-17727 CVE-2026-17728 CVE-2026-17729 CVE-2026-17730 CVE-2026-17731 CVE-2026-17732 CVE-2026-17733 CVE-2026-17734 CVE-2026-17735 CVE-2026-17736 CVE-2026-17737 CVE-2026-17738 CVE-2026-17739 CVE-2026-17740 CVE-2026-17741 CVE-2026-17742 CVE-2026-17743 CVE-2026-17744 CVE-2026-17745 CVE-2026-17746 CVE-2026-17747 CVE-2026-17748 CVE-2026-17749 CVE-2026-17750 CVE-2026-17751 CVE-2026-17752 CVE-2026-17753 CVE-2026-17754 CVE-2026-17755 CVE-2026-17756 CVE-2026-17757 CVE-2026-17758 CVE-2026-17759 CVE-2026-17760 CVE-2026-17761 CVE-2026-17762 CVE-2026-17763 CVE-2026-17764 CVE-2026-17765 CVE-2026-17766 CVE-2026-17767 CVE-2026-17768 CVE-2026-17769 CVE-2026-17770 CVE-2026-17771 CVE-2026-17772 CVE-2026-17773 CVE-2026-17774 CVE-2026-17775 CVE-2026-17776 CVE-2026-17777 CVE-2026-17778 CVE-2026-17779 CVE-2026-17780 CVE-2026-17781 CVE-2026-17782 CVE-2026-17783 CVE-2026-17784 CVE-2026-17785 CVE-2026-17786 CVE-2026-17787 CVE-2026-17788 CVE-2026-17789 CVE-2026-17790 CVE-2026-17791 CVE-2026-17792 CVE-2026-17793 CVE-2026-17794 CVE-2026-17795 CVE-2026-17796 CVE-2026-17797 CVE-2026-17798 CVE-2026-17799 CVE-2026-17800 CVE-2026-17801 CVE-2026-17802 CVE-2026-17803 CVE-2026-17804 CVE-2026-17805 CVE-2026-17806 CVE-2026-17807 CVE-2026-17808 CVE-2026-17809 CVE-2026-17810 CVE-2026-17811 CVE-2026-17812 CVE-2026-17813 CVE-2026-17814 CVE-2026-17815 CVE-2026-17816 CVE-2026-17817 CVE-2026-17818 CVE-2026-17819 CVE-2026-17820 CVE-2026-17821 CVE-2026-17822 CVE-2026-17823 CVE-2026-17824 CVE-2026-17825 CVE-2026-17826 CVE-2026-17827 CVE-2026-17828 CVE-2026-17829 CVE-2026-17830 CVE-2026-17831 CVE-2026-17832 CVE-2026-17833 CVE-2026-17834 CVE-2026-17835 CVE-2026-17836 CVE-2026-17837 CVE-2026-17838 CVE-2026-17839 CVE-2026-17840 CVE-2026-17841 CVE-2026-17842 CVE-2026-17843 CVE-2026-17844 CVE-2026-17845 CVE-2026-17846 CVE-2026-17847 CVE-2026-17848 CVE-2026-17849 CVE-2026-17850 CVE-2026-17851 CVE-2026-17852 CVE-2026-17853 CVE-2026-17854 CVE-2026-17855 CVE-2026-17856 CVE-2026-17857 CVE-2026-17858 CVE-2026-17859 CVE-2026-17860 CVE-2026-17861 CVE-2026-17862 CVE-2026-17863 CVE-2026-17864 CVE-2026-17865 CVE-2026-17866 CVE-2026-17867 CVE-2026-17868 CVE-2026-17869 CVE-2026-17870 CVE-2026-17871 CVE-2026-17872 CVE-2026-17873 CVE-2026-17874 CVE-2026-17875 CVE-2026-17876 CVE-2026-17877 CVE-2026-17878 CVE-2026-17879 CVE-2026-17880 CVE-2026-17881 CVE-2026-17882 CVE-2026-17883 CVE-2026-17884 CVE-2026-17885 CVE-2026-17886 CVE-2026-17887 CVE-2026-17888 CVE-2026-17889 CVE-2026-17890 CVE-2026-17891 CVE-2026-17892 CVE-2026-17893 CVE-2026-17894 CVE-2026-17895 CVE-2026-17896 CVE-2026-17897 CVE-2026-17898 CVE-2026-17899 CVE-2026-17900 CVE-2026-17901 CVE-2026-17902 CVE-2026-17903 CVE-2026-17904 CVE-2026-17905 CVE-2026-17906 CVE-2026-17907 CVE-2026-17908 CVE-2026-17909 CVE-2026-17910 CVE-2026-17911 CVE-2026-17912 CVE-2026-17913 CVE-2026-17914 CVE-2026-17915 CVE-2026-17916 CVE-2026-17917 CVE-2026-17918 CVE-2026-17919 CVE-2026-17920 CVE-2026-17921 CVE-2026-17922 CVE-2026-17923 CVE-2026-17924 CVE-2026-17925 CVE-2026-17926 CVE-2026-17927 CVE-2026-17928 CVE-2026-17929 CVE-2026-17930 CVE-2026-17931 CVE-2026-17932 CVE-2026-17933 CVE-2026-17934 CVE-2026-17935 CVE-2026-17936 CVE-2026-17937 CVE-2026-17938 CVE-2026-17939 CVE-2026-17940 CVE-2026-17941 CVE-2026-17942 CVE-2026-17943 CVE-2026-17944 CVE-2026-17945 CVE-2026-17946 CVE-2026-17947 CVE-2026-17948 CVE-2026-17949 CVE-2026-17950 CVE-2026-17951 CVE-2026-17952 CVE-2026-17953 CVE-2026-17954 CVE-2026-17955 CVE-2026-17956 CVE-2026-17957 CVE-2026-17958 CVE-2026-17959 CVE-2026-17960 CVE-2026-17961 CVE-2026-17962 CVE-2026-17963 CVE-2026-17964 CVE-2026-17965 CVE-2026-17966 CVE-2026-17967 CVE-2026-17968 CVE-2026-17969 CVE-2026-17970 CVE-2026-17971 CVE-2026-17972 CVE-2026-17973 CVE-2026-17974 CVE-2026-17975 