[Git][security-tracker-team/security-tracker][helmutg/type-improvements] 229 commits: LTS: claim libgd2 in dla-needed.txt
Helmut Grohne (@helmutg)
helmutg at debian.org
Thu Aug 6 09:13:45 BST 2026
Helmut Grohne pushed to branch helmutg/type-improvements at Debian Security Tracker / security-tracker
Commits:
4eb6d6de by Guilhem Moulin at 2026-08-02T23:11:32+02:00
LTS: claim libgd2 in dla-needed.txt
- - - - -
b27875be by Thorsten Alteholz at 2026-08-02T23:58:20+02:00
mark CVE-2026-16473 as postponed for Bookworm and Bullseye
- - - - -
6cecdcb6 by Thorsten Alteholz at 2026-08-03T00:02:12+02:00
mark CVE-2026-16313 as postponed for Bookworm and Bullseye
- - - - -
b16088f0 by Thorsten Alteholz at 2026-08-03T00:05:33+02:00
mark CVE-2026-39879 as postponed for Bookworm and Bullseye
- - - - -
fbd7a71e by Thorsten Alteholz at 2026-08-03T00:13:11+02:00
mark CVE-2026-15146 as postponed for wget
- - - - -
50ae844e by Salvatore Bonaccorso at 2026-08-03T08:44:16+02:00
Two dracut issues fixed in unstable
- - - - -
afb50fa8 by Salvatore Bonaccorso at 2026-08-03T08:46:23+02:00
Track fixed version for CVE-2026-58016/glib2.0 via unstable
- - - - -
d7e5881a by security tracker role at 2026-08-03T07:12:29+00:00
automatic update
- - - - -
0c37430c by security tracker role at 2026-08-03T07:13:16+00:00
automatic NOT-FOR-US entries update
- - - - -
22062b2a by Salvatore Bonaccorso at 2026-08-03T09:26:02+02:00
Process some NFUs
- - - - -
b4757268 by Salvatore Bonaccorso at 2026-08-03T09:36:01+02:00
Add CVE-2026-18581/llama.cpp
- - - - -
dcf316c0 by Emilio Pozuelo Monfort at 2026-08-03T12:07:01+02:00
Track openjdk-8 issues fixed in unstable
- - - - -
0532e745 by Emilio Pozuelo Monfort at 2026-08-03T12:08:15+02:00
Drop CVE-2026-46917/openjdk-8 association
- - - - -
4cef7094 by Guilherme Puida Moreira at 2026-08-03T11:30:15+00:00
Update affected versions for CVE-2026-46377 and CVE-2026-46378
- - - - -
fe2bc3f2 by Salvatore Bonaccorso at 2026-08-03T15:27:23+02:00
Merge branch 'dasel-cves' into 'master'
Update affected versions for CVE-2026-46377 and CVE-2026-46378
See merge request security-tracker-team/security-tracker!315
- - - - -
c74cdb93 by Salvatore Bonaccorso at 2026-08-03T18:09:33+02:00
Add CVE-2026-6695/gimp
- - - - -
586b7ffc by Salvatore Bonaccorso at 2026-08-03T18:22:58+02:00
Add CVE-2026-6694/gimp
- - - - -
50a470a7 by Salvatore Bonaccorso at 2026-08-03T19:22:44+02:00
Track fixed version for CVE-2026-14461/mtr via unstable upload
- - - - -
69141fce by Salvatore Bonaccorso at 2026-08-03T19:30:24+02:00
Add some NFUs in XML-Sig Perl module
- - - - -
7255930c by Salvatore Bonaccorso at 2026-08-03T19:32:35+02:00
Add NFUs in Net-SAML2 Perl module
- - - - -
c11fe44f by Salvatore Bonaccorso at 2026-08-03T19:46:37+02:00
Add some new bouncycastle issues
- - - - -
500535a4 by Salvatore Bonaccorso at 2026-08-03T20:22:18+02:00
Add another batch of bouncycastle issues
- - - - -
73b6441c by Salvatore Bonaccorso at 2026-08-03T20:36:15+02:00
Track CVE fixes for perl issues addressed via experimental
- - - - -
07e4aaed by security tracker role at 2026-08-03T19:13:46+00:00
automatic update
- - - - -
012d052b by security tracker role at 2026-08-03T19:14:38+00:00
automatic NOT-FOR-US entries update
- - - - -
9a713ac2 by Salvatore Bonaccorso at 2026-08-03T21:22:45+02:00
Add Debian bug reference for the various bouncycastle issues
- - - - -
e093cc3a by Salvatore Bonaccorso at 2026-08-03T21:35:57+02:00
Process some NFUs
- - - - -
dc035edd by Salvatore Bonaccorso at 2026-08-03T21:37:10+02:00
Add CVE-2026-69153/node-postcss
- - - - -
18bb5da5 by Salvatore Bonaccorso at 2026-08-03T21:37:52+02:00
Add new node-brace-expansion issue (CVE-2026-69152)
- - - - -
c99f09d8 by Salvatore Bonaccorso at 2026-08-03T21:38:50+02:00
Add new angular.js issues
- - - - -
d0e4e489 by Salvatore Bonaccorso at 2026-08-03T21:39:19+02:00
Add new python-git issue
- - - - -
4eed9cf0 by Salvatore Bonaccorso at 2026-08-03T21:39:46+02:00
Add CVE-2026-68930/rust-russh
- - - - -
532d4723 by Salvatore Bonaccorso at 2026-08-03T21:59:46+02:00
Add CVE-2026-68742/sssd
- - - - -
44af0a09 by Salvatore Bonaccorso at 2026-08-03T22:01:24+02:00
Process some NFUs
- - - - -
58384119 by Salvatore Bonaccorso at 2026-08-03T22:02:19+02:00
Add CVE-2026-61372/apache-jena
- - - - -
1f0d70a1 by Salvatore Bonaccorso at 2026-08-03T22:03:00+02:00
Add CVE-2026-18718/ghidra, itp'ed
- - - - -
df57510d by Salvatore Bonaccorso at 2026-08-03T22:03:29+02:00
Add CVE-2026-18651/389-ds-base issue
- - - - -
ee787701 by Salvatore Bonaccorso at 2026-08-03T22:04:11+02:00
Add two tar issues (CVE-2026-18477 and CVE-2026-18508)
- - - - -
5492f5ca by Salvatore Bonaccorso at 2026-08-03T22:07:01+02:00
Add CVE-2026-12259/nltk
- - - - -
11e38771 by Salvatore Bonaccorso at 2026-08-03T22:10:40+02:00
Update status for CVE-2026-18321
- - - - -
ae7f9d19 by Helmut Grohne at 2026-08-03T23:02:59+02:00
web_support.py: tighten the types/encoding of Result objects
The Result class encapsulates the data to be returned for a HTTP
request. The BinaryResult subclass consumes "contents" as str or bytes
and encodes it as needed. Unfortunately, the Content-Length is computed
on the str object. If the contents contain multibyte characters, more
data may be returned than is conveyed via the Content-Length. This is
bad. The BinaryResult now really wants a bytes object to be passed. All
callers are changed to provide one.
For the HTMLResult, we know that encoding is needed and can do so
unconditionally. Thus maybe_encode (and its broad exception catching)
goes away for good.
