[Git][security-tracker-team/security-tracker][master] Reserve DSA number for openssl update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 25 19:44:41 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
67f2df9c by Salvatore Bonaccorso at 2026-08-25T20:42:39+02:00
Reserve DSA number for openssl update
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -3529,7 +3529,6 @@ CVE-2026-XXXX [OSSN-0103]
NOTE: https://bugs.launchpad.net/manila/+bug/2161287
CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
- openssl <unfixed> (bug #1145172)
- [trixie] - openssl <postponed> (Minor issue, fix along with future update)
NOTE: https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a (openssl-4.0.2)
NOTE: https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b (openssl-3.6.4)
NOTE: https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34 (openssl-3.5.8)
@@ -15780,7 +15779,6 @@ CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed as
NOT-FOR-US: WordPress plugin
CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL object) proce ...)
- openssl <unfixed> (bug #1144615)
- [trixie] - openssl <postponed> (Minor issue, fix along with future update)
NOTE: https://openssl-library.org/news/secadv/20260813.txt
NOTE: https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139 (openssl-4.0.2)
NOTE: https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b (openssl-3.6.4)
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[25 Aug 2026] DSA-6465-1 openssl - security update
+ {CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803}
+ [trixie] - openssl 3.5.7-1~deb13u2
[25 Aug 2026] DSA-6464-1 erlang - security update
{CVE-2026-28808 CVE-2026-28810 CVE-2026-32144 CVE-2026-32147 CVE-2026-42789 CVE-2026-42790 CVE-2026-42791 CVE-2026-42792 CVE-2026-47078 CVE-2026-48855 CVE-2026-48856 CVE-2026-48858 CVE-2026-48860 CVE-2026-49759 CVE-2026-49760 CVE-2026-53422 CVE-2026-54886 CVE-2026-54887 CVE-2026-54890 CVE-2026-54891 CVE-2026-55737 CVE-2026-55950 CVE-2026-55952 CVE-2026-55953 CVE-2026-58227 CVE-2026-59250 CVE-2026-59251}
[trixie] - erlang 1:27.3.4.1+dfsg-1+deb13u3
=====================================
data/dsa-needed.txt
=====================================
@@ -96,8 +96,6 @@ nodejs
--
node-dompurify
--
-openssl (carnil)
---
openexr
--
pacemaker
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/67f2df9c345bc10192d4dd4601d1d6a481cc84aa
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/67f2df9c345bc10192d4dd4601d1d6a481cc84aa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/9d8a8f33/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list