CVE-2026-17976 CVE-2026-17977 CVE-2026-17978 CVE-2026-17979 CVE-2026-17980 CVE-2026-17981 CVE-2026-17982 CVE-2026-17983 CVE-2026-17984 CVE-2026-17985 CVE-2026-17986 CVE-2026-17987 CVE-2026-17988 CVE-2026-17989 CVE-2026-17990 CVE-2026-17991 CVE-2026-17992 CVE-2026-17993 CVE-2026-17994 CVE-2026-17995 CVE-2026-17996 CVE-2026-17997 CVE-2026-17998 CVE-2026-17999 CVE-2026-18000 CVE-2026-18001 CVE-2026-18002 CVE-2026-18003 CVE-2026-18004 CVE-2026-18005 CVE-2026-18006 CVE-2026-18007 CVE-2026-18008 CVE-2026-18009 CVE-2026-18010 CVE-2026-18011 CVE-2026-18012 CVE-2026-18013 CVE-2026-18014 CVE-2026-18015 CVE-2026-18016 CVE-2026-18017 CVE-2026-18018 CVE-2026-18019}
+ [trixie] - chromium 151.0.7922.71-1~deb13u1
+[31 Jul 2026] DSA-6407-1 incus - security update
+ {CVE-2026-62313 CVE-2026-62867 CVE-2026-62940 CVE-2026-62941 CVE-2026-63125 CVE-2026-63343}
+ [trixie] - incus 6.0.4-2+deb13u9
+[31 Jul 2026] DSA-6406-1 php8.4 - security update
+ {CVE-2026-7260 CVE-2026-17543 CVE-2026-17544}
+ [trixie] - php8.4 8.4.24-1~deb13u1
+[31 Jul 2026] DSA-6405-1 linux - security update
+ {CVE-2026-45944 CVE-2026-53005 CVE-2026-53260 CVE-2026-53365 CVE-2026-63970 CVE-2026-64192 CVE-2026-64206 CVE-2026-64227 CVE-2026-64286 CVE-2026-64287 CVE-2026-64307 CVE-2026-64341 CVE-2026-64352 CVE-2026-64361 CVE-2026-64363 CVE-2026-64364 CVE-2026-64369 CVE-2026-64371 CVE-2026-64375 CVE-2026-64390 CVE-2026-64401 CVE-2026-64405 CVE-2026-64413 CVE-2026-64416 CVE-2026-64421 CVE-2026-64428 CVE-2026-64434 CVE-2026-64438 CVE-2026-64441 CVE-2026-64461 CVE-2026-64462 CVE-2026-64472 CVE-2026-64481 CVE-2026-64488 CVE-2026-64493 CVE-2026-64507 CVE-2026-64508 CVE-2026-64509 CVE-2026-64510 CVE-2026-64530 CVE-2026-64531 CVE-2026-64532 CVE-2026-64533 CVE-2026-64534 CVE-2026-64535 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64542 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64555 CVE-2026-64557 CVE-2026-64558 CVE-2026-64559 CVE-2026-64560}
+ [trixie] - linux 6.12.100-1
+[30 Jul 2026] DSA-6404-1 expat - security update
+ {CVE-2025-59375 CVE-2026-24515 CVE-2026-25210 CVE-2026-32776 CVE-2026-32777 CVE-2026-32778 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412}
+ [trixie] - expat 2.8.2-1~deb13u1
[29 Jul 2026] DSA-6403-1 nss - security update
{CVE-2026-16389}
[trixie] - nss 2:3.110-1+deb13u4
=====================================
data/dla-needed.txt
=====================================
@@ -40,6 +40,9 @@ activemq
NOTE: 20260715: Also add for bookworm
NOTE: 20260715: Upcoming DSA, though they may just bump version (Beuc/front-desk)
--
+adminer
+ NOTE: 20260801: Added by Front-Desk (ta)
+--
amd64-microcode
NOTE: 20250710: Added by Front-Desk (apo)
NOTE: 20250906: Reached out to maintainer, offering help.
@@ -112,8 +115,8 @@ caddy/bookworm
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
-chromium/bookworm (Emilio)
- NOTE: 20260721: Added by Front-Desk (utkarsh)
+cjson
+ NOTE: 20260801: Added by Front-Desk (ta)
--
ckeditor/bullseye
NOTE: 20241002: Added by Front-Desk (Beuc)
@@ -219,6 +222,9 @@ frr
NOTE: 20260714: Also add for bookworm.
NOTE: 20260714: Many CVEs fixed in bullseye but not in bookworm (low pri) (Beuc/front-desk)
--
+gawk
+ NOTE: 20260801: Added by Front-Desk (ta)
+--
gdal/bullseye
NOTE: 20260419: Added by Front-Desk (rouca)
NOTE: 20260419: Investigate why embded zblib and maybe deemded beginning from sid (rouca/FD)
@@ -257,11 +263,6 @@ golang-glog/bullseye
NOTE: 20251107: https://buildd.debian.org/status/package.php?p=+golang-github-grpc-ecosystem-grpc-gateway&suite=bullseye-security
NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
--
-gsasl (charles)
- NOTE: 20260618: Added by Front-Desk (charles)
- NOTE: 20260618: Bookworm patch proposed by maintainer, DSA 6348-1 already out.
