[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Aug 8 13:06:02 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5a103ba4 by Moritz Muehlenhoff at 2026-08-08T13:58:50+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -20,7 +20,9 @@ CVE-2026-66060 (Home Assistant is open source home automation software focused o
NOT-FOR-US: Home Assistant
CVE-2026-65819 (gopacket provides packet processing capabilities for Go. Through versi ...)
- golang-github-gopacket-gopacket <unfixed>
+ [trixie] - golang-github-gopacket-gopacket <no-dsa> (Minor issue)
- gopacket <unfixed>
+ [trixie] - gopacket <no-dsa> (Minor issue)
NOTE: https://github.com/gopacket/gopacket/security/advisories/GHSA-8mcr-459q-5mx2
NOTE: Fixed by: https://github.com/gopacket/gopacket/commit/210f25fb9b3ca1af2eb649936f78ad6991b6c9c5
CVE-2026-64676 (Kata Containers is an open source implementation of lightweight Virtua ...)
@@ -558,18 +560,21 @@ CVE-2026-70631 (FFmpeg versions from 0.5 up to, but not including, 9.0 contain a
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/3c287af3affe1286350faa69c02bcc5d49de18bb (n9.0)
CVE-2026-70630 (FFmpeg versions from 3.0 up to, but not including, 9.0 contain an unin ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23896
NOTE: Introduced with: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9a3202a98b2e095b54dd784c3e01a09a676fc3fa (n3.0)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/705890061467ad550ecc1dad5eea07f28ccfb43e (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c22667d0fd7916a33fd3e79685b7246fc48f1a62 (n9.0)
CVE-2026-70629 (FFmpeg versions from 3.0 up to, but not including, 9.0 contain an unin ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23895
NOTE: Introduced with: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/533a6198505edd1379e1cd722852350ae4a85acc (n3.0)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/cd1f545cf27ba08f6f5b31b1e92665d7874d4fd7 (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a5fe21a1a410a680fe93c33b0dd696b7e1c3aea4 (n9.0)
CVE-2026-70628 (FFmpeg versions from 0.5 up to, but not including, 9.0 contain a signe ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23897
NOTE: Introduced with: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c6ec28b18cd1eb7d39e6163137367f2d1c62aa7c (v0.5)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/93f2a525ec6c7b467bae68322720d10188fc6e30 (master)
@@ -1093,9 +1098,11 @@ CVE-2026-19177 (Insufficient validation of untrusted input in UI in Google Chrom
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-61478
- libvirt 12.6.0-1
+ [trixie] - libvirt <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/68da70aae766c6271b8d3b466374d3cc7d1a8afb (v12.6.0-rc1)
CVE-2026-61477 (An injection vulnerability was found in libvirt's virtual network driv ...)
- libvirt 12.6.0-1
+ [trixie] - libvirt <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/d44836a1dc6771ac22f69755fc69bf730f0eec87 (v12.6.0-rc1)
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/289ffa796d737a79a4c05d07232ebd75def9a12a (v12.6.0-rc1)
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/cb8974b923e3c40cde96f0c7bceaa638f7f9c72b (v12.6.0-rc1)
@@ -1831,6 +1838,7 @@ CVE-2026-18909 (A stack-based buffer overflow vulnerability exists in ELAN Micro
NOT-FOR-US: ELAN Microelectronics Corp. ELAN Smart-Pad on Windows
CVE-2026-18839 (An integer underflow was found in the popt library when formatting hel ...)
- popt <unfixed>
+ [trixie] - popt <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511010
CVE-2026-18510 (The TranslatePress \u2013 Translate Multilingual sites with AI Transla ...)
NOT-FOR-US: WordPress plugin
@@ -5810,6 +5818,7 @@ CVE-2026-65975 (Pydantic AI is a Python agent framework for building application
NOT-FOR-US: Pydantic AI
CVE-2026-64685 (ImageMagick is free and open-source software used for editing and mani ...)
- imagemagick 8:7.1.2.27+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
[bookworm] - imagemagick <postponed> (minor issue)
[bullseye] - imagemagick <postponed> (minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7rgw-xg25-prjm
@@ -5823,6 +5832,7 @@ CVE-2026-63118 (MCP Ruby SDK is the official Ruby SDK for Model Context Protocol
NOT-FOR-US: MCP Ruby SDK
CVE-2026-62946 (ImageMagick is free and open-source software used for editing and mani ...)
