[Git][security-tracker-team/security-tracker][master] Reserve DLA-4764-1 for libdbi-perl
Guilhem Moulin (@guilhem)
guilhem at debian.org
Mon Aug 31 12:45:54 BST 2026
Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker
Commits:
843f1058 by Guilhem Moulin at 2026-08-31T13:45:38+02:00
Reserve DLA-4764-1 for libdbi-perl
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -58512,23 +58512,17 @@ CVE-2026-14895 (String::Util versions before 1.36 for Perl are susceptible to a
CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code injection vi ...)
{DSA-6473-1}
- libdbi-perl 1.650-1 (bug #1141667)
- [bookworm] - libdbi-perl <postponed> (Minor issue)
- [bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625527/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259 (1.650)
CVE-2026-14739 (DBI versions before 1.650 for Perl have a heap overflow when preparsin ...)
{DSA-6473-1}
- libdbi-perl 1.650-1 (bug #1141667)
- [bookworm] - libdbi-perl <postponed> (Minor issue)
- [bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625530/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395 (1.650)
CVE-2026-14740 (DBI versions before 1.650 for Perl read one byte out-of-bounds in prep ...)
{DSA-6473-1}
- libdbi-perl 1.650-1 (bug #1141667)
- [bookworm] - libdbi-perl <postponed> (Minor issue)
- [bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625532/
NOTE: https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01 (1.650)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,7 @@
+[31 Aug 2026] DLA-4764-1 libdbi-perl - security update
+ {CVE-2026-14380 CVE-2026-14739 CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082 CVE-2026-73193 CVE-2026-73194}
+ [bullseye] - libdbi-perl 1.643-3+deb11u2
+ [bookworm] - libdbi-perl 1.643-4+deb12u2
[31 Aug 2026] DLA-4763-1 librabbitmq - security update
{CVE-2026-59986 CVE-2026-61547}
[bullseye] - librabbitmq 0.10.0-1+deb11u3
=====================================
data/dla-needed.txt
=====================================
@@ -340,9 +340,6 @@ libcryptx-perl
NOTE: 20260725: tag Copy and CVE-2026-13758 memNE both present. Sponsored in
NOTE: 20260725: both suites. (utkarsh/front-desk)
--
-libdbi-perl (guilhem)
- NOTE: 20260801: Added by Front-Desk (ta)
---
libde265
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/843f1058d65879e4927c11f4bffba42d240c03c1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/843f1058d65879e4927c11f4bffba42d240c03c1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/f0d4dd9b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list