- NOTE: 20260618: https://lists.debian.org/debian-lts/2026/06/msg00037.html (charles)
---
gst-plugins-bad1.0
NOTE: 20260612: Added by Front-Desk (rouca)
--
@@ -290,9 +291,15 @@ jackson-databind
NOTE: 20260709: CVE-2026-54512/54513/54514/54515 hit 2.12(bullseye)+2.14(bookworm);
NOTE: 20260709: 54516/54517/54518 (>=2.21) and 50193 (bookworm 2.14) not-affected.
--
+jbig2dec
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
jetty9
NOTE: 20260418: Added by Front-Desk. Fix CVE-2026-5795 maybe other (rouca)
--
+jline3
+ NOTE: 20260801: Added by Front-Desk (ta)
+--
jpeg-xl/bookworm
NOTE: 20260619: Added by Front-Desk (charles)
NOTE: 20260619: Follow DSA-6342-1 (charles)
@@ -341,11 +348,21 @@ libcryptx-perl
NOTE: 20260725: tag Copy and CVE-2026-13758 memNE both present. Sponsored in
NOTE: 20260725: both suites. (utkarsh/front-desk)
--
+libdbi-perl
+ NOTE: 20260801: Added by Front-Desk (ta)
+--
libde265
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
NOTE: 20260709: upstream fixes v1.0.19-v1.1.1 newer than Debian 1.0.11.
--
+libgd2
+ NOTE: 20260731: Added by Front-Desk (ta)
+--
+libgit2
+ NOTE: 20260801: Added by Front-Desk (ta)
+ NOTE: 20260801: not sure whether Bullseye and Bookworm are really affected, please recheck (ta)
+--
libheif
NOTE: 20260612: Added by Front-Desk (rouca)
--
@@ -353,13 +370,22 @@ libio-compress-perl
NOTE: 20260612: Added by Front-Desk (rouca)
NOTE: 20260612: MUST hold-back following the upper suites and wait for green light from security team (rouca/FD)
--
+libnet-dns-perl
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
libpgjava
NOTE: 20260613: Added by Front-Desk (rouca)
--
+librabbitmq
+ NOTE: 20260731: Added by Front-Desk (ta)
+--
libreoffice/bullseye (santiago)
NOTE: 20260508: Added by Front-Desk (dleidert)
NOTE: 20260508: Follow DSA-6251-1 (dleidert/front-desk)
--
+librest
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
libreswan/bookworm
NOTE: 20230301: Added by Security Team (jmm)
NOTE: 20260611: bookworm LTS handover.
@@ -403,6 +429,9 @@ libsoup2.4
NOTE: 20260727: not-affected (no HTTP/2 in libsoup 2.x). Only
NOTE: 20260727: CVE-2026-12548 has an upstream fix (3.7.1). (utkarsh)
--
+libssh
+ NOTE: 20260731: Added by Front-Desk (ta)
+--
libssh2 (eamanu)
NOTE: 20260625: Added by Front-Desk (lamby)
NOTE: 20260702: patches are under review (eamanu)
@@ -422,17 +451,21 @@ libwebsockets/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
--
-libxmltok/bullseye
+libxmltok
NOTE: 20250421: Added by Front-Desk (ta)
NOTE: 20250421: Also review all other expat CVEs. (bunk)
NOTE: 20250421: Fixing the expat copy in xmlrpc-c at the same time would make sense. (bunk)
- NOTE: 20250505: WIP there are lots of CVEs to review (ta)
--
libxslt/bullseye
NOTE: 20250930: Added by Front-Desk (rouca)
NOTE: 20251020: In progress, waiting for upstream action (guilhem)
NOTE: 20251104: Done, but waiting for upstream to merge before uploading and issuing the DLA (guilhem)
--
+libyaml-syck-perl (carnil)
+ NOTE: 20260731: Added by Front-Desk (ta)
+ NOTE: 20260801: https://debusine.debian.net/debian/developers/work-request/971411/ (bookworm-security)
+ NOTE: 20260801: https://debusine.debian.net/debian/developers/work-request/971553/ (bullseye-security)
+--
linux (Ben Hutchings)
NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
--
@@ -527,11 +560,6 @@ node-lodash/bookworm (utkarsh)
NOTE: 20260703: Added by Front-Desk (dleidert)
NOTE: 20260703: Follow DLA 4663-1; assigned to Utkarsh to grab this (dleidert/front-desk)
--
-node-tar/bookworm
- NOTE: 20260717: Added by Front-Desk (Beuc)
- NOTE: 20260717: Follow DLA-4552-1/bullseye
- NOTE: 20260717: ELTS work underway (Beuc/front-desk)
---
nodejs
NOTE: 20260622: Added by Front-Desk (lamby)
--
@@ -561,6 +589,9 @@ opam/bullseye
NOTE: 20260716: Added by Front-Desk (Beuc)
NOTE: 20260716: Follow DSA-6386-1 and DLA-4684-1 (1 CVE) (Beuc/front-desk)
--
+open-iscsi
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
openexr
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260713: Also add for bookworm (Beuc/front-desk)
@@ -582,9 +613,15 @@ openimageio
NOTE: 20260726: 2.5.18.0. Note trixie also lacks USE_OPENJPH, so it looks
NOTE: 20260726: not-affected by CVE-2026-43905. (utkarsh/front-desk)
--
-openvpn/bullseye (dleidert)
+opensc
+ NOTE: 20260731: Added by Front-Desk (ta)
+ NOTE: 20260731: lots of no-dsa issues piled up (ta)
+--
+openvpn/bullseye
NOTE: 20260703: Added by Front-Desk (dleidert)
NOTE: 20260703: A regression has been reported; and a new set of CVEs is out (dleidert/front-desk)
+ NOTE: 20260706: The regression has been fixed. (dleidert)
+ NOTE: 20260731: The new CVEs require a more thorough examination. (dleidert)
--
openvswitch/bullseye
NOTE: 20260405: Added by Front-Desk (ta)
@@ -601,6 +638,9 @@ pacemaker
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Package is in dsa-needed (charles)
--
+pcp
+ NOTE: 20260801: Added by Front-Desk (ta)
+--
pdfminer
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: CVE-2025-70559 is follow-up fix for CVE-2025-64512
@@ -635,9 +675,6 @@ phpseclib/bullseye (Utkarsh)
NOTE: 20260518: Follow bookworm 12.14 (2 CVEs) (Beuc/front-desk)
NOTE: 20260720: will get back to this after releasing squid. (utkarsh)
--
-poppler/bullseye (guilhem)
- NOTE: 20260605: Added by Front-Desk (pochu)
---
proftpd-dfsg
NOTE: 20260511: Added by Beuc for maintainer (Hilmar Preuße)
NOTE: 20260511: https://lists.debian.org/debian-lts/2026/05/msg00015.html
@@ -652,6 +689,9 @@ py7zr
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-23879 (GHSA range <=1.1.2); Debian 0.11.3 in range.
