[Git][security-tracker-team/security-tracker][helmutg/web-adapter] 309 commits: Add CVE-2026-12259/nltk
Helmut Grohne (@helmutg)
helmutg at debian.org
Fri Aug 7 18:28:44 BST 2026
Helmut Grohne pushed to branch helmutg/web-adapter at Debian Security Tracker / security-tracker
Commits:
5492f5ca by Salvatore Bonaccorso at 2026-08-03T22:07:01+02:00
Add CVE-2026-12259/nltk
- - - - -
11e38771 by Salvatore Bonaccorso at 2026-08-03T22:10:40+02:00
Update status for CVE-2026-18321
- - - - -
b6eb8d7f by Carlos Henrique Lima Melara at 2026-08-03T22:01:44-03:00
CVE-2026-XXXX/nginx: mark as fixed in bullseye, fixed by DLA-4660-1
- - - - -
8080503d by Salvatore Bonaccorso at 2026-08-04T05:46:57+02:00
Track fixed version for golang-github-gomarkdown-markdown via unstable
- - - - -
ceaadacf by Salvatore Bonaccorso at 2026-08-04T05:48:30+02:00
Track fixed version for CVE-2026-18446/node-ajv via unstable
- - - - -
d45ccec0 by Abhijith PA at 2026-08-04T10:06:03+05:30
Reserve DLA-4716-1 for ruby2.7
- - - - -
26143405 by Abhijith PA at 2026-08-04T11:03:31+05:30
data/dla-needed.txt: Claim libvncserver
- - - - -
157b9e0f by security tracker role at 2026-08-04T07:12:19+00:00
automatic update
- - - - -
9decb637 by security tracker role at 2026-08-04T07:13:11+00:00
automatic NOT-FOR-US entries update
- - - - -
dc08d304 by Salvatore Bonaccorso at 2026-08-04T09:24:53+02:00
Remove annotations from one now rejected CVE
- - - - -
6468a93c by Salvatore Bonaccorso at 2026-08-04T09:33:43+02:00
Merge Linux CVEs from kernel-sec
- - - - -
39e376d8 by Salvatore Bonaccorso at 2026-08-04T10:37:22+02:00
Add new python-cryptography issues
- - - - -
4b180fbb by Salvatore Bonaccorso at 2026-08-04T10:38:21+02:00
Add two new guzzle issues
- - - - -
06d622c8 by Salvatore Bonaccorso at 2026-08-04T10:50:43+02:00
Add two new python-aiohttp issues
- - - - -
4625f718 by Salvatore Bonaccorso at 2026-08-04T10:56:23+02:00
Add two node-ip-address issues
- - - - -
e8a822fa by Salvatore Bonaccorso at 2026-08-04T11:12:08+02:00
Process some NFUs
- - - - -
56649df2 by Salvatore Bonaccorso at 2026-08-04T11:23:31+02:00
Process some NFUs
- - - - -
c17bbc38 by Salvatore Bonaccorso at 2026-08-04T11:32:23+02:00
Add one more sssd issue
- - - - -
bbb4fd76 by Salvatore Bonaccorso at 2026-08-04T11:35:53+02:00
Add one rust-crossbeam-epoch issue
- - - - -
b94b2a5b by Aron Xu at 2026-08-04T17:43:52+08:00
Take aom
- - - - -
5630c222 by Bastien Roucariès at 2026-08-04T12:10:58+02:00
Add php7.4
- - - - -
e44e2c7d by Salvatore Bonaccorso at 2026-08-04T12:53:54+02:00
Add CVE-2026-69185/node-socket.io-parser
- - - - -
be878ab8 by Salvatore Bonaccorso at 2026-08-04T12:59:57+02:00
Process some NFUs
- - - - -
81595ea3 by Salvatore Bonaccorso at 2026-08-04T13:00:31+02:00
Add CVE-2026-42169/gimp
- - - - -
6f54b953 by Salvatore Bonaccorso at 2026-08-04T13:02:32+02:00
Add CVE-2026-18739/popt
- - - - -
b4000f58 by Salvatore Bonaccorso at 2026-08-04T13:03:06+02:00
Add CVE-2026-18569/keycloak
- - - - -
e2eb7ecb by Salvatore Bonaccorso at 2026-08-04T13:03:52+02:00
Add CVE-2026-17614/WildFly
- - - - -
415b5984 by Bastien Roucariès at 2026-08-04T13:17:38+02:00
Python3.9 triagging
- - - - -
c9e893cf by Bastien Roucariès at 2026-08-04T14:17:40+02:00
CVE-2026-51105/LTS
- - - - -
2d9aa9d8 by Bastien Roucariès at 2026-08-04T15:02:10+02:00
CVE-2026-63317/LTS
- - - - -
38ed927c by Guilhem Moulin at 2026-08-04T15:11:15+02:00
LTS: claim php7.4 in dla-needed.txt
- - - - -
d58b803b by Bastien Roucariès at 2026-08-04T15:39:13+02:00
CVE-2026-47667/LTS
- - - - -
c94e069d by Bastien Roucariès at 2026-08-04T15:42:48+02:00
CVE-2026-67194/LTS
- - - - -
5409a586 by Bastien Roucariès at 2026-08-04T15:48:27+02:00
Add sssd to dla-needed
- - - - -
f3c12b18 by Salvatore Bonaccorso at 2026-08-04T19:56:57+02:00
Track fixed version for netcdf-perallel issues
- - - - -
17204e33 by Salvatore Bonaccorso at 2026-08-04T19:57:32+02:00
Cleanup note for CVE-2026-67194
- - - - -
4bc5b32d by Salvatore Bonaccorso at 2026-08-04T19:59:43+02:00
Track fixed version for golang-golang-x-text addressed via unstable
- - - - -
bb05ff4b by Salvatore Bonaccorso at 2026-08-04T20:07:52+02:00
Add Debian bug references for reported issues
- - - - -
cf23b250 by Salvatore Bonaccorso at 2026-08-04T20:40:51+02:00
Add new python-django issues
- - - - -
ae31154f by Salvatore Bonaccorso at 2026-08-04T20:44:59+02:00
Add references for python-django issues
- - - - -
4d426331 by security tracker role at 2026-08-04T19:12:58+00:00
automatic update
- - - - -
965242af by security tracker role at 2026-08-04T19:13:46+00:00
automatic NOT-FOR-US entries update
- - - - -
635c72fb by Salvatore Bonaccorso at 2026-08-04T21:19:04+02:00
Update status for CVE-2026-64193
- - - - -
d6d1f13c by Salvatore Bonaccorso at 2026-08-04T21:19:48+02:00
Add Debian bug reference for python-django issues
- - - - -
1f43d44e by Salvatore Bonaccorso at 2026-08-04T21:33:11+02:00
Process some NFUs
- - - - -
6e40b3c8 by Salvatore Bonaccorso at 2026-08-04T21:33:50+02:00
Process two new stunnel issues
- - - - -
87922d64 by Salvatore Bonaccorso at 2026-08-04T21:38:12+02:00
Add another sssd issue with only Red Hat bugilla reference
- - - - -
4d36ac94 by Salvatore Bonaccorso at 2026-08-04T21:38:51+02:00
Add three new pdm issues
- - - - -
8940ba87 by Bastien Roucariès at 2026-08-04T21:45:34+02:00
Add php8.2 to dla-needed
- - - - -
81606cf7 by Salvatore Bonaccorso at 2026-08-04T22:13:34+02:00
auto-nfu: Add another product for the Eclipse CNA rule
- - - - -
0ef0f518 by Salvatore Bonaccorso at 2026-08-04T22:14:04+02:00
auto-nfu: Add another product for the NVIDIA CNA rule
- - - - -
3b060f7d by Salvatore Bonaccorso at 2026-08-04T22:14:48+02:00
Process some NFUs
- - - - -
b64da344 by Salvatore Bonaccorso at 2026-08-04T22:24:24+02:00
Add two jackson-core issues
- - - - -
ec027db9 by Salvatore Bonaccorso at 2026-08-04T22:26:04+02:00
Process some NFUs
- - - - -
c37b8647 by Salvatore Bonaccorso at 2026-08-04T22:26:44+02:00
Add CVE-2026-18809/firefox
- - - - -
5ce5209c by Salvatore Bonaccorso at 2026-08-04T22:29:42+02:00
Add two open62541 issues
- - - - -
aeb7df6f by Salvatore Bonaccorso at 2026-08-04T22:30:50+02:00
Add CVE-2026-18772/rlottie
- - - - -
064c1701 by Salvatore Bonaccorso at 2026-08-04T22:31:28+02:00
Add CVE-2026-13229/Zammad, itp'ed
- - - - -
4e7ecf2d by Salvatore Bonaccorso at 2026-08-04T22:32:13+02:00
Add CVE-2026-10050/jetty
- - - - -
c3019565 by Bastien Roucariès at 2026-08-04T22:34:43+02:00
goaccess triagging
- - - - -
8a4c28c7 by Bastien Roucariès at 2026-08-04T22:36:38+02:00
CVE-2026-54332/LTS
- - - - -
3589e8d5 by Bastien Roucariès at 2026-08-04T22:40:16+02:00
Add libarchive
- - - - -
fc438de2 by Bastien Roucariès at 2026-08-04T22:45:49+02:00
Add u-boot to dla-needed
- - - - -
83f57c6b by Bastien Roucariès at 2026-08-04T22:48:33+02:00
Add python-zeroconf
- - - - -
71114246 by Bastien Roucariès at 2026-08-04T22:56:21+02:00
Add node-ip-address
CVE-2026-69192 is high and may lead to security bypass
- - - - -
5d06d218 by Bastien Roucariès at 2026-08-04T22:59:52+02:00
CVE-2026-18536/LTS
- - - - -
1952ac17 by Bastien Roucariès at 2026-08-04T23:02:45+02:00
CVE-2026-18446/LTS
- - - - -
e1fd274a by Bastien Roucariès at 2026-08-04T23:04:42+02:00
Add php-dompdf to dla-needed
- - - - -
0445993a by Bastien Roucariès at 2026-08-04T23:06:59+02:00
Add puma to dla-needed
- - - - -
df4d7d4e by Bastien Roucariès at 2026-08-05T00:03:05+02:00
CVE-2024-42643/LTS
- - - - -
9c0a5697 by Bastien Roucariès at 2026-08-05T00:12:06+02:00
ruby-websocket-driver/LTS
- - - - -
10fa234a by Bastien Roucariès at 2026-08-05T00:24:47+02:00
add to dla-needed ruby-oauth2
- - - - -
3d3a2420 by Bastien Roucariès at 2026-08-05T00:29:45+02:00
CVE-2026-54522/LTS
- - - - -
8d743a7f by Bastien Roucariès at 2026-08-05T00:31:25+02:00
Add dla-needed ruby-jwt
- - - - -
b247c69e by Bastien Roucariès at 2026-08-05T00:34:19+02:00
Add to dla-needed to python-django
- - - - -
36cb527b by Bastien Roucariès at 2026-08-05T00:40:46+02:00
CVE-2026-18321/LTS
- - - - -
6d3d24c6 by Bastien Roucariès at 2026-08-05T00:43:06+02:00
onnx/LTS
- - - - -
d58118ca by Bastien Roucariès at 2026-08-05T00:45:25+02:00
CVE-2026-55995
- - - - -
2f388d30 by Chris Lamb at 2026-08-04T16:35:38-07:00
data/dla-needed.txt: Claim python-django.
- - - - -
a20c058d by Aron Xu at 2026-08-05T10:05:06+08:00
Reserve DSA for aom
- - - - -
c44b4d80 by Aron Xu at 2026-08-05T10:17:25+08:00
Reserve DSA for botan3
- - - - -
7cbd5acd by Aron Xu at 2026-08-05T10:23:40+08:00
Take jq
- - - - -
d63977a6 by Salvatore Bonaccorso at 2026-08-05T05:37:59+02:00
Track fixed versions via unstable for thunderbird issues
- - - - -
4bd72511 by Salvatore Bonaccorso at 2026-08-05T05:39:47+02:00
Add CVE-2026-66901 as NFU
- - - - -
83c4b546 by Salvatore Bonaccorso at 2026-08-05T05:40:34+02:00
Add CVE-2026-66902 as NFU
- - - - -
458340b0 by Salvatore Bonaccorso at 2026-08-05T06:00:29+02:00
Track fixed version for python-django via unstable
- - - - -
3d19c930 by Salvatore Bonaccorso at 2026-08-05T06:04:26+02:00
Track fixed version for CVE-2026-69247/python-cryptography via unstable
- - - - -
173d326c by Salvatore Bonaccorso at 2026-08-05T06:57:54+02:00
Add two new libxfont issues
- - - - -
70631250 by Salvatore Bonaccorso at 2026-08-05T08:02:06+02:00
Update status for CVE-2026-57451/vim
- - - - -
2cfab1d3 by Salvatore Bonaccorso at 2026-08-05T08:09:03+02:00
Correct status for CVE-2026-32316 in trixie
The patch was not applied in the 1.7.1-6+deb13u2
- - - - -
a0abecca by Salvatore Bonaccorso at 2026-08-05T08:19:40+02:00
Track fixed version via unstable for two guzzle issues
- - - - -
800e0af0 by Salvatore Bonaccorso at 2026-08-05T08:48:02+02:00
Add CVE-2026-42170/gimp
- - - - -
2fa5cad0 by security tracker role at 2026-08-05T07:12:32+00:00
automatic update
- - - - -
71faffc8 by security tracker role at 2026-08-05T07:13:19+00:00
automatic NOT-FOR-US entries update
- - - - -
581d7ba3 by Salvatore Bonaccorso at 2026-08-05T09:34:00+02:00
Remove notes from CVE-2026-13325
Red Hat Product Security has come to the conclusion that this CVE is not
needed.
