[Git][security-tracker-team/security-tracker][master] 32 commits: lts: add dovecot to dla-needed

Daniel Leidert (@dleidert) dleidert at debian.org
Mon Aug 31 06:29:58 BST 2026



Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker


Commits:
521e986d by Daniel Leidert at 2026-08-31T07:29:10+02:00
lts: add dovecot to dla-needed

- - - - -
3923a258 by Daniel Leidert at 2026-08-31T07:29:10+02:00
Add patch link for CVE-2026-53499/fort-validator

- - - - -
b7e2d3be by Daniel Leidert at 2026-08-31T07:29:10+02:00
lts: add libapache2-mod-auth-openidc and claim it

- - - - -
46fe5b03 by Daniel Leidert at 2026-08-31T07:29:10+02:00
Add patch links for nagios4 issues

- - - - -
e5d86168 by Daniel Leidert at 2026-08-31T07:29:10+02:00
lts: ignore GHSA-pxhw-h44j-8pfx/bubblewrap

This seems like an intrusive backport. Trixie decided to bump the upstream
version, it seems. I will pass this on to the next FD to check the decision.

- - - - -
315bb6e6 by Daniel Leidert at 2026-08-31T07:29:11+02:00
lts: mark CVE-2026-19685/network-manager as not affecting Bookworm or Bullseye

Same reason as for Trixie.

- - - - -
e654ebd2 by Daniel Leidert at 2026-08-31T07:29:11+02:00
lts: add sabnzbdplus to dla-needed

- - - - -
fd31143b by Daniel Leidert at 2026-08-31T07:29:11+02:00
lts: add suricata-update to dla-needed

- - - - -
f3f2fa23 by Daniel Leidert at 2026-08-31T07:29:11+02:00
lts: close open CVEs for tor fixed by DLA-4656-1

- - - - -
5208d46d by Daniel Leidert at 2026-08-31T07:29:11+02:00
Fix advisory link for CVE-2026-79619/zfs-linux

- - - - -
33873132 by Daniel Leidert at 2026-08-31T07:29:11+02:00
lts: add zfs-linux to dla-needed

- - - - -
b0743d61 by Daniel Leidert at 2026-08-31T07:29:12+02:00
lts: add openssl to dla-needed

- - - - -
897bc9eb by Daniel Leidert at 2026-08-31T07:29:12+02:00
lts: postpone cryptojs issues and add patch link

- - - - -
ab2518fc by Daniel Leidert at 2026-08-31T07:29:12+02:00
lts: mark CVE-2026-77220/ippsample as postponed

- - - - -
13670e0a by Daniel Leidert at 2026-08-31T07:29:12+02:00
Mark pdfio as affected by CVE-2026-77220

- - - - -
8cb8fe96 by Daniel Leidert at 2026-08-31T07:29:12+02:00
Add patch link for CVE-2026-78323/jss

- - - - -
1c275d18 by Daniel Leidert at 2026-08-31T07:29:13+02:00
lts: mark CVE-2026-49289,CVE-2026-49283/simplesamlphp as postponed

Popcon is low. Issue have not even been fixed in Sid yet.

- - - - -
3a140b44 by Daniel Leidert at 2026-08-31T07:29:13+02:00
lts: mark CVE-2026-55558,CVE-2026-53533/aiosmtplib as postponed

- - - - -
a07c8048 by Daniel Leidert at 2026-08-31T07:29:13+02:00
lts: mark CVE-2026-49844/apache-log4j2 as postponed

CVE-2026-49844 contains remaining fixes, CVE-2026-34481 has missed. The latter
has already been postponed.

- - - - -
02489321 by Daniel Leidert at 2026-08-31T07:29:13+02:00
lts: postpone CVE-2026-61372/apache-jena

- - - - -
a39d30ab by Daniel Leidert at 2026-08-31T07:29:14+02:00
lts: add gst-plugins-base1.0 to dla-needed

- - - - -
8d582b40 by Daniel Leidert at 2026-08-31T07:29:14+02:00
lts: add keystone to dla-needed

- - - - -
92b460bc by Daniel Leidert at 2026-08-31T07:29:14+02:00
lts: mark open CVEs for opennds as EOLed

- - - - -
927c6b5e by Daniel Leidert at 2026-08-31T07:29:14+02:00
lts: mark php-horde-imp issues as EOLed

- - - - -
b746cd00 by Daniel Leidert at 2026-08-31T07:29:14+02:00
lts: mark open lxd CVEs as EOLed

- - - - -
8b1e93a6 by Daniel Leidert at 2026-08-31T07:29:15+02:00
lts: mark CVE-2026-54338/jupyterhub as postponed

- - - - -
37860c4f by Daniel Leidert at 2026-08-31T07:29:15+02:00
lts: postpone CVE-2026-12590/node-body-parser

- - - - -
3b98e3c7 by Daniel Leidert at 2026-08-31T07:29:15+02:00
Add upstream bug report link for CVE-2026-18497/libstb

- - - - -
19a065ba by Daniel Leidert at 2026-08-31T07:29:15+02:00
lts: mark CVE-2026-66484..CVE-2026-66486/cpio as postponed

- - - - -
1f0869f2 by Daniel Leidert at 2026-08-31T07:29:16+02:00
lts: mark CVE-2026-19720/inetutils as postponed

Low popcon for talkd and better alternatives.

