[Git][security-tracker-team/security-tracker][master] flatpak, lemonldap, xdg-dbus-proxy DSAs
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 12 19:11:50 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8c629553 by Moritz Mühlenhoff at 2026-08-12T20:11:21+02:00
flatpak, lemonldap, xdg-dbus-proxy DSAs
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -2264,6 +2264,7 @@ CVE-2026-71193
NOTE: https://security.openstack.org/ossa/OSSA-2026-034.html
CVE-2026-XXXX [GHSA-8688-9x26-hhxj]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-8688-9x26-hhxj
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/478072972056d2d15c768c246f80abdf83cf0e5e (1.18.1)
NOTE: Additional tests: https://github.com/flatpak/flatpak/commit/9d26ea5f1e7c8fb43225668a96289d15c62ad6cd (1.18.1)
@@ -2276,6 +2277,7 @@ CVE-2026-XXXX [GHSA-8688-9x26-hhxj]
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
CVE-2026-XXXX [GHSA-qrwq-7qwx-q9rp]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-qrwq-7qwx-q9rp
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/a3583bc87d4f86c2794ff879ea56fce95b0b0b5f (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/b00c7b5073a25bdc34653642de543b5ef6fe0225 (1.18.1)
@@ -2287,6 +2289,7 @@ CVE-2026-XXXX [GHSA-qrwq-7qwx-q9rp]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/769ad563bae82b948496a7edffa5eb3f71d0cc72 (branch flatpak-1.16.x)
CVE-2026-XXXX [GHSA-fqx6-vh4p-42cg]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-fqx6-vh4p-42cg
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/12a30ecb422b1e1246cb2d9af60c14ef7b8f22a4 (1.18.1)
@@ -2302,6 +2305,7 @@ CVE-2026-XXXX [GHSA-fqx6-vh4p-42cg]
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
CVE-2026-XXXX [GHSA-8qxj-x646-phcm]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-8qxj-x646-phcm
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/c42326c74d63e550d874312be0c7a800cf5fc39f (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/12a30ecb422b1e1246cb2d9af60c14ef7b8f22a4 (1.18.1)
@@ -2320,6 +2324,7 @@ CVE-2026-XXXX [GHSA-9rww-v4mm-x4jg]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/e6fa2f9b416ec382644694c8737dc8fbe7f07b89 (1.18.1)
CVE-2026-XXXX [GHSA-v2gw-v9h5-9q4x]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-v2gw-v9h5-9q4x
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/19456b916842b079af833a86b9ab89c5db154b92 (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/01773f84021dd090b2426f79675f94f2564f9279 (1.18.1)
@@ -2330,6 +2335,7 @@ CVE-2026-XXXX [GHSA-v2gw-v9h5-9q4x]
NOTE: Test workaround for old meson: https://github.com/flatpak/flatpak/pull/6768
CVE-2026-XXXX [GHSA-jr92-2v97-wgvc]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-jr92-2v97-wgvc
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/892d261255449d0cd5d97f6a8f2a731e566ff913 (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/c52e851f3f5036b132321c19b3c0102aabda9a3a (1.18.1)
@@ -2339,6 +2345,7 @@ CVE-2026-XXXX [GHSA-jr92-2v97-wgvc]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/a79764d78b29aa592b612061071b2c361bda4f9e (branch flatpak-1.16.x)
CVE-2026-XXXX [GHSA-99wv-m8rp-g58x]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-99wv-m8rp-g58x
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/e13dfeda330625d2fecc3a54672dfd4dc9c83a5c (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/f6c8fb5fdb3737e2f45068afe12c4bf1d808fd55 (1.18.1)
@@ -2350,6 +2357,7 @@ CVE-2026-XXXX [GHSA-99wv-m8rp-g58x]
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
CVE-2026-XXXX [GHSA-w69g-9x8j-7p8f]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-w69g-9x8j-7p8f
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/6ec728c15b4eff47b7d69a2cc22e4aef52011585 (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/ad044fc728cffe22dfa78e14c351bfe907f5164f (1.18.1)
@@ -2359,6 +2367,7 @@ CVE-2026-XXXX [GHSA-w69g-9x8j-7p8f]
NOTE: Additional requirement: https://github.com/flatpak/flatpak/commit/68c12b9695eee4a94d896f0cf2f388f0d3c63df1 (branch flatpak-1.16.x)
CVE-2026-XXXX [GHSA-q4gr-vc25-57m5]
- flatpak 1.18.1-1 (bug #1144130)
+ [trixie] - flatpak 1.16.6-1~deb13u2
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/d5939b0f1751df7dede31a1ee7fb5b8dfe49fd79 (1.18.1)
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/9b990351898b18b48bf4e834bcbc618d270cf8b1 (1.18.1)
@@ -2366,6 +2375,7 @@ CVE-2026-XXXX [GHSA-q4gr-vc25-57m5]
NOTE: Fixed by: https://github.com/flatpak/flatpak/commit/b0f1704b34d2a551c0073a9fc5e918174a97af64 (branch flatpak-1.16.x)
CVE-2026-XXXX [GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses path/interface/member checks]
- xdg-dbus-proxy 0.1.8-1 (bug #1144129)
+ [trixie] - xdg-dbus-proxy 0.1.6-1+deb13u2
[bookworm] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
[bullseye] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
NOTE: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c
@@ -47187,7 +47197,6 @@ CVE-2026-56229 (Capgo before 12.128.2 contains an authorization bypass vulnerabi
NOT-FOR-US: Cap-go
CVE-2026-12804 (A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is ...)
- lemonldap-ng 2.23.1+ds-1
- [trixie] - lemonldap-ng <no-dsa> (Minor issue)
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3619
NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/979
NOTE: Fixed by: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/commit/478bed8e58f0457235e0916e3f73a85a2f19471f (v2.23.1)
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,10 @@
+[12 Aug 2026] DSA-6434-1 lemonldap-ng - security update
+ {CVE-2026-12804 CVE-2026-19349}
+ [trixie] - lemonldap-ng 2.21.2+ds-1+deb13u3
+[12 Aug 2026] DSA-6433-1 xdg-dbus-proxy - security update
+ [trixie] - xdg-dbus-proxy 0.1.6-1+deb13u2
+[12 Aug 2026] DSA-6432-1 flatpak - security update
+ [trixie] - flatpak 1.16.6-1~deb13u2
[11 Aug 2026] DSA-6431-1 openjdk-25 - security update
{CVE-2026-41254 CVE-2026-46917 CVE-2026-46968 CVE-2026-47010 CVE-2026-47021 CVE-2026-47027 CVE-2026-47059 CVE-2026-47063 CVE-2026-60147}
[trixie] - openjdk-25 25.0.4+7-1~deb13u1
=====================================
data/dsa-needed.txt
=====================================
@@ -49,9 +49,6 @@ firebird3.0
--
firebird4.0
--
-flatpak (jmm)
- Maintainer preparing updates
---
gimp
--
gst-plugins-bad1.0
@@ -76,9 +73,6 @@ libde265
librabbitmq
Florian Ernst is preparing updates
--
-lemonldap-ng
- Maintainer prepared an update, debdiff for review and ack
---
linux (carnil)
Wait until more issues have piled up, though try to regulary rebase for point
releases to more 6.12.y versions
@@ -180,9 +174,6 @@ vips
--
weechat
--
-xdg-dbus-proxy (jmm)
- Maintainer preparing updates
---
xorg-server
--
xrdp
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8c629553b67b042aaa5b45bd684a4555419ab06c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8c629553b67b042aaa5b45bd684a4555419ab06c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/8921170e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list