[Git][security-tracker-team/security-tracker][master] Reserve DSA number for libdbi-perl update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 27 10:24:39 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
608f63bd by Salvatore Bonaccorso at 2026-08-27T11:24:02+02:00
Reserve DSA number for libdbi-perl update
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -51127,19 +51127,16 @@ CVE-2026-15747 (Mojolicious versions from 4.59 before 9.48 for Perl expose a sta
NOTE: Fixed by: https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27 (v9.48)
CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the table file ...)
- libdbi-perl 1.651-1 (bug #1142072)
- [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813967/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mh3j-xwf4-jrqw
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/96d62dfe4528bf56fe13f413ed323d4252531728 (1.651)
CVE-2026-60082 (DBI versions before 1.651 for Perl do not enforce statement handle con ...)
- libdbi-perl 1.651-1 (bug #1142072)
- [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813803/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-rwhc-hhmv-cjvg
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/397868704291bbf0989b97e2c0661189890653e2 (1.651)
CVE-2026-60081 (DBI::ProfileData versions before 1.651 for Perl do not limit the path ...)
- libdbi-perl 1.651-1 (bug #1142072)
- [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41813962/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ww49-w4mv-jrr4
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/6764e755e83ee1ebb1b40760e5b53eb50960bd7a (1.651)
@@ -54598,7 +54595,6 @@ CVE-2026-15044 (A flaw was found in the TrustyAI Service Operator. When deployin
NOT-FOR-US: TrustyAI Service Operator
CVE-2026-15043 (DBI::SQL::Nano versions from 1.42 before 1.651 for Perl have inverted ...)
- libdbi-perl 1.651-1 (bug #1142072)
- [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41805128/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-mv45-ff6j-x9jp
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/e9742ef85a75867cbd696860e3bf3e32b681f98d (1.651)
@@ -55136,7 +55132,6 @@ CVE-2026-14895 (String::Util versions before 1.36 for Perl are susceptible to a
NOTE: Fixed by: https://github.com/scottchiefbaker/String-Util/commit/f8150867aaeb8f57c59601aefb2193f2caed8745 (v1.36)
CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code injection vi ...)
- libdbi-perl 1.650-1 (bug #1141667)
- [trixie] - libdbi-perl <no-dsa> (Minor issue)
[bookworm] - libdbi-perl <postponed> (Minor issue)
[bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625527/
@@ -55144,14 +55139,12 @@ CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code inject
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259 (1.650)
CVE-2026-14739 (DBI versions before 1.650 for Perl have a heap overflow when preparsin ...)
- libdbi-perl 1.650-1 (bug #1141667)
- [trixie] - libdbi-perl <no-dsa> (Minor issue)
[bookworm] - libdbi-perl <postponed> (Minor issue)
[bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625530/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395 (1.650)
CVE-2026-14740 (DBI versions before 1.650 for Perl read one byte out-of-bounds in prep ...)
- libdbi-perl 1.650-1 (bug #1141667)
- [trixie] - libdbi-perl <no-dsa> (Minor issue)
[bookworm] - libdbi-perl <postponed> (Minor issue)
[bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625532/
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[27 Aug 2026] DSA-6473-1 libdbi-perl - security update
+ {CVE-2026-14380 CVE-2026-14739 CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082 CVE-2026-73193 CVE-2026-73194}
+ [trixie] - libdbi-perl 1.652-2~deb13u1
[27 Aug 2026] DSA-6472-1 bubblewrap - security update
[trixie] - bubblewrap 0.12.0-1~deb13u1
[27 Aug 2026] DSA-6471-1 wireshark - security update
=====================================
data/dsa-needed.txt
=====================================
@@ -63,8 +63,6 @@ kitty
--
libapache2-mod-auth-openidc (jmm)
--
-libdbi-perl (carnil)
---
libde265
--
libevent
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/608f63bdf01f6f47c1cf8433d4c04df4f5e09bbe
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/608f63bdf01f6f47c1cf8433d4c04df4f5e09bbe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/7b5fad9e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list