[Git][security-tracker-team/security-tracker][master] DLA-4741-1

Andrej Shadura (@andrewsh) andrewsh at debian.org
Sun Aug 16 15:12:39 BST 2026



Andrej Shadura pushed to branch master at Debian Security Tracker / security-tracker


Commits:
890c88f7 by Andrej Shadura at 2026-08-16T16:12:10+02:00
DLA-4741-1

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -22915,13 +22915,19 @@ CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter of
 CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
 	- unzip 6.0-31 (bug #1142906)
 	[trixie] - unzip 6.0-29+deb13u1
+	[bookworm] - unzip 6.0-28+deb12u1
+	[bullseye] - unzip 6.0-26+deb11u2
 CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
 	- unzip 6.0-30 (bug #1142905; unimportant)
 	[trixie] - unzip 6.0-29+deb13u1
+	[bookworm] - unzip 6.0-28+deb12u1
+	[bullseye] - unzip 6.0-26+deb11u2
 	NOTE: Crash in CLI tool, no security impact
 CVE-2026-XXXX [heap OOB read in EF_IZUNIX3 extra field handler]
 	- unzip 6.0-30 (bug #1142904; unimportant)
 	[trixie] - unzip 6.0-29+deb13u1
+	[bookworm] - unzip 6.0-28+deb12u1
+	[bullseye] - unzip 6.0-26+deb11u2
 	NOTE: Crash in CLI tool, no security impact
 CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 ...)
 	NOT-FOR-US: WordPress plugin


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[16 Aug 2026] DLA-4741-1 unzip - security update
+	[bullseye] - unzip 6.0-26+deb11u2
+	[bookworm] - unzip 6.0-28+deb12u1
 [14 Aug 2026] DLA-4740-1 postgresql-15 - security update
 	{CVE-2025-8714 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385}
 	[bookworm] - postgresql-15 15.19-0+deb12u1


=====================================
data/dla-needed.txt
=====================================
@@ -921,9 +921,6 @@ unbound
   NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
   NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
 --
-unzip (andrewsh)
-  NOTE: 20260802: Added by Front-Desk (ta)
---
 uriparser/bullseye
   NOTE: 20260519: Added by Front-Desk (Beuc)
   NOTE: 20260519: Many postponed CVEs piled-up (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/890c88f770b6e374dae38fc3f18a1bb55fde71a6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/890c88f770b6e374dae38fc3f18a1bb55fde71a6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/fc34256b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list