[Git][security-tracker-team/security-tracker][master] Reserve DSA for libde265

Aron Xu (@aron) aron at debian.org
Thu Aug 6 10:29:36 BST 2026



Aron Xu pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1fd648b3 by Aron Xu at 2026-08-06T17:28:47+08:00
Reserve DSA for libde265

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -306986,14 +306986,12 @@ CVE-2024-39241 (Cross Site Scripting (XSS) vulnerability in skycaiji 2.8 allows
 	NOT-FOR-US: skycaiji
 CVE-2024-38950 (Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attacker ...)
 	- libde265 1.1.1-1 (bug #1074416)
-	[trixie] - libde265 <postponed> (Minor issue, revisit when fixed upstream)
 	[bookworm] - libde265 <postponed> (Minor issue, revisit when fixed upstream)
 	[bullseye] - libde265 <no-dsa> (Minor issue)
 	NOTE: https://github.com/strukturag/libde265/issues/460
 	NOTE: https://github.com/strukturag/libde265/commit/4089de0845e0009e019be4ca5cbebaf2aee0a8ce (v1.0.19)
 CVE-2024-38949 (Heap Buffer Overflow vulnerability in Libde265 v1.0.15 allows attacker ...)
 	- libde265 1.1.1-1 (bug #1074416)
-	[trixie] - libde265 <postponed> (Minor issue, revisit when fixed upstream)
 	[bookworm] - libde265 <postponed> (Minor issue, revisit when fixed upstream)
 	[bullseye] - libde265 <no-dsa> (Minor issue)
 	NOTE: https://github.com/strukturag/libde265/issues/460


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[06 Aug 2026] DSA-6413-1 libde265 - security update
+	{CVE-2024-38949 CVE-2024-38950 CVE-2025-61147 CVE-2026-45382 CVE-2026-45383 CVE-2026-49295 CVE-2026-49337 CVE-2026-49346 CVE-2026-54240 CVE-2026-54241}
+	[trixie] - libde265 1.0.15-1+deb13u1
 [05 Aug 2026] DSA-6412-1 botan3 - security update
 	{CVE-2026-44378}
 	[trixie] - botan3 3.12.0+dfsg-2~deb13u1


=====================================
data/dsa-needed.txt
=====================================
@@ -62,9 +62,6 @@ kamailio
 kitty
   Maintainer proposed debdiff for review in https://bugs.debian.org/1139898#15
 --
-libde265 (aron)
-  possibly best to move to 1.1.1
---
 libheif
   possibly best to move to 1.23.0
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fd648b3ae5c53ec85dfe683bba9c6ed7aa91bbd

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fd648b3ae5c53ec85dfe683bba9c6ed7aa91bbd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/1319d203/attachment.htm>


More information about the debian-security-tracker-commits mailing list