--
+pyasn1
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
pypdf2/bullseye (dleidert)
NOTE: 20260328: Added by Front-Desk (Beuc)
NOTE: 20260328: 6 new CVEs, and lots of postponed issues piled-up (Beuc/front-desk)
@@ -660,11 +700,6 @@ python-aiohttp (dleidert)
NOTE: 20260611: Added by Front-Desk (rouca)
NOTE: 20260602: Daniel Leidert is proposing to work on the update and provide debdiffs for bookworm and trixie (carnil)
--
-python-authlib (andrewsh)
- NOTE: 20260709: Added by Front-Desk (utkarsh)
- NOTE: 20260709: CVE-2026-41479 (<1.6.10) + CVE-2026-44681 (<=1.6.11); Debian 0.15.4/1.2.0 in range.
- NOTE: 20260709: See also https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/330
---
python-eventlet/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
@@ -748,14 +783,11 @@ ruby-oj
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: Oj JSON parser memory-safety batch CVE-2026-54500..54903 (GHSA); affects 2.17-3.14.
--
-ruby-rack (Abhijith PA)
- NOTE: 20260413: Added by Front-Desk (rouca)
- NOTE: 20260608: https://people.debian.org/~abhijith/upload/rr/ (abhijith)
- NOTE: 20260706: Please check Bookworm as well (dleidert/front-desk)
---
ruby2.7/bullseye (Abhijith PA)
NOTE: 20260419: Added by Front-Desk (rouca)
NOTE: 20260608: https://people.debian.org/~abhijith/upload/ruby2.7_patches/ (abhijith)
+ NOTE: 20260731: Prepared an upload with already triaged issues. Group Net::IMAP issues
+ NOTE: 20260731: and do upload later (abhijith)
--
ruby3.1/bookworm
NOTE: 20260713: Added by Front-Desk (Beuc)
@@ -833,10 +865,11 @@ spip/bullseye
NOTE: 20260326: very low popcon (Beuc/front-desk)
NOTE: 20260422: https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/342
--
-starlette (dleidert)
+starlette/bullseye (dleidert)
NOTE: 20260528: Added by Front-Desk (dleidert)
NOTE: 20260528: follow DSA-6302-1 (dleidert/front-desk)
NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
+ NOTE: 20260801: Bullseye requires a very intrusive patch (CVE-2023-30798) that is the base to fix other CVEs as well (dleidert)
--
strongswan/bullseye
NOTE: 20260423: Added by Front-Desk (pochu)
@@ -897,10 +930,17 @@ unbound
NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
--
+unzip
+ NOTE: 20260802: Added by Front-Desk (ta)
+--
uriparser/bullseye
NOTE: 20260519: Added by Front-Desk (Beuc)
NOTE: 20260519: Many postponed CVEs piled-up (Beuc/front-desk)
--
+urwid
+ NOTE: 20260802: Added by Front-Desk (ta)
+ NOTE: 20260802: not the same code but the same reasoning (ta)
+--
util-linux (eamanu)
NOTE: 20260619: Added by Front-Desk (charles)
NOTE: 20260619: In dsa-needed, sync with secteam or follow DSA. (charles)
@@ -953,6 +993,8 @@ xorg-server (Emilio)
xrdp (Abhijith PA)
NOTE: 20260418: Added by Front-Desk (rouca)
NOTE: 20260706: Bookworm/Bullseye share the same version - fix in Bookworm first (dleidert/front-desk)
+ NOTE: 20260108: All patches for open issues in v0.9.21.1 except CVE-2026-32107 CVE-2026-33145 (abhijith)
+ NOTE: 20260108: uploaded here https://people.debian.org/~abhijith/upload/xrdp/patches/ (abhijith)
--
zabbix/bullseye
NOTE: 20260328: Added by Front-Desk (Beuc)
=====================================
data/dsa-needed.txt
=====================================
@@ -29,25 +29,18 @@ cacti
--
caddy
--
-chromium (dilinger)
---
cockpit
--
containerd
--
cups
--
-cyrus-imapd
---
docker.io
--
dulwich
--
erlang
--
-expat (aron)
- wait for 2.8.2
---
firebird3.0
--
firebird4.0
@@ -82,6 +75,8 @@ libheif
librabbitmq
Florian Ernst is preparing updates
--
+libyaml-syck-perl (carnil)
+--
linux (carnil)
Wait until more issues have piled up, though try to regulary rebase for point
releases to more 6.12.y versions
@@ -91,7 +86,7 @@ nats-server
--
netty
--
-nginx
+nginx (aron)
Maintainer is working on updates
--
nodejs
@@ -114,9 +109,6 @@ perl (carnil)
--
podman
--
-proftpd-dfsg
- In contact with Hilmar Preusse for potential update
---
prometheus
--
py7zr
=====================================
data/next-point-update.txt
=====================================
@@ -34,98 +34,36 @@ CVE-2026-34956
[trixie] - openvswitch 3.5.4-1~deb13u1
CVE-2026-35444
[trixie] - libsdl2-image 2.8.8+dfsg-1+deb13u1
-CVE-2026-5187
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5188
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
CVE-2026-5194
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5263
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5264
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5295
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5392
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5393
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5446
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5447
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5448
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5460
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5466
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5477
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5479
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5500
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5501
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5503
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5504
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5507
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5772
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-5778
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-4159
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3849
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3580
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3579
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3549
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3548
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3547
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3503
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3230
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-3229
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-2646
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-2645
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-1005
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-0819
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2026-4395
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-13912
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-12888
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-11936
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-11935
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-11934
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-11933
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-11932
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-11931
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
-CVE-2025-12889
- [trixie] - wolfssl 5.9.1-0.1~deb13u1
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-55960
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-55961
