[Git][security-tracker-team/security-tracker][master] 3 commits: Revert triage of qpid-proton assigned issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 6 16:15:07 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
818d2759 by Salvatore Bonaccorso at 2026-08-06T17:09:53+02:00
Revert triage of qpid-proton assigned issues
All issues are in Apache Qpid ProtonJ2 which is a distinct source and
not packaged in Debian.
- - - - -
edbbd3f2 by Salvatore Bonaccorso at 2026-08-06T17:10:58+02:00
auto-nfu: Add another covered product for the Apache CNA rule
- - - - -
3046c92f by Salvatore Bonaccorso at 2026-08-06T17:14:34+02:00
Process some NFUs
- - - - -
2 changed files:
- data/CVE/list
- data/packages/nfu.yaml
Changes:
=====================================
data/CVE/list
=====================================
@@ -1135,20 +1135,15 @@ CVE-2026-67855 (open62541 contains a heap use-after-free in the GDS PushManageme
- open62541 <unfixed>
NOTE: https://github.com/open62541/open62541/issues/8093
CVE-2026-67592 (It was not possible to govern the maximum number of transfer frames pe ...)
- - qpid-proton <unfixed>
- NOTE: https://lists.apache.org/thread/b4pv9hfdk7ox78pss77sb4nzwjrvqhhz
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-67591 (An authenticated attacker could exceed the session flow control incomi ...)
- - qpid-proton <unfixed>
- NOTE: https://lists.apache.org/thread/rwmggh2bkm6qotxpdfcplht3jgw5n036
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-67590 (A pre-authentication attacker could leverage type nesting to cause a S ...)
- - qpid-proton <unfixed>
- NOTE: https://lists.apache.org/thread/kmov6k7f3moqy01m1s370fl61vgos3ly
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-67589 (A pre-authentication attacker could leverage type size/count handling ...)
- - qpid-proton <unfixed>
- NOTE: https://lists.apache.org/thread/bs24x4778dh72xtfs299cy8krvdlo47q
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-67588 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
- - qpid-proton <unfixed>
- NOTE: https://lists.apache.org/thread/vk4j02dzggfdrdkwvzmqo4jro2tgj0jt
+ NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-67555 (It was not possible to govern the maximum number of transfer frames pe ...)
NOT-FOR-US: Apache Qpid Proton-Dotnet
CVE-2026-67554 (An authenticated attacker can craft a disposition frame with large or ...)
=====================================
data/packages/nfu.yaml
=====================================
@@ -382,6 +382,7 @@
- product: Apache OpenMeetings
- product: Apache OpenOffice
- product: Apache Polaris
+ - product: Apache Qpid ProtonJ2
- product: Apache Ranger
- product: Apache SIS
- product: Apache Seata (incubating)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c883516ca9b4ef0fe7a835c6e05cfb4f233c9ad5...3046c92fdb20f43f79ae014813494a8db42099dd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/c883516ca9b4ef0fe7a835c6e05cfb4f233c9ad5...3046c92fdb20f43f79ae014813494a8db42099dd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/e34f3c71/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list