- imagemagick 8:7.1.2.27+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
[bookworm] - imagemagick <postponed> (minor issue)
[bullseye] - imagemagick <postponed> (minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h22j-f9xw-xjjm
@@ -5830,6 +5840,7 @@ CVE-2026-62946 (ImageMagick is free and open-source software used for editing an
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/8018a5c3214ca9bf11a86c2816833dee920b1340 (6.9.13-52)
CVE-2026-62363 (ImageMagick is free and open-source software used for editing and mani ...)
- imagemagick 8:7.1.2.27+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
[bookworm] - imagemagick <postponed> (minor issue)
[bullseye] - imagemagick <postponed> (minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-422r-8c97-xcg4
@@ -5837,6 +5848,7 @@ CVE-2026-62363 (ImageMagick is free and open-source software used for editing an
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/0bbf7e48f5dd0ef540d3ae1ae8dfc6cd036fb640 (7.1.2-27)
CVE-2026-62343 (ImageMagick is free and open-source software used for editing and mani ...)
- imagemagick 8:7.1.2.26+dfsg1-1
+ [trixie] - imagemagick <no-dsa> (Minor issue)
[bookworm] - imagemagick <postponed> (minor issue)
[bullseye] - imagemagick <postponed> (minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-f5m7-cqgw-8hm7
@@ -8298,6 +8310,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
NOTE: https://github.com/python/cpython/issues/152674
NOTE: https://github.com/python/cpython/pull/152676
NOTE: https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0 (main)
+ NOTE: https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db (v3.13.15)
CVE-2026-67185 (TinyWeb through 0.0.8 contains a path traversal vulnerability that all ...)
NOT-FOR-US: TinyWeb
CVE-2026-67184 (TinyWeb through 0.0.8 contains a null pointer dereference vulnerabilit ...)
@@ -8454,9 +8467,11 @@ CVE-2026-54345 (gopacket provides packet processing capabilities for Go. In vers
NOTE: Fixed by: https://github.com/gopacket/gopacket/commit/145859d0eaee1a6f5925ffb93851c976449c3311 (v1.6.1)
CVE-2026-54332 (gopacket provides packet processing capabilities for Go. In version 1. ...)
- golang-github-gopacket-gopacket <unfixed> (bug #1143056)
+ [trixie] - golang-github-gopacket-gopacket <no-dsa> (Minor issue)
[bookworm] - golang-github-gopacket-gopacket <postponed> (minor issue; DoS; limited go language support)
[bullseye] - golang-github-gopacket-gopacket <postponed> (minor issue; DoS; limited go language support)
- gopacket <unfixed> (bug #1143055)
+ [trixie] - gopacket <no-dsa> (Minor issue)
[bookworm] - gopacket <postponed> (minor issue; DoS; limited go language support)
[bullseye] - gopacket <postponed> (minor issue; DoS; limited go language support)
NOTE: https://github.com/gopacket/gopacket/security/advisories/GHSA-g6v3-7xmc-w563
@@ -8592,8 +8607,10 @@ CVE-2026-18028 (The "quick setup" view presented to users after they first creat
NOT-FOR-US: rami.io products
CVE-2026-17072 (A flaw was found in GStreamer's gst-plugins-good. A heap-based out-of- ...)
- gst-plugins-good1.0 <unfixed>
+ [trixie] - gst-plugins-good1.0 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506750
- TODO: check ater information published on upstream, should become https://gstreamer.freedesktop.org/security/sa-2026-0073.html
+ NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a75bd8187bb716cf543ea2c545002fa38b31e3c7
+ NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0073.html
CVE-2026-16774 (The Chatbot plugin for WordPress is vulnerable to Missing Authorizatio ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16773 (The WPBot \u2013 AI ChatBot for Live Support, Lead Generation, AI Serv ...)