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-55962
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-55967
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6092
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6094
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6325
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6329
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6331
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6450
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6678
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6681
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-6731
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
+CVE-2026-7511
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
CVE-2026-8836
[trixie] - lwip 2.2.1+dfsg1-1+deb13u1
CVE-2026-48112
@@ -284,3 +222,97 @@ CVE-2026-61475
[trixie] - qemu 1:10.0.12+ds-0+deb13u1
CVE-2026-63319
[trixie] - qemu 1:10.0.12+ds-0+deb13u1
+CVE-2026-44331
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
+CVE-2026-53994
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
+CVE-2026-63091
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
+CVE-2026-63090
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
+CVE-2026-55995
+ [trixie] - open-isns 0.101-1+deb13u1
+CVE-2025-53643
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-22815
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34513
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34514
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34516
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34517
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34518
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34519
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34520
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34525
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-34993
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-47265
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-50269
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-54274
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-54275
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-54277
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-54279
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-54280
+ [trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2025-68276
+ [trixie] - avahi 0.8-18~deb13u1
+CVE-2025-68468
+ [trixie] - avahi 0.8-18~deb13u1
+CVE-2025-68471
+ [trixie] - avahi 0.8-18~deb13u1
+CVE-2026-24401
+ [trixie] - avahi 0.8-18~deb13u1
+CVE-2024-52616
+ [trixie] - avahi 0.8-18~deb13u1
+CVE-2026-5342
+ [trixie] - libraw 0.21.4-2+deb13u1
+CVE-2026-20884
+ [trixie] - libraw 0.21.4-2+deb13u1
+CVE-2026-20889
+ [trixie] - libraw 0.21.4-2+deb13u1
+CVE-2026-21413
+ [trixie] - libraw 0.21.4-2+deb13u1
+CVE-2026-24450
+ [trixie] - libraw 0.21.4-2+deb13u1
+CVE-2026-24660
+ [trixie] - libraw 0.21.4-2+deb13u1
+CVE-2026-57965
+ [trixie] - spice-vdagent 0.22.1-4.1+deb13u1
+CVE-2026-57966
+ [trixie] - spice-vdagent 0.22.1-4.1+deb13u1
+CVE-2026-47084
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-47086
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-47087
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-47081
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-47089
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-47085
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-47083
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-47088
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-47082
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
+CVE-2026-8276
+ [trixie] - bettercap 2.33.0-1+deb13u1
+CVE-2026-14258
+ [trixie] - dhcpcd 1:10.1.0-11+deb13u4
=====================================
data/packages/nfu.yaml
=====================================
@@ -781,19 +781,21 @@
- product: Spring Data Commons
- product: Spring Data KeyValue
- product: Spring Data MongoDB
- - product: Spring Data Relational
- product: Spring Data REST
- - product: Spring for Apache Kafka
- - product: Spring for Apache Pulsar
- - product: Spring for GraphQL
+ - product: Spring Data Relational
- product: Spring HATEOAS
- product: Spring Integration
- product: Spring LDAP
- product: Spring REST Docs
- product: Spring Retry
- product: Spring Statemachine
+ - product: Spring Tools for Eclipse
- product: Spring Web Flow
- product: Spring Web Services
+ - product: Spring for Apache Kafka
+ - product: Spring for Apache Pulsar
+ - product: Spring for GraphQL
+ - product: Spring gRPC
- product: VMware Cloud Foundation
- product: VMware ESXi
- product: VMware NSX
=====================================
lib/python/bugs.py
=====================================
@@ -31,10 +31,10 @@ def listUrgencies():
Urgency.urgencies = urgencies
return urgencies
def internUrgency(name, urgencies=listUrgencies()):
- if name in urgencies:
+ try:
return urgencies[name]
- else:
- return None
+ except KeyError as err:
+ raise ValueError("invalid urgency") from err
del listUrgencies
def to_integer(expr):
@@ -63,13 +63,9 @@ class PackageNote:
else:
if isinstance(release, str):
release = debian_support.internRelease(release)
- if release is None:
- raise ValueError("invalid release")
self.release = release
if isinstance(urgency, str):
urgency = internUrgency(urgency)
- if urgency is None:
- raise ValueError("invalid urgency")
self.urgency = urgency
self.bugs = []
self.package_kind = "unknown"
@@ -144,10 +140,11 @@ class PackageNoteParsed(PackageNote):
urgency = 'not yet assigned'
if notes is not None:
for n in self.re_notes_split.split(notes):
- u = internUrgency(n)
- if u:
- urgency = u
+ try:
+ urgency = internUrgency(n)
continue
+ except ValueError:
+ pass
if n == 'bug filed':
continue
@@ -172,10 +169,7 @@ class PackageNoteNoDSA:
else:
assert isinstance(reason, str)
self.package = package
- release = debian_support.internRelease(release)
- if release is None:
- raise ValueError("invalid release")
- self.release = release
+ self.release = debian_support.internRelease(release)
self.comment = comment
self.reason = reason
=====================================
lib/python/debian_support.py
=====================================
@@ -218,10 +218,10 @@ def listReleases():
Release.releases = releases
return releases
def internRelease(name, releases=listReleases()):
- if name in releases:
+ try:
return releases[name]
- else:
- return None
+ except KeyError as err:
+ raise ValueError("invalid release") from err
del listReleases
def readLinesSHA1(lines):
=====================================
lib/python/security_db.py
=====================================
@@ -73,14 +73,7 @@ def mergeLists(a, b):
b = []
else:
b = b.split(',')
- result = {}
- for x in a:
- result[x] = 1
- for x in b:
- result[x] = 1
- result = list(result.keys())
- result.sort()
- return result
+ return sorted(set(a).union(b))
class NVDEntry:
"""A class for an entry in the nvd_data table.