- - - - -
6f69b4ca by Daniel Leidert at 2026-08-31T07:29:16+02:00
lts: mark CVE-2026-71497/jsoup as not affecting Bullseye

and add the commit link that introduces the issue

- - - - -
d51273be by Daniel Leidert at 2026-08-31T07:29:16+02:00
lts: mark CVE-2026-78161/libwebsockets as not affecting LTS

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2073,15 +2073,19 @@ CVE-2026-3129 (The LiteSpeed Cache plugin for WordPress is vulnerable to Stored
 	NOT-FOR-US: WordPress plugin
 CVE-2026-38822 (In openNDS before 11.0.0, the client_params.sh script, invoked by the  ...)
 	- opennds <unfixed>
+	[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/294983e859bb678eef7db06fc9f6afab0b489d8e (v11.0.0)
 CVE-2026-38821 (A heap-based buffer overflow vulnerability exists in openNDS before 11 ...)
 	- opennds <unfixed>
+	[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/3b5f7ef40cd048826d3c4a16f61a73a1768fd5a9 (v11.0.0)
 CVE-2026-38820 (openNDS before 11.0.0 is susceptible to unauthenticated OS command exe ...)
 	- opennds <unfixed>
+	[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/8c03750d9a17d601fa7bd03ae7cde20c7c8d1252 (v11.0.0)
 CVE-2026-38819 (Multiple memory leaks in openNDS before 11.0.0 allow an unauthenticate ...)
 	- opennds <unfixed>
+	[bookworm] - opennds <end-of-life> (EOL in bookworm LTS)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/f2332e68c6d34f8403db346e380fff3817020d5c (v11.0.0)
 	NOTE: Fixed by: https://github.com/openNDS/openNDS/commit/b2801d9f14af44a23be7e9a1c378623bc5947c4c (v11.0.0)
 CVE-2026-38350 (An integer overflow in the target_sws_fuzzer() function (libswscale/ou ...)
@@ -3861,8 +3865,10 @@ CVE-2026-48786 (Fleet is an open-source device management platform built on osqu
 	NOT-FOR-US: Fleet
 CVE-2026-48549 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSR ...)
 	- nagios4 <unfixed> (bug #1145888)
+	NOTE: Fixed by: https://github.com/NagiosEnterprises/nagioscore/commit/02aba584656eb10c2ff83a696b166f4bc7dd1304 (nagios-4.5.13)
 CVE-2026-48548 (Nagios Core before 4.5.12 contains a cross-site request forgery vulner ...)
 	- nagios4 4.5.12+ds-1
+	NOTE: Fixed by: https://github.com/NagiosEnterprises/nagioscore/commit/e5ed38e53a5d65721520c7c67be0746d63da28cb (nagios-4.5.12)
 CVE-2026-47841 (An application using Spring Security's WebAuthn support may be vulnera ...)
 	- libspring-security-2.0-java <removed>
 CVE-2026-47837 (Missing Authentication for Critical Function vulnerability in Spring S ...)
@@ -3956,6 +3962,8 @@ CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incor
 CVE-2026-XXXX [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup]
 	- bubblewrap 0.12.0-1 (bug #1145655)
 	[trixie] - bubblewrap 0.12.0-1~deb13u1
+	[bookworm] - bubblewrap <ignored> (Intrusive backport due to a complete rewrite)
+	[bullseye] - bubblewrap <ignored> (Intrusive backport due to a complete rewrite)
 	NOTE: https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
 CVE-2026-9805 (SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32 ...)
 	NOT-FOR-US: Insyde
@@ -6503,6 +6511,8 @@ CVE-2026-78329 (Improper input validation vulnerability in Apache Camel Undertow
 CVE-2026-78323 (A flaw was found in JSS (Java Security Services). The JSSTrustManager  ...)
 	- jss <unfixed> (bug #1145877)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2521775
+	NOTE: Fixed by: https://github.com/dogtagpki/jss/commit/cffadbb2b53157014bc2ffb46d5a8fd4979623d1 (master)
+	NOTE: Fix has been marked as provided or written by AI.
 	TODO: check upstream details
 CVE-2026-78321 (The HTTP media server on DJI drones does not enforce sufficient limits ...)
 	NOT-FOR-US: DJI
@@ -6619,6 +6629,9 @@ CVE-2026-78166 (A security flaw has been discovered in provectus kafka-ui up to
 CVE-2026-78161 (A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is  ...)
 	- libwebsockets 4.3.5-6 (bug #1145789)
 	[trixie] - libwebsockets <no-dsa> (Minor issue; will be fixed via point release)
