[Git][security-tracker-team/security-tracker][master] Reserve DLA-4718-1 for 7zip

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Wed Aug 5 14:31:00 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b76e1ee9 by Sylvain Beucler at 2026-08-05T15:30:52+02:00
Reserve DLA-4718-1 for 7zip

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -32133,7 +32133,6 @@ CVE-2026-58053 (Gitea act_runner with the Docker backend (through act 0.262.0) p
 CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-the-Web  ...)
 	- 7zip 26.02+dfsg-1
 	[trixie] - 7zip <ignored> (Only affects Windows NTFS with transparent ADS and :$DATA canonicalization, i.e. not the current ntfs-3g)
-	[bookworm] - 7zip <ignored> (Only affects Windows NTFS with transparent ADS and :$DATA canonicalization, i.e. not the current ntfs-3g)
 	- p7zip 16.02+transitional.1
 	[bookworm] - p7zip <ignored> (Only affects Windows NTFS with transparent ADS and :$DATA canonicalization, i.e. not the current ntfs-3g)
 	[bullseye] - p7zip <ignored> (Only affects Windows NTFS with transparent ADS and :$DATA canonicalization, i.e. not the current ntfs-3g)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[05 Aug 2026] DLA-4718-1 7zip - security update
+	{CVE-2026-14266 CVE-2026-58052}
+	[bookworm] - 7zip 22.01+really26.02+dfsg-0+deb12u1
 [05 Aug 2026] DLA-4717-1 linux - security update
 	{CVE-2022-49803 CVE-2022-50114 CVE-2023-52494 CVE-2025-23131 CVE-2025-39931 CVE-2026-23204 CVE-2026-31451 CVE-2026-31755 CVE-2026-43216 CVE-2026-43219 CVE-2026-43499 CVE-2026-46116 CVE-2026-46135 CVE-2026-46252 CVE-2026-46331 CVE-2026-52942 CVE-2026-53138 CVE-2026-53157 CVE-2026-53158 CVE-2026-53159 CVE-2026-53167 CVE-2026-53177 CVE-2026-53325 CVE-2026-53329 CVE-2026-53332 CVE-2026-53381 CVE-2026-53382 CVE-2026-53385 CVE-2026-53392 CVE-2026-53393 CVE-2026-53397 CVE-2026-53398 CVE-2026-53399 CVE-2026-53400 CVE-2026-53402 CVE-2026-53403 CVE-2026-63794 CVE-2026-63796 CVE-2026-63798 CVE-2026-63800 CVE-2026-63801 CVE-2026-63803 CVE-2026-63806 CVE-2026-63808 CVE-2026-63809 CVE-2026-63814 CVE-2026-63815 CVE-2026-63818 CVE-2026-63822 CVE-2026-63823 CVE-2026-63824 CVE-2026-63827 CVE-2026-63828 CVE-2026-63829 CVE-2026-63830 CVE-2026-63831 CVE-2026-63834 CVE-2026-63835 CVE-2026-63836 CVE-2026-64188 CVE-2026-64189 CVE-2026-64191 CVE-2026-64206 CVE-2026-64249 CVE-2026-64252 CVE-2026-64266 CVE-2026-64268 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64296 CVE-2026-64298 CVE-2026-64299 CVE-2026-64303 CVE-2026-64304 CVE-2026-64306 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64318 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64329 CVE-2026-64330 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64345 CVE-2026-64347 CVE-2026-64348 CVE-2026-64351 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361 CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64370 CVE-2026-64371 CVE-2026-64372 CVE-2026-64373 CVE-2026-64374 CVE-2026-64375 CVE-2026-64378 CVE-2026-64379 CVE-2026-64380 CVE-2026-64381 CVE-2026-64403 CVE-2026-64406 CVE-2026-64408 CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64420 CVE-2026-64422 CVE-2026-64423 CVE-2026-64425 CVE-2026-64429 CVE-2026-64435 CVE-2026-64436 CVE-2026-64438 CVE-2026-64442 CVE-2026-64445 CVE-2026-64446 CVE-2026-64448 CVE-2026-64450 CVE-2026-64452 CVE-2026-64455 CVE-2026-64456 CVE-2026-64461 CVE-2026-64462 CVE-2026-64465 CVE-2026-64468 CVE-2026-64469 CVE-2026-64470 CVE-2026-64471 CVE-2026-64475 CVE-2026-64478 CVE-2026-64483 CVE-2026-64484 CVE-2026-64487 CVE-2026-64488 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64510 CVE-2026-64514 CVE-2026-64529 CVE-2026-64534 CVE-2026-64538 CVE-2026-64540 CVE-2026-64541 CVE-2026-64544 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64553 CVE-2026-64554 CVE-2026-64560}
 	[bullseye] - linux 5.10.262-1


=====================================
data/dla-needed.txt
=====================================
@@ -30,11 +30,6 @@ rather than remove/replace existing ones.
   NOTE: 20260413: Try to clean postponed CVE (rouca/FD)
   NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
 --
-7zip/bookworm (Sylvain Beucler)
-  NOTE: 20260718: Added by Front-Desk (Beuc)
-  NOTE: 20260718: Maintainer updated the trixie SPU with 26.02.
-  NOTE: 20260718: Maintainer sent me a bookworm update for review. (Beuc)
---
 activemq
   NOTE: 20260413: Added by Front-Desk (rouca)
   NOTE: 20260715: Also add for bookworm



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b76e1ee94c9b7ab957d8ff5ef9b295b3f8d464cf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b76e1ee94c9b7ab957d8ff5ef9b295b3f8d464cf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/a02ee8b5/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list