@@ -155,7 +148,7 @@ def getBugsForSourcePackage(cursor, pkg):
# Restrict to regular releases excluding e.g. backports.
release_names = tuple(debian_support.Release.releases)
- data = itertools.starmap(
+ data_iter = itertools.starmap(
BugsForSourcePackage_internal,
cursor.execute(
BugsForSourcePackage_query.replace(
@@ -168,7 +161,7 @@ def getBugsForSourcePackage(cursor, pkg):
all_bugs = []
version_key = functools.cmp_to_key(version_compare)
# Group by bug name.
- for bug_name, data in itertools.groupby(data,
+ for bug_name, data in itertools.groupby(data_iter,
lambda row: row.bug_name):
description = None
open_seen = False
@@ -863,7 +856,7 @@ class DB:
# stores aggregated data, and there is no efficient way to
# handle updates of the records related to a single file.
- packages = {}
+ packages = defaultdict(set)
unchanged = True
for filename in filenames:
match = re_packages.match(filename)
@@ -884,10 +877,7 @@ class DB:
% (arch, name))
key = (name, release, subrelease, archive, version,
source, source_version)
- if key in packages:
- packages[key][arch] = 1
- else:
- packages[key] = {arch : 1}
+ packages[key].add(arch)
if unchanged:
if self.verbose:
@@ -899,18 +889,12 @@ class DB:
cursor.execute("DELETE FROM binary_packages")
self._clearVersions(cursor)
- l = list(packages.keys())
-
- if len(l) == 0:
+ if len(packages) == 0:
raise ValueError("no binary packages found")
- l.sort()
def gen():
- for key in l:
- archs = list(packages[key].keys())
- archs.sort()
- archs = ','.join(archs)
- yield key + (archs,)
+ for key, archs in sorted(packages.items()):
+ yield key + (",".join(sorted(archs)),)
if self.verbose:
print(" storing binary package data")
@@ -1500,28 +1484,21 @@ class DB:
# Check if any packages in plain testing are vulnerable, and
# if all of those have been fixed in the security archive.
fixed_in_security = True
- unfixed_pkgs = {}
- undet_pkgs = {}
- unimp_pkgs = {}
+ unfixed_pkgs = set()
+ undet_pkgs = set()
+ unimp_pkgs = set()
for ((package, note), (vulnerable, urgency)) in status[''].items():
if vulnerable == 1:
if urgency == 'unimportant':
- unimp_pkgs[package] = True
+ unimp_pkgs.add(package)
else:
- unfixed_pkgs[package] = True
+ unfixed_pkgs.add(package)
if status['security'].get((package, note), True):
fixed_in_security = False
elif status['lts'].get((package, note), True):
fixed_in_security = False
elif vulnerable == 2:
- undet_pkgs[package] = True
-
- unfixed_pkgs = list(unfixed_pkgs.keys())
- unfixed_pkgs.sort()
- undet_pkgs = list(undet_pkgs.keys())
- undet_pkgs.sort()
- unimp_pkgs = list(unimp_pkgs.keys())
- unimp_pkgs.sort()
+ undet_pkgs.add(package)
pkgs = ""
result = "undetermined"
@@ -1533,9 +1510,9 @@ class DB:
result = "fixed"
if len(unfixed_pkgs) > 0:
if len(unfixed_pkgs) == 1:
- pkgs += "package " + unfixed_pkgs[0] + " is "
+ pkgs += "package " + next(iter(unfixed_pkgs)) + " is "
else:
- pkgs += "packages " + ", ".join(unfixed_pkgs) + " are "
+ pkgs += "packages " + ", ".join(sorted(unfixed_pkgs)) + " are "
if fixed_in_security:
pkgs = "%sfixed in %s-security. " % (pkgs, suite)
if suite == "stable":
@@ -1547,15 +1524,15 @@ class DB:
result = "vulnerable"
if len(undet_pkgs) > 0:
if len(undet_pkgs) == 1:
- pkgs += "package " + undet_pkgs[0] + " may be vulnerable but needs to be checked."
+ pkgs += "package " + next(iter(undet_pkgs)) + " may be vulnerable but needs to be checked."
else:
- pkgs += "packages " + ", ".join(undet_pkgs) + " may be vulnerable but need to be checked."