+	[bookworm] - libwebsockets <not-affected> (Vulnerable code introduced in v4.3.0)
+	[bullseye] - libwebsockets <not-affected> (Vulnerable code introduced in v4.3.0)
+	NOTE: Introduced by: https://github.com/warmcat/libwebsockets/commit/dcaa0013b425882aa71cfb1a5b350d67b6717608 (v4.3.0)
 	NOTE: Fixed by: https://github.com/warmcat/libwebsockets/commit/1d44554a1bb262db63ff4e240152a9deecd99054 (v5.0.0)
 	NOTE: https://github.com/biniamf/pocs/tree/main/libwebsockets-lecp-lecp_parse-cbor_pos_oob_write
 CVE-2026-78160 (A vulnerability has been found in Dolibarr ERP up to 18.0.10/22.0.5/23 ...)
@@ -6856,6 +6869,7 @@ CVE-2026-66906 (Relative path traversal vulnerability in Apache Camel Azure Stor
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66897 (A path traversal vulnerability in LXD's instance template processing a ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-q39m-8fx9-42fv
 CVE-2026-66671 (Unauthenticated Local File Inclusion in Verdure Core <= 1.2 versions.)
 	NOT-FOR-US: WordPress plugin or theme
@@ -6879,6 +6893,7 @@ CVE-2026-66584 (Unauthenticated Cross Site Scripting (XSS) in 12 Step Meeting Li
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-65053 (Horde IMP's AppleDouble MIME viewer writes an attacker-controlled atta ...)
 	- php-horde-imp <unfixed> (bug #1145884)
+	[bookworm] - php-horde-imp <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/horde/imp/pull/107
 	NOTE: https://github.com/horde/imp/commit/f31449a12e3f945c90015d29524925c4c43f6324
 	NOTE: https://blog.evan.lat/posts/CVE-2026-65053/
@@ -7989,7 +8004,7 @@ CVE-2026-74584 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a capabili ...)
 	{DSA-6462-1}
 	- zfs-linux 2.4.4-1
-	NOTE: https://github.com/advisories/GHSA-mhf5-q8gw-qg9v
+	NOTE: https://github.com/openzfs/zfs/security/advisories/GHSA-mhf5-q8gw-qg9v
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/16/5
 	NOTE: https://github.com/openzfs/zfs/issues/18936
 	NOTE: https://github.com/openzfs/zfs/pull/18959
@@ -8022,6 +8037,8 @@ CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From 0.1
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/1223a0f215d2cf9beb2d9eb9ea2649d001c21388 (v0.142.0)
 CVE-2026-77220 (PDFio before 1.6.5 contains a dangling pointer vulnerability in the di ...)
 	- ippsample <unfixed> (bug #1145176)
+	[bookworm] - ippsample <postponed> (Minor issue, low popcon)
+	- pdfio <unfixed>
 	NOTE: Fixed by: https://github.com/michaelrsweet/pdfio/commit/22b9afc800c5833f9e851e35938972bd4c76a357 (v1.6.5)
 CVE-2026-77219 (GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/P ...)
 	- emacs <unfixed> (bug #1145175)
@@ -8149,6 +8166,7 @@ CVE-2026-53509 (CKAN MCP Server is a tool for querying CKAN open data portals. A
 CVE-2026-53499 (FORT Validator is a Resource Public Key Infrastructure (RPKI) relying- ...)
 	- fort-validator 1.6.8-1
 	NOTE: https://github.com/NICMx/FORT-validator/security/advisories/GHSA-qfm3-577x-rh54
+	NOTE: Fixed by: https://github.com/NICMx/FORT-validator/commit/17188768a80bc3393a9923f257129213ca019f9a (1.6.8)
 CVE-2026-53497 (CrossWatch (CW) is a synchronization engine. Prior to version 0.9.21,  ...)
 	NOT-FOR-US: CrossWatch
 CVE-2026-53487 (Kite is a Kubernetes dashboard. Prior to version 0.12.3, authenticated ...)
@@ -8962,6 +8980,8 @@ CVE-2026-74580 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2026-19685 (NetworkManager did not apply the private_user restriction to the 802-1 ...)
 	- network-manager <unfixed> (bug #1145199)
 	[trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
+	[bookworm] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
+	[bullseye] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
 	NOTE: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513
 	NOTE: Introduced with: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf (1.57.1-dev)
 	NOTE: The introducing commit is part of the patchseries for CVE-2025-9615
@@ -9410,6 +9430,7 @@ CVE-2026-55586 (SumatraPDF is a multi-format reader for Windows. In 3.6.1 and ea
