[Git][security-tracker-team/security-tracker][master] Reserve DLA-4762-1 for libarchive
Abhijith PA (@abhijith)
abhijith at debian.org
Mon Aug 31 08:19:10 BST 2026
Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker
Commits:
07f44ef0 by Abhijith PA at 2026-08-31T12:48:49+05:30
Reserve DLA-4762-1 for libarchive
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -64577,8 +64577,6 @@ CVE-2026-28979 (An out-of-bounds access issue was addressed with improved bounds
CVE-2026-14164 (A double free issue has been identified in libarchive's RAR5 reader. D ...)
- libarchive 3.8.8-1 (bug #1141180)
[trixie] - libarchive <no-dsa> (Minor issue)
- [bookworm] - libarchive <postponed> (Minor issue, DoS)
- [bullseye] - libarchive <postponed> (Minor issue, DoS)
NOTE: https://github.com/libarchive/libarchive/issues/3069
NOTE: https://github.com/libarchive/libarchive/pull/3071
NOTE: https://github.com/libarchive/libarchive/commit/1c914cdfef533cbee1ae3aa21a89ba02ed4d5f61 (master)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,7 @@
+[31 Aug 2026] DLA-4762-1 libarchive - security update
+ {CVE-2026-14164 CVE-2026-15028 CVE-2026-16517}
+ [bullseye] - libarchive 3.4.3-2+deb11u5
+ [bookworm] - libarchive 3.6.2-1+deb12u5
[30 Aug 2026] DLA-4761-1 libnet-dns-perl - security update
{CVE-2026-64194}
[bullseye] - libnet-dns-perl 1.29-1+deb11u1
=====================================
data/dla-needed.txt
=====================================
@@ -321,9 +321,6 @@ ldap-account-manager
libapache2-mod-auth-openidc (dleidert)
NOTE: 20260830: Added by Front-Desk (dleidert)
--
-libarchive (Abhijith PA)
- NOTE: 20260804: Added by Front-Desk. Take care of CVE-2026-15028 (rouca)
---
libass
NOTE: 20260712: Added by Front-Desk (utkarsh)
NOTE: 20260712: TEMP-0000000-AA08BC (GHSA-pjjp-65r7-ppgm): OOB read+write in wrap_lines_measure from untrusted subtitles; secteam fixed stable via point release. Affected in bullseye (0.15.0) and bookworm (0.17.1). (utkarsh/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07f44ef04ebede918f9663feef408b054f02e9b2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/07f44ef04ebede918f9663feef408b054f02e9b2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/e0774b8f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list