+ pkgs += "packages " + ", ".join(sorted(undet_pkgs)) + " may be vulnerable but need to be checked."
if len(unimp_pkgs) > 0 and len(undet_pkgs) == 0 and len(unfixed_pkgs) == 0:
result = "fixed"
if len(unimp_pkgs) == 1:
- pkgs = "package %s is vulnerable; however, the security impact is unimportant." % unimp_pkgs[0]
+ pkgs = "package %s is vulnerable; however, the security impact is unimportant." % next(iter(unimp_pkgs))
else:
- pkgs = "packages %s are vulnerable; however, the security impact is unimportant." % (', '.join(unimp_pkgs))
+ pkgs = "packages %s are vulnerable; however, the security impact is unimportant." % (', '.join(sorted(unimp_pkgs)))
cursor.execute("""INSERT INTO bug_status
(bug_name, release, status, reason)
@@ -1665,9 +1642,9 @@ class DB:
kind, urgency_to_flag[urgency], remote,
fix_available,
package, fixed_version, description))
- result = zlib.compress(''.join(result).encode('utf-8'), 9)
+ compressed = zlib.compress(''.join(result).encode('utf-8'), 9)
- self.storeExport('debsecan/release/' + release, 'application/octet-stream', result)
+ self.storeExport('debsecan/release/' + release, 'application/octet-stream', compressed)
c.execute("DROP TABLE vulnlist")
@@ -1711,7 +1688,7 @@ class DB:
'not yet assigned' : ' '}
vuln_list = []
- source_packages = {}
+ source_packages = set()
def fill_vuln_list(source_packages=source_packages):
for (bug, package) in list(c.execute(
"""SELECT DISTINCT bug_name, package
@@ -1732,7 +1709,7 @@ class DB:
unstable_fixed = ''
total_urgency = ''
- other_versions = {}
+ other_versions = set()
is_binary = False
is_unknown = False
fixed_releases = {}
@@ -1755,7 +1732,7 @@ class DB:
if kind == 'binary':
is_binary = True
elif kind == 'source':
- source_packages[package] = True
+ source_packages.add(package)
else:
is_unknown = True
@@ -1784,7 +1761,7 @@ class DB:
if v is None:
continue
if debian_support.Version(v) >= v_ref:
- other_versions[v] = True
+ other_versions.add(v)
# The second part of this SELECT statement
# covers binary-only NMUs.
@@ -1796,7 +1773,7 @@ class DB:
AND release = ?2 AND subrelease IN ('', 'security', 'lts')""",
(package, release)):
if debian_support.Version(v) >= v_ref:
- other_versions[v] = True
+ other_versions.add(v)
if not total_urgency:
total_urgency = 'unknown'
@@ -1818,9 +1795,7 @@ class DB:
elif is_unknown:
bs_flag = ' '
- other_versions = list(other_versions.keys())
- other_versions.sort()
- other_versions = ' '.join(other_versions)
+ other_versions_str = ' '.join(sorted(other_versions))
vuln_list.append(("%s,%d,%c%c%c"
% (package, bug_to_index[bug],
@@ -1828,14 +1803,12 @@ class DB:
bug_to_remote_flag[bug]),
fixed_releases.keys(),
",%s,%s"
- % (unstable_fixed, other_versions)))
+ % (unstable_fixed, other_versions_str)))
fill_vuln_list()
- source_packages = list(source_packages.keys())
- source_packages.sort()
def store_value(name, value):
- value = zlib.compress(value.encode('utf-8'), 9)
- self.storeExport('debsecan/' + name, 'application/octet-stream', value)
+ compressed = zlib.compress(value.encode('utf-8'), 9)
+ self.storeExport('debsecan/' + name, 'application/octet-stream', compressed)
def gen_release(release):
result = result_start[:]
@@ -1848,7 +1821,7 @@ class DB:
result.append(prefix + fixed + suffix)
result.append('')
- for sp in source_packages:
+ for sp in sorted(source_packages):
bp_list = []
for (bp,) in c.execute("""SELECT name FROM binary_packages
WHERE source = ? AND release = ? AND subrelease = ''
@@ -1867,7 +1840,7 @@ class DB:
gen_release(release)
result = result_start
- for (prefix, release, suffix) in vuln_list:
+ for (prefix, releases, suffix) in vuln_list:
result.append(prefix + ' ' + suffix)
result.append('')
result.append('')
@@ -2126,8 +2099,8 @@ class DB:
RELEASE-LIST, VERSION, VULNERABLE-FLAG) of source packages
which are related to the given bug."""
- releases = config.get_supported_releases()
- values = [bug] + releases
+ supported_releases = config.get_supported_releases()
+ values = [bug] + supported_releases
for (package, releases, version, vulnerable) in cursor.execute(
"""SELECT package, string_list(release), version, vulnerable
@@ -2136,7 +2109,7 @@ class DB:
p.version AS version, s.vulnerable AS vulnerable
FROM source_package_status AS s, source_packages AS p
WHERE s.bug_name = ? AND p.rowid = s.package
- AND release in (""" + ",".join("?" * len(releases)) + """))
+ AND release in (""" + ",".join("?" * len(supported_releases)) + """))
GROUP BY package, version, vulnerable
ORDER BY package, releasepart_to_number(release), subreleasepart_to_number(release), version COLLATE version""",
values):
@@ -2448,7 +2421,5 @@ def test():
else:
assert False
- assert bugs.BugFromDB(cursor, 'DSA-311').isKernelOnly()
-
if __name__ == "__main__":
test()
=====================================
lib/python/web_support.py
=====================================
@@ -15,14 +15,7 @@
# along with this program; if not, write to the Free Software
# Foundation, Inc., 51 Franklin Street, Fifth Floor, Boston, MA 02110-1301 USA
-import cgi
-import os
import re
-import socket
-import struct
-import sys
-import grp
-import traceback
import threading
from urllib.parse import quote as urllib_quote
from urllib.parse import parse_qs
@@ -30,107 +23,6 @@ from socketserver import ThreadingMixIn
from http.server import HTTPServer, BaseHTTPRequestHandler
from io import StringIO
-class ServinvokeError(Exception):
- pass
-
-class Service:
- """A class for service objects.