- - - - -
276cf5c1 by Salvatore Bonaccorso at 2026-08-05T09:53:10+02:00
Add new Ghost CMS issues
- - - - -
2cc78837 by Emilio Pozuelo Monfort at 2026-08-05T09:58:35+02:00
Reserve DLA-4717-1 for linux
- - - - -
bd1be042 by Bastien Roucariès at 2026-08-05T10:12:26+02:00
pglogical triagging
- - - - -
7dfbf181 by Bastien Roucariès at 2026-08-05T10:14:05+02:00
Add pglogical
- - - - -
041b3f53 by Bastien Roucariès at 2026-08-05T10:18:32+02:00
Add pipewire to dla-needed
- - - - -
a454be6d by Salvatore Bonaccorso at 2026-08-05T10:19:42+02:00
Process some NFUs
- - - - -
dd02e904 by Bastien Roucariès at 2026-08-05T10:25:39+02:00
imagemagick/LTS
Postpone a few issue:
- DoS only
- Need particular flags
May be fixed with later release
- - - - -
751147a2 by Bastien Roucariès at 2026-08-05T10:26:31+02:00
Add python-cryptography to dla-needed
- - - - -
49a1cf89 by Salvatore Bonaccorso at 2026-08-05T10:33:53+02:00
Add CVE-2026-71201/ironic
- - - - -
89258b23 by Salvatore Bonaccorso at 2026-08-05T10:36:28+02:00
CVEs for swift issues now assigned
- - - - -
9dc5ab50 by Bastien Roucariès at 2026-08-05T10:49:00+02:00
Add neutron to dla-needed
- - - - -
e73faa3d by Bastien Roucariès at 2026-08-05T10:49:00+02:00
Add rails to dla-needed
- - - - -
b16bc458 by Salvatore Bonaccorso at 2026-08-05T10:52:35+02:00
Add new batch of qpid-java issues
- - - - -
b1307967 by Salvatore Bonaccorso at 2026-08-05T10:55:00+02:00
Add new batch of open62541 issues
- - - - -
b9eee8c6 by Salvatore Bonaccorso at 2026-08-05T11:01:58+02:00
Add new qpid-proton issues
- - - - -
1cd76a84 by Salvatore Bonaccorso at 2026-08-05T11:11:21+02:00
Process some NFUs
- - - - -
6049dc93 by Emilio Pozuelo Monfort at 2026-08-05T12:20:17+02:00
Track xorg-server issues fixed in unstable
- - - - -
069ad916 by Emilio Pozuelo Monfort at 2026-08-05T12:22:16+02:00
Track xwayland issues fixed in unstable
- - - - -
b7cecc9b by Salvatore Bonaccorso at 2026-08-05T13:39:13+02:00
Process some NFUs
- - - - -
759b9edf by Salvatore Bonaccorso at 2026-08-05T13:40:12+02:00
Add new opensips issues
- - - - -
42334221 by Salvatore Bonaccorso at 2026-08-05T13:41:40+02:00
Add CVE-2026-18819/racktables
- - - - -
ece73735 by Salvatore Bonaccorso at 2026-08-05T13:46:47+02:00
Associate some CVEs with src:opensips
- - - - -
6329b243 by Sylvain Beucler at 2026-08-05T14:46:13+02:00
lts: claim p7zip
- - - - -
e67cf99d by Bastien Roucariès at 2026-08-05T14:52:52+02:00
Add calibre to dla-needed
- - - - -
49f2d92b by Bastien Roucariès at 2026-08-05T15:10:43+02:00
Add texworks for affected by CVE-2026-63729
Not fixed: https://sources.debian.org/src/texworks/0.6.10%2Bds-1/modules/synctex/synctex_parser.c?hl=1431#L907
fixed: https://sources.debian.org/src/texworks/0.6.11+ds-2/modules/synctex/synctex_parser.c?hl=1431#L1431
- - - - -
c51f4b33 by Bastien Roucariès at 2026-08-05T15:14:29+02:00
Add texsudio for CVE-2026-63729
not-affected: https://sources.debian.org/src/texstudio/4.9.6+ds-1/src/pdfviewer/synctex/synctex_parser.c?hl=1431#L1431
affected: https://sources.debian.org/src/texstudio/4.9.2%2Bds-1/src/pdfviewer/synctex/synctex_parser.c?hl=1431#L920
- - - - -
240ebba0 by Bastien Roucariès at 2026-08-05T15:17:14+02:00
Add emacs-pdf-tools for CVE-2026-63729
use old version: https://sources.debian.org/src/emacs-pdf-tools/1.3.0-1/server/synctex_parser.c?hl=4781#L4781
- - - - -
d25487b5 by Bastien Roucariès at 2026-08-05T15:28:02+02:00
Add synctex to embeded code copy
- - - - -
9350717e by Bastien Roucariès at 2026-08-05T15:29:48+02:00
Add okular for syntex CVE
affected: https://sources.debian.org/src/okular/4:26.04.2-1/core/synctex/synctex_parser.c?hl=4609#L870
- - - - -
b76e1ee9 by Sylvain Beucler at 2026-08-05T15:30:52+02:00
Reserve DLA-4718-1 for 7zip
- - - - -
a0b9eb20 by Sylvain Beucler at 2026-08-05T15:32:27+02:00
Reserve DLA-4719-1 for p7zip
- - - - -
968a0a9a by Bastien Roucariès at 2026-08-05T15:33:56+02:00
Add libmojo-jwt-perl to dla-needed
- - - - -
101abf56 by Bastien Roucariès at 2026-08-05T16:10:33+02:00
Ignore CVE-2026-66011 for LTS
- - - - -
17a52a24 by Emilio Pozuelo Monfort at 2026-08-05T17:14:29+02:00
lts: add dist to php packages
- - - - -
75a8f044 by Salvatore Bonaccorso at 2026-08-05T17:43:42+02:00
Merge Linux CVEs from kernel-sec
- - - - -
7de74f17 by Salvatore Bonaccorso at 2026-08-05T17:46:47+02:00
Merge Linux CVEs from kernel-sec
- - - - -
2cf7fa7d by Ben Hutchings at 2026-08-05T18:07:01+02:00
Reserve DLA-4720-1 for linux
- - - - -
c7992233 by Bastien Roucariès at 2026-08-05T18:15:15+02:00
CVE-2026-64685
- - - - -
7be3fc91 by Santiago Ruano Rincón at 2026-08-05T14:46:07-03:00
Removed fontforge from dla-needed.txt
No open CVEs remaining.
- - - - -
d9060f41 by Bastien Roucariès at 2026-08-05T19:52:05+02:00
Remove a few packages from dla-needed
- - - - -
cbdedc7e by Salvatore Bonaccorso at 2026-08-05T19:57:08+02:00
Add CVE-2026-54876/openssl
- - - - -
1517fea5 by Bastien Roucariès at 2026-08-05T20:07:13+02:00
libpgjava/LTS
- - - - -
372bccc7 by Bastien Roucariès at 2026-08-05T20:08:40+02:00
Remove from dla-needed libpgjava
- - - - -
c0eb18cb by Salvatore Bonaccorso at 2026-08-05T20:35:28+02:00
Track fixed version for CVE-2025-70952/libpf4j-java via unstable
- - - - -
de38be23 by Bastien Roucariès at 2026-08-05T20:37:10+02:00
libxmltok/LTS
- - - - -
2c7564cc by Bastien Roucariès at 2026-08-05T20:37:35+02:00
Remove libxmltok from dla-needed
- - - - -
9bd38c97 by Salvatore Bonaccorso at 2026-08-05T20:44:19+02:00
Track fixed version for CVE-2026-9064/389-ds-base
- - - - -
b3323e2e by security tracker role at 2026-08-05T19:14:01+00:00
automatic update
- - - - -
3e2f532f by security tracker role at 2026-08-05T19:14:53+00:00
automatic NOT-FOR-US entries update
- - - - -
e9807efd by Salvatore Bonaccorso at 2026-08-05T21:24:35+02:00
Process some NFUs
- - - - -
1fb40135 by Salvatore Bonaccorso at 2026-08-05T21:40:19+02:00
Process some NFUs
- - - - -
616c556f by Salvatore Bonaccorso at 2026-08-05T21:41:55+02:00
Add CVE-2026-71265/domoticz, itp'ed
- - - - -
6468e0eb by Salvatore Bonaccorso at 2026-08-05T21:42:28+02:00
Add CVE-2026-71236/grocy, itp'ed
- - - - -
8bf68d21 by Salvatore Bonaccorso at 2026-08-05T21:44:02+02:00
Reassign some CVEs with grocy, itp'ed entry
- - - - -
b9c7d284 by Salvatore Bonaccorso at 2026-08-05T21:57:00+02:00
Add new libkcapi with some AI assisted overhead
- - - - -
8ced0a4d by Salvatore Bonaccorso at 2026-08-05T21:58:53+02:00
Process some NFUs
- - - - -
ea882b38 by Salvatore Bonaccorso at 2026-08-05T22:02:57+02:00
Add new batch of electron issues, itp'ed
- - - - -
bd3b40c0 by Salvatore Bonaccorso at 2026-08-05T22:07:00+02:00
Add two ghost issues, itp'ed
- - - - -
1e83a3de by Bastien Roucariès at 2026-08-05T22:28:47+02:00
Fix libsynctex embed copy
texlive is considered as main source under debian
- - - - -
caf1ae8a by Salvatore Bonaccorso at 2026-08-05T22:38:14+02:00
auto-nfu: Add another product covered by the Apache CNA rule
- - - - -
ebe019cb by Salvatore Bonaccorso at 2026-08-05T22:42:48+02:00
Process some NFUs
- - - - -
caed5c92 by Salvatore Bonaccorso at 2026-08-05T22:44:16+02:00
Add new keycloak issues
- - - - -
4bb3d97e by Bastien Roucariès at 2026-08-05T22:50:21+02:00
libsynctex is used by emacs-pdf-tools
- - - - -
bd8cdb0d by Bastien Roucariès at 2026-08-05T22:50:25+02:00
mark emacs-pdf-tools has not affected by libsyntex CVE
- - - - -
3f795233 by Bastien Roucariès at 2026-08-05T23:00:04+02:00
texworks not affected by libsynctex
- - - - -
b40ed93b by Emmanuel Arias at 2026-08-06T00:34:54-03:00
Add NOTE for CVE-2026-13321
- - - - -
55e1a607 by Emmanuel Arias at 2026-08-06T00:43:56-03:00
Add NOTE for CVE-2026-13204
- - - - -
aa8de11f by Emmanuel Arias at 2026-08-06T00:50:39-03:00
CVE-2026-12617: mark not-affected in bullseye; add commit for bookworm
- - - - -
885f9ddf by Aron Xu at 2026-08-06T12:59:24+08:00
Take libde265
- - - - -
d93f2f2f by Salvatore Bonaccorso at 2026-08-06T07:02:47+02:00
Drop entries with no security impact on CVE-2026-63729
- - - - -
fa6a453a by Salvatore Bonaccorso at 2026-08-06T07:17:01+02:00
Track fixed version for libxfont issues
- - - - -
788b1f3d by Salvatore Bonaccorso at 2026-08-06T07:39:37+02:00
Drop trailing whitespaces
- - - - -
b5c1c7eb by Salvatore Bonaccorso at 2026-08-06T07:40:07+02:00
Update status for some hdf5 issues
- - - - -
2422cc31 by Salvatore Bonaccorso at 2026-08-06T07:42:17+02:00
Update status for CVE-2025-2153
- - - - -
8f2daced by Salvatore Bonaccorso at 2026-08-06T07:46:40+02:00
Update status for hdf5 issues
- - - - -
f8d2266e by security tracker role at 2026-08-06T07:12:31+00:00
automatic update
- - - - -
0c07b4ba by security tracker role at 2026-08-06T07:13:21+00:00
automatic NOT-FOR-US entries update
- - - - -
6d299b6b by Salvatore Bonaccorso at 2026-08-06T09:42:59+02:00
Process some NFUs
- - - - -
8622a70c by Salvatore Bonaccorso at 2026-08-06T09:43:54+02:00
Add new rclone issues
- - - - -
250c3830 by Emilio Pozuelo Monfort at 2026-08-06T07:46:12+00:00
Merge branch 'helmutg/web-result-encoding' into 'master'
web_support.py: tighten the types/encoding of Result objects
See merge request security-tracker-team/security-tracker!316
- - - - -
0cbdfe6c by Salvatore Bonaccorso at 2026-08-06T09:48:47+02:00
Merge Linux CVEs from kernel-sec
- - - - -
6fb57bd1 by Bastien Roucariès at 2026-08-06T09:52:42+02:00
LTS triagging
- - - - -
fde003d9 by Bastien Roucariès at 2026-08-06T09:54:10+02:00
ruby-sqlite3/LTS
- - - - -
c965fa47 by Salvatore Bonaccorso at 2026-08-06T09:54:52+02:00
Merge Linux CVEs from kernel-sec
- - - - -
01e114e1 by Bastien Roucariès at 2026-08-06T10:09:34+02:00
pypy3/LTS
- - - - -
1161736b by Bastien Roucariès at 2026-08-06T10:16:52+02:00
Add node-re2 to dla-needed
- - - - -
2232e1d6 by Bastien Roucariès at 2026-08-06T10:25:17+02:00
nodejs triagging
- - - - -
1bb5bfd6 by Salvatore Bonaccorso at 2026-08-06T10:37:07+02:00
Process some NFUs
- - - - -
aab97c25 by Salvatore Bonaccorso at 2026-08-06T10:37:43+02:00
Add new open62541 issues
- - - - -
bd6d251a by Salvatore Bonaccorso at 2026-08-06T11:00:05+02:00
Add CVE-2026-34966/gitea
- - - - -
3d141b58 by Salvatore Bonaccorso at 2026-08-06T11:02:25+02:00
Add new batch of hdf5 issues
- - - - -
21ec91eb by Salvatore Bonaccorso at 2026-08-06T11:04:43+02:00
Add CVE-2026-18967/Keycloak
- - - - -
df79ef55 by Salvatore Bonaccorso at 2026-08-06T11:05:33+02:00
Process some NFUs
- - - - -
1fd648b3 by Aron Xu at 2026-08-06T17:28:47+08:00
Reserve DSA for libde265
- - - - -
f651ceee by Bastien Roucariès at 2026-08-06T12:49:49+02:00
Add qpid-proton to dla-needed
- - - - -
83c9a465 by Aron Xu at 2026-08-06T19:40:35+08:00
Triage libheif CVEs
- - - - -
ac0638cc by Aron Xu at 2026-08-06T19:41:17+08:00
Take libheif
- - - - -
7d8767bf by Emmanuel Arias at 2026-08-06T08:55:32-03:00
CVE-2026-13321: Add NOTE for bookworm version
- - - - -
9c238f00 by Salvatore Bonaccorso at 2026-08-06T13:57:06+02:00
Update status for CVE-2026-47251
- - - - -
a4aef467 by Emmanuel Arias at 2026-08-06T08:59:41-03:00
CVE-2026-13204: Add NOTE for bookworm version
- - - - -
827aeadf by Emmanuel Arias at 2026-08-06T09:07:26-03:00
CVE-2026-11721: Add NOTE for bullseyes and bookworm version
- - - - -
3ba1cbda by Emmanuel Arias at 2026-08-06T09:10:40-03:00
CVE-2026-11622: Add NOTE for bullseyes and bookworm version
- - - - -
675105e9 by Salvatore Bonaccorso at 2026-08-06T14:23:19+02:00
Add Debian bug reference for CVE-2026-71201/ironic
- - - - -
ee44ce89 by Salvatore Bonaccorso at 2026-08-06T14:24:56+02:00
Track fixed version for CVE-2026-71201/ironic via unstable
- - - - -
5bfa2d78 by Alberto Garcia at 2026-08-06T15:00:23+02:00
Add udisks2 CVE-2026-7867
- - - - -
78fc5056 by Bastien Roucariès at 2026-08-06T15:20:34+02:00
Proton CVE look mistriaged wait for dla-needed
- - - - -
2d0d9611 by Bastien Roucariès at 2026-08-06T16:30:56+02:00
CVE-2026-35563/LTS
- - - - -
a1b42629 by Salvatore Bonaccorso at 2026-08-06T17:03:23+02:00
Track fixed version for CVE-2026-41579 via unstable
- - - - -
c883516c by Salvatore Bonaccorso at 2026-08-06T17:04:39+02:00
Mark CVE-2026-14957 as no-dsa for trixie
- - - - -
818d2759 by Salvatore Bonaccorso at 2026-08-06T17:09:53+02:00
Revert triage of qpid-proton assigned issues
All issues are in Apache Qpid ProtonJ2 which is a distinct source and
not packaged in Debian.
