[Git][security-tracker-team/security-tracker][master] Reserve DSA number for openssl update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 25 19:44:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
67f2df9c by Salvatore Bonaccorso at 2026-08-25T20:42:39+02:00
Reserve DSA number for openssl update

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -3529,7 +3529,6 @@ CVE-2026-XXXX [OSSN-0103]
 	NOTE: https://bugs.launchpad.net/manila/+bug/2161287
 CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
 	- openssl <unfixed> (bug #1145172)
-	[trixie] - openssl <postponed> (Minor issue, fix along with future update)
 	NOTE: https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a (openssl-4.0.2)
 	NOTE: https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b (openssl-3.6.4)
 	NOTE: https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34 (openssl-3.5.8)
@@ -15780,7 +15779,6 @@ CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed as
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL object) proce ...)
 	- openssl <unfixed> (bug #1144615)
-	[trixie] - openssl <postponed> (Minor issue, fix along with future update)
 	NOTE: https://openssl-library.org/news/secadv/20260813.txt
 	NOTE: https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139 (openssl-4.0.2)
 	NOTE: https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b (openssl-3.6.4)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[25 Aug 2026] DSA-6465-1 openssl - security update
+	{CVE-2026-14456 CVE-2026-14457 CVE-2026-18798 CVE-2026-54874 CVE-2026-63072 CVE-2026-63073 CVE-2026-63074 CVE-2026-63075 CVE-2026-63076 CVE-2026-75803}
+	[trixie] - openssl 3.5.7-1~deb13u2
 [25 Aug 2026] DSA-6464-1 erlang - security update
 	{CVE-2026-28808 CVE-2026-28810 CVE-2026-32144 CVE-2026-32147 CVE-2026-42789 CVE-2026-42790 CVE-2026-42791 CVE-2026-42792 CVE-2026-47078 CVE-2026-48855 CVE-2026-48856 CVE-2026-48858 CVE-2026-48860 CVE-2026-49759 CVE-2026-49760 CVE-2026-53422 CVE-2026-54886 CVE-2026-54887 CVE-2026-54890 CVE-2026-54891 CVE-2026-55737 CVE-2026-55950 CVE-2026-55952 CVE-2026-55953 CVE-2026-58227 CVE-2026-59250 CVE-2026-59251}
 	[trixie] - erlang 1:27.3.4.1+dfsg-1+deb13u3


=====================================
data/dsa-needed.txt
=====================================
@@ -96,8 +96,6 @@ nodejs
 --
 node-dompurify
 --
-openssl (carnil)
---
 openexr
 --
 pacemaker



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/67f2df9c345bc10192d4dd4601d1d6a481cc84aa

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/67f2df9c345bc10192d4dd4601d1d6a481cc84aa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/9d8a8f33/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list