[Git][security-tracker-team/security-tracker][master] Reserve DLA-4737-1 for xorg-server

Arnaud Rebillout (@arnaudr) arnaudr at debian.org
Thu Aug 13 05:41:17 BST 2026



Arnaud Rebillout pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9aff8316 by Arnaud Rebillout at 2026-08-13T11:40:27+07:00
Reserve DLA-4737-1 for xorg-server

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -241353,7 +241353,6 @@ CVE-2024-13126 (The Download Manager WordPress plugin before 3.3.07 doesn't prev
 	NOT-FOR-US: WordPress plugin
 CVE-2022-49737 (In X.Org X server 20.11 through 21.1.16, when a client application use ...)
 	- xorg-server 2:21.1.16-1.1 (bug #1081338)
-	[bookworm] - xorg-server <postponed> (Minor issue, can be fixed along in future DSA)
 	[bullseye] - xorg-server <postponed> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/issues/1260
 	NOTE: https://gitlab.freedesktop.org/xorg/xserver/-/commit/dc7cb45482cea6ccec22d117ca0b489500b4d0a0 (master)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[13 Aug 2026] DLA-4737-1 xorg-server - security update
+	{CVE-2022-49737 CVE-2026-50256 CVE-2026-50257 CVE-2026-50258 CVE-2026-50259 CVE-2026-50260 CVE-2026-50261 CVE-2026-50262 CVE-2026-50263 CVE-2026-50264}
+	[bookworm] - xorg-server 2:21.1.7-3+deb12u13
 [12 Aug 2026] DLA-4736-1 python-django - security update
 	{CVE-2026-15337 CVE-2026-15920}
 	[bullseye] - python-django 2:2.2.28-1~deb11u13


=====================================
data/dla-needed.txt
=====================================
@@ -985,11 +985,6 @@ xmlrpc-c/bullseye
   NOTE: 20250705: Ping'd secteam asking for current bookworm plans. (Beuc)
   NOTE: 20250705: https://lists.debian.org/debian-lts/2025/07/msg00006.html
 --
-xorg-server (arnaudr)
-  NOTE: 20260522: Added by Front-Desk (Beuc)
-  NOTE: 20260522: Follow bookworm 12.14 (5 CVEs) (Beuc/front-desk)
-  NOTE: 20260713: Follow DSA-6370-1/trixie (9 CVEs) (Beuc/front-desk)
---
 xrdp (Abhijith PA)
   NOTE: 20260418: Added by Front-Desk (rouca)
   NOTE: 20260706: Bookworm/Bullseye share the same version - fix in Bookworm first (dleidert/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9aff8316089f62ce0fc161049fcf2ee545e44897

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9aff8316089f62ce0fc161049fcf2ee545e44897
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/a2dfc14a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list