- - - - -
edbbd3f2 by Salvatore Bonaccorso at 2026-08-06T17:10:58+02:00
auto-nfu: Add another covered product for the Apache CNA rule
- - - - -
3046c92f by Salvatore Bonaccorso at 2026-08-06T17:14:34+02:00
Process some NFUs
- - - - -
215124a2 by Salvatore Bonaccorso at 2026-08-06T17:37:27+02:00
Add reference for CVE-2026-64564
- - - - -
dc4975af by Chris Lamb at 2026-08-06T08:52:00-07:00
Reserve DLA-4721-1 for async-http-client
- - - - -
8442b454 by Alberto Garcia at 2026-08-06T18:08:08+02:00
udisks2 DSA-6414-1
- - - - -
a3e6de6f by Salvatore Bonaccorso at 2026-08-06T18:12:03+02:00
Add reference for CVE-2026-64561
- - - - -
4ef7958d by Helmut Grohne at 2026-08-06T18:35:56+02:00
security_db.py: track source_package_status.vulnerable as an enum
The vulnerable column of source_package_status can take three possible
values:
* 0 (fixed)
* 1 (affected)
* 2 (undetermined)
We can encapsulate this as an IntEnum on the Python side. Then we can
use those names in place of magic numbers. Additionally, we may add a
constraint to the database column. Since the old schema is compatible,
we do not incur a new schema version.
Reported-by: Emilio Pozuelo Monfort <pochu at debian.org>
- - - - -
07664783 by Alberto Garcia at 2026-08-06T18:38:54+02:00
CVE-2026-7867: mark as fixed in udisks2 2.11.2-1
- - - - -
46fb69af by Salvatore Bonaccorso at 2026-08-06T19:37:23+02:00
Add back reference for CVE-2026-7867
- - - - -
bc1bda9b by Salvatore Bonaccorso at 2026-08-06T19:40:14+02:00
Reserve DSA number for linux update
- - - - -
9e414281 by Salvatore Bonaccorso at 2026-08-06T19:48:12+02:00
Add references for udisks2 issue
- - - - -
56780e02 by Salvatore Bonaccorso at 2026-08-06T19:54:10+02:00
Add new PowerDNS issues (pdns, pdns-recursor, dnsdist)
- - - - -
df1aa3a8 by Salvatore Bonaccorso at 2026-08-06T20:09:26+02:00
Add CVE-2026-68480/linux
- - - - -
18943ca6 by security tracker role at 2026-08-06T19:13:34+00:00
automatic update
- - - - -
71501bad by security tracker role at 2026-08-06T19:14:27+00:00
automatic NOT-FOR-US entries update
- - - - -
7ad1e24a by Salvatore Bonaccorso at 2026-08-06T21:26:06+02:00
Add reference for CVE-2026-68480
- - - - -
ba179060 by Bastien Roucariès at 2026-08-06T21:28:12+02:00
docker-registry/LTS
- - - - -
8b0fb265 by Bastien Roucariès at 2026-08-06T21:30:14+02:00
docker-registry/bullseye
- - - - -
c8bef499 by Bastien Roucariès at 2026-08-06T21:31:38+02:00
Add libgd-securityimage-perl
- - - - -
8eaee7ae by Salvatore Bonaccorso at 2026-08-06T21:33:29+02:00
Remove notes from CVE-2026-51992
- - - - -
ead69fd5 by Bastien Roucariès at 2026-08-06T21:44:03+02:00
Add python-asyncssh
- - - - -
c433e104 by Salvatore Bonaccorso at 2026-08-06T21:56:51+02:00
Add CVE-2026-61477/libvirt
- - - - -
ad845536 by Bastien Roucariès at 2026-08-06T22:01:08+02:00
node-tar/LTS
- - - - -
1e850af3 by Salvatore Bonaccorso at 2026-08-06T22:03:07+02:00
Process some NFUs
- - - - -
bf21c3ce by Bastien Roucariès at 2026-08-06T22:07:16+02:00
node-ua-parser-js/LTS
- - - - -
eb0f2c8b by Bastien Roucariès at 2026-08-06T22:09:09+02:00
CVE-2026-69185/LTS
- - - - -
72640d07 by Salvatore Bonaccorso at 2026-08-06T22:26:17+02:00
Add CVE-2026-43622/llama.cpp
- - - - -
ce7104ed by Salvatore Bonaccorso at 2026-08-06T22:29:43+02:00
Process some NFUs
- - - - -
fa94027e by Salvatore Bonaccorso at 2026-08-06T22:31:38+02:00
Add CVE-2026-18839/popt
- - - - -
53399357 by Salvatore Bonaccorso at 2026-08-06T22:49:56+02:00
Update status for libsynctex2
emacs-pdf-tools contained the patch to use the system provided library
form tine initial upload 0.70-1 already. Drop it.
- - - - -
9d2bf7d9 by Salvatore Bonaccorso at 2026-08-06T22:53:32+02:00
Drop entry completely as we track already bit before:
texlive-bin
- texstudio 2.8.0+debian-1 (embed; bug #753806)
NOTE: embeds synctex parser
- texmaker 4.2-2 (embed; bug #753812)
NOTE: embeds synctex parser
- texworks 0.5~svn1363-5 (embed; bug #753818)
NOTE: embeds synctex parser
- gummi <unfixed> (embed; bug #753827)
NOTE: embeds synctex parser
- evince <unfixed> (embed; bug #754136)
NOTE: embeds synctex parser
- okular <unfixed> (embed; bug #754137)
NOTE: embeds synctex parser
- qpdfview <unfixed> (embed; bug #754138)
NOTE: embeds synctex parser
- - - - -
1a5e7b32 by Salvatore Bonaccorso at 2026-08-06T22:56:30+02:00
Demote now CVE-2026-66011 to unimportant
- - - - -
05c1543a by Chris Lamb at 2026-08-06T14:36:14-07:00
Reserve DLA-4722-1 for redis
- - - - -
e9427f95 by Salvatore Bonaccorso at 2026-08-06T23:40:29+02:00
Add new set of apr-util issues
- - - - -
1e700f1c by Emilio Pozuelo Monfort at 2026-08-06T21:41:08+00:00
Merge branch 'helmutg/vulnerable-enum' into 'master'
security_db.py: track source_package_status.vulnerable as an enum
See merge request security-tracker-team/security-tracker!318
- - - - -
98c1ccf5 by Emmanuel Arias at 2026-08-06T18:49:18-03:00
CVE-2026-13321: Fix commits links
- - - - -
0b649152 by Emmanuel Arias at 2026-08-06T22:09:53-03:00
CVE-2026-13204: Fix commits links
- - - - -
01c7ee94 by Emmanuel Arias at 2026-08-06T22:15:14-03:00
CVE-2026-12617: fix commit link and add new one
- - - - -
4b721b61 by Emmanuel Arias at 2026-08-06T22:19:05-03:00
CVE-2026-11721: fix commits links
- - - - -
363088e9 by Emmanuel Arias at 2026-08-06T22:20:54-03:00
CVE-2026-11622: fix commits links
- - - - -
0d796885 by Emmanuel Arias at 2026-08-06T22:26:42-03:00
CVE-2026-11331: add commits link
- - - - -
a0136d39 by Emmanuel Arias at 2026-08-06T22:30:59-03:00
CVE-2026-10822: not-affected in bullseye, add commits links for bookworm
- - - - -
db8187a5 by Aron Xu at 2026-08-07T09:49:11+08:00
DSA for jq
- - - - -
385fe377 by Emmanuel Arias at 2026-08-06T23:18:56-03:00
CVE-2026-10723: add commits link
- - - - -
d009f471 by Emmanuel Arias at 2026-08-06T23:18:57-03:00
CVE-2026-5950: Add commit link
- - - - -
5741c1c7 by Emmanuel Arias at 2026-08-06T23:18:58-03:00
CVE-2026-5946: add commits link
- - - - -
91d98830 by Emmanuel Arias at 2026-08-06T23:21:10-03:00
CVE-2026-3592: Add commits links
- - - - -
86ffb990 by Emmanuel Arias at 2026-08-06T23:22:49-03:00
CVE-2026-3039: add commits links
- - - - -
d341dbb4 by Salvatore Bonaccorso at 2026-08-07T05:59:46+02:00
Track some fixes for rust-coreutils via unstable
At least one CVE is possibly not yet fixed, left untouched and asked
back to the maintainer.
- - - - -
f6233b14 by Salvatore Bonaccorso at 2026-08-07T06:02:29+02:00
Track fixed version for CVE-2026-1836 via unstable
- - - - -
3e49c316 by Salvatore Bonaccorso at 2026-08-07T06:06:40+02:00
Update status for CVE-2026-18401
- - - - -
8bcac43b by Salvatore Bonaccorso at 2026-08-07T06:28:29+02:00
Add Debian bug reference for two tar issues
- - - - -
79d7023c by Salvatore Bonaccorso at 2026-08-07T06:41:18+02:00
Add Debian bug reference for apr-util issues
- - - - -
a859d4db by Salvatore Bonaccorso at 2026-08-07T06:49:19+02:00
Merge Linux CVEs from kernel-sec
- - - - -
5b4be9f8 by Salvatore Bonaccorso at 2026-08-07T06:51:23+02:00
Track fixes via unstable for PowerDNS issue (CVE-2026-52682)
- - - - -
468b948b by Salvatore Bonaccorso at 2026-08-07T06:59:06+02:00
Add new chromium issues
- - - - -
da6ede3f by Salvatore Bonaccorso at 2026-08-07T06:59:47+02:00
Add chromium to dsa-needed list
- - - - -
832e5521 by Helmut Grohne at 2026-08-07T08:39:32+02:00
lib: change internUrgency not to return None
A number of callers of internUrgency are not prepared to handle its None
return value. Rather than fix all the callers, make it raise an
exception and adapt the one place that wants to handle it.
- - - - -
299395b2 by Helmut Grohne at 2026-08-07T08:39:32+02:00
lib: change internRelease not to return None
A number of callers of internRelease are not prepared to handle its None
return value. Rather than fix all the callers, make it raise an
exception.
- - - - -
5fc88e8e by Helmut Grohne at 2026-08-07T08:39:32+02:00
web tracker: delete method pre_dispatch
None of the implementations is non-trivial, but the more striking issue
is that their argument count varies. Rather than figure out, what is
right, dispose this unused mechanism.
- - - - -
c33e857c by Helmut Grohne at 2026-08-07T08:39:32+02:00
delete test of isKernOnly
Fixes: efd6f70f4aca ("Remove unused methods")
- - - - -
611a6f09 by Helmut Grohne at 2026-08-07T08:40:13+02:00
security_db.py: use sets
Some of this code predates the introduction of the set type to Python
and uses dicts with True values instead. We can now convert this to
proper sets. More importantly, this helps avoid variable type changes.
The list conversion can be deferred.
- - - - -
0b09d8e2 by Helmut Grohne at 2026-08-07T08:40:15+02:00
security_db.py: rewrite mergeLists using sets
Aside from being faster, this avoids changing the type of the result
variable.
- - - - -
e9c773c7 by Helmut Grohne at 2026-08-07T08:40:15+02:00
python: avoid more variable type changes
If we ever want to head into type checking, the type of value stored in
a variable should not change. Thus rename affected assignments or elide
them entirely.
- - - - -
6e5b6e82 by Helmut Grohne at 2026-08-07T08:40:15+02:00
tracker_service.py: narrow implied type of filters attribute
The lookup in params may return None in principle. This influences type
deduction and filters is assumed to be able to hold None, but the next
line changes that. In combining them, the deduced type of filters
becomes narrower.
- - - - -
77f14a6d by Helmut Grohne at 2026-08-07T08:40:15+02:00
tracker_service.py: don't pass None via body_attribs
While a None value might be acceptable there, it is discarded anyway.
Rather than supporting that use case, simply avoid passing it.
- - - - -
53e84bf6 by Helmut Grohne at 2026-08-07T08:40:15+02:00
tracker_service.py: explicitly cast hide_check to bool
When we pass it to getTODOs a real bool is expected, so convert the
thing that might be a list early.
