[Git][security-tracker-team/security-tracker][master] 2 commits: Triage CVE-2026-15307 & CVE-2026-15830 in python-django for bookworm and bullseye LTS.
Chris Lamb (@lamby)
lamby at debian.org
Wed Aug 12 20:22:28 BST 2026
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
86008409 by Chris Lamb at 2026-08-12T12:21:54-07:00
Triage CVE-2026-15307 & CVE-2026-15830 in python-django for bookworm and bullseye LTS.
- - - - -
4e7a551b by Chris Lamb at 2026-08-12T12:21:54-07:00
Reserve DLA-4736-1 for python-django
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -9053,6 +9053,8 @@ CVE-2026-15920 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 befo
NOTE: Fixed by: https://github.com/django/django/commit/b9adb81339cc418f8f56b1050cca6dfec3ab6349 (5.2.17)
CVE-2026-15830 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
- python-django 3:5.2.17-1 (bug #1143611)
+ [bookworm] - python-django <ignored> (Invasive fix; too difficult to backport; affects only GeoSpatial component)
+ [bullseye] - python-django <ignored> (Invasive fix; too difficult to backport; affects only GeoSpatial component)
NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by: https://github.com/django/django/commit/ba80833fa656dd09660b97c4429331067db1b080 (5.2.17)
CVE-2026-15337 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
@@ -9061,6 +9063,8 @@ CVE-2026-15337 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 befo
NOTE: Fixed by: https://github.com/django/django/commit/c72a5dbb64d0777f3f471f1be94e8b2ca91e0959 (5.2.17)
CVE-2026-15307 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 before 6.0 ...)
- python-django 3:5.2.17-1 (bug #1143611)
+ [bookworm] - python-django <ignored> (Invasive fix; too difficult to backport; affects only GeoSpatial component)
+ [bullseye] - python-django <ignored> (Invasive fix; too difficult to backport; affects only GeoSpatial component)
NOTE: https://www.djangoproject.com/weblog/2026/aug/04/security-releases/
NOTE: Fixed by: https://github.com/django/django/commit/115ffd0463a765ab1cc93de18e94b5459b8a300e (5.2.17)
CVE-2026-XXXX [RUSTSEC-2026-0204]
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,7 @@
+[12 Aug 2026] DLA-4736-1 python-django - security update
+ {CVE-2026-15337 CVE-2026-15920}
+ [bullseye] - python-django 2:2.2.28-1~deb11u13
+ [bookworm] - python-django 3:3.2.25-0+deb12u4
[12 Aug 2026] DLA-4735-1 neutron - security update
{CVE-2026-55707}
[bookworm] - neutron 2:21.0.0-7+deb12u1
=====================================
data/dla-needed.txt
=====================================
@@ -678,9 +678,6 @@ python-asyncssh
python-cryptography
NOTE: 20260805: Added by Front-Desk (rouca)
--
-python-django (Chris Lamb)
- NOTE: 20260805: Added by Front-Desk (rouca)
---
python-eventlet/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e8c860baaa7cae0149821630c5f2f637262030c9...4e7a551bf02e6cbab7268a875d8c851ba6122736
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e8c860baaa7cae0149821630c5f2f637262030c9...4e7a551bf02e6cbab7268a875d8c851ba6122736
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/2156fdc6/attachment.htm>
More information about the debian-security-tracker-commits
mailing list