 CVE-2026-55558 (aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior  ...)
 	- aiosmtplib 5.1.2-1
 	[trixie] - aiosmtplib <no-dsa> (Minor issue)
+	[bookworm] - aiosmtplib <postponed> (Minor issue; can be fixed with next update)
 	NOTE: https://github.com/cole/aiosmtplib/security/advisories/GHSA-vxj7-4xrp-5vr4
 	NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/9fab7ba1361dbf7622ede1315a24be805cff09c9 (v5.1.2)
 CVE-2026-55095 (OpenProject is open-source, web-based project management software. In  ...)
@@ -10995,11 +11016,15 @@ CVE-2026-49392 (Wazuh is a free and open source platform used for threat prevent
 	NOT-FOR-US: Wazuh
 CVE-2026-49289 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...)
 	- simplesamlphp <unfixed>
+	[bookworm] - simplesamlphp <postponed> (Minor issue; low popcon)
+	[bullseye] - simplesamlphp <postponed> (Minor issue; low popcon)
 	NOTE: https://github.com/simplesamlphp/saml2/security/advisories/GHSA-5cjr-mxj5-wmrx
 	NOTE: Fixed by: https://github.com/simplesamlphp/saml2/commit/0043033891fdba9618386ab583e1d8afdf8aea6e (v4.20.3)
 	NOTE: Fixed by: https://github.com/simplesamlphp/saml2/commit/6695eb923da491f716009c2a26b34a463ac05c6b (v4.19.3)
 CVE-2026-49283 (The SimpleSAMLphp SAML2 library is a PHP library for SAML2 related fun ...)
 	- simplesamlphp <unfixed>
+	[bookworm] - simplesamlphp <postponed> (Minor issue; low popcon)
+	[bullseye] - simplesamlphp <postponed> (Minor issue; low popcon)
 	NOTE: https://github.com/simplesamlphp/saml2/security/advisories/GHSA-6929-8p9f-26jx
 	NOTE: Fixed by: https://github.com/simplesamlphp/saml2/commit/4a71b20d8d845579fd0a54d6449c265b40db459d (v6.2.1)
 	NOTE: Fixed by: https://github.com/simplesamlphp/saml2/commit/a2c1ac588c70d7b7998546cf32675fb113f22a5f (v5.0.6)
@@ -14322,6 +14347,7 @@ CVE-2026-54552 (sh provides Python process launching. Prior to 2.2.4, the _uid o
 CVE-2026-53533 (aiosmtplib is an asynchronous SMTP client for use with asyncio. Prior  ...)
 	- aiosmtplib 5.1.2-1
 	[trixie] - aiosmtplib <no-dsa> (Minor issue)
+	[bookworm] - aiosmtplib <postponed> (Minor issue; can be fixed with next update)
 	NOTE: https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq
 	NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/8eaf6efc9a8f59e2e09d3ef11246a058c46bd3ba (v5.1.1)
 CVE-2026-52723 (ePA 3.x Integration implements the authorization workflow and writes M ...)
@@ -16616,6 +16642,8 @@ CVE-2026-12128 (The Pinpoint Booking System \u2013 Version 2 plugin for WordPres
 CVE-2026-19720
 	- inetutils 2:2.8-3
 	[trixie] - inetutils <no-dsa> (Minor issue)
+	[bookworm] - inetutils <postponed> (Minor issue; low popcon)
+	[bullseye] - inetutils <postponed> (Minor issue; low popcon)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/25/3
 	NOTE: Introduced with: https://codeberg.org/inetutils/inetutils/commit/9974e41e9fd957b0271d4dc0af773a9f998f1eb2 (inetutils-1_4)
 	NOTE: Fixed by: https://codeberg.org/inetutils/inetutils/commit/81987d968ab831c08bd7e42a46f4a4823729cf1e
@@ -22612,6 +22640,7 @@ CVE-2026-67579 (Deserialization of Untrusted Data vulnerability in ash-project a
 	NOT-FOR-US: ash-project ash
 CVE-2026-66898 (A path traversal vulnerability in LXD allows an attacker to manipulate ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-m857-c7gc-c984
 CVE-2026-65370 (ServiceTalk HTTP/1.x incorrectly handles malformed Transfer-Encoding w ...)
 	NOT-FOR-US: Apple
@@ -22619,34 +22648,43 @@ CVE-2026-64826 (rConfig before 8.2.13 contains a path traversal vulnerability th
 	NOT-FOR-US: rConfig
 CVE-2026-63300 (An improper validation vulnerability in the instancePostMigration func ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-5g5r-wh97-qcq2
 	NOTE: https://github.com/canonical/lxd/pull/18605 (main)
 	NOTE: https://github.com/canonical/lxd/pull/18651 (stable-5.21)
 CVE-2026-63299 (An authorization bypass vulnerability in LXD allows an authenticated u ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-5h78-p252-989h