- - - - -
b6eb8d7f by Carlos Henrique Lima Melara at 2026-08-03T22:01:44-03:00
CVE-2026-XXXX/nginx: mark as fixed in bullseye, fixed by DLA-4660-1
- - - - -
8080503d by Salvatore Bonaccorso at 2026-08-04T05:46:57+02:00
Track fixed version for golang-github-gomarkdown-markdown via unstable
- - - - -
ceaadacf by Salvatore Bonaccorso at 2026-08-04T05:48:30+02:00
Track fixed version for CVE-2026-18446/node-ajv via unstable
- - - - -
d45ccec0 by Abhijith PA at 2026-08-04T10:06:03+05:30
Reserve DLA-4716-1 for ruby2.7
- - - - -
26143405 by Abhijith PA at 2026-08-04T11:03:31+05:30
data/dla-needed.txt: Claim libvncserver
- - - - -
157b9e0f by security tracker role at 2026-08-04T07:12:19+00:00
automatic update
- - - - -
9decb637 by security tracker role at 2026-08-04T07:13:11+00:00
automatic NOT-FOR-US entries update
- - - - -
dc08d304 by Salvatore Bonaccorso at 2026-08-04T09:24:53+02:00
Remove annotations from one now rejected CVE
- - - - -
6468a93c by Salvatore Bonaccorso at 2026-08-04T09:33:43+02:00
Merge Linux CVEs from kernel-sec
- - - - -
39e376d8 by Salvatore Bonaccorso at 2026-08-04T10:37:22+02:00
Add new python-cryptography issues
- - - - -
4b180fbb by Salvatore Bonaccorso at 2026-08-04T10:38:21+02:00
Add two new guzzle issues
- - - - -
06d622c8 by Salvatore Bonaccorso at 2026-08-04T10:50:43+02:00
Add two new python-aiohttp issues
- - - - -
4625f718 by Salvatore Bonaccorso at 2026-08-04T10:56:23+02:00
Add two node-ip-address issues
- - - - -
e8a822fa by Salvatore Bonaccorso at 2026-08-04T11:12:08+02:00
Process some NFUs
- - - - -
56649df2 by Salvatore Bonaccorso at 2026-08-04T11:23:31+02:00
Process some NFUs
- - - - -
c17bbc38 by Salvatore Bonaccorso at 2026-08-04T11:32:23+02:00
Add one more sssd issue
- - - - -
bbb4fd76 by Salvatore Bonaccorso at 2026-08-04T11:35:53+02:00
Add one rust-crossbeam-epoch issue
- - - - -
b94b2a5b by Aron Xu at 2026-08-04T17:43:52+08:00
Take aom
- - - - -
5630c222 by Bastien Roucariès at 2026-08-04T12:10:58+02:00
Add php7.4
- - - - -
e44e2c7d by Salvatore Bonaccorso at 2026-08-04T12:53:54+02:00
Add CVE-2026-69185/node-socket.io-parser
- - - - -
be878ab8 by Salvatore Bonaccorso at 2026-08-04T12:59:57+02:00
Process some NFUs
- - - - -
81595ea3 by Salvatore Bonaccorso at 2026-08-04T13:00:31+02:00
Add CVE-2026-42169/gimp
- - - - -
6f54b953 by Salvatore Bonaccorso at 2026-08-04T13:02:32+02:00
Add CVE-2026-18739/popt
- - - - -
b4000f58 by Salvatore Bonaccorso at 2026-08-04T13:03:06+02:00
Add CVE-2026-18569/keycloak
- - - - -
e2eb7ecb by Salvatore Bonaccorso at 2026-08-04T13:03:52+02:00
Add CVE-2026-17614/WildFly
- - - - -
415b5984 by Bastien Roucariès at 2026-08-04T13:17:38+02:00
Python3.9 triagging
- - - - -
c9e893cf by Bastien Roucariès at 2026-08-04T14:17:40+02:00
CVE-2026-51105/LTS
- - - - -
2d9aa9d8 by Bastien Roucariès at 2026-08-04T15:02:10+02:00
CVE-2026-63317/LTS
- - - - -
38ed927c by Guilhem Moulin at 2026-08-04T15:11:15+02:00
LTS: claim php7.4 in dla-needed.txt
- - - - -
d58b803b by Bastien Roucariès at 2026-08-04T15:39:13+02:00
CVE-2026-47667/LTS
- - - - -
c94e069d by Bastien Roucariès at 2026-08-04T15:42:48+02:00
CVE-2026-67194/LTS
- - - - -
5409a586 by Bastien Roucariès at 2026-08-04T15:48:27+02:00
Add sssd to dla-needed
- - - - -
f3c12b18 by Salvatore Bonaccorso at 2026-08-04T19:56:57+02:00
Track fixed version for netcdf-perallel issues
- - - - -
17204e33 by Salvatore Bonaccorso at 2026-08-04T19:57:32+02:00
Cleanup note for CVE-2026-67194
- - - - -
4bc5b32d by Salvatore Bonaccorso at 2026-08-04T19:59:43+02:00
Track fixed version for golang-golang-x-text addressed via unstable
- - - - -
bb05ff4b by Salvatore Bonaccorso at 2026-08-04T20:07:52+02:00
Add Debian bug references for reported issues
- - - - -
cf23b250 by Salvatore Bonaccorso at 2026-08-04T20:40:51+02:00
Add new python-django issues
- - - - -
ae31154f by Salvatore Bonaccorso at 2026-08-04T20:44:59+02:00
Add references for python-django issues
- - - - -
4d426331 by security tracker role at 2026-08-04T19:12:58+00:00
automatic update
- - - - -
965242af by security tracker role at 2026-08-04T19:13:46+00:00
automatic NOT-FOR-US entries update
- - - - -
635c72fb by Salvatore Bonaccorso at 2026-08-04T21:19:04+02:00
Update status for CVE-2026-64193
- - - - -
d6d1f13c by Salvatore Bonaccorso at 2026-08-04T21:19:48+02:00
Add Debian bug reference for python-django issues
- - - - -
1f43d44e by Salvatore Bonaccorso at 2026-08-04T21:33:11+02:00
Process some NFUs
- - - - -
6e40b3c8 by Salvatore Bonaccorso at 2026-08-04T21:33:50+02:00
Process two new stunnel issues
- - - - -
87922d64 by Salvatore Bonaccorso at 2026-08-04T21:38:12+02:00
Add another sssd issue with only Red Hat bugilla reference
- - - - -
4d36ac94 by Salvatore Bonaccorso at 2026-08-04T21:38:51+02:00
Add three new pdm issues
- - - - -
8940ba87 by Bastien Roucariès at 2026-08-04T21:45:34+02:00
Add php8.2 to dla-needed
- - - - -
81606cf7 by Salvatore Bonaccorso at 2026-08-04T22:13:34+02:00
auto-nfu: Add another product for the Eclipse CNA rule
- - - - -
0ef0f518 by Salvatore Bonaccorso at 2026-08-04T22:14:04+02:00
auto-nfu: Add another product for the NVIDIA CNA rule
- - - - -
3b060f7d by Salvatore Bonaccorso at 2026-08-04T22:14:48+02:00
Process some NFUs
- - - - -
b64da344 by Salvatore Bonaccorso at 2026-08-04T22:24:24+02:00
Add two jackson-core issues
- - - - -
ec027db9 by Salvatore Bonaccorso at 2026-08-04T22:26:04+02:00
Process some NFUs
- - - - -
c37b8647 by Salvatore Bonaccorso at 2026-08-04T22:26:44+02:00
Add CVE-2026-18809/firefox
- - - - -
5ce5209c by Salvatore Bonaccorso at 2026-08-04T22:29:42+02:00
Add two open62541 issues
- - - - -
aeb7df6f by Salvatore Bonaccorso at 2026-08-04T22:30:50+02:00
Add CVE-2026-18772/rlottie
- - - - -
064c1701 by Salvatore Bonaccorso at 2026-08-04T22:31:28+02:00
Add CVE-2026-13229/Zammad, itp'ed
- - - - -
4e7ecf2d by Salvatore Bonaccorso at 2026-08-04T22:32:13+02:00
Add CVE-2026-10050/jetty
- - - - -
c3019565 by Bastien Roucariès at 2026-08-04T22:34:43+02:00
goaccess triagging
- - - - -
8a4c28c7 by Bastien Roucariès at 2026-08-04T22:36:38+02:00
CVE-2026-54332/LTS
- - - - -
3589e8d5 by Bastien Roucariès at 2026-08-04T22:40:16+02:00
Add libarchive
- - - - -
fc438de2 by Bastien Roucariès at 2026-08-04T22:45:49+02:00
Add u-boot to dla-needed
- - - - -
83f57c6b by Bastien Roucariès at 2026-08-04T22:48:33+02:00
Add python-zeroconf
- - - - -
71114246 by Bastien Roucariès at 2026-08-04T22:56:21+02:00
Add node-ip-address
CVE-2026-69192 is high and may lead to security bypass
- - - - -
5d06d218 by Bastien Roucariès at 2026-08-04T22:59:52+02:00
CVE-2026-18536/LTS
- - - - -
1952ac17 by Bastien Roucariès at 2026-08-04T23:02:45+02:00
CVE-2026-18446/LTS
- - - - -
e1fd274a by Bastien Roucariès at 2026-08-04T23:04:42+02:00
Add php-dompdf to dla-needed
- - - - -
0445993a by Bastien Roucariès at 2026-08-04T23:06:59+02:00
Add puma to dla-needed
- - - - -
df4d7d4e by Bastien Roucariès at 2026-08-05T00:03:05+02:00
CVE-2024-42643/LTS
- - - - -
9c0a5697 by Bastien Roucariès at 2026-08-05T00:12:06+02:00
ruby-websocket-driver/LTS
- - - - -
10fa234a by Bastien Roucariès at 2026-08-05T00:24:47+02:00
add to dla-needed ruby-oauth2
- - - - -
3d3a2420 by Bastien Roucariès at 2026-08-05T00:29:45+02:00
CVE-2026-54522/LTS
- - - - -
8d743a7f by Bastien Roucariès at 2026-08-05T00:31:25+02:00
Add dla-needed ruby-jwt
- - - - -
b247c69e by Bastien Roucariès at 2026-08-05T00:34:19+02:00
Add to dla-needed to python-django
- - - - -
36cb527b by Bastien Roucariès at 2026-08-05T00:40:46+02:00
CVE-2026-18321/LTS
- - - - -
6d3d24c6 by Bastien Roucariès at 2026-08-05T00:43:06+02:00
onnx/LTS
- - - - -
d58118ca by Bastien Roucariès at 2026-08-05T00:45:25+02:00
CVE-2026-55995
- - - - -
2f388d30 by Chris Lamb at 2026-08-04T16:35:38-07:00
data/dla-needed.txt: Claim python-django.
- - - - -
a20c058d by Aron Xu at 2026-08-05T10:05:06+08:00
Reserve DSA for aom
- - - - -
c44b4d80 by Aron Xu at 2026-08-05T10:17:25+08:00
Reserve DSA for botan3
- - - - -
7cbd5acd by Aron Xu at 2026-08-05T10:23:40+08:00
Take jq
- - - - -
d63977a6 by Salvatore Bonaccorso at 2026-08-05T05:37:59+02:00
Track fixed versions via unstable for thunderbird issues
- - - - -
4bd72511 by Salvatore Bonaccorso at 2026-08-05T05:39:47+02:00
Add CVE-2026-66901 as NFU
- - - - -
83c4b546 by Salvatore Bonaccorso at 2026-08-05T05:40:34+02:00
Add CVE-2026-66902 as NFU
- - - - -
458340b0 by Salvatore Bonaccorso at 2026-08-05T06:00:29+02:00
Track fixed version for python-django via unstable
- - - - -
3d19c930 by Salvatore Bonaccorso at 2026-08-05T06:04:26+02:00
Track fixed version for CVE-2026-69247/python-cryptography via unstable
- - - - -
173d326c by Salvatore Bonaccorso at 2026-08-05T06:57:54+02:00
Add two new libxfont issues
- - - - -
70631250 by Salvatore Bonaccorso at 2026-08-05T08:02:06+02:00
Update status for CVE-2026-57451/vim
- - - - -
2cfab1d3 by Salvatore Bonaccorso at 2026-08-05T08:09:03+02:00
Correct status for CVE-2026-32316 in trixie
The patch was not applied in the 1.7.1-6+deb13u2
- - - - -
a0abecca by Salvatore Bonaccorso at 2026-08-05T08:19:40+02:00
Track fixed version via unstable for two guzzle issues
- - - - -
800e0af0 by Salvatore Bonaccorso at 2026-08-05T08:48:02+02:00
Add CVE-2026-42170/gimp
- - - - -
2fa5cad0 by security tracker role at 2026-08-05T07:12:32+00:00
automatic update
- - - - -
71faffc8 by security tracker role at 2026-08-05T07:13:19+00:00
automatic NOT-FOR-US entries update
- - - - -
581d7ba3 by Salvatore Bonaccorso at 2026-08-05T09:34:00+02:00
Remove notes from CVE-2026-13325
Red Hat Product Security has come to the conclusion that this CVE is not
needed.
