[Git][security-tracker-team/security-tracker][master] flatpak, lemonldap, xdg-dbus-proxy DSAs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 12 19:11:50 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8c629553 by Moritz Mühlenhoff at 2026-08-12T20:11:21+02:00
flatpak, lemonldap, xdg-dbus-proxy DSAs

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2264,6 +2264,7 @@ CVE-2026-71193
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
 CVE-2026-XXXX [GHSA-8688-9x26-hhxj]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/478072972056d2d15c768c246f80abdf83cf0e5e (1.18.1)
 	NOTE: Additional tests: https://github.com/flatpak/flatpak/commit/9d26ea5f1e7c8fb43225668a96289d15c62ad6cd (1.18.1)
@@ -2276,6 +2277,7 @@ CVE-2026-XXXX [GHSA-8688-9x26-hhxj]
 	NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
 CVE-2026-XXXX [GHSA-qrwq-7qwx-q9rp]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/a3583bc87d4f86c2794ff879ea56fce95b0b0b5f (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/b00c7b5073a25bdc34653642de543b5ef6fe0225 (1.18.1)
@@ -2287,6 +2289,7 @@ CVE-2026-XXXX [GHSA-qrwq-7qwx-q9rp]
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/769ad563bae82b948496a7edffa5eb3f71d0cc72 (branch flatpak-1.16.x)
 CVE-2026-XXXX [GHSA-fqx6-vh4p-42cg]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/12a30ecb422b1e1246cb2d9af60c14ef7b8f22a4 (1.18.1)
@@ -2302,6 +2305,7 @@ CVE-2026-XXXX [GHSA-fqx6-vh4p-42cg]
 	NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
 CVE-2026-XXXX [GHSA-8qxj-x646-phcm]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/12a30ecb422b1e1246cb2d9af60c14ef7b8f22a4 (1.18.1)
@@ -2320,6 +2324,7 @@ CVE-2026-XXXX [GHSA-9rww-v4mm-x4jg]
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/e6fa2f9b416ec382644694c8737dc8fbe7f07b89 (1.18.1)
 CVE-2026-XXXX [GHSA-v2gw-v9h5-9q4x]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/19456b916842b079af833a86b9ab89c5db154b92 (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/01773f84021dd090b2426f79675f94f2564f9279 (1.18.1)
@@ -2330,6 +2335,7 @@ CVE-2026-XXXX [GHSA-v2gw-v9h5-9q4x]
 	NOTE: Test workaround for old meson: https://github.com/flatpak/flatpak/pull/6768
 CVE-2026-XXXX [GHSA-jr92-2v97-wgvc]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/892d261255449d0cd5d97f6a8f2a731e566ff913 (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/c52e851f3f5036b132321c19b3c0102aabda9a3a (1.18.1)
@@ -2339,6 +2345,7 @@ CVE-2026-XXXX [GHSA-jr92-2v97-wgvc]
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/a79764d78b29aa592b612061071b2c361bda4f9e (branch flatpak-1.16.x)
 CVE-2026-XXXX [GHSA-99wv-m8rp-g58x]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/e13dfeda330625d2fecc3a54672dfd4dc9c83a5c (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/f6c8fb5fdb3737e2f45068afe12c4bf1d808fd55 (1.18.1)
@@ -2350,6 +2357,7 @@ CVE-2026-XXXX [GHSA-99wv-m8rp-g58x]
 	NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
 CVE-2026-XXXX [GHSA-w69g-9x8j-7p8f]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-w69g-9x8j-7p8f
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/6ec728c15b4eff47b7d69a2cc22e4aef52011585 (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/ad044fc728cffe22dfa78e14c351bfe907f5164f (1.18.1)
@@ -2359,6 +2367,7 @@ CVE-2026-XXXX [GHSA-w69g-9x8j-7p8f]
 	NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
 CVE-2026-XXXX [GHSA-q4gr-vc25-57m5]
 	- flatpak 1.18.1-1 (bug #1144130)
+	[trixie] - flatpak 1.16.6-1~deb13u2
 	NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/d5939b0f1751df7dede31a1ee7fb5b8dfe49fd79 (1.18.1)
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/9b990351898b18b48bf4e834bcbc618d270cf8b1 (1.18.1)
@@ -2366,6 +2375,7 @@ CVE-2026-XXXX [GHSA-q4gr-vc25-57m5]
 	NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/b0f1704b34d2a551c0073a9fc5e918174a97af64 (branch flatpak-1.16.x)
 CVE-2026-XXXX [GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses path/interface/member checks]
 	- xdg-dbus-proxy 0.1.8-1 (bug #1144129)
+	[trixie] - xdg-dbus-proxy 0.1.6-1+deb13u2
 	[bookworm] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
 	[bullseye] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c
@@ -47187,7 +47197,6 @@ CVE-2026-56229 (Capgo before 12.128.2 contains an authorization bypass vulnerabi
 	NOT-FOR-US: Cap-go
 CVE-2026-12804 (A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is ...)
 	- lemonldap-ng 2.23.1+ds-1
-	[trixie] - lemonldap-ng <no-dsa> (Minor issue)
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3619
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/979
 	NOTE: Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/478bed8e58f0457235e0916e3f73a85a2f19471f (v2.23.1)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,10 @@
+[12 Aug 2026] DSA-6434-1 lemonldap-ng - security update
+	{CVE-2026-12804 CVE-2026-19349}
+	[trixie] - lemonldap-ng 2.21.2+ds-1+deb13u3
+[12 Aug 2026] DSA-6433-1 xdg-dbus-proxy - security update
+	[trixie] - xdg-dbus-proxy 0.1.6-1+deb13u2
+[12 Aug 2026] DSA-6432-1 flatpak - security update
+	[trixie] - flatpak 1.16.6-1~deb13u2
 [11 Aug 2026] DSA-6431-1 openjdk-25 - security update
 	{CVE-2026-41254 CVE-2026-46917 CVE-2026-46968 CVE-2026-47010 CVE-2026-47021 CVE-2026-47027 CVE-2026-47059 CVE-2026-47063 CVE-2026-60147}
 	[trixie] - openjdk-25 25.0.4+7-1~deb13u1


=====================================
data/dsa-needed.txt
=====================================
@@ -49,9 +49,6 @@ firebird3.0
 --
 firebird4.0
 --
-flatpak (jmm)
-  Maintainer preparing updates
---
 gimp
 --
 gst-plugins-bad1.0
@@ -76,9 +73,6 @@ libde265
 librabbitmq
   Florian Ernst is preparing updates
 --
-lemonldap-ng
-  Maintainer prepared an update, debdiff for review and ack
---
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more 6.12.y versions
@@ -180,9 +174,6 @@ vips
 --
 weechat
 --
-xdg-dbus-proxy (jmm)
-  Maintainer preparing updates
---
 xorg-server
 --
 xrdp



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8c629553b67b042aaa5b45bd684a4555419ab06c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8c629553b67b042aaa5b45bd684a4555419ab06c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/8921170e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list