[Git][security-tracker-team/security-tracker][master] DLA-4741-1
Andrej Shadura (@andrewsh)
andrewsh at debian.org
Sun Aug 16 15:12:39 BST 2026
Andrej Shadura pushed to branch master at Debian Security Tracker / security-tracker
Commits:
890c88f7 by Andrej Shadura at 2026-08-16T16:12:10+02:00
DLA-4741-1
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -22915,13 +22915,19 @@ CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter of
CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
- unzip 6.0-31 (bug #1142906)
[trixie] - unzip 6.0-29+deb13u1
+ [bookworm] - unzip 6.0-28+deb12u1
+ [bullseye] - unzip 6.0-26+deb11u2
CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
- unzip 6.0-30 (bug #1142905; unimportant)
[trixie] - unzip 6.0-29+deb13u1
+ [bookworm] - unzip 6.0-28+deb12u1
+ [bullseye] - unzip 6.0-26+deb11u2
NOTE: Crash in CLI tool, no security impact
CVE-2026-XXXX [heap OOB read in EF_IZUNIX3 extra field handler]
- unzip 6.0-30 (bug #1142904; unimportant)
[trixie] - unzip 6.0-29+deb13u1
+ [bookworm] - unzip 6.0-28+deb12u1
+ [bullseye] - unzip 6.0-26+deb11u2
NOTE: Crash in CLI tool, no security impact
CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 ...)
NOT-FOR-US: WordPress plugin
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[16 Aug 2026] DLA-4741-1 unzip - security update
+ [bullseye] - unzip 6.0-26+deb11u2
+ [bookworm] - unzip 6.0-28+deb12u1
[14 Aug 2026] DLA-4740-1 postgresql-15 - security update
{CVE-2025-8714 CVE-2026-6464 CVE-2026-6469 CVE-2026-6470 CVE-2026-6471 CVE-2026-6473 CVE-2026-14662 CVE-2026-14663 CVE-2026-14664 CVE-2026-14666 CVE-2026-14668 CVE-2026-14669 CVE-2026-14670 CVE-2026-14671 CVE-2026-14673 CVE-2026-14677 CVE-2026-14678 CVE-2026-14679 CVE-2026-14680 CVE-2026-15741 CVE-2026-15742 CVE-2026-16239 CVE-2026-16241 CVE-2026-18024 CVE-2026-18408 CVE-2026-19385}
[bookworm] - postgresql-15 15.19-0+deb12u1
=====================================
data/dla-needed.txt
=====================================
@@ -921,9 +921,6 @@ unbound
NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
--
-unzip (andrewsh)
- NOTE: 20260802: Added by Front-Desk (ta)
---
uriparser/bullseye
NOTE: 20260519: Added by Front-Desk (Beuc)
NOTE: 20260519: Many postponed CVEs piled-up (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/890c88f770b6e374dae38fc3f18a1bb55fde71a6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/890c88f770b6e374dae38fc3f18a1bb55fde71a6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/fc34256b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list