- - - - -
276cf5c1 by Salvatore Bonaccorso at 2026-08-05T09:53:10+02:00
Add new Ghost CMS issues
- - - - -
2cc78837 by Emilio Pozuelo Monfort at 2026-08-05T09:58:35+02:00
Reserve DLA-4717-1 for linux
- - - - -
bd1be042 by Bastien Roucariès at 2026-08-05T10:12:26+02:00
pglogical triagging
- - - - -
7dfbf181 by Bastien Roucariès at 2026-08-05T10:14:05+02:00
Add pglogical
- - - - -
041b3f53 by Bastien Roucariès at 2026-08-05T10:18:32+02:00
Add pipewire to dla-needed
- - - - -
a454be6d by Salvatore Bonaccorso at 2026-08-05T10:19:42+02:00
Process some NFUs
- - - - -
dd02e904 by Bastien Roucariès at 2026-08-05T10:25:39+02:00
imagemagick/LTS
Postpone a few issue:
- DoS only
- Need particular flags
May be fixed with later release
- - - - -
751147a2 by Bastien Roucariès at 2026-08-05T10:26:31+02:00
Add python-cryptography to dla-needed
- - - - -
49a1cf89 by Salvatore Bonaccorso at 2026-08-05T10:33:53+02:00
Add CVE-2026-71201/ironic
- - - - -
89258b23 by Salvatore Bonaccorso at 2026-08-05T10:36:28+02:00
CVEs for swift issues now assigned
- - - - -
9dc5ab50 by Bastien Roucariès at 2026-08-05T10:49:00+02:00
Add neutron to dla-needed
- - - - -
e73faa3d by Bastien Roucariès at 2026-08-05T10:49:00+02:00
Add rails to dla-needed
- - - - -
b16bc458 by Salvatore Bonaccorso at 2026-08-05T10:52:35+02:00
Add new batch of qpid-java issues
- - - - -
b1307967 by Salvatore Bonaccorso at 2026-08-05T10:55:00+02:00
Add new batch of open62541 issues
- - - - -
b9eee8c6 by Salvatore Bonaccorso at 2026-08-05T11:01:58+02:00
Add new qpid-proton issues
- - - - -
1cd76a84 by Salvatore Bonaccorso at 2026-08-05T11:11:21+02:00
Process some NFUs
- - - - -
6049dc93 by Emilio Pozuelo Monfort at 2026-08-05T12:20:17+02:00
Track xorg-server issues fixed in unstable
- - - - -
069ad916 by Emilio Pozuelo Monfort at 2026-08-05T12:22:16+02:00
Track xwayland issues fixed in unstable
- - - - -
b7cecc9b by Salvatore Bonaccorso at 2026-08-05T13:39:13+02:00
Process some NFUs
- - - - -
759b9edf by Salvatore Bonaccorso at 2026-08-05T13:40:12+02:00
Add new opensips issues
- - - - -
42334221 by Salvatore Bonaccorso at 2026-08-05T13:41:40+02:00
Add CVE-2026-18819/racktables
- - - - -
ece73735 by Salvatore Bonaccorso at 2026-08-05T13:46:47+02:00
Associate some CVEs with src:opensips
- - - - -
6329b243 by Sylvain Beucler at 2026-08-05T14:46:13+02:00
lts: claim p7zip
- - - - -
e67cf99d by Bastien Roucariès at 2026-08-05T14:52:52+02:00
Add calibre to dla-needed
- - - - -
49f2d92b by Bastien Roucariès at 2026-08-05T15:10:43+02:00
Add texworks for affected by CVE-2026-63729
Not fixed: https://sources.debian.org/src/texworks/0.6.10%2Bds-1/modules/synctex/synctex_parser.c?hl=1431#L907
fixed: https://sources.debian.org/src/texworks/0.6.11+ds-2/modules/synctex/synctex_parser.c?hl=1431#L1431
- - - - -
c51f4b33 by Bastien Roucariès at 2026-08-05T15:14:29+02:00
Add texsudio for CVE-2026-63729
not-affected: https://sources.debian.org/src/texstudio/4.9.6+ds-1/src/pdfviewer/synctex/synctex_parser.c?hl=1431#L1431
affected: https://sources.debian.org/src/texstudio/4.9.2%2Bds-1/src/pdfviewer/synctex/synctex_parser.c?hl=1431#L920
- - - - -
240ebba0 by Bastien Roucariès at 2026-08-05T15:17:14+02:00
Add emacs-pdf-tools for CVE-2026-63729
use old version: https://sources.debian.org/src/emacs-pdf-tools/1.3.0-1/server/synctex_parser.c?hl=4781#L4781
- - - - -
d25487b5 by Bastien Roucariès at 2026-08-05T15:28:02+02:00
Add synctex to embeded code copy
- - - - -
9350717e by Bastien Roucariès at 2026-08-05T15:29:48+02:00
Add okular for syntex CVE
affected: https://sources.debian.org/src/okular/4:26.04.2-1/core/synctex/synctex_parser.c?hl=4609#L870
- - - - -
b76e1ee9 by Sylvain Beucler at 2026-08-05T15:30:52+02:00
Reserve DLA-4718-1 for 7zip
- - - - -
a0b9eb20 by Sylvain Beucler at 2026-08-05T15:32:27+02:00
Reserve DLA-4719-1 for p7zip
- - - - -
968a0a9a by Bastien Roucariès at 2026-08-05T15:33:56+02:00
Add libmojo-jwt-perl to dla-needed
- - - - -
101abf56 by Bastien Roucariès at 2026-08-05T16:10:33+02:00
Ignore CVE-2026-66011 for LTS
- - - - -
17a52a24 by Emilio Pozuelo Monfort at 2026-08-05T17:14:29+02:00
lts: add dist to php packages
- - - - -
75a8f044 by Salvatore Bonaccorso at 2026-08-05T17:43:42+02:00
Merge Linux CVEs from kernel-sec
- - - - -
7de74f17 by Salvatore Bonaccorso at 2026-08-05T17:46:47+02:00
Merge Linux CVEs from kernel-sec
- - - - -
2cf7fa7d by Ben Hutchings at 2026-08-05T18:07:01+02:00
Reserve DLA-4720-1 for linux
- - - - -
c7992233 by Bastien Roucariès at 2026-08-05T18:15:15+02:00
CVE-2026-64685
- - - - -
7be3fc91 by Santiago Ruano Rincón at 2026-08-05T14:46:07-03:00
Removed fontforge from dla-needed.txt
No open CVEs remaining.
