[Git][security-tracker-team/security-tracker][master] DSA for icinga2

Aron Xu (@aron) aron at debian.org
Mon Aug 10 18:01:23 BST 2026



Aron Xu pushed to branch master at Debian Security Tracker / security-tracker


Commits:
992af914 by Aron Xu at 2026-08-10T19:44:21+08:00
DSA for icinga2

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -163313,7 +163313,6 @@ CVE-2025-61922 (PrestaShop Checkout is the PrestaShop official payment module in
 	NOT-FOR-US: PrestaShop
 CVE-2025-61909 (Icinga 2 is an open source monitoring system. From 2.10.0 to before 2. ...)
 	- icinga2 2.15.1-1
-	[trixie] - icinga2 <no-dsa> (Minor issue)
 	[bookworm] - icinga2 <no-dsa> (Minor issue)
 	[bullseye] - icinga2 <postponed> (Minor issue, requires a compromised icinga/nagios system user)
 	NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-pg6g-g99v-mw46
@@ -163322,7 +163321,6 @@ CVE-2025-61909 (Icinga 2 is an open source monitoring system. From 2.10.0 to bef
 	NOTE: https://icinga.com/blog/releasing-icinga-2-v2-15-1-2-14-7-and-2-13-13-and-icinga-db-web-v1-2-3-and-1-1-4/
 CVE-2025-61908 (Icinga 2 is an open source monitoring system. From 2.10.0 to before 2. ...)
 	- icinga2 2.15.1-1
-	[trixie] - icinga2 <no-dsa> (Minor issue)
 	[bookworm] - icinga2 <no-dsa> (Minor issue)
 	[bullseye] - icinga2 <postponed> (Minor issue, only exploitable by already authenticated users)
 	NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-v9jg-xqhj-f43g
@@ -163332,7 +163330,6 @@ CVE-2025-61908 (Icinga 2 is an open source monitoring system. From 2.10.0 to bef
 	NOTE: https://icinga.com/blog/releasing-icinga-2-v2-15-1-2-14-7-and-2-13-13-and-icinga-db-web-v1-2-3-and-1-1-4/
 CVE-2025-61907 (Icinga 2 is an open source monitoring system. In Icinga 2 versions 2.4 ...)
 	- icinga2 2.15.1-1
-	[trixie] - icinga2 <no-dsa> (Minor issue)
 	[bookworm] - icinga2 <no-dsa> (Minor issue)
 	[bullseye] - icinga2 <postponed> (Minor issue, only exploitable by already authenticated users)
 	NOTE: https://github.com/Icinga/icinga2/security/advisories/GHSA-gg32-w9rm-vp2v


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[10 Aug 2026] DSA-6426-1 icinga2 - security update
+	{CVE-2025-61907 CVE-2025-61908 CVE-2025-61909}
+	[trixie] - icinga2 2.14.6-1+deb13u1
 [10 Aug 2026] DSA-6425-1 openjdk-21 - security update
 	{CVE-2026-41254 CVE-2026-46917 CVE-2026-46968 CVE-2026-47010 CVE-2026-47021 CVE-2026-47027 CVE-2026-47059 CVE-2026-47063 CVE-2026-60147}
 	[trixie] - openjdk-21 21.0.12+8-1~deb13u1


=====================================
data/dsa-needed.txt
=====================================
@@ -49,9 +49,6 @@ firebird4.0
 --
 gimp
 --
-icinga2 (aron)
-  Maintainers proposed an update, needs review
---
 jackson-databind
 --
 jetty9



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/992af914a791c6fc0a8e1e592151c9aed9f322a4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/992af914a791c6fc0a8e1e592151c9aed9f322a4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/5abc1eb9/attachment.htm>


More information about the debian-security-tracker-commits mailing list