- - - - -
3065bbe7 by Salvatore Bonaccorso at 2026-08-07T08:42:42+02:00
Add Debian bug reference for CVE-2026-54876
- - - - -
c796d6c8 by Salvatore Bonaccorso at 2026-08-07T08:54:12+02:00
Add CVE-2026-64638/wordpress
- - - - -
ceeeff4e by Salvatore Bonaccorso at 2026-08-07T08:58:44+02:00
Add Debian bug reference for rclone issues
- - - - -
3bbd7963 by Salvatore Bonaccorso at 2026-08-07T09:00:36+02:00
Add CVE-2026-18938/p11-kit
- - - - -
1ebbe4cd by Salvatore Bonaccorso at 2026-08-07T09:04:15+02:00
Add Debian bug reference for wordpress issues
- - - - -
bd9ca69b by security tracker role at 2026-08-07T07:13:31+00:00
automatic update
- - - - -
c07613ad by security tracker role at 2026-08-07T07:14:25+00:00
automatic NOT-FOR-US entries update
- - - - -
9ee57096 by Salvatore Bonaccorso at 2026-08-07T09:22:03+02:00
Cleanup two CVEs
- - - - -
c48fbdc4 by Salvatore Bonaccorso at 2026-08-07T09:45:58+02:00
Process some NFUs
- - - - -
03fbea77 by Salvatore Bonaccorso at 2026-08-07T09:46:33+02:00
Add CVE-2026-71554/python-h2
- - - - -
45d19dbb by Salvatore Bonaccorso at 2026-08-07T09:47:51+02:00
Add two node-re2 issues
- - - - -
242c61a6 by Salvatore Bonaccorso at 2026-08-07T09:48:37+02:00
Add CVE-2026-71497/jsoup
- - - - -
d791d2de by Salvatore Bonaccorso at 2026-08-07T09:49:10+02:00
Add some new node-mermaid issues
- - - - -
874fa1f4 by Salvatore Bonaccorso at 2026-08-07T09:50:07+02:00
Add new Traefik issues
- - - - -
9acb7c77 by Salvatore Bonaccorso at 2026-08-07T09:52:39+02:00
Update status for CVE-2026-35345 according to maintainer's information
- - - - -
d7eb6f1b by Emilio Pozuelo Monfort at 2026-08-07T10:01:13+02:00
Reserve DLA-4723-1 for linux-6.1
- - - - -
5f9de31c by Emilio Pozuelo Monfort at 2026-08-07T10:07:49+02:00
lts: unclaim xorg-server
- - - - -
6ae578c4 by Emilio Pozuelo Monfort at 2026-08-07T10:08:45+02:00
lts: drop shim
It's not relevant to LTS
- - - - -
06935cdd by Emilio Pozuelo Monfort at 2026-08-07T10:39:09+02:00
lts: take chromium
- - - - -
76747f13 by Salvatore Bonaccorso at 2026-08-07T10:49:57+02:00
Track fixed version for CVE-2026-64638/wordpress
- - - - -
01163123 by Salvatore Bonaccorso at 2026-08-07T11:08:22+02:00
Add new llama.cpp issues
- - - - -
028f865a by Salvatore Bonaccorso at 2026-08-07T11:09:39+02:00
Add wordpress to dsa-needed list
- - - - -
d73c7f7c by Salvatore Bonaccorso at 2026-08-07T11:11:15+02:00
Add new ffmpeg issues
- - - - -
c8f0fe7d by Ben Hutchings at 2026-08-07T11:11:45+02:00
Reserve DLA-4724-1 for linux-6.12
- - - - -
7cec0c62 by Salvatore Bonaccorso at 2026-08-07T12:54:50+02:00
Process some NFUs
- - - - -
cc0ff17a by Emmanuel Arias at 2026-08-07T08:20:03-03:00
Reserve DLA-4725-1 for bind9
- - - - -
984693fe by Bastien Roucariès at 2026-08-07T14:20:49+02:00
Add wordpress to dla-needed (follow dsa)
- - - - -
c0245516 by Emilio Pozuelo Monfort at 2026-08-07T14:51:13+00:00
Merge branch 'helmutg/type-improvements' into 'master'
lib: tweak code to make it easier consumable by type checkers
See merge request security-tracker-team/security-tracker!314
- - - - -
1662da53 by Salvatore Bonaccorso at 2026-08-07T17:30:11+02:00
Track fixed version for apr-util issues via unstable
- - - - -
432060c7 by Salvatore Bonaccorso at 2026-08-07T17:41:36+02:00
Add temporary entry for zip issue
- - - - -
d5fcb675 by Salvatore Bonaccorso at 2026-08-07T18:00:07+02:00
Remove for now no-dsa tag until clarified with maintainer
- - - - -
6f70127e by Bastien Roucariès at 2026-08-07T18:57:29+02:00
Add apr-utils fixes
- - - - -
274ae049 by Bastien Roucariès at 2026-08-07T18:59:34+02:00
Add apr-utils
- - - - -
0bbfb347 by Bastien Roucariès at 2026-08-07T19:04:49+02:00
Take apr-utils
- - - - -
254a3d5d by Aron Xu at 2026-08-08T01:05:14+08:00
DSA for libheif
Not moving to new version because of upstream regression:
https://github.com/strukturag/libheif/issues/1881
- - - - -
59cac62e by Bastien Roucariès at 2026-08-07T19:07:14+02:00
CVE-2026-32327/commit
- - - - -
95cc0471 by Helmut Grohne at 2026-08-07T19:28:12+02:00
web tracker: refactor service class hierarchy
The hierarchy was weird. The lowest level is WebServiceBase and mainly
is a URL router. From there we go to WebServiceHTTP (and earlier also
WebService) implementing the network facing side. Then TrackerService
inherits from one of the services. Until WebService was removed, the
class hierarchy was dependent on command line arguments. This is a
coding smell of using a wrong pattern.
The ability to swap out the base class of TrackerService hints at it not
integrating tightly with its direct base class. Indeed, the
TrackerService doesn't need to know anything about how requests arrive
at the url router or are delivered from there. We can reparent it to
WebServiceBase with little loss. What is lost in the process is the
ability to actually service any requests.
The former base class WebServiceHTTP needs to reenter the picture
somehow. The WebServiceHTTP does not directly interface with
TrackerService as all of the interaction is handled via the
WebServiceBase URL router. Instead of inheriting from WebServiceBase,
WebServiceHTTP can be passed a WebServiceBase instance and redirect some
attribute lookups. In effect, we replace inheritance with composition.
To reflect this, I also rename WebServiceHTTP to WebServiceHTTPAdapter.
This results in the class hierarchy becoming static. Even if WebService
were not removed yet, TrackerService would only inherit from
WebServiceBase. Consequently, the caller of TrackerService now has to
separately instantiate WebServiceHTTPAdapter and in doing so can choose
the adapter without changing the class hierarchy.
The real goal behind this refactoring is the ability to provide more
adapter classes. Thus we can experiment with another adapter supporting
HTTP/1.1 without interfering with the existing deployment. In
particular, it seems possible to adapt the service to WSGI which opens a
door to a lot of deployment strategies.
- - - - -
12 changed files:
- bin/tracker_service.py
- data/CVE/list
- data/DLA/list
- data/DSA/list
- data/dla-needed.txt
- data/dsa-needed.txt
- data/embedded-code-copies
- data/packages/nfu.yaml
- lib/python/bugs.py
- lib/python/debian_support.py
- lib/python/security_db.py
- lib/python/web_support.py
Changes:
=====================================
bin/tracker_service.py
=====================================
@@ -45,9 +45,9 @@ class BugFilter:
self.params = {}
for (prop, desc, field) in self.action_list:
self.params[prop] = int(params.get(prop, (0,))[0])
- self.filters=params.get('filter')
- if not self.filters:
- self.filters=['high_urgency', 'medium_urgency', 'low_urgency', 'unassigned_urgency']
+ self.filters = (
+ params.get('filter') or ['high_urgency', 'medium_urgency', 'low_urgency', 'unassigned_urgency']
+ )
def actions(self, url):
"""Returns a HTML snippet which can be used to change the filter."""
@@ -73,7 +73,7 @@ class BugFilter:
urg in ('medium', 'medium**')
filterhigh = not self.params['high_urgency'] and \
urg in ('high', 'high**')
- filterund = not self.params['undetermined_issues'] and vuln == 2
+ filterund = not self.params['undetermined_issues'] and vuln == security_db.Vulnerable.UNDETERMINED
filteruni = not self.params['unimportant_urgency'] \
and urg == 'unimportant'
filteruna = not self.params['unassigned_urgency'] \
@@ -98,7 +98,8 @@ class BugFilter:
"""Returns True for postponedissues if filtered."""
return no_dsa_reason == 'postponed' and not self.params['nopostponed']
-class TrackerService(WebServiceHTTP):
+
+class TrackerService:
nvd_text = P('''If a "**" is included, the urgency field was automatically
assigned by the NVD (National Vulnerability Database). Note that this
rating is automatically derived from a set of known factors about the
@@ -107,8 +108,7 @@ class TrackerService(WebServiceHTTP):
determining the values of these factors, but the rating itself comes
from a fully automated formula.''')
- def __init__(self, socket_name, db_name):
- WebServiceHTTP.__init__(self, socket_name)
+ def __init__(self, db_name):
self.db = security_db.DB(db_name)
self.stable_releases = config.get_supported_releases()
@@ -424,10 +424,10 @@ data source.""")],
package = compose(
self.make_source_package_ref(url, package),
" (", self.make_pts_ref(url, package, 'PTS'), ")")
- if vulnerable == 1:
+ if vulnerable == security_db.Vulnerable.AFFECTED:
vuln = self.make_red('vulnerable')
version = self.make_red(version)
- elif vulnerable == 2:
+ elif vulnerable == security_db.Vulnerable.UNDETERMINED:
vuln = self.make_purple('undetermined')
version = self.make_purple(version)
else:
@@ -598,7 +598,7 @@ to improve our documentation and procedures, so feedback is welcome.""")])])
def format_summary_entry(per_release):
if per_release is None:
return self.make_purple('unknown')
- if per_release.vulnerable == 1:
+ if per_release.vulnerable == security_db.Vulnerable.AFFECTED:
if per_release.state == 'no-dsa':
if per_release.reason:
text = 'vulnerable (no DSA, %s)' % per_release.reason
@@ -609,9 +609,9 @@ to improve our documentation and procedures, so feedback is welcome.""")])])
text=hint)
else:
return self.make_red('vulnerable')
- if per_release.vulnerable == 2:
+ if per_release.vulnerable == security_db.Vulnerable.UNDETERMINED:
return self.make_purple('undetermined')
- assert per_release.vulnerable == 0
+ assert per_release.vulnerable == security_db.Vulnerable.FIXED
return self.make_green('fixed')
def gen_summary(bugs):
@@ -704,7 +704,7 @@ to improve our documentation and procedures, so feedback is welcome.""")])])
if urgency.startswith('high'):
urgency = self.make_red(urgency)
- elif vulnerable == 2:
+ elif vulnerable == security_db.Vulnerable.UNDETERMINED:
urgency = self.make_purple(urgency)
else:
if no_dsa:
@@ -765,7 +765,7 @@ to improve our documentation and procedures, so feedback is welcome.""")])])
if urgency.startswith('high'):
urgency = self.make_red(urgency)
- elif vulnerable == 2:
+ elif vulnerable == security_db.Vulnerable.UNDETERMINED:
urgency = self.make_purple(urgency)
yield (self.make_source_package_ref(url, pkg_name, title), self.make_xref(url, bug_name),
@@ -792,9 +792,10 @@ to improve our documentation and procedures, so feedback is welcome.""")])])
(SELECT range_remote FROM nvd_data
WHERE cve_name = st.bug_name)
FROM source_package_status AS st, source_packages AS sp
- WHERE st.vulnerable AND sp.rowid = st.package
+ WHERE st.vulnerable != ? AND sp.rowid = st.package
AND sp.release = ? AND sp.subrelease = ''
- ORDER BY sp.name, st.bug_name COLLATE version""", (rel,)):
+ ORDER BY sp.name, st.bug_name COLLATE version""",
+ (security_db.Vulnerable.FIXED, rel,)):
if bf.urgencyFiltered(urgency, vulnerable):
continue
if bf.remoteFiltered(remote):
@@ -818,7 +819,7 @@ to improve our documentation and procedures, so feedback is welcome.""")])])
if urgency.startswith('high'):
urgency = self.make_red(urgency)
- elif vulnerable == 2:
+ elif vulnerable == security_db.Vulnerable.UNDETERMINED:
urgency = self.make_purple(urgency)
yield self.make_source_package_ref(url, pkg_name, title), self.make_xref(url, bug_name), urgency, remote
@@ -900,7 +901,7 @@ to improve our documentation and procedures, so feedback is welcome.""")])])
if urgency.startswith('high'):
urgency = self.make_red(urgency)
- elif vulnerable == 2:
+ elif vulnerable == security_db.Vulnerable.UNDETERMINED:
urgency = self.make_purple(urgency)
if stable_later:
@@ -925,7 +926,7 @@ checker to find out why they have not entered testing yet."""),
"Remote", ""))])
def page_status_todo(self, path, params, url):
- hide_check = params.get('hide_check', False)
+ hide_check = bool(params.get('hide_check', False))
if hide_check:
flags = A(url.updateParamsDict({'hide_check' : None}),
'Show "check" TODOs')
@@ -952,10 +953,11 @@ checker to find out why they have not entered testing yet."""),
"""SELECT DISTINCT sp.name, st.bug_name, sp.release,
bugs.description
FROM source_package_status AS st, source_packages AS sp, bugs
- WHERE st.vulnerable == 2 AND sp.rowid = st.package
+ WHERE st.vulnerable == ? AND sp.rowid = st.package
AND sp.release IN (""" + ",".join("?" * len(releases)) + """)
AND sp.subrelease = '' AND st.bug_name == bugs.name
- ORDER BY sp.name, st.bug_name COLLATE version""", releases):
+ ORDER BY sp.name, st.bug_name COLLATE version""",
+ (security_db.Vulnerable.UNDETERMINED, *releases)):
if old_bug == '':
old_bug = bug_name
@@ -996,11 +998,12 @@ checker to find out why they have not entered testing yet."""),
"""SELECT DISTINCT sp.name, st.bug_name, sp.release,
bugs.description
FROM source_package_status AS st, source_packages AS sp, bugs
- WHERE st.vulnerable > 0 AND sp.rowid = st.package
+ WHERE st.vulnerable != ? AND sp.rowid = st.package
AND sp.release IN (""" + ",".join("?" * len(releases)) + """)
AND st.urgency == 'unimportant'
AND sp.subrelease = '' AND st.bug_name == bugs.name
- ORDER BY sp.name, st.bug_name COLLATE version""", releases):
+ ORDER BY sp.name, st.bug_name COLLATE version""",
+ (security_db.Vulnerable.FIXED, *releases)):
if old_bug == '':
old_bug = bug_name
@@ -1177,13 +1180,9 @@ not unimportant."""),
def gen():
for (rel, subrel, archive, sources, archs) \
in self.db.availableReleases():
- if sources:
- sources = 'yes'
- else:
- sources = 'no'
if 'source' in archs:
archs.remove('source')
- yield rel, subrel, archive, sources, make_list(archs)
+ yield rel, subrel, archive, "yes" if sources else "no" , make_list(archs)
return self.create_page(
url, "Available releases",
[P("""The security issue database is checked against
@@ -1237,8 +1236,8 @@ issue (or a bug has been created and is not recorded in this database).
In the second kind of names, there is a Debian bug for the issue, and the "''',
CODE("000000"), '''"part of the name is replaced with the
Debian bug number.'''),
- make_table(gen(1),title=H2('With unfixed issues'), caption=("Bug", "Description")),
- make_table(gen(0),title=H2('The rest'), caption=("Bug", "Description")),
+ make_table(gen(security_db.Vulnerable.AFFECTED),title=H2('With unfixed issues'), caption=("Bug", "Description")),
+ make_table(gen(security_db.Vulnerable.FIXED),title=H2('The rest'), caption=("Bug", "Description")),
])
def page_data_pts(self, path, params, url):
@@ -1248,10 +1247,10 @@ Debian bug number.'''),
(SELECT package, bug, urgency FROM stable_status
UNION ALL SELECT DISTINCT sp.name, st.bug_name, st.urgency
FROM source_package_status AS st, source_packages AS sp
- WHERE st.vulnerable AND st.urgency <> 'unimportant'
+ WHERE st.vulnerable != ? AND st.urgency <> 'unimportant'
AND sp.rowid = st.package AND sp.release = 'sid'
AND sp.subrelease = '') x WHERE urgency <> 'unimportant'
- GROUP BY package ORDER BY package"""):
+ GROUP BY package ORDER BY package""", (security_db.Vulnerable.FIXED,)):
data.append(pkg)
data.append(':')
data.append(str(bugs))
@@ -1289,17 +1288,16 @@ Debian bug number.'''),
"Source"),
" ", A(url.absolute("https://salsa.debian.org/security-tracker-team/security-tracker"), "(Git)"),
)))
+ body_attribs = {}
if search_in_page:
- on_load = "selectSearch()"
- else:
- on_load = None
+ body_attribs["onload"] = "selectSearch()"
head_contents = compose(
LINK(' ', href=url.scriptRelative("style.css")),
SCRIPT(' ', src=url.scriptRelative("script.js")),
).toHTML()
return HTMLResult(self.add_title(title, body,
head_contents=head_contents,
- body_attribs={'onload': on_load}),
+ body_attribs=body_attribs),
doctype=self.html_dtd(),
status=status)
@@ -1527,8 +1525,5 @@ Debian bug number.'''),
def make_dangerous(self, contents):
return SPAN(contents, _class="dangerous")
- def pre_dispatch(self):
- pass
-
if __name__ == "__main__":
- TrackerService(socket_name, db_name).run()
+ WebServiceHTTPAdapter(TrackerService(db_name), socket_name).run()
=====================================
data/CVE/list
=====================================
The diff for this file was not included because it is too large.
