[Git][security-tracker-team/security-tracker][master] Reserve DSA for libgit2
Aron Xu (@aron)
aron at debian.org
Thu Aug 20 18:08:02 BST 2026
Aron Xu pushed to branch master at Debian Security Tracker / security-tracker
Commits:
83212c23 by Aron Xu at 2026-08-20T22:20:57+08:00
Reserve DSA for libgit2
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -24941,27 +24941,22 @@ CVE-2026-60074 (Date::Manip versions through 6.99 for Perl return corrupted date
NOTE: https://security.metacpan.org/patches/D/Date-Manip/6.99/CVE-2026-60074-r1.patch
CVE-2026-53587
- libgit2 1.9.6+ds-1
- [trixie] - libgit2 <no-dsa> (Minor issue)
NOTE: https://github.com/libgit2/libgit2/security/advisories/GHSA-pm24-4jhq-3xvm
NOTE: Fixed by: https://github.com/libgit2/libgit2/commit/affda60c10fcef16723451c0d7dc71b71dc20ad3 (v1.9.5)
CVE-2026-53586
- libgit2 1.9.6+ds-1
- [trixie] - libgit2 <no-dsa> (Minor issue)
NOTE: https://github.com/libgit2/libgit2/security/advisories/GHSA-2889-x8f6-mc4x
NOTE: Fixed by: https://github.com/libgit2/libgit2/commit/af2b29ad0a74d5bac9751376879ddaf848136d3b (v1.9.5)
CVE-2026-53585
- libgit2 1.9.6+ds-1
- [trixie] - libgit2 <no-dsa> (Minor issue)
NOTE: https://github.com/libgit2/libgit2/security/advisories/GHSA-27m5-gxxh-x79j
NOTE: Fixed by: https://github.com/libgit2/libgit2/commit/0cdfdd5fa8f8514c82413025e1e0808866cf7c30 (v1.9.5)
CVE-2026-53584
- libgit2 1.9.6+ds-1
- [trixie] - libgit2 <no-dsa> (Minor issue)
NOTE: https://github.com/libgit2/libgit2/security/advisories/GHSA-cw77-j82w-mchm
NOTE: Fixed by: https://github.com/libgit2/libgit2/commit/ec7371da9f359cd8293e9108e7a0b1c1b61b67c4 (v1.9.5)
CVE-2026-53583
- libgit2 1.9.6+ds-1
- [trixie] - libgit2 <no-dsa> (Minor issue)
NOTE: https://github.com/libgit2/libgit2/security/advisories/GHSA-h7gc-w2gg-p9xp
NOTE: Fixed by: https://github.com/libgit2/libgit2/commit/c2aa35409ee0e6515df64da49750f13a0a42c47f (v1.9.5)
CVE-2026-62268
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[20 Aug 2026] DSA-6453-1 libgit2 - security update
+ {CVE-2026-5917 CVE-2026-53583 CVE-2026-53584 CVE-2026-53585 CVE-2026-53586 CVE-2026-53587}
+ [trixie] - libgit2 1.9.0+ds-2+deb13u1
[19 Aug 2026] DSA-6452-1 designate - security update
{CVE-2026-71193 CVE-2026-71194}
[trixie] - designate 1:20.0.0-2+deb13u1
=====================================
data/dsa-needed.txt
=====================================
@@ -65,9 +65,6 @@ libdbi-perl (carnil)
--
libde265
--
-libgit2 (aron)
- Timo Röhling posted debdiff for review
---
libnet-dns-perl (carnil)
--
linux (carnil)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83212c23ea3279eef6c93dd4c45966c014182581
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83212c23ea3279eef6c93dd4c45966c014182581
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/a151ef7c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list