@@ -11499,18 +11516,25 @@ CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in th
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/532
CVE-2026-66041 (FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
+ [bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
+ [bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23625
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4da9812e25894fb51d62a8875cfa8eb39b5e20f5
+ NOTE: Introduced with https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/030e1401451200566a5303f35cbe1456e31dd81e (n7.0)
CVE-2026-66040 (FFmpeg through 8.1.2, fixed in commit b506faf, contains a heap out-of- ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23786
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b506fafec9a19fcbc2be5271875fd4a63d6615bc
CVE-2026-66039 (FFmpeg through 8.1.2, fixed in commit aafb5c6, contains a signed integ ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23631
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/aafb5c655edc76a753275c383ebb139feb032718
CVE-2026-66038 (FFmpeg through 8.1.2, fixed in commit 8670835, contains an information ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23626
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c
CVE-2026-66037 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolle ...)
@@ -12264,6 +12288,7 @@ CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious boot
NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
CVE-2026-58264 [heap-based buffer overrun in command handler]
- fluidsynth 2.5.6+dfsg-1
+ [trixie] - fluidsynth <no-dsa> (Minor issue)
[bookworm] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
[bullseye] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-mqmq-w63q-cj94
@@ -12272,6 +12297,7 @@ CVE-2026-58264 [heap-based buffer overrun in command handler]
NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/762a3bd39a431cd45abf3bbcce7286c87909d087 (v2.5.6)
CVE-2026-61714 [heap-based buffer overflow in MIDI player]
- fluidsynth 2.5.6+dfsg-1
+ [trixie] - fluidsynth <no-dsa> (Minor issue)
[bookworm] - fluidsynth <postponed> (Needs a non-default synth.midi-channels > 16; MIDI file channels are masked to 4 bits so a crafted file cannot reach it)
[bullseye] - fluidsynth <not-affected> (Vulnerable code not present)
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6
@@ -20444,17 +20470,20 @@ CVE-2026-50197 (Skipper is an HTTP router and reverse proxy for service composit
NOT-FOR-US: Zalando Skipper
CVE-2026-50163 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, en ...)
- golang-oras-oras-go 2.6.2-1 (bug #1142456)
+ [trixie] - golang-oras-oras-go <no-dsa> (Minor issue)
[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, content/utils.go os.Link()s the unresolved Linkname)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp
NOTE: https://github.com/oras-project/oras-go/pull/1232
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/c463c654ab3ef34422c1764cd619806cebf20451 (v2.6.2)
CVE-2026-50162 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...)
- golang-oras-oras-go 2.6.2-1 (bug #1142456)
+ [trixie] - golang-oras-oras-go <no-dsa> (Minor issue)
[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, content/file.go resolveWritePath() lacks symlink resolution)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5 (v2.6.1)
CVE-2026-50151 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...)
- golang-oras-oras-go 2.6.2-1 (bug #1142456)
+ [trixie] - golang-oras-oras-go <no-dsa> (Minor issue)
[bookworm] - golang-oras-oras-go <not-affected> (Blob upload path not present in v1.1.1; no blobStore and the Location header is never read)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7
NOTE: https://github.com/oras-project/oras-go/pull/1152
@@ -20483,6 +20512,7 @@ CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information disc
NOTE: https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...)
- golang-oras-oras-go 2.6.2-1 (bug #1142456)
+ [trixie] - golang-oras-oras-go <no-dsa> (Minor issue)
[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, auth/client.go follows an unvalidated WWW-Authenticate realm)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/7a9f4b0b9558821b0422152ebe21ae56930fe764 (v2.6.1)
@@ -20811,6 +20841,7 @@ CVE-2026-13410 (Dancer::Plugin::Auth::Google versions through 0.07 for Perl have
NOT-FOR-US: Dancer::Plugin::Auth::Google Perl module
CVE-2026-13082 (GD::SecurityImage versions through 1.75 for Perl use rand to generate ...)
- libgd-securityimage-perl <unfixed> (bug #1142330)
+ [trixie] - libgd-securityimage-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41903267/
NOTE: https://security.metacpan.org/patches/G/GD-SecurityImage/1.75/CVE-2026-13082-r1.patch
CVE-2026-12715 (Missing Authorization in Google Cloud Firebase Studio versions prior t ...)
@@ -23029,6 +23060,7 @@ CVE-2026-51807 (Heap-based out-of-bounds write in j2k_precinct_subband::parse_pa
NOT-FOR-US: OpenHTJ2K
CVE-2026-51105 (Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3 allows a ...)