 CVE-2026-63298 (An improper neutralization of special elements vulnerability in LXD's  ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-vfh7-q59q-54v2
 CVE-2026-63297 (An authorization bypass vulnerability in LXD due to a timing flaw duri ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-v989-qw7w-xvg4
 CVE-2026-63296 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-gcr9-5q6r-w625
 CVE-2026-63295 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-7vp9-3vmp-c5jm
 CVE-2026-63294 (A link following vulnerability in LXD allows an attacker to achieve ro ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-fv82-v4fj-mm4m
 CVE-2026-63293 (A link following vulnerability in LXD allows an attacker to achieve ar ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-j825-cg34-5fr5
 CVE-2026-62421
 	REJECTED
 CVE-2026-62420 (An authorization bypass vulnerability in LXD allows an authenticated a ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-v9wr-9r7q-fh4g
 	NOTE: https://github.com/canonical/lxd/pull/18605
 	NOTE: https://github.com/canonical/lxd/pull/18651 (stable-5.21)
@@ -22789,6 +22827,7 @@ CVE-2026-16480 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is affe
 	NOT-FOR-US: IBM
 CVE-2026-16033 (A path traversal vulnerability in LXD allows an attacker to achieve ar ...)
 	- lxd <removed>
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-9hcm-hxh5-7xxh
 CVE-2026-15424
 	REJECTED
@@ -23158,14 +23197,19 @@ CVE-2026-49262 (In the Aimeos Pagible content management system prior to version
 	NOT-FOR-US: Aimeos Pagible content management system
 CVE-2026-48554 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable ...)
 	- nagios4 <unfixed> (bug #1144495)
+	NOTE: Fixed by: https://github.com/NagiosEnterprises/nagioscore/commit/1d1f65390dae0bdff05da4ccba4b2db58c0f0d8e (nagios-4.5.14)
 CVE-2026-48553 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable ...)
 	- nagios4 <unfixed> (bug #1144495)
+	NOTE: Fixed by: https://github.com/NagiosEnterprises/nagioscore/commit/0b68220529d461c9fba198a904049ea332bdb1da (nagios-4.5.13)
 CVE-2026-48552 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable ...)
 	- nagios4 <unfixed> (bug #1144495)
+	NOTE: Fixed by: https://github.com/NagiosEnterprises/nagioscore/commit/acd2365e816dda4a8dce61709f8d3a3b4ab04a6f (nagios-4.5.14)
 CVE-2026-48551 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 contain a cros ...)
 	- nagios4 <unfixed> (bug #1144495)
+	NOTE: Fixed by: https://github.com/NagiosEnterprises/nagioscore/commit/bcd4c2a4b5dfe51bdb2b227af8945ad8751a820d (nagios-4.5.14)
 CVE-2026-48550 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable ...)
 	- nagios4 <unfixed> (bug #1144495)
+	NOTE: Fixed by: https://github.com/NagiosEnterprises/nagioscore/commit/acd2365e816dda4a8dce61709f8d3a3b4ab04a6f (nagios-4.5.14)
 CVE-2026-47234 (Admidio is an open-source user management solution. Prior to version 5 ...)
 	NOT-FOR-US: Admidio
 CVE-2026-47233 (Admidio is an open-source user management solution. Version 5.0.9 adde ...)
@@ -26487,16 +26531,22 @@ CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella a
 CVE-2026-66486 (GNU cpio is vulnerable to improper encoding or escaping of output in i ...)
 	- cpio <unfixed> (bug #1144387)
 	[trixie] - cpio <no-dsa> (Minor issue)
+	[bookworm] - cpio <postponed> (Minor issue)
+	[bullseye] - cpio <postponed> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=2ff9600c9ef32e88759843cdbde74c8db5ae9b30
 CVE-2026-66485 (GNU cpio is vulnerable to an uncontrolled memory allocation in the mak ...)
 	- cpio <unfixed> (bug #1144387)
 	[trixie] - cpio <no-dsa> (Minor issue)
+	[bookworm] - cpio <postponed> (Minor issue)
+	[bullseye] - cpio <postponed> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=3cd514031371d8aeeaf2048aa10103e02831aaa9
 CVE-2026-66484 (GNU cpio contains a Path Traversal vulnerability in its tar archive ex ...)
 	- cpio <unfixed> (bug #1144387)
