[Git][security-tracker-team/security-tracker][master] Reserve DLA-4755-1 for libvncserver
Abhijith PA (@abhijith)
abhijith at debian.org
Tue Aug 25 14:20:05 BST 2026
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2a6e1cf5 by Abhijith PA at 2026-08-25T18:49:37+05:30
Reserve DLA-4755-1 for libvncserver
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -122246,14 +122246,12 @@ CVE-2026-32854 (LibVNCServer versions 0.9.15 and prior (fixed incommit dc78dee)
- libvncserver 0.9.15+dfsg-3 (bug #1132017)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u1
[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u1
- [bullseye] - libvncserver <postponed> (Minor issue)
NOTE: https://github.com/LibVNC/libvncserver/security/advisories/GHSA-xjp8-4qqv-5x4x
NOTE: Fixed by: https://github.com/LibVNC/libvncserver/commit/dc78dee51a7e270e537a541a17befdf2073f5314
CVE-2026-32853 (LibVNCServer versions 0.9.15 and prior (fixed incommit 009008e) contai ...)
- libvncserver 0.9.15+dfsg-3 (bug #1132016)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u1
[bookworm] - libvncserver 0.9.14+dfsg-1+deb12u1
- [bullseye] - libvncserver <postponed> (Minor issue)
NOTE: https://github.com/LibVNC/libvncserver/security/advisories/GHSA-87q7-v983-qwcj
NOTE: Fixed by: https://github.com/LibVNC/libvncserver/commit/009008e2f4d5a54dd71f422070df3af7b3dbc931
CVE-2026-32647 (NGINX Open Source and NGINX Plus have a vulnerability in the ngx_http_ ...)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[25 Aug 2026] DLA-4755-1 libvncserver - security update
+ {CVE-2026-32853 CVE-2026-32854 CVE-2026-44988 CVE-2026-50538}
+ [bullseye] - libvncserver 0.9.13+dfsg-2+deb11u2
[25 Aug 2026] DLA-4754-1 thunderbird - security update
{CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74948 CVE-2026-74949 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959 CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74967 CVE-2026-74969 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74983 CVE-2026-74987 CVE-2026-74990}
[bullseye] - thunderbird 1:140.14.0esr-1~deb11u1
=====================================
data/dla-needed.txt
=====================================
@@ -430,9 +430,6 @@ libstb/bullseye
NOTE: 20260226: Fixed CVE-2021-28021 CVE-2021-37789 CVE-2021-42715 CVE-2022-28041 CVE-2022-28042 with DLA-4493-1 (abhijith)
NOTE: 20260429: Revisit when upstream merge the proposed fixes. Though other embed libstb projects patched (abhijith)
--
-libvncserver (Abhijith PA)
- NOTE: 20260612: Added by Front-Desk (rouca)
---
libwebsockets/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a6e1cf5a97676baf836917baf7179efdf79aa33
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a6e1cf5a97676baf836917baf7179efdf79aa33
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/7c3e9d32/attachment.htm>
More information about the debian-security-tracker-commits
mailing list