[Git][security-tracker-team/security-tracker][master] CVE-2026-6879/python3.11: mark as postponed for bookworm

Carlos Henrique Lima Melara (@charles) gitlab at salsa.debian.org
Thu Aug 13 04:24:15 BST 2026



Carlos Henrique Lima Melara pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b3458e5a by Carlos Henrique Lima Melara at 2026-08-13T00:23:20-03:00
CVE-2026-6879/python3.11: mark as postponed for bookworm

Follow secteam triage and add upstream commit fix as reference.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14165,6 +14165,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
 	- python3.13 3.13.15-1
 	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
+	[bookworm] - python3.11 <postponed> (Minor issue)
 	- python3.9 <removed>
 	[bullseye] - python3.9 <postponed> (Minor issue)
 	- python2.7 <removed>
@@ -14179,6 +14180,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
 	NOTE: https://github.com/python/cpython/commit/2ffab083782968a4d732738f4f1dff6bbd69d2b0 (main)
 	NOTE: https://github.com/python/cpython/commit/cb409342a19f25656f62e679f8bac265fe1442c3 (v3.14.7)
 	NOTE: https://github.com/python/cpython/commit/390337b8ba1658833fdef379e1739c9f9533a8db (v3.13.15)
+	NOTE: https://github.com/python/cpython/commit/0583f24ae678993e3f7939f51ad5bcae5ad9dc70 (v3.11.16)
 CVE-2026-67185 (TinyWeb through 0.0.8 contains a path traversal vulnerability that all ...)
 	NOT-FOR-US: TinyWeb
 CVE-2026-67184 (TinyWeb through 0.0.8 contains a null pointer dereference vulnerabilit ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3458e5a83777d5f8549b3f8414c3b8cff744d23

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b3458e5a83777d5f8549b3f8414c3b8cff744d23
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/c010b0c6/attachment.htm>


More information about the debian-security-tracker-commits mailing list