[Git][security-tracker-team/security-tracker][master] 2 commits: Reserve DLA-4732-1 for php8.2

Guilhem Moulin (@guilhem) guilhem at debian.org
Tue Aug 11 22:50:35 BST 2026



Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4af3af7c by Guilhem Moulin at 2026-08-11T23:50:03+02:00
Reserve DLA-4732-1 for php8.2

- - - - -
df52eb40 by Guilhem Moulin at 2026-08-11T23:50:05+02:00
Reserve DLA-4733-1 for php7.4

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -10523,7 +10523,9 @@ CVE-2026-9672
 	- php8.4 8.4.24-1 (unimportant)
 	[trixie] - php8.4 8.4.24-1~deb13u1
 	- php8.2 <removed> (unimportant)
+	[bookworm] - php8.2 8.2.33-1~deb12u1
 	- php7.4 <removed> (unimportant)
+	[bullseye] - php7.4 7.4.33-1+deb11u12
 	NOTE: Fixed by: https://github.com/php/php-src/commit/b590f0380fda26ed180874a0255f0be078434315 (php-8.4.24)
 CVE-2026-17544 (Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...)
 	{DSA-6406-1}


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,9 @@
+[11 Aug 2026] DLA-4733-1 php7.4 - security update
+	{CVE-2026-7260 CVE-2026-17543}
+	[bullseye] - php7.4 7.4.33-1+deb11u12
+[11 Aug 2026] DLA-4732-1 php8.2 - security update
+	{CVE-2026-7260 CVE-2026-17543}
+	[bookworm] - php8.2 8.2.33-1~deb12u1
 [11 Aug 2026] DLA-4731-1 libgd2 - security update
 	{CVE-2026-9672}
 	[bullseye] - libgd2 2.3.0-2+deb11u2


=====================================
data/dla-needed.txt
=====================================
@@ -640,13 +640,6 @@ php-twig/bullseye
   NOTE: 20260521: Added by Front-Desk (Beuc)
   NOTE: 20260521: Cf. symfony batch of CVEs, upcoming DSA (Beuc/front-desk)
 --
-php7.4/bullseye (guilhem)
-  NOTE: 20260804: Added by Front-Desk (rouca)
-  NOTE: 20260804: Follow DSA-6406-1 (rouca/front-desk)
---
-php8.2/bookworm (guilhem)
-  NOTE: 20260804: Added by Front-Desk (rouca)
---
 phpseclib/bullseye (Utkarsh)
   NOTE: 20260518: Added by Front-Desk (Beuc)
   NOTE: 20260518: Follow bookworm 12.14 (2 CVEs) (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/502211c70a775711b44ab9c85efd1de658f940ec...df52eb40821f03aee57b026b1b2aba8fc097df41

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/502211c70a775711b44ab9c85efd1de658f940ec...df52eb40821f03aee57b026b1b2aba8fc097df41
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/2e1a8d91/attachment.htm>


More information about the debian-security-tracker-commits mailing list