- - - - -
d9060f41 by Bastien Roucariès at 2026-08-05T19:52:05+02:00
Remove a few packages from dla-needed
- - - - -
cbdedc7e by Salvatore Bonaccorso at 2026-08-05T19:57:08+02:00
Add CVE-2026-54876/openssl
- - - - -
1517fea5 by Bastien Roucariès at 2026-08-05T20:07:13+02:00
libpgjava/LTS
- - - - -
372bccc7 by Bastien Roucariès at 2026-08-05T20:08:40+02:00
Remove from dla-needed libpgjava
- - - - -
c0eb18cb by Salvatore Bonaccorso at 2026-08-05T20:35:28+02:00
Track fixed version for CVE-2025-70952/libpf4j-java via unstable
- - - - -
de38be23 by Bastien Roucariès at 2026-08-05T20:37:10+02:00
libxmltok/LTS
- - - - -
2c7564cc by Bastien Roucariès at 2026-08-05T20:37:35+02:00
Remove libxmltok from dla-needed
- - - - -
9bd38c97 by Salvatore Bonaccorso at 2026-08-05T20:44:19+02:00
Track fixed version for CVE-2026-9064/389-ds-base
- - - - -
b3323e2e by security tracker role at 2026-08-05T19:14:01+00:00
automatic update
- - - - -
3e2f532f by security tracker role at 2026-08-05T19:14:53+00:00
automatic NOT-FOR-US entries update
- - - - -
e9807efd by Salvatore Bonaccorso at 2026-08-05T21:24:35+02:00
Process some NFUs
- - - - -
1fb40135 by Salvatore Bonaccorso at 2026-08-05T21:40:19+02:00
Process some NFUs
- - - - -
616c556f by Salvatore Bonaccorso at 2026-08-05T21:41:55+02:00
Add CVE-2026-71265/domoticz, itp'ed
- - - - -
6468e0eb by Salvatore Bonaccorso at 2026-08-05T21:42:28+02:00
Add CVE-2026-71236/grocy, itp'ed
- - - - -
8bf68d21 by Salvatore Bonaccorso at 2026-08-05T21:44:02+02:00
Reassign some CVEs with grocy, itp'ed entry
- - - - -
b9c7d284 by Salvatore Bonaccorso at 2026-08-05T21:57:00+02:00
Add new libkcapi with some AI assisted overhead
- - - - -
8ced0a4d by Salvatore Bonaccorso at 2026-08-05T21:58:53+02:00
Process some NFUs
- - - - -
ea882b38 by Salvatore Bonaccorso at 2026-08-05T22:02:57+02:00
Add new batch of electron issues, itp'ed
- - - - -
bd3b40c0 by Salvatore Bonaccorso at 2026-08-05T22:07:00+02:00
Add two ghost issues, itp'ed
- - - - -
1e83a3de by Bastien Roucariès at 2026-08-05T22:28:47+02:00
Fix libsynctex embed copy
texlive is considered as main source under debian
- - - - -
caf1ae8a by Salvatore Bonaccorso at 2026-08-05T22:38:14+02:00
auto-nfu: Add another product covered by the Apache CNA rule
- - - - -
ebe019cb by Salvatore Bonaccorso at 2026-08-05T22:42:48+02:00
Process some NFUs
- - - - -
caed5c92 by Salvatore Bonaccorso at 2026-08-05T22:44:16+02:00
Add new keycloak issues
- - - - -
4bb3d97e by Bastien Roucariès at 2026-08-05T22:50:21+02:00
libsynctex is used by emacs-pdf-tools
- - - - -
bd8cdb0d by Bastien Roucariès at 2026-08-05T22:50:25+02:00
mark emacs-pdf-tools has not affected by libsyntex CVE
- - - - -
3f795233 by Bastien Roucariès at 2026-08-05T23:00:04+02:00
texworks not affected by libsynctex
- - - - -
b40ed93b by Emmanuel Arias at 2026-08-06T00:34:54-03:00
Add NOTE for CVE-2026-13321
- - - - -
55e1a607 by Emmanuel Arias at 2026-08-06T00:43:56-03:00
Add NOTE for CVE-2026-13204
- - - - -
aa8de11f by Emmanuel Arias at 2026-08-06T00:50:39-03:00
CVE-2026-12617: mark not-affected in bullseye; add commit for bookworm
- - - - -
885f9ddf by Aron Xu at 2026-08-06T12:59:24+08:00
Take libde265
- - - - -
d93f2f2f by Salvatore Bonaccorso at 2026-08-06T07:02:47+02:00
Drop entries with no security impact on CVE-2026-63729
- - - - -
fa6a453a by Salvatore Bonaccorso at 2026-08-06T07:17:01+02:00
Track fixed version for libxfont issues
- - - - -
788b1f3d by Salvatore Bonaccorso at 2026-08-06T07:39:37+02:00
Drop trailing whitespaces
- - - - -
b5c1c7eb by Salvatore Bonaccorso at 2026-08-06T07:40:07+02:00
Update status for some hdf5 issues
- - - - -
2422cc31 by Salvatore Bonaccorso at 2026-08-06T07:42:17+02:00
Update status for CVE-2025-2153
- - - - -
8f2daced by Salvatore Bonaccorso at 2026-08-06T07:46:40+02:00
Update status for hdf5 issues
- - - - -
f8d2266e by security tracker role at 2026-08-06T07:12:31+00:00
automatic update
- - - - -
0c07b4ba by security tracker role at 2026-08-06T07:13:21+00:00
automatic NOT-FOR-US entries update
- - - - -
6d299b6b by Salvatore Bonaccorso at 2026-08-06T09:42:59+02:00
Process some NFUs
- - - - -
8622a70c by Salvatore Bonaccorso at 2026-08-06T09:43:54+02:00
Add new rclone issues
- - - - -
250c3830 by Emilio Pozuelo Monfort at 2026-08-06T07:46:12+00:00
Merge branch 'helmutg/web-result-encoding' into 'master'
web_support.py: tighten the types/encoding of Result objects
See merge request security-tracker-team/security-tracker!316
- - - - -
0cbdfe6c by Salvatore Bonaccorso at 2026-08-06T09:48:47+02:00
Merge Linux CVEs from kernel-sec
- - - - -
6fb57bd1 by Bastien Roucariès at 2026-08-06T09:52:42+02:00
LTS triagging
- - - - -
fde003d9 by Bastien Roucariès at 2026-08-06T09:54:10+02:00
ruby-sqlite3/LTS
- - - - -
c965fa47 by Salvatore Bonaccorso at 2026-08-06T09:54:52+02:00
Merge Linux CVEs from kernel-sec
- - - - -
bf26fe38 by Helmut Grohne at 2026-08-06T10:10:16+02:00
lib: change internUrgency not to return None
A number of callers of internUrgency are not prepared to handle its None
return value. Rather than fix all the callers, make it raise an
exception and adapt the one place that wants to handle it.
- - - - -
b0c0ac7c by Helmut Grohne at 2026-08-06T10:10:16+02:00
lib: change internRelease not to return None
A number of callers of internRelease are not prepared to handle its None
return value. Rather than fix all the callers, make it raise an
exception.
- - - - -
844275b3 by Helmut Grohne at 2026-08-06T10:10:16+02:00
web tracker: delete method pre_dispatch
None of the implementations is non-trivial, but the more striking issue
is that their argument count varies. Rather than figure out, what is
right, dispose this unused mechanism.
- - - - -
6f2e2ba2 by Helmut Grohne at 2026-08-06T10:10:16+02:00
delete test of isKernOnly
Fixes: efd6f70f4aca ("Remove unused methods")
- - - - -
f2b26c11 by Helmut Grohne at 2026-08-06T10:10:16+02:00
security_db.py: use sets
Some of this code predates the introduction of the set type to Python
and uses dicts with True values instead. We can now convert this to
proper sets. More importantly, this helps avoid variable type changes.
The list conversion can be deferred.
- - - - -
169198d1 by Helmut Grohne at 2026-08-06T10:10:16+02:00
tracker_service.py: pass a bool where a bool is expected
The getFakeBugs parameter vulnerability actually expects a bool. Pass it
as such.
- - - - -
5c76015e by Helmut Grohne at 2026-08-06T10:10:16+02:00
security_db.py: rewrite mergeLists using sets
Aside from being faster, this avoids changing the type of the result
variable.
- - - - -
f3cb7adb by Helmut Grohne at 2026-08-06T10:11:52+02:00
python: avoid more variable type changes
If we ever want to head into type checking, the type of value stored in
a variable should not change. Thus rename affected assignments or elide
them entirely.
- - - - -
1003eb6d by Helmut Grohne at 2026-08-06T10:11:58+02:00
tracker_service.py: narrow implied type of filters attribute
The lookup in params may return None in principle. This influences type
deduction and filters is assumed to be able to hold None, but the next
line changes that. In combining them, the deduced type of filters
becomes narrower.
- - - - -
a81ad957 by Helmut Grohne at 2026-08-06T10:11:58+02:00
tracker_service.py: don't pass None via body_attribs
While a None value might be acceptable there, it is discarded anyway.
Rather than supporting that use case, simply avoid passing it.
- - - - -
b8f08ba5 by Helmut Grohne at 2026-08-06T10:11:58+02:00
tracker_service.py: explicitly cast hide_check to bool
When we pass it to getTODOs a real bool is expected, so convert the
thing that might be a list early.
- - - - -
12 changed files:
- bin/tracker_service.py
- data/CVE/list
- data/DLA/list
- data/DSA/list
- data/dla-needed.txt
- data/dsa-needed.txt
- data/embedded-code-copies
- data/packages/nfu.yaml
- lib/python/bugs.py
- lib/python/debian_support.py
- lib/python/security_db.py
- lib/python/web_support.py
Changes:
=====================================
bin/tracker_service.py
=====================================
@@ -45,9 +45,9 @@ class BugFilter:
self.params = {}
for (prop, desc, field) in self.action_list:
self.params[prop] = int(params.get(prop, (0,))[0])
- self.filters=params.get('filter')
- if not self.filters:
- self.filters=['high_urgency', 'medium_urgency', 'low_urgency', 'unassigned_urgency']
+ self.filters = (
+ params.get('filter') or ['high_urgency', 'medium_urgency', 'low_urgency', 'unassigned_urgency']
+ )
def actions(self, url):
"""Returns a HTML snippet which can be used to change the filter."""
@@ -156,7 +156,7 @@ class TrackerService(WebServiceHTTP):
self.register('script.js', self.page_script_js)
def page_style_css(self, path, params, url):
- with open('../static/style.css', 'r') as f:
+ with open('../static/style.css', 'rb') as f:
content=f.read()
return BinaryResult(content,'text/css')
@@ -166,12 +166,12 @@ class TrackerService(WebServiceHTTP):
return BinaryResult(content,'image/png')
def page_distributions_json(self, path, params, url):
- with open('../static/distributions.json', 'r') as f:
+ with open('../static/distributions.json', 'rb') as f:
content=f.read()
return BinaryResult(content,'application/json')
def page_script_js(self, path, params, url):
- with open('../static/script.js', 'r') as f:
+ with open('../static/script.js', 'rb') as f:
content=f.read()
return BinaryResult(content,'text/javascript')
@@ -925,7 +925,7 @@ checker to find out why they have not entered testing yet."""),
"Remote", ""))])
def page_status_todo(self, path, params, url):
- hide_check = params.get('hide_check', False)
+ hide_check = bool(params.get('hide_check', False))
if hide_check:
flags = A(url.updateParamsDict({'hide_check' : None}),
'Show "check" TODOs')
@@ -1177,13 +1177,9 @@ not unimportant."""),
def gen():
for (rel, subrel, archive, sources, archs) \
in self.db.availableReleases():
- if sources:
- sources = 'yes'
- else:
- sources = 'no'
if 'source' in archs:
archs.remove('source')
- yield rel, subrel, archive, sources, make_list(archs)
+ yield rel, subrel, archive, "yes" if sources else "no" , make_list(archs)
return self.create_page(
url, "Available releases",
[P("""The security issue database is checked against
@@ -1237,8 +1233,8 @@ issue (or a bug has been created and is not recorded in this database).
