[Git][security-tracker-team/security-tracker][master] Reserve DLA-4764-1 for libdbi-perl

Guilhem Moulin (@guilhem) guilhem at debian.org
Mon Aug 31 12:45:54 BST 2026



Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker


Commits:
843f1058 by Guilhem Moulin at 2026-08-31T13:45:38+02:00
Reserve DLA-4764-1 for libdbi-perl

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -58512,23 +58512,17 @@ CVE-2026-14895 (String::Util versions before 1.36 for Perl are susceptible to a
 CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code injection vi ...)
 	{DSA-6473-1}
 	- libdbi-perl 1.650-1 (bug #1141667)
-	[bookworm] - libdbi-perl <postponed> (Minor issue)
-	[bullseye] - libdbi-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625527/
 	NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259 (1.650)
 CVE-2026-14739 (DBI versions before 1.650 for Perl have a heap overflow when preparsin ...)
 	{DSA-6473-1}
 	- libdbi-perl 1.650-1 (bug #1141667)
-	[bookworm] - libdbi-perl <postponed> (Minor issue)
-	[bullseye] - libdbi-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625530/
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395 (1.650)
 CVE-2026-14740 (DBI versions before 1.650 for Perl read one byte out-of-bounds in prep ...)
 	{DSA-6473-1}
 	- libdbi-perl 1.650-1 (bug #1141667)
-	[bookworm] - libdbi-perl <postponed> (Minor issue)
-	[bullseye] - libdbi-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625532/
 	NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01 (1.650)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,7 @@
+[31 Aug 2026] DLA-4764-1 libdbi-perl - security update
+	{CVE-2026-14380 CVE-2026-14739 CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082 CVE-2026-73193 CVE-2026-73194}
+	[bullseye] - libdbi-perl 1.643-3+deb11u2
+	[bookworm] - libdbi-perl 1.643-4+deb12u2
 [31 Aug 2026] DLA-4763-1 librabbitmq - security update
 	{CVE-2026-59986 CVE-2026-61547}
 	[bullseye] - librabbitmq 0.10.0-1+deb11u3


=====================================
data/dla-needed.txt
=====================================
@@ -340,9 +340,6 @@ libcryptx-perl
   NOTE: 20260725: tag Copy and CVE-2026-13758 memNE both present. Sponsored in
   NOTE: 20260725: both suites. (utkarsh/front-desk)
 --
-libdbi-perl (guilhem)
-  NOTE: 20260801: Added by Front-Desk (ta)
---
 libde265
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/843f1058d65879e4927c11f4bffba42d240c03c1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/843f1058d65879e4927c11f4bffba42d240c03c1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/f0d4dd9b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list