[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 19 16:47:38 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
be76a6d0 by Moritz Muehlenhoff at 2026-08-19T17:41:35+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -23639,6 +23639,7 @@ CVE-2026-7260 (Circular symbolic links in phar archives could lead to unbounded
 	NOTE: Fixed by: https://github.com/php/php-src/commit/16af1694dd4e0d0e4a24f90740651d3053edffa3 (php-8.4.24)
 CVE-2026-71190 (In OpenStack Swift through 2.38.0, the proxy server Accept header pars ...)
 	- swift 2.37.1-6 (bug #1142973)
+	[trixie] - swift <no-dsa> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-031.html
 	NOTE: https://bugs.launchpad.net/swift/+bug/2158771
 CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does not sanit ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -34,7 +34,7 @@ containerd
 --
 cups
 --
-designate
+designate (jmm)
 --
 dulwich
 --
@@ -97,6 +97,10 @@ node-dompurify
 --
 openexr
 --
+openjdk-21 (jmm)
+--
+openjdk-25 (jmm)
+--
 pacemaker
 --
 pdfminer (carnil)
@@ -142,6 +146,8 @@ runc
 rust-wasmtime
   for CVE-2026-34987 CVE-2026-34971, rest would also be fine to ignore
 --
+sabnzbdplus (jmm)
+--
 shaarli
 --
 sogo



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be76a6d0e9f41c8b1b250bbbf3fac6d2aaca2da4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be76a6d0e9f41c8b1b250bbbf3fac6d2aaca2da4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260819/6c6794e8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list