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,37 @@
+[07 Aug 2026] DLA-4725-1 bind9 - security update
+ {CVE-2026-3039 CVE-2026-3592 CVE-2026-5946 CVE-2026-5950 CVE-2026-10723 CVE-2026-10822 CVE-2026-11331 CVE-2026-11605 CVE-2026-11622 CVE-2026-11721 CVE-2026-12617 CVE-2026-13204 CVE-2026-13321}
+ [bullseye] - bind9 1:9.16.50-1~deb11u6
+ [bookworm] - bind9 1:9.18.49-1~deb12u2
+[07 Aug 2026] DLA-4724-1 linux-6.12 - security update
+ {CVE-2025-21807 CVE-2026-45944 CVE-2026-46093 CVE-2026-53005 CVE-2026-53027 CVE-2026-53226 CVE-2026-53260 CVE-2026-53365 CVE-2026-53392 CVE-2026-53399 CVE-2026-53402 CVE-2026-63815 CVE-2026-63816 CVE-2026-63818 CVE-2026-63970 CVE-2026-64187 CVE-2026-64189 CVE-2026-64192 CVE-2026-64206 CVE-2026-64227 CVE-2026-64241 CVE-2026-64256 CVE-2026-64265 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64270 CVE-2026-64271 CVE-2026-64272 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64279 CVE-2026-64284 CVE-2026-64286 CVE-2026-64287 CVE-2026-64289 CVE-2026-64294 CVE-2026-64296 CVE-2026-64297 CVE-2026-64298 CVE-2026-64299 CVE-2026-64301 CVE-2026-64303 CVE-2026-64304 CVE-2026-64305 CVE-2026-64306 CVE-2026-64307 CVE-2026-64308 CVE-2026-64309 CVE-2026-64310 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64318 CVE-2026-64319 CVE-2026-64320 CVE-2026-64321 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64326 CVE-2026-64327 CVE-2026-64328 CVE-2026-64329 CVE-2026-64330 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64336 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64341 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64345 CVE-2026-64346 CVE-2026-64347 CVE-2026-64348 CVE-2026-64350 CVE-2026-64351 CVE-2026-64352 CVE-2026-64354 CVE-2026-64355 CVE-2026-64357 CVE-2026-64358 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361 CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64365 CVE-2026-64367 CVE-2026-64368 CVE-2026-64369 CVE-2026-64370 CVE-2026-64371 CVE-2026-64372 CVE-2026-64373 CVE-2026-64374 CVE-2026-64375 CVE-2026-64376 CVE-2026-64377 CVE-2026-64378 CVE-2026-64379 CVE-2026-64380 CVE-2026-64381 CVE-2026-64382 CVE-2026-64383 CVE-2026-64384 CVE-2026-64385 CVE-2026-64386 CVE-2026-64387 CVE-2026-64390 CVE-2026-64391 CVE-2026-64392 CVE-2026-64393 CVE-2026-64394 CVE-2026-64395 CVE-2026-64396 CVE-2026-64397 CVE-2026-64398 CVE-2026-64399 CVE-2026-64401 CVE-2026-64402 CVE-2026-64403 CVE-2026-64404 CVE-2026-64405 CVE-2026-64406 CVE-2026-64407 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64414 CVE-2026-64415 CVE-2026-64416 CVE-2026-64417 CVE-2026-64418 CVE-2026-64419 CVE-2026-64420 CVE-2026-64421 CVE-2026-64422 CVE-2026-64423 CVE-2026-64424 CVE-2026-64425 CVE-2026-64428 CVE-2026-64429 CVE-2026-64430 CVE-2026-64432 CVE-2026-64433 CVE-2026-64434 CVE-2026-64435 CVE-2026-64436 CVE-2026-64437 CVE-2026-64438 CVE-2026-64440 CVE-2026-64441 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64446 CVE-2026-64448 CVE-2026-64449 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64456 CVE-2026-64457 CVE-2026-64458 CVE-2026-64461 CVE-2026-64462 CVE-2026-64463 CVE-2026-64465 CVE-2026-64468 CVE-2026-64469 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64473 CVE-2026-64474 CVE-2026-64475 CVE-2026-64476 CVE-2026-64477 CVE-2026-64478 CVE-2026-64479 CVE-2026-64480 CVE-2026-64481 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64488 CVE-2026-64489 CVE-2026-64490 CVE-2026-64493 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64499 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64507 CVE-2026-64508 CVE-2026-64509 CVE-2026-64510 CVE-2026-64511 CVE-2026-64512 CVE-2026-64514 CVE-2026-64530 CVE-2026-64531 CVE-2026-64532 CVE-2026-64533 CVE-2026-64534 CVE-2026-64535 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64542 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64555 CVE-2026-64556 CVE-2026-64557 CVE-2026-64558 CVE-2026-64559 CVE-2026-64560 CVE-2026-64582 CVE-2026-64585 CVE-2026-64589 CVE-2026-64590 CVE-2026-64592 CVE-2026-64593 CVE-2026-64594 CVE-2026-64597 CVE-2026-64598 CVE-2026-64599 CVE-2026-64600 CVE-2026-64602 CVE-2026-64603 CVE-2026-64604}
+ [bookworm] - linux-6.12 6.12.100-1~deb12u1
+[07 Aug 2026] DLA-4723-1 linux-6.1 - security update
+ {CVE-2024-36013 CVE-2025-40196 CVE-2026-31610 CVE-2026-43216 CVE-2026-46135 CVE-2026-53332 CVE-2026-53392 CVE-2026-53393 CVE-2026-53399 CVE-2026-53400 CVE-2026-53402 CVE-2026-63797 CVE-2026-63806 CVE-2026-63810 CVE-2026-63815 CVE-2026-63818 CVE-2026-63829 CVE-2026-64187 CVE-2026-64189 CVE-2026-64206 CVE-2026-64248 CVE-2026-64250 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64279 CVE-2026-64296 CVE-2026-64297 CVE-2026-64298 CVE-2026-64299 CVE-2026-64301 CVE-2026-64303 CVE-2026-64304 CVE-2026-64306 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64318 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64329 CVE-2026-64330 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64336 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346 CVE-2026-64347 CVE-2026-64350 CVE-2026-64351 CVE-2026-64352 CVE-2026-64355 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361 CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64365 CVE-2026-64370 CVE-2026-64371 CVE-2026-64372 CVE-2026-64373 CVE-2026-64374 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378 CVE-2026-64379 CVE-2026-64380 CVE-2026-64381 CVE-2026-64390 CVE-2026-64393 CVE-2026-64394 CVE-2026-64395 CVE-2026-64396 CVE-2026-64397 CVE-2026-64398 CVE-2026-64399 CVE-2026-64401 CVE-2026-64403 CVE-2026-64406 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64417 CVE-2026-64419 CVE-2026-64420 CVE-2026-64422 CVE-2026-64423 CVE-2026-64425 CVE-2026-64428 CVE-2026-64429 CVE-2026-64430 CVE-2026-64432 CVE-2026-64435 CVE-2026-64436 CVE-2026-64437 CVE-2026-64438 CVE-2026-64440 CVE-2026-64441 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64446 CVE-2026-64448 CVE-2026-64449 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64456 CVE-2026-64458 CVE-2026-64461 CVE-2026-64462 CVE-2026-64465 CVE-2026-64468 CVE-2026-64469 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64475 CVE-2026-64476 CVE-2026-64478 CVE-2026-64480 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64488 CVE-2026-64489 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64510 CVE-2026-64512 CVE-2026-64514 CVE-2026-64530 CVE-2026-64531 CVE-2026-64532 CVE-2026-64533 CVE-2026-64534 CVE-2026-64535 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64557 CVE-2026-64560 CVE-2026-64600}
+ [bullseye] - linux-6.1 6.1.180-1~deb11u1
+[06 Aug 2026] DLA-4722-1 redis - security update
+ {CVE-2026-66373}
+ [bullseye] - redis 5:6.0.16-1+deb11u9
+ [bookworm] - redis 5:7.0.15-1~deb12u9
+[06 Aug 2026] DLA-4721-1 async-http-client - security update
+ {CVE-2026-55688}
+ [bullseye] - async-http-client 2.12.2-1+deb11u1
+ [bookworm] - async-http-client 2.12.3-1+deb12u1
+[05 Aug 2026] DLA-4720-1 linux - security update
+ {CVE-2024-36013 CVE-2025-40196 CVE-2026-31610 CVE-2026-43216 CVE-2026-46135 CVE-2026-53332 CVE-2026-53392 CVE-2026-53393 CVE-2026-53399 CVE-2026-53400 CVE-2026-53402 CVE-2026-63797 CVE-2026-63806 CVE-2026-63810 CVE-2026-63815 CVE-2026-63818 CVE-2026-63829 CVE-2026-64187 CVE-2026-64189 CVE-2026-64206 CVE-2026-64248 CVE-2026-64250 CVE-2026-64266 CVE-2026-64268 CVE-2026-64269 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64279 CVE-2026-64296 CVE-2026-64297 CVE-2026-64298 CVE-2026-64299 CVE-2026-64301 CVE-2026-64303 CVE-2026-64304 CVE-2026-64306 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64318 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64329 CVE-2026-64330 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64336 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64346 CVE-2026-64347 CVE-2026-64350 CVE-2026-64351 CVE-2026-64352 CVE-2026-64355 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361 CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64365 CVE-2026-64370 CVE-2026-64371 CVE-2026-64372 CVE-2026-64373 CVE-2026-64374 CVE-2026-64375 CVE-2026-64376 CVE-2026-64378 CVE-2026-64379 CVE-2026-64380 CVE-2026-64381 CVE-2026-64390 CVE-2026-64393 CVE-2026-64394 CVE-2026-64395 CVE-2026-64396 CVE-2026-64397 CVE-2026-64398 CVE-2026-64399 CVE-2026-64401 CVE-2026-64403 CVE-2026-64406 CVE-2026-64408 CVE-2026-64409 CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64417 CVE-2026-64419 CVE-2026-64420 CVE-2026-64422 CVE-2026-64423 CVE-2026-64425 CVE-2026-64428 CVE-2026-64429 CVE-2026-64430 CVE-2026-64432 CVE-2026-64435 CVE-2026-64436 CVE-2026-64437 CVE-2026-64438 CVE-2026-64440 CVE-2026-64441 CVE-2026-64442 CVE-2026-64443 CVE-2026-64444 CVE-2026-64445 CVE-2026-64446 CVE-2026-64448 CVE-2026-64449 CVE-2026-64450 CVE-2026-64452 CVE-2026-64454 CVE-2026-64455 CVE-2026-64456 CVE-2026-64458 CVE-2026-64461 CVE-2026-64462 CVE-2026-64465 CVE-2026-64468 CVE-2026-64469 CVE-2026-64470 CVE-2026-64471 CVE-2026-64472 CVE-2026-64475 CVE-2026-64476 CVE-2026-64478 CVE-2026-64480 CVE-2026-64482 CVE-2026-64483 CVE-2026-64484 CVE-2026-64486 CVE-2026-64487 CVE-2026-64488 CVE-2026-64489 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64510 CVE-2026-64512 CVE-2026-64514 CVE-2026-64530 CVE-2026-64531 CVE-2026-64532 CVE-2026-64533 CVE-2026-64534 CVE-2026-64535 CVE-2026-64536 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64557 CVE-2026-64560 CVE-2026-64600}
+ [bookworm] - linux 6.1.180-1
+[05 Aug 2026] DLA-4719-1 p7zip - security update
+ {CVE-2026-14266 CVE-2026-58052}
+ [bullseye] - p7zip 16.02+really26.02+dfsg-0+deb11u1
+ [bookworm] - p7zip 16.02+really26.02+dfsg-0+deb12u1
+[05 Aug 2026] DLA-4718-1 7zip - security update
+ {CVE-2026-14266 CVE-2026-58052}
+ [bookworm] - 7zip 22.01+really26.02+dfsg-0+deb12u1
+[05 Aug 2026] DLA-4717-1 linux - security update
+ {CVE-2022-49803 CVE-2022-50114 CVE-2023-52494 CVE-2025-23131 CVE-2025-39931 CVE-2026-23204 CVE-2026-31451 CVE-2026-31755 CVE-2026-43216 CVE-2026-43219 CVE-2026-43499 CVE-2026-46116 CVE-2026-46135 CVE-2026-46252 CVE-2026-46331 CVE-2026-52942 CVE-2026-53138 CVE-2026-53157 CVE-2026-53158 CVE-2026-53159 CVE-2026-53167 CVE-2026-53177 CVE-2026-53325 CVE-2026-53329 CVE-2026-53332 CVE-2026-53381 CVE-2026-53382 CVE-2026-53385 CVE-2026-53392 CVE-2026-53393 CVE-2026-53397 CVE-2026-53398 CVE-2026-53399 CVE-2026-53400 CVE-2026-53402 CVE-2026-53403 CVE-2026-63794 CVE-2026-63796 CVE-2026-63798 CVE-2026-63800 CVE-2026-63801 CVE-2026-63803 CVE-2026-63806 CVE-2026-63808 CVE-2026-63809 CVE-2026-63814 CVE-2026-63815 CVE-2026-63818 CVE-2026-63822 CVE-2026-63823 CVE-2026-63824 CVE-2026-63827 CVE-2026-63828 CVE-2026-63829 CVE-2026-63830 CVE-2026-63831 CVE-2026-63834 CVE-2026-63835 CVE-2026-63836 CVE-2026-64188 CVE-2026-64189 CVE-2026-64191 CVE-2026-64206 CVE-2026-64249 CVE-2026-64252 CVE-2026-64266 CVE-2026-64268 CVE-2026-64271 CVE-2026-64273 CVE-2026-64274 CVE-2026-64275 CVE-2026-64276 CVE-2026-64277 CVE-2026-64296 CVE-2026-64298 CVE-2026-64299 CVE-2026-64303 CVE-2026-64304 CVE-2026-64306 CVE-2026-64312 CVE-2026-64313 CVE-2026-64315 CVE-2026-64316 CVE-2026-64317 CVE-2026-64318 CVE-2026-64322 CVE-2026-64323 CVE-2026-64324 CVE-2026-64329 CVE-2026-64330 CVE-2026-64331 CVE-2026-64332 CVE-2026-64333 CVE-2026-64334 CVE-2026-64335 CVE-2026-64337 CVE-2026-64338 CVE-2026-64340 CVE-2026-64342 CVE-2026-64343 CVE-2026-64344 CVE-2026-64345 CVE-2026-64347 CVE-2026-64348 CVE-2026-64351 CVE-2026-64359 CVE-2026-64360 CVE-2026-64361 CVE-2026-64362 CVE-2026-64363 CVE-2026-64364 CVE-2026-64370 CVE-2026-64371 CVE-2026-64372 CVE-2026-64373 CVE-2026-64374 CVE-2026-64375 CVE-2026-64378 CVE-2026-64379 CVE-2026-64380 CVE-2026-64381 CVE-2026-64403 CVE-2026-64406 CVE-2026-64408 CVE-2026-64411 CVE-2026-64412 CVE-2026-64413 CVE-2026-64420 CVE-2026-64422 CVE-2026-64423 CVE-2026-64425 CVE-2026-64429 CVE-2026-64435 CVE-2026-64436 CVE-2026-64438 CVE-2026-64442 CVE-2026-64445 CVE-2026-64446 CVE-2026-64448 CVE-2026-64450 CVE-2026-64452 CVE-2026-64455 CVE-2026-64456 CVE-2026-64461 CVE-2026-64462 CVE-2026-64465 CVE-2026-64468 CVE-2026-64469 CVE-2026-64470 CVE-2026-64471 CVE-2026-64475 CVE-2026-64478 CVE-2026-64483 CVE-2026-64484 CVE-2026-64487 CVE-2026-64488 CVE-2026-64494 CVE-2026-64495 CVE-2026-64496 CVE-2026-64497 CVE-2026-64500 CVE-2026-64503 CVE-2026-64504 CVE-2026-64505 CVE-2026-64510 CVE-2026-64514 CVE-2026-64529 CVE-2026-64534 CVE-2026-64538 CVE-2026-64540 CVE-2026-64541 CVE-2026-64544 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64553 CVE-2026-64554 CVE-2026-64560}