-
- Service objects are contacted by the program servinvoke and
- process HTTP requests in a serialized fashion. (Only the data
- transfer from and to the client happens in parallel, and this is
- handled by the servinvoke program.)
-
- If the newly created socket is owned by the www-data group, it is
- automatically made readable by that group.
- """
-
- def __init__(self, socket_name):
- self.socket_name = socket_name
- self._unlinkSocket()
- self.socket = socket.socket(socket.AF_UNIX, socket.SOCK_STREAM, 0)
- self.socket.bind(self.socket_name)
- self.socket.listen(5)
- self._chmod()
-
- def __del__(self):
- self._unlinkSocket()
-
- def _unlinkSocket(self):
- try:
- os.unlink(self.socket_name)
- except OSError:
- pass
-
- def _chmod(self):
- gid = os.stat(self.socket_name).st_gid
- grpent = grp.getgrgid(gid)
- if grpent[0] == 'www-data':
- os.chmod(self.socket_name, 0o660)
-
- def log(self, msg, *args):
- sys.stderr.write((msg % args) + "\n")
-
- def run(self):
- while 1:
- (client, addr) = self.socket.accept()
-
- def read(count):
- data = ''
- cnt = 0
- while cnt != count:
- d = client.recv(count - cnt)
- if d:
- data += d
- cnt = len(data)
- else:
- self.log("unexpected end of data from servinvoke")
- raise ServinvokeError()
-
- return data
-
- try:
- header = read(24)
- (magic, version, cli_size, cli_count, env_size, env_count) = \
- struct.unpack("!6I", header)
- if magic != 0x15fd34df:
- self.log("unknown magic number %08X", magic)
- if version != 1:
- self.log("unknown version %08X", version)
- cli = read(cli_size).split('\0')[:-1]
- env = {}
- for x in read(env_size).split('\0')[:-1]:
- (key, value) = x.split('=', 1)
- env[key] = value
- data = []
- while 1:
- d = client.recv(4096)
- if d:
- data.append(d)
- else:
- break
- data = ''.join(data)
- result = StringIO()
- self.handle(cli, env, data, result)
- client.sendall(result.getvalue())
- client.close()
-
- except ServinvokeError:
- client.close()
- pass
- except KeyboardInterrupt:
- client.close()
- raise
- except:
- client.close()
- target = StringIO()
- traceback.print_exc(None, target)
- self.log("%s", target.getvalue())
-
- def handle(args, environ, data):
- """Invoke by run to handle a single request. Should
- return the data to be sent back to the client."""
- return ""
class URL:
"""A simple wrapper class for strings which are interpreted as URLs."""
@@ -648,13 +540,12 @@ class HTMLResult(Result):
buf.write(self.doctype)
buf.write('\n')
self.contents.flatten(buf.write)
- buf = buf.getvalue()
- buf = maybe_encode(buf)
- self.headers['Content-Length'] = str(len(buf))
+ data = maybe_encode(buf.getvalue())
+ self.headers['Content-Length'] = str(len(data))
def later(req):
headers_later(req)
if req.command != 'HEAD':
- req.wfile.write(buf)
+ req.wfile.write(data)
return later
class BinaryResult(Result):
@@ -726,39 +617,6 @@ class WebServiceBase:
return Tag('html',
(HEAD(head_list), Tag('body', body_list, **body_attribs)))
- def pre_dispatch(self, url):
- """Invoked by handle prior to calling the registered handler."""
- pass
-
-class WebService(Service, WebServiceBase):
- "CGI service implemented using servinvoke"
- def __init__(self, socket_name):
- Service.__init__(self, socket_name)
- WebServiceBase.__init__(self)
-
- def __writeError(self, result, code, msg):
- result.write('Status: %d\nContent-Type: text/plain\n\n%s\n'
- % (code, msg))
-
- def handle(self, args, environment, data, result):
- params = cgi.parse(data, environment)
- path = environment.get('PATH_INFO', '')
- server_name = environment.get('SERVER_NAME', '')
- server_port = environment.get('SERVER_PORT', '')
- if server_port and server_port != 80:
- server_name = server_name + ":" + server_port
- script_name = environment.get('SCRIPT_NAME', '')
-
- try:
- (method, remaining) = self.router.get(path)
- except InvalidPath:
- self.__writeError(result, 404, "page not found")
- return
- self.pre_dispatch()
- url = URLFactory(server_name, script_name, path, params)
- r = method(remaining, params, url)
- assert isinstance(r, Result), repr(r)
- r.flatten(result.write)
class ThreadingHTTPServer(ThreadingMixIn, HTTPServer):
daemon_threads = True
@@ -787,7 +645,6 @@ class WebServiceHTTP(WebServiceBase):
service_self.lock.acquire()
try:
- service_self.pre_dispatch()
r = method(remaining, params, url)
assert isinstance(r, Result), repr(r)
result = r.flatten_later()
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8e79d833de8f0cd2c33f3282facdb9f8bb51da12...13a2bb9656c305a0f01f91088680bcdce7662ddd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8e79d833de8f0cd2c33f3282facdb9f8bb51da12...13a2bb9656c305a0f01f91088680bcdce7662ddd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/f93fe7a3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list