In the second kind of names, there is a Debian bug for the issue, and the "''',
CODE("000000"), '''"part of the name is replaced with the
Debian bug number.'''),
- make_table(gen(1),title=H2('With unfixed issues'), caption=("Bug", "Description")),
- make_table(gen(0),title=H2('The rest'), caption=("Bug", "Description")),
+ make_table(gen(True),title=H2('With unfixed issues'), caption=("Bug", "Description")),
+ make_table(gen(False),title=H2('The rest'), caption=("Bug", "Description")),
])
def page_data_pts(self, path, params, url):
@@ -1256,7 +1252,7 @@ Debian bug number.'''),
data.append(':')
data.append(str(bugs))
data.append('\n')
- return BinaryResult(''.join(data),'application/octet-stream')
+ return BinaryResult(''.join(data).encode("utf-8"), 'application/octet-stream')
def exported_result(self, path, url):
data = self.db.getExported(path)
@@ -1289,17 +1285,16 @@ Debian bug number.'''),
"Source"),
" ", A(url.absolute("https://salsa.debian.org/security-tracker-team/security-tracker"), "(Git)"),
)))
+ body_attribs = {}
if search_in_page:
- on_load = "selectSearch()"
- else:
- on_load = None
+ body_attribs["onload"] = "selectSearch()"
head_contents = compose(
LINK(' ', href=url.scriptRelative("style.css")),
SCRIPT(' ', src=url.scriptRelative("script.js")),
).toHTML()
return HTMLResult(self.add_title(title, body,
head_contents=head_contents,
- body_attribs={'onload': on_load}),
+ body_attribs=body_attribs),
doctype=self.html_dtd(),
status=status)
@@ -1527,8 +1522,5 @@ Debian bug number.'''),
def make_dangerous(self, contents):
return SPAN(contents, _class="dangerous")
- def pre_dispatch(self):
- pass
-
if __name__ == "__main__":
TrackerService(socket_name, db_name).run()
=====================================
data/CVE/list
=====================================
The diff for this file was not included because it is too large.
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,19 @@
+[05 Aug 2026] DLA-4720-1 linux - security update
+ {CVE-2024-36013 CVE-2025-40196 CVE-2026-31610 CVE-2026-43216 CVE-2026-46135 CVE-2026-53332 CVE-2026-53392 CVE-2026-53393 CVE-2026-53399 CVE-2026-53400 CVE-2026-53402 CVE-2026-63797 CVE-2026-63806 CVE-2026-63810 CVE-2026-63815 CVE-2026-63818 CVE-2026-63829 CVE-2026-64187 CVE-2026-64189 CVE-2026-64206 CVE-2026-64248 CVE-2026-64250 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64279 CVE-2026-64296 CVE-2026-64297 CVE-2026-64298 CVE-2026-64299 CVE-2026-64301 CVE-2026-64303 CVE-2026-64304 CVE-2026-64306 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64318 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64329 CVE-2026-64330 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64336 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346 CVE-2026-64347 CVE-2026-64350 CVE-2026-64351 CVE-2026-64352 CVE-2026-64355 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361 CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64365 CVE-2026-64370 CVE-2026-64371 CVE-2026-64372 CVE-2026-64373 CVE-2026-64374 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378 CVE-2026-64379 CVE-2026-64380 CVE-2026-64381 CVE-2026-64390 CVE-2026-64393 CVE-2026-64394 CVE-2026-64395 CVE-2026-64396 CVE-2026-64397 CVE-2026-64398 CVE-2026-64399 CVE-2026-64401 CVE-2026-64403 CVE-2026-64406 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64417 CVE-2026-64419 CVE-2026-64420 CVE-2026-64422 CVE-2026-64423 CVE-2026-64425 CVE-2026-64428 CVE-2026-64429 CVE-2026-64430 CVE-2026-64432 CVE-2026-64435 CVE-2026-64436 CVE-2026-64437 CVE-2026-64438 CVE-2026-64440 CVE-2026-64441 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64446 CVE-2026-64448 CVE-2026-64449 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64456 CVE-2026-64458 CVE-2026-64461 CVE-2026-64462 CVE-2026-64465 CVE-2026-64468 CVE-2026-64469 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64475 CVE-2026-64476 CVE-2026-64478 CVE-2026-64480 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64488 CVE-2026-64489 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64510 CVE-2026-64512 CVE-2026-64514 CVE-2026-64530 CVE-2026-64531 CVE-2026-64532 CVE-2026-64533 CVE-2026-64534 CVE-2026-64535 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64557 CVE-2026-64560 CVE-2026-64600}
+ [bookworm] - linux 6.1.180-1
+[05 Aug 2026] DLA-4719-1 p7zip - security update
+ {CVE-2026-14266 CVE-2026-58052}
+ [bullseye] - p7zip 16.02+really26.02+dfsg-0+deb11u1
+ [bookworm] - p7zip 16.02+really26.02+dfsg-0+deb12u1
+[05 Aug 2026] DLA-4718-1 7zip - security update
+ {CVE-2026-14266 CVE-2026-58052}
+ [bookworm] - 7zip 22.01+really26.02+dfsg-0+deb12u1
+[05 Aug 2026] DLA-4717-1 linux - security update
+ {CVE-2022-49803 CVE-2022-50114 CVE-2023-52494 CVE-2025-23131 CVE-2025-39931 CVE-2026-23204 CVE-2026-31451 CVE-2026-31755 CVE-2026-43216 CVE-2026-43219 CVE-2026-43499 CVE-2026-46116 CVE-2026-46135 CVE-2026-46252 CVE-2026-46331 CVE-2026-52942 CVE-2026-53138 CVE-2026-53157 CVE-2026-53158 CVE-2026-53159 CVE-2026-53167 CVE-2026-53177 CVE-2026-53325 CVE-2026-53329 CVE-2026-53332 CVE-2026-53381 CVE-2026-53382 CVE-2026-53385 CVE-2026-53392 CVE-2026-53393 CVE-2026-53397 CVE-2026-53398 CVE-2026-53399 CVE-2026-53400 CVE-2026-53402 CVE-2026-53403 CVE-2026-63794 CVE-2026-63796 CVE-2026-63798 CVE-2026-63800 CVE-2026-63801 CVE-2026-63803 CVE-2026-63806 CVE-2026-63808 CVE-2026-63809 CVE-2026-63814 CVE-2026-63815 CVE-2026-63818 CVE-2026-63822 CVE-2026-63823 CVE-2026-63824 CVE-2026-63827 CVE-2026-63828 CVE-2026-63829 CVE-2026-63830 CVE-2026-63831 CVE-2026-63834 CVE-2026-63835 CVE-2026-63836 CVE-2026-64188 CVE-2026-64189 CVE-2026-64191 CVE-2026-64206 CVE-2026-64249 CVE-2026-64252 CVE-2026-64266 CVE-2026-64268 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64296 CVE-2026-64298 CVE-2026-64299 CVE-2026-64303 CVE-2026-64304 CVE-2026-64306 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64318 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64329 CVE-2026-64330 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64345 CVE-2026-64347 CVE-2026-64348 CVE-2026-64351 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361 CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64370 CVE-2026-64371 CVE-2026-64372 CVE-2026-64373 CVE-2026-64374 CVE-2026-64375 CVE-2026-64378 CVE-2026-64379 CVE-2026-64380 CVE-2026-64381 CVE-2026-64403 CVE-2026-64406 CVE-2026-64408 CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64420 CVE-2026-64422 CVE-2026-64423 CVE-2026-64425 CVE-2026-64429 CVE-2026-64435 CVE-2026-64436 CVE-2026-64438 CVE-2026-64442 CVE-2026-64445 CVE-2026-64446 CVE-2026-64448 CVE-2026-64450 CVE-2026-64452 CVE-2026-64455 CVE-2026-64456 CVE-2026-64461 CVE-2026-64462 CVE-2026-64465 CVE-2026-64468 CVE-2026-64469 CVE-2026-64470 CVE-2026-64471 CVE-2026-64475 CVE-2026-64478 CVE-2026-64483 CVE-2026-64484 CVE-2026-64487 CVE-2026-64488 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64510 CVE-2026-64514 CVE-2026-64529 CVE-2026-64534 CVE-2026-64538 CVE-2026-64540 CVE-2026-64541 CVE-2026-64544 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64553 CVE-2026-64554 CVE-2026-64560}
+ [bullseye] - linux 5.10.262-1
+[04 Aug 2026] DLA-4716-1 ruby2.7 - security update
+ {CVE-2025-24294 CVE-2025-61594 CVE-2026-27820 CVE-2026-41316}
+ [bullseye] - ruby2.7 2.7.4-1+deb11u6
[02 Aug 2026] DLA-4715-1 kissfft - security update
{CVE-2025-34297 CVE-2026-41445}
[bullseye] - kissfft 131.1.0-1+deb11u1
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,9 @@
+[05 Aug 2026] DSA-6412-1 botan3 - security update
+ {CVE-2026-44378}
+ [trixie] - botan3 3.12.0+dfsg-2~deb13u1
+[05 Aug 2026] DSA-6411-1 aom - security update
+ {CVE-2026-56208 CVE-2026-56209 CVE-2026-56210 CVE-2026-56211}
+ [trixie] - aom 3.12.1-1+deb13u1
[02 Aug 2026] DSA-6410-1 libssh - security update
{CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-15370 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850}
[trixie] - libssh 0.11.5-0+deb13u1
=====================================
data/dla-needed.txt
=====================================
@@ -30,11 +30,6 @@ rather than remove/replace existing ones.
NOTE: 20260413: Try to clean postponed CVE (rouca/FD)
NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
--
-7zip/bookworm (Sylvain Beucler)
- NOTE: 20260718: Added by Front-Desk (Beuc)
- NOTE: 20260718: Maintainer updated the trixie SPU with 26.02.