 	[trixie] - cpio <no-dsa> (Minor issue)
+	[bookworm] - cpio <postponed> (Minor issue)
+	[bullseye] - cpio <postponed> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=e2b9cbdd3354d2b1569b7390d1bc15c1930559ad
 CVE-2026-66411 (DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authenticatio ...)
@@ -29226,6 +29276,7 @@ CVE-2026-58262 (Klever-Go is the Go implementation of the Klever blockchain prot
 CVE-2026-54338 (JupyterHub is software that allows users to create a multi-user server ...)
 	- jupyterhub <unfixed> (bug #1143967)
 	[trixie] - jupyterhub <no-dsa> (Minor issue)
+	[bookworm] - jupyterhub <postponed> (Minor issue)
 	NOTE: https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h
 	NOTE: Fixed by: https://github.com/jupyterhub/jupyterhub/commit/d6dc595f84b7509969686da31d87d6d69e7fce0a (5.5.0)
 CVE-2026-52880 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
@@ -29383,6 +29434,8 @@ CVE-2026-71852 (pypdf is a free and open-source pure-python PDF library. Prior t
 	NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/51cb6acf9e8a35b77e90b4d87d28fe3e1416d7d7 (6.15.0)
 CVE-2026-71851 (crypto-js is a JavaScript library of crypto standards. Versions of cry ...)
 	- cryptojs <removed>
+	[bookworm] - cryptojs <postponed> (Minor issue, low popcon)
+	[bullseye] - cryptojs <postponed> (Minor issue, low popcon)
 	NOTE: https://github.com/brix/crypto-js/security/advisories/GHSA-rg76-677x-56q9
 CVE-2026-71850 (Hono is a Web application framework that provides support for any Java ...)
 	NOT-FOR-US: Hono
@@ -29595,6 +29648,7 @@ CVE-2026-19079 (A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerabilit
 	NOTE: Fixed by: https://github.com/SELinuxProject/selinux/commit/a556538c2d5d2583273e025b45c02651fef47679
 CVE-2026-18497 (A heap-buffer-overflow vulnerability exists in the nothings stb TrueTy ...)
 	- libstb <undetermined>
+	NOTE: https://github.com/nothings/stb/issues/1962
 	TODO: check, missing upstream details
 CVE-2026-17603 (Nexus Repository 3 did not sufficiently restrict which HikariCP connec ...)
 	NOT-FOR-US: Sonatype
@@ -29696,8 +29750,10 @@ CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. P
 CVE-2026-71497 (jsoup is a Java library for working with real-world HTML. From 1.14.3  ...)
 	- jsoup <unfixed> (bug #1143906)
 	[trixie] - jsoup <no-dsa> (Minor issue)
+	[bullseye] - jsoup <not-affected> (Vulnerable code introduced in 1.14.3)
 	NOTE: https://github.com/jhy/jsoup/security/advisories/GHSA-pmhh-3w7g-xqp8
 	NOTE: https://github.com/jhy/jsoup/issues/2538
+	NOTE: Introduced by: https://github.com/jhy/jsoup/commit/86602ebe8827631d291d56705cfd61f5ef513e62 (jsoup-1.14.3)
 	NOTE: Fixed by: https://github.com/jhy/jsoup/commit/92f1aca552548b484bc7d4b94c51e48b8e6eca70 (jsoup-1.23.1)
 CVE-2026-71488 (league/commonmark is a PHP library for parsing and rendering CommonMar ...)
 	- php-league-commonmark 2.9.0-1
@@ -33031,6 +33087,7 @@ CVE-2026-61523 (WebsiteBaker CMS before 2.13.10 contains a code injection vulner
 CVE-2026-61372 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
 	- apache-jena <unfixed> (bug #1143599)
 	[trixie] - apache-jena <no-dsa> (Minor issue)
+	[bookworm] - apache-jena <postponed> (Minor issue)
 	NOTE: https://lists.apache.org/thread/h206tpxtbzts7m254og6ffqljjdjkm84
 CVE-2026-60011 (Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly a ...)
 	NOT-FOR-US: Sharp and Toshiba Tec MFPs
@@ -55387,6 +55444,7 @@ CVE-2026-4661 (The WP CTA \u2013 Sticky CTA Builder, Generate Leads, Promote Sal
 CVE-2026-49844 (Improper encoding of non-finite floating-point values during MapMessag ...)
 	- apache-log4j2 <unfixed> (bug #1141960)
 	[trixie] - apache-log4j2 <no-dsa> (Minor issue)
+	[bookworm] - apache-log4j2 <postponed> (Minor issue; same as CVE-2026-34481)
 	NOTE: https://logging.apache.org/security.html#CVE-2026-49844
 	NOTE: https://github.com/apache/logging-log4j2/pull/4163
 	NOTE: Fixed by: https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300 (2.x branch)