+ [bullseye] - linux 5.10.262-1
+[04 Aug 2026] DLA-4716-1 ruby2.7 - security update
+ {CVE-2025-24294 CVE-2025-61594 CVE-2026-27820 CVE-2026-41316}
+ [bullseye] - ruby2.7 2.7.4-1+deb11u6
[02 Aug 2026] DLA-4715-1 kissfft - security update
{CVE-2025-34297 CVE-2026-41445}
[bullseye] - kissfft 131.1.0-1+deb11u1
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,24 @@
+[08 Aug 2026] DSA-6417-1 libheif - security update
+ {CVE-2025-68431 CVE-2026-32740 CVE-2026-32741 CVE-2026-32882 CVE-2026-47178 CVE-2026-47247 CVE-2026-47709 CVE-2026-47714 CVE-2026-48029 CVE-2026-49271 CVE-2026-62289 CVE-2026-62292}
+ [trixie] - libheif 1.19.8-1+deb13u1
+[07 Aug 2026] DSA-6416-1 jq - security update
+ {CVE-2024-53427 CVE-2026-32316 CVE-2026-40612 CVE-2026-41256 CVE-2026-41257 CVE-2026-43894 CVE-2026-43895 CVE-2026-43896 CVE-2026-44777 CVE-2026-47770 CVE-2026-49839 CVE-2026-54679}
+ [trixie] - jq 1.7.1-6+deb13u3
+[06 Aug 2026] DSA-6415-1 linux - security update
+ {CVE-2025-40098 CVE-2026-45897 CVE-2026-45901 CVE-2026-53078 CVE-2026-53090 CVE-2026-64205 CVE-2026-64280 CVE-2026-64290 CVE-2026-64561 CVE-2026-64562 CVE-2026-64563 CVE-2026-64564 CVE-2026-64565 CVE-2026-64567 CVE-2026-64568 CVE-2026-64569 CVE-2026-64570 CVE-2026-64571 CVE-2026-64572 CVE-2026-64573 CVE-2026-64574 CVE-2026-64576 CVE-2026-64577 CVE-2026-64578 CVE-2026-64579 CVE-2026-64580 CVE-2026-64583 CVE-2026-64584}
+ [trixie] - linux 6.12.101-1
+[06 Aug 2026] DSA-6414-1 udisks2 - security update
+ {CVE-2026-7867}
+ [trixie] - udisks2 2.10.1-12.1+deb13u2
+[06 Aug 2026] DSA-6413-1 libde265 - security update
+ {CVE-2024-38949 CVE-2024-38950 CVE-2025-61147 CVE-2026-45382 CVE-2026-45383 CVE-2026-49295 CVE-2026-49337 CVE-2026-49346 CVE-2026-54240 CVE-2026-54241}
+ [trixie] - libde265 1.0.15-1+deb13u1
+[05 Aug 2026] DSA-6412-1 botan3 - security update
+ {CVE-2026-44378}
+ [trixie] - botan3 3.12.0+dfsg-2~deb13u1
+[05 Aug 2026] DSA-6411-1 aom - security update
+ {CVE-2026-56208 CVE-2026-56209 CVE-2026-56210 CVE-2026-56211}
+ [trixie] - aom 3.12.1-1+deb13u1
[02 Aug 2026] DSA-6410-1 libssh - security update
{CVE-2026-0964 CVE-2026-0965 CVE-2026-0966 CVE-2026-0967 CVE-2026-0968 CVE-2026-3731 CVE-2026-15370 CVE-2026-59843 CVE-2026-59844 CVE-2026-59845 CVE-2026-59846 CVE-2026-59847 CVE-2026-59848 CVE-2026-59849 CVE-2026-59850}
[trixie] - libssh 0.11.5-0+deb13u1
=====================================
data/dla-needed.txt
=====================================
@@ -30,11 +30,6 @@ rather than remove/replace existing ones.
NOTE: 20260413: Try to clean postponed CVE (rouca/FD)
NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
--
-7zip/bookworm (Sylvain Beucler)
- NOTE: 20260718: Added by Front-Desk (Beuc)
- NOTE: 20260718: Maintainer updated the trixie SPU with 26.02.
- NOTE: 20260718: Maintainer sent me a bookworm update for review. (Beuc)
---
activemq
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260715: Also add for bookworm
@@ -63,21 +58,11 @@ aom/bookworm
NOTE: 20260709: AV1 *encoder* flaws (SVC layer-id/LAP), CVE-2026-56208..56211; only
NOTE: 20260709: bookworm (3.6.0) affected, bullseye not-affected (code added in aom 2.0.0).
--
-apache-directory-api
- NOTE: 20260608: Added by Front-Desk (rouca)
---
apache-log4j2/bullseye
NOTE: 20260413: Added by Front-Desk (rouca)
--
-async-http-client (Chris Lamb)
- NOTE: 20260610: Added by Front-Desk (rouca)
---
-bind9 (eamanu)
- NOTE: 20260520: Added by Front-Desk (Beuc)
- NOTE: 20260520: 6 new CVEs including 1 memory corruption, upcoming DSA (Beuc/front-desk)
- NOTE: 20260629: finishing backporting patches (eamanu)
- NOTE: 20260713: still in review (eamanu)
- NOTE: 20260724: Also add for bookworm (9.18.49); 8/9 CVEs affecting. (utkarsh/front-desk)
+apr-util (rouca)
+ NOTE: 20260807: Added by Front-Desk (rouca)
--
bouncycastle
NOTE: 20260417: Added by Front-Desk (rouca)
@@ -90,9 +75,6 @@ busybox
NOTE: 20260722: Also add for bookworm; CVE-2026-38752..38755 (ash/awk)
NOTE: 20260722: share code, sponsored, already queued bullseye+ELTS (utkarsh)
--
-c3p0/bullseye
- NOTE: 20260414: Added by Front-Desk (rouca)
---
ca-certificates (rouca)
NOTE: 20250613: Added by Front-Desk (rouca)
NOTE: 20250613: Lack some certificates #1095913 (rouca/FD)
@@ -115,13 +97,15 @@ caddy/bookworm
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
+calibre (Abhijith)
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
+chromium/bookworm (Emilio)
+ NOTE: 20260807: Added by pochu
+--
cjson
NOTE: 20260801: Added by Front-Desk (ta)
--
-ckeditor/bullseye
- NOTE: 20241002: Added by Front-Desk (Beuc)
- NOTE: 20241002: Multiple CVEs have been piling up (Beuc/front-desk)
---
clamav (Emilio)
NOTE: 20260711: Added by Front-Desk (utkarsh)
NOTE: 20260711: Needs a newer rustc to be backported as well. (utkarsh)
@@ -147,12 +131,6 @@ cyrus-imapd
NOTE: 20260717: Added by Front-Desk (Beuc)
NOTE: 20260717: Upcoming DSA (Beuc/front-desk)
--
-docker-registry
- NOTE: 20260419: Added by Front-Desk (rouca)
- NOTE: 20260725: Also add for bookworm (2.8.2); CVE-2026-33540 proxyauth.go
- NOTE: 20260725: realm handling identical to bullseye. CVE-2026-41888 is
- NOTE: 20260725: not-affected there (tag-delete code is 3.0.0+). (utkarsh/front-desk)
---
docker.io
NOTE: 20250805: Added by Front-Desk (rouca)
NOTE: 20260714: Also add for bookworm (Beuc/front-desk)
@@ -209,9 +187,6 @@ firmware-nonfree/bullseye
flatpak/bullseye
NOTE: 20260413: Added by Front-Desk (rouca)
--
-fontforge/bullseye
- NOTE: 20260216: Added by Front-Desk (rouca)
---
freerdp2
NOTE: 20260127: Added by Front-Desk (Beuc)
NOTE: 20260127: Many CVEs fixed in 3.20.1 and 3.21, but missing fix commits (Beuc/front-desk)
@@ -247,16 +222,6 @@ glances/bullseye
NOTE: 20260518: Added by Front-Desk (Beuc)
NOTE: 20260518: Many postponed vulnerabilities piled-up (Beuc/front-desk)
--
-golang-github-gorilla-csrf/bullseye
- NOTE: 20250422: Added by Front-Desk (rouca)
- NOTE: 20250422: Need to binNMU reverse depends (in that order): golang-github-alecthomas-chroma, golang-github-niklasfasching-go-org, golang-github-yuin-goldmark-highlighting, hugo (rouca)
- NOTE: 20250621: Re-add as binNMUs are not all properly Installed in the archive, e.g.
- NOTE: 20250621: https://buildd.debian.org/status/package.php?p=hugo&suite=bullseye-security
- NOTE: 20250621: https://buildd.debian.org/status/package.php?p=golang-github-alecthomas-chroma&suite=bullseye-security
- NOTE: 20250621: https://buildd.debian.org/status/package.php?p=golang-github-niklasfasching-go-org&suite=bullseye-security
- NOTE: 20250621: still stuck at Uploaded phase, probably due to missing sources at security.debian.org (Beuc)
- NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
---
golang-glog/bullseye
NOTE: 20250209: Added by Front-Desk (apo)
NOTE: 20251107: Re-add as binNMUs are not all properly Installed in the archive:
@@ -329,6 +294,9 @@ ldap-account-manager
NOTE: 20260725: Also add for bookworm (8.3); CVE-2026-27894 PDF-export LFI,
NOTE: 20260725: unvalidated pdf_structure/pdf_font identical to bullseye. (utkarsh/front-desk)
--
+libarchive
+ NOTE: 20260804: Added by Front-Desk. Take care of CVE-2026-15028 (rouca)
+--
libass
NOTE: 20260712: Added by Front-Desk (utkarsh)
NOTE: 20260712: TEMP-0000000-AA08BC (GHSA-pjjp-65r7-ppgm): OOB read+write in wrap_lines_measure from untrusted subtitles; secteam fixed stable via point release. Affected in bullseye (0.15.0) and bookworm (0.17.1). (utkarsh/front-desk)
@@ -356,6 +324,9 @@ libde265
NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
NOTE: 20260709: upstream fixes v1.0.19-v1.1.1 newer than Debian 1.0.11.
--
+libgd-securityimage-perl
+ NOTE: 20260806: Added by Front-Desk (rouca)
+--
libgd2 (guilhem)
NOTE: 20260731: Added by Front-Desk (ta)
--
@@ -370,12 +341,12 @@ libio-compress-perl
NOTE: 20260612: Added by Front-Desk (rouca)
NOTE: 20260612: MUST hold-back following the upper suites and wait for green light from security team (rouca/FD)
--
+libmojo-jwt-perl
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
libnet-dns-perl
NOTE: 20260802: Added by Front-Desk (ta)
--
-libpgjava
- NOTE: 20260613: Added by Front-Desk (rouca)
---
librabbitmq
NOTE: 20260731: Added by Front-Desk (ta)
--
@@ -444,18 +415,13 @@ libstb/bullseye
NOTE: 20260226: Fixed CVE-2021-28021 CVE-2021-37789 CVE-2021-42715 CVE-2022-28041 CVE-2022-28042 with DLA-4493-1 (abhijith)
NOTE: 20260429: Revisit when upstream merge the proposed fixes. Though other embed libstb projects patched (abhijith)
--
-libvncserver
+libvncserver (Abhijith PA)
NOTE: 20260612: Added by Front-Desk (rouca)
--
libwebsockets/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
--
-libxmltok
- NOTE: 20250421: Added by Front-Desk (ta)
- NOTE: 20250421: Also review all other expat CVEs. (bunk)
- NOTE: 20250421: Fixing the expat copy in xmlrpc-c at the same time would make sense. (bunk)
---
libxslt/bullseye
NOTE: 20250930: Added by Front-Desk (rouca)
NOTE: 20251020: In progress, waiting for upstream action (guilhem)
@@ -544,6 +510,9 @@ netty (rouca)
NOTE: 20260114: fix remaining CVE wait DSA (rouca)
NOTE: 20260331: release DLA-4519-1 netty. Unfortunatly partial due to new CVEs (rouca)
--
+neutron
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
nginx (charles)
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Special care is needed for the HTTP2 Bomb (TEMP-1138794-BADE22)
@@ -556,10 +525,17 @@ node-dompurify/bookworm
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
+node-ip-address
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
node-lodash/bookworm (utkarsh)
NOTE: 20260703: Added by Front-Desk (dleidert)
NOTE: 20260703: Follow DLA 4663-1; assigned to Utkarsh to grab this (dleidert/front-desk)
--
+node-re2
+ NOTE: 20260806: Added by Front-Desk (rouca)
+ NOTE: 20260806: CVE-2026-68499 is worth fixing due to re2 used for fixing redos and other regex problem on backport (rouca)
+--
nodejs
NOTE: 20260622: Added by Front-Desk (lamby)
--
@@ -630,10 +606,6 @@ openvswitch/bullseye
orthanc/bullseye
NOTE: 20260419: Added by Front-Desk (rouca)
--
-p7zip
- NOTE: 20260718: Added by Front-Desk (Beuc)
- NOTE: 20260718: Follow 7zip updates.