- NOTE: 20260718: Maintainer sent me a bookworm update for review. (Beuc)
---
activemq
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260715: Also add for bookworm
@@ -63,9 +58,6 @@ aom/bookworm
NOTE: 20260709: AV1 *encoder* flaws (SVC layer-id/LAP), CVE-2026-56208..56211; only
NOTE: 20260709: bookworm (3.6.0) affected, bullseye not-affected (code added in aom 2.0.0).
--
-apache-directory-api
- NOTE: 20260608: Added by Front-Desk (rouca)
---
apache-log4j2/bullseye
NOTE: 20260413: Added by Front-Desk (rouca)
--
@@ -90,9 +82,6 @@ busybox
NOTE: 20260722: Also add for bookworm; CVE-2026-38752..38755 (ash/awk)
NOTE: 20260722: share code, sponsored, already queued bullseye+ELTS (utkarsh)
--
-c3p0/bullseye
- NOTE: 20260414: Added by Front-Desk (rouca)
---
ca-certificates (rouca)
NOTE: 20250613: Added by Front-Desk (rouca)
NOTE: 20250613: Lack some certificates #1095913 (rouca/FD)
@@ -115,13 +104,12 @@ caddy/bookworm
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
+calibre (Abhijith)
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
cjson
NOTE: 20260801: Added by Front-Desk (ta)
--
-ckeditor/bullseye
- NOTE: 20241002: Added by Front-Desk (Beuc)
- NOTE: 20241002: Multiple CVEs have been piling up (Beuc/front-desk)
---
clamav (Emilio)
NOTE: 20260711: Added by Front-Desk (utkarsh)
NOTE: 20260711: Needs a newer rustc to be backported as well. (utkarsh)
@@ -147,12 +135,6 @@ cyrus-imapd
NOTE: 20260717: Added by Front-Desk (Beuc)
NOTE: 20260717: Upcoming DSA (Beuc/front-desk)
--
-docker-registry
- NOTE: 20260419: Added by Front-Desk (rouca)
- NOTE: 20260725: Also add for bookworm (2.8.2); CVE-2026-33540 proxyauth.go
- NOTE: 20260725: realm handling identical to bullseye. CVE-2026-41888 is
- NOTE: 20260725: not-affected there (tag-delete code is 3.0.0+). (utkarsh/front-desk)
---
docker.io
NOTE: 20250805: Added by Front-Desk (rouca)
NOTE: 20260714: Also add for bookworm (Beuc/front-desk)
@@ -209,9 +191,6 @@ firmware-nonfree/bullseye
flatpak/bullseye
NOTE: 20260413: Added by Front-Desk (rouca)
--
-fontforge/bullseye
- NOTE: 20260216: Added by Front-Desk (rouca)
---
freerdp2
NOTE: 20260127: Added by Front-Desk (Beuc)
NOTE: 20260127: Many CVEs fixed in 3.20.1 and 3.21, but missing fix commits (Beuc/front-desk)
@@ -247,16 +226,6 @@ glances/bullseye
NOTE: 20260518: Added by Front-Desk (Beuc)
NOTE: 20260518: Many postponed vulnerabilities piled-up (Beuc/front-desk)
--
-golang-github-gorilla-csrf/bullseye
- NOTE: 20250422: Added by Front-Desk (rouca)
- NOTE: 20250422: Need to binNMU reverse depends (in that order): golang-github-alecthomas-chroma, golang-github-niklasfasching-go-org, golang-github-yuin-goldmark-highlighting, hugo (rouca)
- NOTE: 20250621: Re-add as binNMUs are not all properly Installed in the archive, e.g.
- NOTE: 20250621: https://buildd.debian.org/status/package.php?p=hugo&suite=bullseye-security
- NOTE: 20250621: https://buildd.debian.org/status/package.php?p=golang-github-alecthomas-chroma&suite=bullseye-security
- NOTE: 20250621: https://buildd.debian.org/status/package.php?p=golang-github-niklasfasching-go-org&suite=bullseye-security
- NOTE: 20250621: still stuck at Uploaded phase, probably due to missing sources at security.debian.org (Beuc)
- NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
---
golang-glog/bullseye
NOTE: 20250209: Added by Front-Desk (apo)
NOTE: 20251107: Re-add as binNMUs are not all properly Installed in the archive:
@@ -329,6 +298,9 @@ ldap-account-manager
NOTE: 20260725: Also add for bookworm (8.3); CVE-2026-27894 PDF-export LFI,
NOTE: 20260725: unvalidated pdf_structure/pdf_font identical to bullseye. (utkarsh/front-desk)
--
+libarchive
+ NOTE: 20260804: Added by Front-Desk. Take care of CVE-2026-15028 (rouca)
+--
libass
NOTE: 20260712: Added by Front-Desk (utkarsh)
NOTE: 20260712: TEMP-0000000-AA08BC (GHSA-pjjp-65r7-ppgm): OOB read+write in wrap_lines_measure from untrusted subtitles; secteam fixed stable via point release. Affected in bullseye (0.15.0) and bookworm (0.17.1). (utkarsh/front-desk)
@@ -356,7 +328,7 @@ libde265
NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
NOTE: 20260709: upstream fixes v1.0.19-v1.1.1 newer than Debian 1.0.11.
--
-libgd2
+libgd2 (guilhem)
NOTE: 20260731: Added by Front-Desk (ta)
--
libgit2
@@ -370,12 +342,12 @@ libio-compress-perl
NOTE: 20260612: Added by Front-Desk (rouca)
NOTE: 20260612: MUST hold-back following the upper suites and wait for green light from security team (rouca/FD)
--
+libmojo-jwt-perl
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
libnet-dns-perl
NOTE: 20260802: Added by Front-Desk (ta)
--
-libpgjava
- NOTE: 20260613: Added by Front-Desk (rouca)
---
librabbitmq
NOTE: 20260731: Added by Front-Desk (ta)
--
@@ -444,18 +416,13 @@ libstb/bullseye
NOTE: 20260226: Fixed CVE-2021-28021 CVE-2021-37789 CVE-2021-42715 CVE-2022-28041 CVE-2022-28042 with DLA-4493-1 (abhijith)
NOTE: 20260429: Revisit when upstream merge the proposed fixes. Though other embed libstb projects patched (abhijith)
--
-libvncserver
+libvncserver (Abhijith PA)
NOTE: 20260612: Added by Front-Desk (rouca)
--
libwebsockets/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
--
-libxmltok
- NOTE: 20250421: Added by Front-Desk (ta)
- NOTE: 20250421: Also review all other expat CVEs. (bunk)
- NOTE: 20250421: Fixing the expat copy in xmlrpc-c at the same time would make sense. (bunk)
---
libxslt/bullseye
NOTE: 20250930: Added by Front-Desk (rouca)
NOTE: 20251020: In progress, waiting for upstream action (guilhem)
@@ -544,6 +511,9 @@ netty (rouca)
NOTE: 20260114: fix remaining CVE wait DSA (rouca)
NOTE: 20260331: release DLA-4519-1 netty. Unfortunatly partial due to new CVEs (rouca)
--
+neutron
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
nginx (charles)
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Special care is needed for the HTTP2 Bomb (TEMP-1138794-BADE22)
@@ -556,6 +526,9 @@ node-dompurify/bookworm
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
+node-ip-address
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
node-lodash/bookworm (utkarsh)
NOTE: 20260703: Added by Front-Desk (dleidert)
NOTE: 20260703: Follow DLA 4663-1; assigned to Utkarsh to grab this (dleidert/front-desk)
@@ -630,10 +603,6 @@ openvswitch/bullseye
orthanc/bullseye
NOTE: 20260419: Added by Front-Desk (rouca)
--
-p7zip
- NOTE: 20260718: Added by Front-Desk (Beuc)
- NOTE: 20260718: Follow 7zip updates.
---
pacemaker
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Package is in dsa-needed (charles)
@@ -654,6 +623,12 @@ pgextwlist
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Follow DSA-6385-1 (1 CVE) (Beuc/front-desk)
--
+pglogical
+ NOTE: 20260805: Added by Front-Desk, due to CVE-2026-50738 (rouca)
+--
+php-dompdf
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
php-horde-imp/bullseye
NOTE: 20260714: Added by Front-Desk (Beuc)
--
@@ -670,11 +645,21 @@ php-twig/bullseye
NOTE: 20260521: Added by Front-Desk (Beuc)
NOTE: 20260521: Cf. symfony batch of CVEs, upcoming DSA (Beuc/front-desk)
--
+php7.4/bullseye (guilhem)
+ NOTE: 20260804: Added by Front-Desk (rouca)
+ NOTE: 20260804: Follow DSA-6406-1 (rouca/front-desk)
+--
+php8.2/bookworm (guilhem)
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
phpseclib/bullseye (Utkarsh)
NOTE: 20260518: Added by Front-Desk (Beuc)
NOTE: 20260518: Follow bookworm 12.14 (2 CVEs) (Beuc/front-desk)
NOTE: 20260720: will get back to this after releasing squid. (utkarsh)
--
+pipewire
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
proftpd-dfsg
NOTE: 20260511: Added by Beuc for maintainer (Hilmar Preuße)
NOTE: 20260511: https://lists.debian.org/debian-lts/2026/05/msg00015.html
@@ -685,6 +670,9 @@ prosody/bullseye
NOTE: 20260511: Added by Front-Desk (dleidert)
NOTE: 20260511: Follow DSA 6252-1 fixing 4 CVEs (dleidert/front-desk)
--
+puma
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
py7zr
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-23879 (GHSA range <=1.1.2); Debian 0.11.3 in range.