- amule <unfixed> (bug #1142276)
+ [trixie] - amule <no-dsa> (Minor issue)
[bookworm] - amule <postponed> (minor issue; DoS)
[bullseye] - amule <postponed> (minor issue; DoS)
NOTE: https://github.com/amule-project/amule/issues/445
@@ -24127,29 +24159,36 @@ CVE-2026-15715 (A vulnerability was identified in SourceCodester Class and Exam
NOT-FOR-US: SourceCodester
CVE-2026-15714 (An out-of-bounds read vulnerability was found in libsoup's multipart p ...)
- libsoup3 <unfixed> (bug #1142843)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499942
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/542
CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implementation. ...)
- libsoup3 <unfixed> (bug #1142842)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499941
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/541
CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in libsoup's (ver ...)
- libsoup3 <unfixed> (bug #1142841)
- - libsoup2.4 <removed>
- [bookworm] - libsoup2.4 <not-affected> (HTTP/2 support is libsoup3-only, libsoup 2.x has no HTTP/2 implementation)
- [bullseye] - libsoup2.4 <not-affected> (HTTP/2 support is libsoup3-only, libsoup 2.x has no HTTP/2 implementation)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
+ - libsoup2.4 <not-affected> (HTTP/2 support is libsoup3-only, libsoup 2.x has no HTTP/2 implementation)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499939
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540
CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing impleme ...)
- libsoup3 <unfixed> (bug #1142840)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499924
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/515
CVE-2026-15709 (A flaw was found in libsoup's WebSocket implementation when using the ...)
- libsoup3 <unfixed> (bug #1142839)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499922
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/511
CVE-2026-15703 (A vulnerability was detected in SourceCodester Simple and Nice Shoppin ...)
@@ -40054,7 +40093,7 @@ CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/
NOTE: https://github.com/python/cpython/issues/151981
NOTE: https://github.com/python/cpython/commit/e86666c9dd256d52d0fbef6feb1ea4a51768fdec (3.14)
- NOTE: https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9 (3.13)
+ NOTE: https://github.com/python/cpython/commit/3f031d431f80668e14f3bc066bbf4369cd9281b9 (v3.13.15)
CVE-2026-11820 (A flaw was found in the community.general Ansible collection's nexmo m ...)
NOT-FOR-US: Red Hat
CVE-2026-11819 (Module: plugins/modules/keyring_info.py CVSS 3.1: 5.5 MEDIUM \u2014 ...)
@@ -40695,7 +40734,7 @@ CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar' filter could be b
NOTE: https://github.com/python/cpython/pull/151559
NOTE: https://github.com/python/cpython/commit/672825e2f36a57e173959b0d9d409d4560dab8df (3.15 branch)
NOTE: https://github.com/python/cpython/commit/79c06bd5c6afa3c440d50faf7ee1b147c8832b4c (3.14 branch)
- NOTE: https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde (3.13 branch)
+ NOTE: https://github.com/python/cpython/commit/771d12dda5140313db0ac550292987975651bbde (v3.13.15)
CVE-2026-55556
- rsyslog 8.2604.0-1 (unimportant)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/23/4
@@ -69520,6 +69559,7 @@ CVE-2026-7210 (`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient
NOTE: https://github.com/python/cpython/commit/24b8f12544468e4cedf5bfbe25442fcd495391e4 (main)
NOTE: https://github.com/python/cpython/pull/149645 (3.15)
NOTE: https://github.com/python/cpython/pull/149646 (3.14)
+ NOTE: https://github.com/python/cpython/commit/fc9b11ff49cbc82e6f917d07a61517a2b5f3145f (v3.13.14)
NOTE: Fully mitigating this vulnerability requires fixing both libexpat
NOTE: (CVE-2026-41080) and applying the python patch for CVE-2026-7210.
CVE-2026-6956 (ATutor is vulnerable to Reflected XSS in/install/install.php endpoint. ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -154,6 +154,8 @@ vim
some of the issues seem worth fixing
Lee Garrett is interested in contributing an update for stable
--
+vips
+--
wordpress (carnil)
Maintainer prepared update, asked for review
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5a103ba43f4bf3cf9037d384a273fdcee99e699f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5a103ba43f4bf3cf9037d384a273fdcee99e699f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/3f3c4644/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list