---
pacemaker
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Package is in dsa-needed (charles)
@@ -654,6 +626,12 @@ pgextwlist
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Follow DSA-6385-1 (1 CVE) (Beuc/front-desk)
--
+pglogical
+ NOTE: 20260805: Added by Front-Desk, due to CVE-2026-50738 (rouca)
+--
+php-dompdf
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
php-horde-imp/bullseye
NOTE: 20260714: Added by Front-Desk (Beuc)
--
@@ -670,11 +648,21 @@ php-twig/bullseye
NOTE: 20260521: Added by Front-Desk (Beuc)
NOTE: 20260521: Cf. symfony batch of CVEs, upcoming DSA (Beuc/front-desk)
--
+php7.4/bullseye (guilhem)
+ NOTE: 20260804: Added by Front-Desk (rouca)
+ NOTE: 20260804: Follow DSA-6406-1 (rouca/front-desk)
+--
+php8.2/bookworm (guilhem)
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
phpseclib/bullseye (Utkarsh)
NOTE: 20260518: Added by Front-Desk (Beuc)
NOTE: 20260518: Follow bookworm 12.14 (2 CVEs) (Beuc/front-desk)
NOTE: 20260720: will get back to this after releasing squid. (utkarsh)
--
+pipewire
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
proftpd-dfsg
NOTE: 20260511: Added by Beuc for maintainer (Hilmar Preuße)
NOTE: 20260511: https://lists.debian.org/debian-lts/2026/05/msg00015.html
@@ -685,6 +673,9 @@ prosody/bullseye
NOTE: 20260511: Added by Front-Desk (dleidert)
NOTE: 20260511: Follow DSA 6252-1 fixing 4 CVEs (dleidert/front-desk)
--
+puma
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
py7zr
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-23879 (GHSA range <=1.1.2); Debian 0.11.3 in range.
@@ -700,6 +691,15 @@ python-aiohttp (dleidert)
NOTE: 20260611: Added by Front-Desk (rouca)
NOTE: 20260602: Daniel Leidert is proposing to work on the update and provide debdiffs for bookworm and trixie (carnil)
--
+python-asyncssh
+ NOTE: 20260806: Added by Front-Desk (rouca)
+--
+python-cryptography
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
+python-django (Chris Lamb)
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
python-eventlet/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
@@ -747,6 +747,9 @@ python-tornado
NOTE: 20260722: Extend to bullseye; CVE-2026-49853/49854/49855 in 6.1.0 too,
NOTE: 20260722: shared with bookworm; fix in 6.5.6 (utkarsh/front-desk)
--
+python-zeroconf
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
qemu
NOTE: 20260520: Added by Front-Desk (Beuc)
NOTE: 20260520: Many postponed CVEs piled up (Beuc/front-desk)
@@ -761,13 +764,8 @@ rabbitmq-server/bullseye
NOTE: 20260504: Added by coordinator (santiago)
NOTE: 20260504: Added to address out-standing minor issues
--
-redis (Chris Lamb)
- NOTE: 20260727: Added by Front-Desk (utkarsh)
- NOTE: 20260727: CVE-2026-66373: double free in the stream consumer PEL
- NOTE: 20260727: loader (rdbLoadObject), reachable via RESTORE. Fixed
- NOTE: 20260727: upstream in 6.2.23/7.2.15/8.6.5; bookworm ships
- NOTE: 20260727: 7.0.15-1~deb12u8 and bullseye 6.0.16-1+deb11u8, both
- NOTE: 20260727: still unguarded.
+rails
+ NOTE: 20260805: Added by Front-Desk (rouca)
--
request-tracker4/bullseye (Andrew Ruthven)
NOTE: 20260529: Added by Front-Desk (dleidert)
@@ -779,6 +777,12 @@ rsync (Thorsten Alteholz)
NOTE: 20260615: Requested by Sylvain to track regressions, same as in dsa-needed. (charles)
NOTE: 20260705: making progress with updated patches
--
+ruby-jwt
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
+ruby-oauth2
+ NOTE: 20260805: Added by Front-Desk (rouca)
+--
ruby-oj
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: Oj JSON parser memory-safety batch CVE-2026-54500..54903 (GHSA); affects 2.17-3.14.
@@ -788,6 +792,7 @@ ruby2.7/bullseye (Abhijith PA)
NOTE: 20260608: https://people.debian.org/~abhijith/upload/ruby2.7_patches/ (abhijith)
NOTE: 20260731: Prepared an upload with already triaged issues. Group Net::IMAP issues
NOTE: 20260731: and do upload later (abhijith)
+ NOTE: 20260804: Uploaded 2.7.4-1+deb11u6 and released DLA-4716-1 (abhijith)
--
ruby3.1/bookworm
NOTE: 20260713: Added by Front-Desk (Beuc)
@@ -817,11 +822,6 @@ rust-openssl/bullseye
NOTE: 20251107: https://buildd.debian.org/status/package.php?p=rust-debcargo&suite=bullseye-security
NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
--
-shim/bullseye (Emilio)
- NOTE: 20260511: Added by pochu
- NOTE: 20260715: the update will happen once bullseye becomes ELTS since
- NOTE: 20260715: it adds Freexian's CA (pochu)
---
shiro
NOTE: 20260726: Added by Front-Desk (utkarsh)
NOTE: 20260726: CVE-2026-56091: SimpleFilterChainResolver in shiro-guice
@@ -865,6 +865,11 @@ spip/bullseye
NOTE: 20260326: very low popcon (Beuc/front-desk)
NOTE: 20260422: https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/342
--
+sssd
+ NOTE: 20260804: Added by Front-Desk (rouca)
+ NOTE: 20260804: Crash or DoS of sssd may lead to user lockdown (rouca/FD)
+ NOTE: 20260804: SSSD should be tested carefully, with integration test (rouca/FD)
+--
starlette/bullseye (dleidert)
NOTE: 20260528: Added by Front-Desk (dleidert)
NOTE: 20260528: follow DSA-6302-1 (dleidert/front-desk)
@@ -925,6 +930,9 @@ trafficserver/bullseye
NOTE: 20250403: There are multiple new CVEs. But none of them is addresses in Sid and maintainers didn't reply to me last time (dleidert)
NOTE: 20250405: DSA 5896-1 is out (Beuc/front-desk)
--
+u-boot
+ NOTE: 20260804: Added by Front-Desk (rouca)
+--
unbound
NOTE: 20260520: Added by Front-Desk (Beuc)
NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
@@ -971,6 +979,9 @@ wireshark
NOTE: 20260430: Added by Front-Desk (lamby)
NOTE: 20260706: Also add for bookworm (Beuc/front-desk)
--
+wordpress
+ NOTE: 20260807: Added by Front-Desk. Follow DSA (rouca)
+--
xen/bookworm
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie (Beuc/front-desk)
@@ -985,7 +996,7 @@ xmlrpc-c/bullseye
NOTE: 20250705: Ping'd secteam asking for current bookworm plans. (Beuc)
NOTE: 20250705: https://lists.debian.org/debian-lts/2025/07/msg00006.html
--
-xorg-server (Emilio)
+xorg-server
NOTE: 20260522: Added by Front-Desk (Beuc)
NOTE: 20260522: Follow bookworm 12.14 (5 CVEs) (Beuc/front-desk)
NOTE: 20260713: Follow DSA-6370-1/trixie (9 CVEs) (Beuc/front-desk)
=====================================
data/dsa-needed.txt
=====================================
@@ -20,15 +20,13 @@ activemq
amd64-microcode (carnil)
Coordinating with maintainer DSA/bookworm-pu and sync with mitgations in src:linux
--
-aom
---
-botan3 (aron)
---
cacti
probably best to move to 1.2.31
--
caddy
--
+chromium (dilinger)
+--
cockpit
--
containerd
@@ -56,9 +54,6 @@ jetty9
--
jetty12
--
-jq
- possibly move trixie to 1.8.2
---
jupyterlab
--
kamailio
@@ -66,12 +61,6 @@ kamailio
kitty
Maintainer proposed debdiff for review in https://bugs.debian.org/1139898#15
--
-libde265
- possibly best to move to 1.1.1
---
-libheif
- possibly best to move to 1.23.0
---
librabbitmq
Florian Ernst is preparing updates
--
@@ -160,6 +149,9 @@ vim
some of the issues seem worth fixing
Lee Garrett is interested in contributing an update for stable
--
+wordpress
+ Maintainer prepared update, asked for review
+--
xen
--
xorg-server
=====================================
data/embedded-code-copies
=====================================
@@ -3073,6 +3073,7 @@ texlive-bin
NOTE: embeds synctex parser
- qpdfview <unfixed> (embed; bug #754138)
NOTE: embeds synctex parser
+ NOTE: texlive-bin is considered under Debian main source for synctex parser
libmspack
- cabextract 1.4-5 (embed; bug #675560)
=====================================
data/packages/nfu.yaml
=====================================
@@ -372,6 +372,7 @@
- product: Apache Kyuubi
- product: Apache Livy
- product: Apache Lucene.Net
+ - product: Apache Lucy
- product: Apache Mynewt NimBLE
- product: Apache Neethi
- product: Apache NiFi
@@ -381,6 +382,7 @@
- product: Apache OpenMeetings
- product: Apache OpenOffice
- product: Apache Polaris
+ - product: Apache Qpid ProtonJ2
- product: Apache Ranger
- product: Apache SIS
- product: Apache Seata (incubating)
@@ -462,6 +464,7 @@
- product: Eclipse Glassfish
- product: Eclipse KUKSA - Databroker
- product: Eclipse Kura
+ - product: Eclipse Milo
- product: Eclipse OMR
- product: Eclipse OpenJ9
- product: Eclipse Parsson
@@ -585,6 +588,7 @@
- product: DALI
- product: DGX Spark
- product: DLS component of NVIDIA License System
+ - product: Dynamo
- product: FLARE SDK
- product: Isaac Lab
- product: Isaac Launchable
=====================================
lib/python/bugs.py
=====================================
@@ -31,10 +31,10 @@ def listUrgencies():
Urgency.urgencies = urgencies
return urgencies
def internUrgency(name, urgencies=listUrgencies()):
- if name in urgencies:
+ try:
return urgencies[name]
- else:
- return None
+ except KeyError as err:
+ raise ValueError("invalid urgency") from err
del listUrgencies
def to_integer(expr):
@@ -63,13 +63,9 @@ class PackageNote:
else:
if isinstance(release, str):
release = debian_support.internRelease(release)
- if release is None:
- raise ValueError("invalid release")
self.release = release
if isinstance(urgency, str):
urgency = internUrgency(urgency)
- if urgency is None:
- raise ValueError("invalid urgency")
self.urgency = urgency
self.bugs = []
self.package_kind = "unknown"
@@ -144,10 +140,11 @@ class PackageNoteParsed(PackageNote):
urgency = 'not yet assigned'
if notes is not None:
for n in self.re_notes_split.split(notes):
- u = internUrgency(n)
- if u:
- urgency = u
+ try:
+ urgency = internUrgency(n)
continue
+ except ValueError:
+ pass
if n == 'bug filed':
continue
@@ -172,10 +169,7 @@ class PackageNoteNoDSA:
else:
assert isinstance(reason, str)
self.package = package
- release = debian_support.internRelease(release)
- if release is None:
- raise ValueError("invalid release")
- self.release = release
+ self.release = debian_support.internRelease(release)
self.comment = comment
self.reason = reason
=====================================
lib/python/debian_support.py
=====================================
@@ -218,10 +218,10 @@ def listReleases():
Release.releases = releases
return releases
def internRelease(name, releases=listReleases()):
- if name in releases:
+ try:
return releases[name]
- else:
- return None
+ except KeyError as err:
+ raise ValueError("invalid release") from err
del listReleases
def readLinesSHA1(lines):
=====================================
lib/python/security_db.py
=====================================
@@ -31,6 +31,7 @@ import apsw
import bugs
from collections import defaultdict, namedtuple
import email.utils
+import enum
import functools
import json
import pickle
@@ -61,6 +62,15 @@ class InsertError(Exception):
def __str__(self):
return self.errors[0] + ' [more...]'
+
+class Vulnerable(enum.IntEnum):
+ """vulnerable column value for source_package_status table"""
+
+ FIXED = 0
+ AFFECTED = 1
+ UNDETERMINED = 2
+
+
def mergeLists(a, b):
"""Merges two lists."""
if isinstance(a, str):
@@ -73,14 +83,7 @@ def mergeLists(a, b):
b = []
else:
b = b.split(',')
- result = {}
- for x in a:
- result[x] = 1
- for x in b:
- result[x] = 1
- result = list(result.keys())
- result.sort()
- return result
+ return sorted(set(a).union(b))
class NVDEntry:
"""A class for an entry in the nvd_data table.
@@ -155,7 +158,7 @@ def getBugsForSourcePackage(cursor, pkg):
# Restrict to regular releases excluding e.g. backports.
release_names = tuple(debian_support.Release.releases)
- data = itertools.starmap(
+ data_iter = itertools.starmap(
BugsForSourcePackage_internal,
cursor.execute(
BugsForSourcePackage_query.replace(
@@ -168,7 +171,7 @@ def getBugsForSourcePackage(cursor, pkg):
all_bugs = []
version_key = functools.cmp_to_key(version_compare)
# Group by bug name.
- for bug_name, data in itertools.groupby(data,
+ for bug_name, data in itertools.groupby(data_iter,
lambda row: row.bug_name):
description = None
open_seen = False
@@ -190,7 +193,7 @@ def getBugsForSourcePackage(cursor, pkg):
# Compute state. Update state-seen flags for global state
# determination.
- if best_row.vulnerable:
+ if best_row.vulnerable != Vulnerable.FIXED:
if best_row.urgency == 'unimportant':
state = 'unimportant'
unimportant_seen = True
@@ -207,7 +210,7 @@ def getBugsForSourcePackage(cursor, pkg):
bug = BugForSourcePackageRelease(
best_row.release, best_row.subrelease, best_row.version,
- best_row.vulnerable, state, comment, reason)
+ Vulnerable(best_row.vulnerable), state, comment, reason)
releases[best_row.release] = bug
# Compute global_state.
@@ -442,7 +445,7 @@ class DB:
cursor.execute("""CREATE TABLE source_package_status
(bug_name TEXT NOT NULL,
package INTEGER NOT NULL REFERENCES source_packages(rowid),
- vulnerable INTEGER NOT NULL,
+ vulnerable INTEGER NOT NULL CHECK (vulnerable IN (0, 1, 2)),
urgency TEXT NOT NULL,
PRIMARY KEY (bug_name, package))""")
cursor.execute(
@@ -863,7 +866,7 @@ class DB:
# stores aggregated data, and there is no efficient way to
# handle updates of the records related to a single file.
- packages = {}
+ packages = defaultdict(set)
unchanged = True
for filename in filenames:
match = re_packages.match(filename)
@@ -884,10 +887,7 @@ class DB:
% (arch, name))
key = (name, release, subrelease, archive, version,
source, source_version)
- if key in packages:
- packages[key][arch] = 1
- else:
- packages[key] = {arch : 1}
+ packages[key].add(arch)
if unchanged:
if self.verbose:
@@ -899,18 +899,12 @@ class DB:
cursor.execute("DELETE FROM binary_packages")
self._clearVersions(cursor)
- l = list(packages.keys())
-
- if len(l) == 0:
+ if len(packages) == 0:
raise ValueError("no binary packages found")
- l.sort()
def gen():
- for key in l:
- archs = list(packages[key].keys())
- archs.sort()
- archs = ','.join(archs)
- yield key + (archs,)
+ for key, archs in sorted(packages.items()):
+ yield key + (",".join(sorted(archs)),)
if self.verbose:
print(" storing binary package data")
@@ -1432,12 +1426,12 @@ class DB:
ORDER BY sp.name""",
(bug_name,)):
have_something = True
- if vulnerable == 1:
+ if vulnerable == Vulnerable.AFFECTED:
if urgency == 'unimportant':
unimportant_packages.append( package )
else:
vulnerable_packages.append(package)
- elif vulnerable == 2:
+ elif vulnerable == Vulnerable.UNDETERMINED:
undetermined_packages.append(package)
if vulnerable_packages or undetermined_packages:
@@ -1485,7 +1479,7 @@ class DB:
# here.
status = {'' : {}, 'security' : {}, 'lts' : {}}
- for (package, note, subrelease, vulnerable, urgency) in cursor.execute(
+ for (package, note, subrelease, vulnerable_int, urgency) in cursor.execute(
"""SELECT DISTINCT sp.name, n.id, sp.subrelease,
st.vulnerable, n.urgency
FROM source_package_status AS st,
@@ -1495,33 +1489,26 @@ class DB:
AND n.bug_name = st.bug_name AND n.package = sp.name
ORDER BY sp.name""",
(bug_name, nickname)):
- status[subrelease][(package, note)] = (vulnerable,urgency)
+ status[subrelease][(package, note)] = (Vulnerable(vulnerable_int), urgency)
# Check if any packages in plain testing are vulnerable, and
# if all of those have been fixed in the security archive.
fixed_in_security = True
- unfixed_pkgs = {}
- undet_pkgs = {}
- unimp_pkgs = {}
+ unfixed_pkgs = set()
+ undet_pkgs = set()
+ unimp_pkgs = set()
for ((package, note), (vulnerable, urgency)) in status[''].items():
- if vulnerable == 1:
+ if vulnerable == Vulnerable.AFFECTED:
if urgency == 'unimportant':
- unimp_pkgs[package] = True
+ unimp_pkgs.add(package)
else:
- unfixed_pkgs[package] = True
+ unfixed_pkgs.add(package)
if status['security'].get((package, note), True):
fixed_in_security = False
elif status['lts'].get((package, note), True):
fixed_in_security = False
- elif vulnerable == 2:
- undet_pkgs[package] = True
-
- unfixed_pkgs = list(unfixed_pkgs.keys())
- unfixed_pkgs.sort()
- undet_pkgs = list(undet_pkgs.keys())
- undet_pkgs.sort()
- unimp_pkgs = list(unimp_pkgs.keys())
- unimp_pkgs.sort()
+ elif vulnerable == Vulnerable.UNDETERMINED:
+ undet_pkgs.add(package)
pkgs = ""
result = "undetermined"
@@ -1533,9 +1520,9 @@ class DB:
result = "fixed"
if len(unfixed_pkgs) > 0:
if len(unfixed_pkgs) == 1:
- pkgs += "package " + unfixed_pkgs[0] + " is "
+ pkgs += "package " + next(iter(unfixed_pkgs)) + " is "
else:
- pkgs += "packages " + ", ".join(unfixed_pkgs) + " are "
+ pkgs += "packages " + ", ".join(sorted(unfixed_pkgs)) + " are "
if fixed_in_security:
pkgs = "%sfixed in %s-security. " % (pkgs, suite)
if suite == "stable":
@@ -1547,15 +1534,15 @@ class DB:
result = "vulnerable"
if len(undet_pkgs) > 0:
if len(undet_pkgs) == 1:
- pkgs += "package " + undet_pkgs[0] + " may be vulnerable but needs to be checked."
+ pkgs += "package " + next(iter(undet_pkgs)) + " may be vulnerable but needs to be checked."
else:
- pkgs += "packages " + ", ".join(undet_pkgs) + " may be vulnerable but need to be checked."
+ pkgs += "packages " + ", ".join(sorted(undet_pkgs)) + " may be vulnerable but need to be checked."
if len(unimp_pkgs) > 0 and len(undet_pkgs) == 0 and len(unfixed_pkgs) == 0:
result = "fixed"
if len(unimp_pkgs) == 1:
- pkgs = "package %s is vulnerable; however, the security impact is unimportant." % unimp_pkgs[0]
+ pkgs = "package %s is vulnerable; however, the security impact is unimportant." % next(iter(unimp_pkgs))
else:
- pkgs = "packages %s are vulnerable; however, the security impact is unimportant." % (', '.join(unimp_pkgs))
+ pkgs = "packages %s are vulnerable; however, the security impact is unimportant." % (', '.join(sorted(unimp_pkgs)))
cursor.execute("""INSERT INTO bug_status
(bug_name, release, status, reason)
@@ -1641,8 +1628,7 @@ class DB:
if fix_available_sql:
for (v,) in c.execute(fix_available_sql,
(package, release, name)):
- assert v is not None
- if not v:
+ if Vulnerable(v) == Vulnerable.FIXED:
fix_available = 'F'
break
@@ -1665,9 +1651,9 @@ class DB:
kind, urgency_to_flag[urgency], remote,
fix_available,
package, fixed_version, description))
- result = zlib.compress(''.join(result).encode('utf-8'), 9)
+ compressed = zlib.compress(''.join(result).encode('utf-8'), 9)
- self.storeExport('debsecan/release/' + release, 'application/octet-stream', result)
+ self.storeExport('debsecan/release/' + release, 'application/octet-stream', compressed)
c.execute("DROP TABLE vulnlist")
@@ -1711,7 +1697,7 @@ class DB:
'not yet assigned' : ' '}
vuln_list = []
- source_packages = {}
+ source_packages = set()
def fill_vuln_list(source_packages=source_packages):
for (bug, package) in list(c.execute(
"""SELECT DISTINCT bug_name, package
@@ -1732,7 +1718,7 @@ class DB:
unstable_fixed = ''
total_urgency = ''
- other_versions = {}
+ other_versions = set()
is_binary = False
is_unknown = False
fixed_releases = {}
@@ -1755,7 +1741,7 @@ class DB:
if kind == 'binary':
is_binary = True
elif kind == 'source':
- source_packages[package] = True
+ source_packages.add(package)
else:
is_unknown = True
@@ -1784,7 +1770,7 @@ class DB:
if v is None:
continue
if debian_support.Version(v) >= v_ref:
- other_versions[v] = True
+ other_versions.add(v)
# The second part of this SELECT statement
# covers binary-only NMUs.
@@ -1796,7 +1782,7 @@ class DB:
AND release = ?2 AND subrelease IN ('', 'security', 'lts')""",
(package, release)):
if debian_support.Version(v) >= v_ref:
- other_versions[v] = True
+ other_versions.add(v)
if not total_urgency:
total_urgency = 'unknown'
@@ -1818,9 +1804,7 @@ class DB:
elif is_unknown:
bs_flag = ' '
- other_versions = list(other_versions.keys())
- other_versions.sort()
- other_versions = ' '.join(other_versions)
+ other_versions_str = ' '.join(sorted(other_versions))
vuln_list.append(("%s,%d,%c%c%c"
% (package, bug_to_index[bug],
@@ -1828,14 +1812,12 @@ class DB:
bug_to_remote_flag[bug]),
fixed_releases.keys(),
",%s,%s"
- % (unstable_fixed, other_versions)))
+ % (unstable_fixed, other_versions_str)))
fill_vuln_list()
- source_packages = list(source_packages.keys())
- source_packages.sort()
def store_value(name, value):
- value = zlib.compress(value.encode('utf-8'), 9)
- self.storeExport('debsecan/' + name, 'application/octet-stream', value)
+ compressed = zlib.compress(value.encode('utf-8'), 9)
+ self.storeExport('debsecan/' + name, 'application/octet-stream', compressed)
def gen_release(release):
result = result_start[:]
@@ -1848,7 +1830,7 @@ class DB:
result.append(prefix + fixed + suffix)
result.append('')
- for sp in source_packages:
+ for sp in sorted(source_packages):
bp_list = []
for (bp,) in c.execute("""SELECT name FROM binary_packages
WHERE source = ? AND release = ? AND subrelease = ''
@@ -1867,7 +1849,7 @@ class DB:
gen_release(release)
result = result_start
- for (prefix, release, suffix) in vuln_list:
+ for (prefix, releases, suffix) in vuln_list:
result.append(prefix + ' ' + suffix)
result.append('')
result.append('')
@@ -1907,7 +1889,7 @@ class DB:
nodsa_reason = defaultdict(lambda: defaultdict(dict))
next_point_update = defaultdict(lambda: defaultdict(set))
supported_releases = config.get_supported_releases()
- for (pkg, issue, desc, debianbug, release, subrelease, db_version, db_fixed_version, db_status, db_urgency, db_remote, db_nodsa, db_nodsa_reason, db_next_point_update) in self.cursor().execute(
+ for (pkg, issue, desc, debianbug, release, subrelease, db_version, db_fixed_version, db_vulnerable_int, db_urgency, db_remote, db_nodsa, db_nodsa_reason, db_next_point_update) in self.cursor().execute(
"""SELECT sp.name, st.bug_name,
(SELECT cve_desc FROM nvd_data
WHERE cve_name = st.bug_name),
@@ -1937,9 +1919,10 @@ class DB:
AND sp.release IN (""" + ",".join("?" * len(supported_releases)) + """)
ORDER BY sp.name, st.bug_name, sp.release, sp.subrelease""" , supported_releases):
+ db_vulnerable = Vulnerable(db_vulnerable_int)
### to ease debugging...:
#if issue in ('CVE-2012-6656','CVE-2014-8738','CVE-2013-6673') :
- # print pkg, issue, release, subrelease, db_version, db_fixed_version, db_status
+ # print pkg, issue, release, subrelease, db_version, db_fixed_version, db_vulnerable
if pkg not in packages:
packages.append(pkg)
if issue not in issues[pkg]:
@@ -1958,7 +1941,7 @@ class DB:
repositories[pkg][issue].append(repository)
version[pkg][issue][repository] = db_version
fixed_version[pkg][issue][repository] = db_fixed_version
- status[pkg][issue][repository] = db_status
+ status[pkg][issue][repository] = db_vulnerable
urgency[pkg][issue][repository] = db_urgency
if db_next_point_update:
next_point_update[pkg][issue].add(db_next_point_update)
@@ -2006,11 +1989,10 @@ class DB:
# keep looking for a real winner...
winner=suffix
repository=release+winner
- if status[pkg][issue][repository] == 0:
- # 1 = vulnerable, 2 = undetermined
+ if status[pkg][issue][repository] == Vulnerable.FIXED:
state = "resolved"
suite_fixed_version = fixed_version[pkg][issue][repository]
- elif status[pkg][issue][repository] == 2:
+ elif status[pkg][issue][repository] == Vulnerable.UNDETERMINED:
state = "undetermined"
else:
state = "open"
@@ -2127,21 +2109,21 @@ class DB:
RELEASE-LIST, VERSION, VULNERABLE-FLAG) of source packages
which are related to the given bug."""
- releases = config.get_supported_releases()
- values = [bug] + releases
+ supported_releases = config.get_supported_releases()
+ values = [bug] + supported_releases
- for (package, releases, version, vulnerable) in cursor.execute(
+ for (package, releases, version, vulnerable_int) in cursor.execute(
"""SELECT package, string_list(release), version, vulnerable
FROM (SELECT p.name AS package,
release_name(p.release, p.subrelease, p.archive) AS release,
p.version AS version, s.vulnerable AS vulnerable
FROM source_package_status AS s, source_packages AS p
WHERE s.bug_name = ? AND p.rowid = s.package
- AND release in (""" + ",".join("?" * len(releases)) + """))
+ AND release in (""" + ",".join("?" * len(supported_releases)) + """))
GROUP BY package, version, vulnerable
ORDER BY package, releasepart_to_number(release), subreleasepart_to_number(release), version COLLATE version""",
values):
- yield package, releases.split(', '), version, vulnerable
+ yield package, releases.split(', '), version, Vulnerable(vulnerable_int)
def getBugsFromDebianBug(self, cursor, number):
"""A generator which returns a list of tuples
@@ -2284,7 +2266,7 @@ class DB:
if old_package:
yield (old_package, bugs)
- def getFakeBugs(self, cursor=None, vulnerability=0):
+ def getFakeBugs(self, cursor=None, vulnerability=Vulnerable.FIXED):
"""Returns a list of pairs (BUG-NAME, DESCRIPTION)."""
if cursor is None:
@@ -2449,7 +2431,5 @@ def test():
else:
assert False
- assert bugs.BugFromDB(cursor, 'DSA-311').isKernelOnly()
-
if __name__ == "__main__":
test()
=====================================
lib/python/web_support.py
=====================================
@@ -612,44 +612,37 @@ class WebServiceBase:
return Tag('html',
(HEAD(head_list), Tag('body', body_list, **body_attribs)))
- def pre_dispatch(self, url):
- """Invoked by handle prior to calling the registered handler."""
- pass
-
class ThreadingHTTPServer(ThreadingMixIn, HTTPServer):
daemon_threads = True
RE_BASE_URL = re.compile(r'^(https?)://([^/]+)(.*)')
-class WebServiceHTTP(WebServiceBase):
- def __init__(self, socket_name):
- WebServiceBase.__init__(self)
+
+class WebServiceHTTPAdapter:
+ def __init__(self, service: WebServiceBase, socket_name):
+ self.service = service
(base_url, address, port) = socket_name
self.lock = threading.Lock()
self.__parse_base_url(base_url)
- service_self = self
+ adapter_self = self
class Handler(BaseHTTPRequestHandler):
def do_GET(self):
(method, path, remaining, params) = self.route()
if path is None:
return
- url = URLFactory(service_self.server_name,
- service_self.script_name,
+ url = URLFactory(adapter_self.service.server_name,
+ adapter_self.service.script_name,
path, params,
- secure=service_self.secure)
+ secure=adapter_self.service.secure)
- service_self.lock.acquire()
- try:
- service_self.pre_dispatch()
+ with adapter_self.lock:
r = method(remaining, params, url)
assert isinstance(r, Result), repr(r)
result = r.flatten_later()
- finally:
- service_self.lock.release()
result(self)
do_HEAD = do_GET
@@ -665,14 +658,14 @@ class WebServiceHTTP(WebServiceBase):
def route(self):
(path, params) = self.__parse_path()
- prefix_len = len(service_self.script_name)
+ prefix_len = len(adapter_self.service.script_name)
prefix = path[0:prefix_len]
result = None
- if prefix == service_self.script_name:
+ if prefix == adapter_self.service..script_name:
suffix = path[prefix_len:]
try:
(method, remaining) = \
- service_self.router.get(suffix)
+ adapter_self.service.router.get(suffix)
return (method, suffix, remaining, params)
except InvalidPath:
pass
@@ -688,9 +681,9 @@ class WebServiceHTTP(WebServiceBase):
m = RE_BASE_URL.match(url)
if m is None:
raise ValueError("invalid base URL: " + url)
- self.secure = m.group(1) == "https"
- self.server_name = m.group(2)
- self.script_name = m.group(3)
+ self.service.secure = m.group(1) == "https"
+ self.service.server_name = m.group(2)
+ self.service.script_name = m.group(3)
def __test():
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9bb84e70d260a8eb4389e6171d1ace98334b64f4...95cc0471bcf2cc6494f333f2f4998ede09ccf5b5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9bb84e70d260a8eb4389e6171d1ace98334b64f4...95cc0471bcf2cc6494f333f2f4998ede09ccf5b5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260807/b0f7e16c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list