@@ -700,6 +688,12 @@ python-aiohttp (dleidert)
NOTE: 20260611: Added by Front-Desk (rouca)
NOTE: 20260602: Daniel Leidert is proposing to work on the update and provide debdiffs for bookworm and trixie (carnil)
--
+python-cryptography
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
+python-django (Chris Lamb)
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
python-eventlet/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
@@ -747,6 +741,9 @@ python-tornado
NOTE: 20260722: Extend to bullseye; CVE-2026-49853/49854/49855 in 6.1.0 too,
NOTE: 20260722: shared with bookworm; fix in 6.5.6 (utkarsh/front-desk)
--
+python-zeroconf
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
qemu
NOTE: 20260520: Added by Front-Desk (Beuc)
NOTE: 20260520: Many postponed CVEs piled up (Beuc/front-desk)
@@ -761,6 +758,9 @@ rabbitmq-server/bullseye
NOTE: 20260504: Added by coordinator (santiago)
NOTE: 20260504: Added to address out-standing minor issues
--
+rails
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
redis (Chris Lamb)
NOTE: 20260727: Added by Front-Desk (utkarsh)
NOTE: 20260727: CVE-2026-66373: double free in the stream consumer PEL
@@ -779,6 +779,12 @@ rsync (Thorsten Alteholz)
NOTE: 20260615: Requested by Sylvain to track regressions, same as in dsa-needed. (charles)
NOTE: 20260705: making progress with updated patches
--
+ruby-jwt
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
+ruby-oauth2
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
ruby-oj
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: Oj JSON parser memory-safety batch CVE-2026-54500..54903 (GHSA); affects 2.17-3.14.
@@ -788,6 +794,7 @@ ruby2.7/bullseye (Abhijith PA)
NOTE: 20260608: https://people.debian.org/~abhijith/upload/ruby2.7_patches/ (abhijith)
NOTE: 20260731: Prepared an upload with already triaged issues. Group Net::IMAP issues
NOTE: 20260731: and do upload later (abhijith)
+ NOTE: 20260804: Uploaded 2.7.4-1+deb11u6 and released DLA-4716-1 (abhijith)
--
ruby3.1/bookworm
NOTE: 20260713: Added by Front-Desk (Beuc)
@@ -865,6 +872,11 @@ spip/bullseye
NOTE: 20260326: very low popcon (Beuc/front-desk)
NOTE: 20260422: https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/342
--
+sssd
+ NOTE: 20260804: Added by Front-Desk (rouca)
+ NOTE: 20260804: Crash or DoS of sssd may lead to user lockdown (rouca/FD)
+ NOTE: 20260804: SSSD should be tested carefully, with integration test (rouca/FD)
+--
starlette/bullseye (dleidert)
NOTE: 20260528: Added by Front-Desk (dleidert)
NOTE: 20260528: follow DSA-6302-1 (dleidert/front-desk)
@@ -925,6 +937,9 @@ trafficserver/bullseye
NOTE: 20250403: There are multiple new CVEs. But none of them is addresses in Sid and maintainers didn't reply to me last time (dleidert)
NOTE: 20250405: DSA 5896-1 is out (Beuc/front-desk)
--
+u-boot
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
unbound
NOTE: 20260520: Added by Front-Desk (Beuc)
NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
=====================================
data/dsa-needed.txt
=====================================
@@ -20,10 +20,6 @@ activemq
amd64-microcode (carnil)
Coordinating with maintainer DSA/bookworm-pu and sync with mitgations in src:linux
--
-aom
---
-botan3 (aron)
---
cacti
probably best to move to 1.2.31
--
@@ -56,7 +52,7 @@ jetty9
--
jetty12
--
-jq
+jq (aron)
possibly move trixie to 1.8.2
--
jupyterlab
@@ -66,7 +62,7 @@ kamailio
kitty
Maintainer proposed debdiff for review in https://bugs.debian.org/1139898#15
--
-libde265
+libde265 (aron)
possibly best to move to 1.1.1
--
libheif
=====================================
data/embedded-code-copies
=====================================
@@ -3975,3 +3975,11 @@ erlang-cowlib
node-systeminformation
- jupyterlab 4.0.11+ds5+~cs11.25.27-1 (embed)
NOTE: node-systeminformation split from jupyterlab
+
+libsynctex2 (embed in texlive-bin)
+ - texlive-bin <unfixable> (embed)
+ - texworks 0.5~svn1363-5 (embed but not compiled)
+ - texstudio <unfixed> (embed)
+ - emacs-pdf-tools 0.90-1 (embed)
+ - okular <unfixed> (embed)
+ NOTE: texlive-bin is considered under debian as main source
=====================================
data/packages/nfu.yaml
=====================================
@@ -372,6 +372,7 @@
- product: Apache Kyuubi
- product: Apache Livy
- product: Apache Lucene.Net
+ - product: Apache Lucy
- product: Apache Mynewt NimBLE
- product: Apache Neethi
- product: Apache NiFi
@@ -462,6 +463,7 @@
- product: Eclipse Glassfish
- product: Eclipse KUKSA - Databroker
- product: Eclipse Kura
+ - product: Eclipse Milo
- product: Eclipse OMR
- product: Eclipse OpenJ9
- product: Eclipse Parsson
@@ -585,6 +587,7 @@
- product: DALI
- product: DGX Spark
- product: DLS component of NVIDIA License System
+ - product: Dynamo
- product: FLARE SDK
- product: Isaac Lab
- product: Isaac Launchable
=====================================
lib/python/bugs.py
=====================================
@@ -31,10 +31,10 @@ def listUrgencies():
Urgency.urgencies = urgencies
return urgencies
def internUrgency(name, urgencies=listUrgencies()):
- if name in urgencies:
+ try:
return urgencies[name]
- else:
- return None
+ except KeyError as err:
+ raise ValueError("invalid urgency") from err
del listUrgencies
def to_integer(expr):
@@ -63,13 +63,9 @@ class PackageNote:
else:
if isinstance(release, str):
release = debian_support.internRelease(release)
- if release is None:
- raise ValueError("invalid release")
self.release = release
if isinstance(urgency, str):
urgency = internUrgency(urgency)
- if urgency is None:
- raise ValueError("invalid urgency")
self.urgency = urgency
self.bugs = []
self.package_kind = "unknown"
@@ -144,10 +140,11 @@ class PackageNoteParsed(PackageNote):
urgency = 'not yet assigned'
if notes is not None:
for n in self.re_notes_split.split(notes):
- u = internUrgency(n)
- if u:
- urgency = u
+ try:
+ urgency = internUrgency(n)
continue
+ except ValueError:
+ pass
if n == 'bug filed':
continue
@@ -172,10 +169,7 @@ class PackageNoteNoDSA:
else:
assert isinstance(reason, str)
self.package = package
- release = debian_support.internRelease(release)
- if release is None:
- raise ValueError("invalid release")
- self.release = release
+ self.release = debian_support.internRelease(release)
self.comment = comment
self.reason = reason
=====================================
lib/python/debian_support.py
=====================================
@@ -218,10 +218,10 @@ def listReleases():
Release.releases = releases
return releases
def internRelease(name, releases=listReleases()):
- if name in releases:
+ try:
return releases[name]
- else:
- return None
+ except KeyError as err:
+ raise ValueError("invalid release") from err
del listReleases
def readLinesSHA1(lines):
=====================================
lib/python/security_db.py
=====================================
@@ -73,14 +73,7 @@ def mergeLists(a, b):
b = []
else:
b = b.split(',')
- result = {}
- for x in a:
- result[x] = 1
- for x in b:
- result[x] = 1
- result = list(result.keys())
- result.sort()
- return result
+ return sorted(set(a).union(b))
class NVDEntry:
"""A class for an entry in the nvd_data table.
@@ -155,7 +148,7 @@ def getBugsForSourcePackage(cursor, pkg):
# Restrict to regular releases excluding e.g. backports.
release_names = tuple(debian_support.Release.releases)
- data = itertools.starmap(
+ data_iter = itertools.starmap(
BugsForSourcePackage_internal,
cursor.execute(
BugsForSourcePackage_query.replace(
@@ -168,7 +161,7 @@ def getBugsForSourcePackage(cursor, pkg):
all_bugs = []
version_key = functools.cmp_to_key(version_compare)
# Group by bug name.
- for bug_name, data in itertools.groupby(data,
+ for bug_name, data in itertools.groupby(data_iter,
lambda row: row.bug_name):
description = None
open_seen = False
@@ -863,7 +856,7 @@ class DB:
# stores aggregated data, and there is no efficient way to
# handle updates of the records related to a single file.
- packages = {}
+ packages = defaultdict(set)
unchanged = True
for filename in filenames:
match = re_packages.match(filename)
@@ -884,10 +877,7 @@ class DB:
% (arch, name))
key = (name, release, subrelease, archive, version,
source, source_version)
- if key in packages:
- packages[key][arch] = 1
- else:
- packages[key] = {arch : 1}
+ packages[key].add(arch)
if unchanged:
if self.verbose:
@@ -899,18 +889,12 @@ class DB:
cursor.execute("DELETE FROM binary_packages")
self._clearVersions(cursor)
- l = list(packages.keys())
-
- if len(l) == 0:
+ if len(packages) == 0:
raise ValueError("no binary packages found")
- l.sort()
def gen():
- for key in l:
- archs = list(packages[key].keys())
- archs.sort()
- archs = ','.join(archs)
- yield key + (archs,)
+ for key, archs in sorted(packages.items()):
+ yield key + (",".join(sorted(archs)),)
if self.verbose:
print(" storing binary package data")
@@ -1500,28 +1484,21 @@ class DB:
# Check if any packages in plain testing are vulnerable, and
# if all of those have been fixed in the security archive.
fixed_in_security = True
- unfixed_pkgs = {}
- undet_pkgs = {}
- unimp_pkgs = {}
+ unfixed_pkgs = set()
+ undet_pkgs = set()
+ unimp_pkgs = set()
for ((package, note), (vulnerable, urgency)) in status[''].items():
if vulnerable == 1:
if urgency == 'unimportant':
- unimp_pkgs[package] = True
+ unimp_pkgs.add(package)
else:
- unfixed_pkgs[package] = True
+ unfixed_pkgs.add(package)
if status['security'].get((package, note), True):
fixed_in_security = False
elif status['lts'].get((package, note), True):
fixed_in_security = False
elif vulnerable == 2:
- undet_pkgs[package] = True
-
- unfixed_pkgs = list(unfixed_pkgs.keys())
- unfixed_pkgs.sort()
- undet_pkgs = list(undet_pkgs.keys())
- undet_pkgs.sort()
- unimp_pkgs = list(unimp_pkgs.keys())
- unimp_pkgs.sort()
+ undet_pkgs.add(package)
pkgs = ""
result = "undetermined"
@@ -1533,9 +1510,9 @@ class DB:
result = "fixed"
if len(unfixed_pkgs) > 0:
if len(unfixed_pkgs) == 1:
- pkgs += "package " + unfixed_pkgs[0] + " is "
+ pkgs += "package " + next(iter(unfixed_pkgs)) + " is "
else:
- pkgs += "packages " + ", ".join(unfixed_pkgs) + " are "
+ pkgs += "packages " + ", ".join(sorted(unfixed_pkgs)) + " are "
if fixed_in_security:
pkgs = "%sfixed in %s-security. " % (pkgs, suite)
if suite == "stable":
@@ -1547,15 +1524,15 @@ class DB:
result = "vulnerable"
if len(undet_pkgs) > 0:
if len(undet_pkgs) == 1:
- pkgs += "package " + undet_pkgs[0] + " may be vulnerable but needs to be checked."
+ pkgs += "package " + next(iter(undet_pkgs)) + " may be vulnerable but needs to be checked."
else:
- pkgs += "packages " + ", ".join(undet_pkgs) + " may be vulnerable but need to be checked."
+ pkgs += "packages " + ", ".join(sorted(undet_pkgs)) + " may be vulnerable but need to be checked."
if len(unimp_pkgs) > 0 and len(undet_pkgs) == 0 and len(unfixed_pkgs) == 0:
result = "fixed"
if len(unimp_pkgs) == 1:
- pkgs = "package %s is vulnerable; however, the security impact is unimportant." % unimp_pkgs[0]
+ pkgs = "package %s is vulnerable; however, the security impact is unimportant." % next(iter(unimp_pkgs))
else:
- pkgs = "packages %s are vulnerable; however, the security impact is unimportant." % (', '.join(unimp_pkgs))
+ pkgs = "packages %s are vulnerable; however, the security impact is unimportant." % (', '.join(sorted(unimp_pkgs)))
cursor.execute("""INSERT INTO bug_status
(bug_name, release, status, reason)
@@ -1665,9 +1642,9 @@ class DB:
kind, urgency_to_flag[urgency], remote,
fix_available,
package, fixed_version, description))
- result = zlib.compress(''.join(result).encode('utf-8'), 9)
+ compressed = zlib.compress(''.join(result).encode('utf-8'), 9)
- self.storeExport('debsecan/release/' + release, 'application/octet-stream', result)
+ self.storeExport('debsecan/release/' + release, 'application/octet-stream', compressed)
c.execute("DROP TABLE vulnlist")
@@ -1711,7 +1688,7 @@ class DB:
'not yet assigned' : ' '}
vuln_list = []
- source_packages = {}
+ source_packages = set()
def fill_vuln_list(source_packages=source_packages):
for (bug, package) in list(c.execute(
"""SELECT DISTINCT bug_name, package
@@ -1732,7 +1709,7 @@ class DB:
unstable_fixed = ''
total_urgency = ''
- other_versions = {}
+ other_versions = set()
is_binary = False
is_unknown = False
fixed_releases = {}
@@ -1755,7 +1732,7 @@ class DB:
if kind == 'binary':
is_binary = True
elif kind == 'source':
- source_packages[package] = True
+ source_packages.add(package)
else:
is_unknown = True
@@ -1784,7 +1761,7 @@ class DB:
if v is None:
continue
if debian_support.Version(v) >= v_ref:
- other_versions[v] = True
+ other_versions.add(v)
# The second part of this SELECT statement
# covers binary-only NMUs.
@@ -1796,7 +1773,7 @@ class DB:
AND release = ?2 AND subrelease IN ('', 'security', 'lts')""",
(package, release)):
if debian_support.Version(v) >= v_ref:
- other_versions[v] = True
+ other_versions.add(v)
if not total_urgency:
total_urgency = 'unknown'
@@ -1818,9 +1795,7 @@ class DB:
elif is_unknown:
bs_flag = ' '
- other_versions = list(other_versions.keys())
- other_versions.sort()
- other_versions = ' '.join(other_versions)
+ other_versions_str = ' '.join(sorted(other_versions))
vuln_list.append(("%s,%d,%c%c%c"
% (package, bug_to_index[bug],
@@ -1828,14 +1803,12 @@ class DB:
bug_to_remote_flag[bug]),
fixed_releases.keys(),
",%s,%s"
- % (unstable_fixed, other_versions)))
+ % (unstable_fixed, other_versions_str)))
fill_vuln_list()
- source_packages = list(source_packages.keys())
- source_packages.sort()
def store_value(name, value):
- value = zlib.compress(value.encode('utf-8'), 9)
- self.storeExport('debsecan/' + name, 'application/octet-stream', value)
+ compressed = zlib.compress(value.encode('utf-8'), 9)
+ self.storeExport('debsecan/' + name, 'application/octet-stream', compressed)
def gen_release(release):
result = result_start[:]
@@ -1848,7 +1821,7 @@ class DB:
result.append(prefix + fixed + suffix)
result.append('')
- for sp in source_packages:
+ for sp in sorted(source_packages):
bp_list = []
for (bp,) in c.execute("""SELECT name FROM binary_packages
WHERE source = ? AND release = ? AND subrelease = ''
@@ -1867,7 +1840,7 @@ class DB:
gen_release(release)
result = result_start
- for (prefix, release, suffix) in vuln_list:
+ for (prefix, releases, suffix) in vuln_list:
result.append(prefix + ' ' + suffix)
result.append('')
result.append('')
@@ -1885,6 +1858,7 @@ class DB:
for (data, content_type, last_modified) in self.cursor().execute(
"SELECT data, content_type, last_modified FROM export_data WHERE path = ?",
(name,)):
+ assert isinstance(data, bytes)
return (data, content_type, last_modified)
return None
@@ -2126,8 +2100,8 @@ class DB:
RELEASE-LIST, VERSION, VULNERABLE-FLAG) of source packages
which are related to the given bug."""
- releases = config.get_supported_releases()
- values = [bug] + releases
+ supported_releases = config.get_supported_releases()
+ values = [bug] + supported_releases
for (package, releases, version, vulnerable) in cursor.execute(
"""SELECT package, string_list(release), version, vulnerable
@@ -2136,7 +2110,7 @@ class DB:
p.version AS version, s.vulnerable AS vulnerable
FROM source_package_status AS s, source_packages AS p
WHERE s.bug_name = ? AND p.rowid = s.package
- AND release in (""" + ",".join("?" * len(releases)) + """))
+ AND release in (""" + ",".join("?" * len(supported_releases)) + """))
GROUP BY package, version, vulnerable
ORDER BY package, releasepart_to_number(release), subreleasepart_to_number(release), version COLLATE version""",
values):
@@ -2448,7 +2422,5 @@ def test():
else:
assert False
- assert bugs.BugFromDB(cursor, 'DSA-311').isKernelOnly()
-
if __name__ == "__main__":
test()
=====================================
lib/python/web_support.py
=====================================
@@ -512,11 +512,6 @@ class RedirectResult(Result):
self.status = 302
self.headers['Location'] = str(url)
-def maybe_encode(obj):
- try:
- return obj.encode()
- except:
- return obj
class HTMLResult(Result):
"""An object of this class combines a status code with HTML contents."""
@@ -540,13 +535,12 @@ class HTMLResult(Result):
buf.write(self.doctype)
buf.write('\n')
self.contents.flatten(buf.write)
- buf = buf.getvalue()
- buf = maybe_encode(buf)
- self.headers['Content-Length'] = str(len(buf))
+ encoded_data = buf.getvalue().encode("utf-8")
+ self.headers['Content-Length'] = str(len(encoded_data))
def later(req):
headers_later(req)
if req.command != 'HEAD':
- req.wfile.write(buf)
+ req.wfile.write(encoded_data)
return later
class BinaryResult(Result):
@@ -569,7 +563,7 @@ class BinaryResult(Result):
def later(req):
headers_later(req)
if req.command != 'HEAD':
- req.wfile.write(maybe_encode(self.contents))
+ req.wfile.write(self.contents)
return later
class WebServiceBase:
@@ -618,10 +612,6 @@ class WebServiceBase:
return Tag('html',
(HEAD(head_list), Tag('body', body_list, **body_attribs)))
- def pre_dispatch(self, url):
- """Invoked by handle prior to calling the registered handler."""
- pass
-
class ThreadingHTTPServer(ThreadingMixIn, HTTPServer):
daemon_threads = True
@@ -650,7 +640,6 @@ class WebServiceHTTP(WebServiceBase):
service_self.lock.acquire()
try:
- service_self.pre_dispatch()
r = method(remaining, params, url)
assert isinstance(r, Result), repr(r)
result = r.flatten_later()
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/13a2bb9656c305a0f01f91088680bcdce7662ddd...b8f08ba5f10aef1461adcb8f71a5231f78dad818
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/13a2bb9656c305a0f01f91088680bcdce7662ddd...b8f08ba5f10aef1461adcb8f71a5231f78dad818
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/b1a88187/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list