@@ -56591,6 +56649,7 @@ CVE-2026-12593 (The implementation of an internalandundocumentedDashboardAPI end
 CVE-2026-12590 (Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 ( ...)
 	- node-body-parser 2.3.0+~1.19.6-1 (bug #1143074)
 	[trixie] - node-body-parser <no-dsa> (Minor issue)
+	[bookworm] - node-body-parser <postponed> (Minor issue)
 	NOTE: https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6
 	NOTE: https://github.com/expressjs/body-parser/pull/698
 	NOTE: Fixed by: https://github.com/expressjs/body-parser/commit/2322e111cc321413ec2b7b76d01be533d3de9d7d (v2.3.0)
@@ -198375,21 +198434,21 @@ CVE-2025-54291 (Information disclosure in images API in Canonical LXD before 6.5
 	- incus 6.0.5-1
 	- lxd <removed>
 	[trixie] - lxd <ignored> (Minor issue, no fixed planned by upstream for 5.0)
-	[bookworm] - lxd <ignored> (Minor issue, no fixed planned by upstream for 5.0)
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-xch9-h8qw-85c7
 CVE-2025-54290 (Information disclosure in image export API in Canonical LXD before 6.5 ...)
 	{DSA-6027-1}
 	- incus 6.0.5-1
 	- lxd <removed>
 	[trixie] - lxd <ignored> (Minor issue, no fixed planned by upstream for 5.0)
-	[bookworm] - lxd <ignored> (Minor issue, no fixed planned by upstream for 5.0)
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-p3x5-mvmp-5f35
 CVE-2025-54289 (Privilege Escalation in operations API in Canonical LXD <6.5 on multip ...)
 	{DSA-6027-1}
 	- incus 6.0.5-1
 	- lxd <removed>
 	[trixie] - lxd <ignored> (Minor issue, no fixed planned by upstream for 5.0)
-	[bookworm] - lxd <ignored> (Minor issue, no fixed planned by upstream for 5.0)
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-3g72-chj4-2228
 CVE-2025-54288 (Information Spoofing in devLXD Server in Canonical LXD versions 4.0 an ...)
 	{DSA-6028-1 DSA-6027-1}
@@ -263257,7 +263316,7 @@ CVE-2025-26796 (** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Input
 CVE-2025-30349 (Horde IMP through 6.2.27, as used with Horde Application Framework thr ...)
 	{DLA-4113-1}
 	- php-horde-imp <unfixed> (bug #1102003)
-	[bookworm] - php-horde-imp <ignored> (Horde in Bookworm is broken due to PHP 8 issues and will be removed in the next point release)
+	[bookworm] - php-horde-imp <end-of-life> (EOL in bookworm LTS)
 	NOTE: https://web.archive.org/web/20250321152616/https://lists.horde.org/archives/imp/Week-of-Mon-20250317/057781.html
 	NOTE: https://web.archive.org/web/20250321162434/https://lists.horde.org/archives/imp/Week-of-Mon-20250317/057784.html
 	NOTE: https://github.com/horde/imp/pull/15/
@@ -296696,7 +296755,7 @@ CVE-2024-6219 (Mark Laing discovered in LXD's PKI mode, until version 5.21.1, th
 CVE-2024-6156 (Mark Laing discovered that LXD's PKI mode, until version 5.21.2, could ...)
 	- lxd <removed> (bug #1103702)
 	[trixie] - lxd <ignored> (Minor issue; intrusive to backport)
-	[bookworm] - lxd <ignored> (Minor issue; intrusive to backport)
+	[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
 	- incus 6.0.3-1
 	NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-4c49-9fpc-hc3v
 	NOTE: Fixed by: https://github.com/canonical/lxd/commit/fb0525e1bdd6a99c4eedacbe9e6c2c7b8e0d9a89 (lxd-5.0.4)
@@ -422890,7 +422949,10 @@ CVE-2023-35031 (Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 an
 	NOT-FOR-US: Unify
 CVE-2020-36732 (The crypto-js package before 3.2.1 for Node.js generates random number ...)
 	- cryptojs <removed>
+	[bookworm] - cryptojs <postponed> (Minor issue, low popcon)
+	[bullseye] - cryptojs <postponed> (Minor issue, low popcon)
 	NOTE: https://security.snyk.io/vuln/SNYK-JS-CRYPTOJS-548472
+	NOTE: Fixed by: https://github.com/brix/crypto-js/commit/103304018778513052b3560f12a7812f4543e392 (3.2.1)
 CVE-2015-10118 (A vulnerability classified as problematic was found in cchetanonline W ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2023-3195 (A stack-based buffer overflow issue was found in ImageMagick's coders/ ...)


=====================================
data/DLA/list
=====================================
@@ -349,6 +349,7 @@
 	{CVE-2025-71276 CVE-2026-8496 CVE-2026-8851 CVE-2026-33550 CVE-2026-46445 CVE-2026-46446}
 	[bookworm] - sogo 5.8.0-2+deb12u3
 [28 Jun 2026] DLA-4656-1 tor - security update
+	{CVE-2026-77584 CVE-2026-77587 CVE-2026-77638}
 	[bookworm] - tor 0.4.9.11-0+deb12u1
 [28 Jun 2026] DLA-4655-1 libhtml-parser-perl - security update
 	{CVE-2026-8829}


=====================================
data/dla-needed.txt
=====================================
@@ -134,6 +134,10 @@ docker.io
   NOTE: 20250805: Added by Front-Desk (rouca)
   NOTE: 20260714: Also add for bookworm (Beuc/front-desk)
 --
+dovecot
+  NOTE: 20260829: Added by Front-Desk (dleidert)
+  NOTE: 20260829: Upcoming DSA (dleidert/front-desk)
+--
 dracut
   NOTE: 20260611: Added by Front-Desk (rouca)
   NOTE: 20260611: Please investigate impact of legacy network on older release of dracut aka CVE-2026-6893 (rouca/FD)
@@ -243,6 +247,9 @@ golang-glog/bullseye
 gst-plugins-bad1.0
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
+gst-plugins-base1.0
+  NOTE: 20260831: Added by Front-Desk (dleidert)
+--
 gst-plugins-good1.0
   NOTE: 20260520: Added by Front-Desk (Beuc)
   NOTE: 20260520: 6 CVEs piled up since December (Beuc)
@@ -285,6 +292,10 @@ jpeg-xl/bookworm
 kamailio
   NOTE: 20260413: Added by Front-Desk (rouca)
 --
+keystone
+  NOTE: 20260830: Added by Front-Desk (dleidert)
+  NOTE: 20260830: Upcoming DSA (dleidert/front-desk)
+--
 kitty
   NOTE: 20260522: Added by Front-Desk (Beuc)
   NOTE: 20260522: Upcoming DSA (Beuc/front-desk)
@@ -307,6 +318,9 @@ ldap-account-manager
   NOTE: 20260725: Also add for bookworm (8.3); CVE-2026-27894 PDF-export LFI,
   NOTE: 20260725: unvalidated pdf_structure/pdf_font identical to bullseye. (utkarsh/front-desk)
 --
+libapache2-mod-auth-openidc (dleidert)
+  NOTE: 20260830: Added by Front-Desk (dleidert)
+--
 libarchive (Abhijith PA)
   NOTE: 20260804: Added by Front-Desk. Take care of CVE-2026-15028 (rouca)
 --
@@ -582,6 +596,11 @@ opensc
   NOTE: 20260731: Added by Front-Desk (ta)
   NOTE: 20260731: lots of no-dsa issues piled up (ta)
 --
+openssl
+  NOTE: 20260830: Added by Front-Desk (dleidert)
+  NOTE: 20260830: Another round of CVEs; follow DSA-6465-1 (dleidert/front-desk)
+  NOTE: 20260830: For Bookworm, 3.0.22 should contain all fixes (dleidert/front-desk)
+--
 openvpn/bullseye
   NOTE: 20260703: Added by Front-Desk (dleidert)
   NOTE: 20260703: A regression has been reported; and a new set of CVEs is out (dleidert/front-desk)
@@ -796,6 +815,10 @@ rust-openssl/bullseye
   NOTE: 20251107: https://buildd.debian.org/status/package.php?p=rust-debcargo&suite=bullseye-security
   NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
 --
+sabnzbdplus
+  NOTE: 20260830: Added by Front-Desk (dleidert)
+  NOTE: 20260830: Follow DSA 6454-1 (dleidert/front-desk)
+--
 samba (Markus Koschany)
   NOTE: 20260809: Added by Front-Desk (rouca)
 --
@@ -857,6 +880,10 @@ suricata/bullseye
   NOTE: 20250331: re added to fix next bunch of CVEs (ta)
   NOTE: 20250825: testing package (ta)
 --
+suricata-update
+  NOTE: 20260830: Added by Front-Desk (dleidert)
+  NOTE: 20260830: Follow DSA-6475-1 (dleidert/front-desk)
+--
 swift
   NOTE: 20260726: Added by Front-Desk (utkarsh)
   NOTE: 20260726: CVE-2026-50221: proxy gatekeeper does not strip the
@@ -975,6 +1002,10 @@ zabbix/bullseye
   NOTE: 20260328: Added by Front-Desk (Beuc)
   NOTE: 20260328: CVE-2026-23919->24 appear to be in supported scope (Beuc/front-desk)
 --
+zfs-linux
+  NOTE: 20260830: Added by Front-Desk (dleidert)
+  NOTE: 20260830: Follow DSA-6462-1 (dleidert/front-desk)
+--
 zip
   NOTE: 20260809: Added by Front-Desk. Track #1143866 (rouca)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/f3d183a44e12343af5fd011b13eb7688aecda07d...d51273bee7feb8d668c5f11a62e2aee33b1b7d0b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/f3d183a44e12343af5fd011b13eb7688aecda07d...d51273bee7feb8d668c5f11a62e2aee33b1b7d0b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/bd080941/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list