[Git][security-tracker-team/security-tracker][master] 5 commits: mark CVE-2026-24001 as postponed for Bullseye
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Thu Feb 5 15:19:33 GMT 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
853cce79 by Thorsten Alteholz at 2026-02-05T16:19:07+01:00
mark CVE-2026-24001 as postponed for Bullseye
- - - - -
afa5991a by Thorsten Alteholz at 2026-02-05T16:19:08+01:00
add phpunit
- - - - -
58b766f3 by Thorsten Alteholz at 2026-02-05T16:19:10+01:00
mark CVE-2025-8194 as postponed for Bullseye
- - - - -
a9d8d624 by Thorsten Alteholz at 2026-02-05T16:19:12+01:00
mark CVE-2026-1703 as postponed for Bullseye
- - - - -
d49be00d by Thorsten Alteholz at 2026-02-05T16:19:14+01:00
mark CVE-2026-25541 as not-affected in Bullseye and add NOTE about introduced commit
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -805,9 +805,11 @@ CVE-2026-25541 (Bytes is a utility library for working with bytes. From version
- rust-bytes 1.11.1-1
[trixie] - rust-bytes <no-dsa> (Minor issue)
[bookworm] - rust-bytes <no-dsa> (Minor issue)
+ [bullseye] - rust-bytes <not-affected> (Vulnerable code was introduced in v1.2.1)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0007.html
NOTE: https://github.com/advisories/GHSA-434x-w66g-qw3r
NOTE: Fixed by: https://github.com/tokio-rs/bytes/commit/d0293b0e35838123c51ca5dfdf468ecafee4398f (v1.11.1)
+ NOTE: Introduced by: https://github.com/tokio-rs/bytes/commit/d6e1999d978a688625441348a81504ccab669aed (v1.2.1)
CVE-2026-1801 (A flaw was found in libsoup, an HTTP client/server library. This HTTP ...)
- libsoup3 3.6.5-8
[trixie] - libsoup3 <no-dsa> (Minor issue)
@@ -1530,6 +1532,7 @@ CVE-2026-1703 (When pip is installing and extracting a maliciously crafted wheel
- python-pip 26.0+dfsg-1 (bug #1126875)
[trixie] - python-pip <no-dsa> (Minor issue)
[bookworm] - python-pip <no-dsa> (Minor issue)
+ [bullseye] - python-pip <postponed> (Minor issue)
NOTE: https://github.com/pypa/pip/pull/13777
NOTE: Fixed by: https://github.com/pypa/pip/commit/4c651b70d60ed91b13663bcda9b3ed41748d0124 (26.0)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ/
@@ -4845,6 +4848,7 @@ CVE-2026-24001 (jsdiff is a JavaScript text differencing implementation. Prior t
- node-diff <unfixed> (bug #1126272)
[trixie] - node-diff <no-dsa> (Minor issue)
[bookworm] - node-diff <no-dsa> (Minor issue)
+ [bullseye] - node-diff <postponed> (Minor issue)
NOTE: https://github.com/kpdecker/jsdiff/security/advisories/GHSA-73rr-hh4g-fpgx
NOTE: https://github.com/kpdecker/jsdiff/issues/653
NOTE: https://github.com/kpdecker/jsdiff/pull/649
@@ -70098,6 +70102,7 @@ CVE-2025-8194 (There is a defect in the CPython \u201ctarfile\u201d module affec
- pypy3 <unfixed> (bug #1126758)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <no-dsa> (Minor issue)
+ [bullseye] - pypy3 <postponed> (Minor issue)
NOTE: https://github.com/python/cpython/issues/130577
NOTE: https://github.com/python/cpython/pull/137027
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/
=====================================
data/dla-needed.txt
=====================================
@@ -323,6 +323,9 @@ php-laravel-framework
NOTE: 20251027: tests is required to prevent regressions, but I could not get the upstream
NOTE: 20251027: test suite to work. It is not exercised as part of Debian packages build. (paride)
--
+phpunit
+ NOTE: 20260205: Added by Front-Desk (ta)
+--
python-aiohttp (dleidert)
NOTE: 20260106: Added by Front-Desk (lamby)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6051fd7faaa16a6277f7173c75d2974b00102187...d49be00d7ed927c177ef77388c70b3f75c84038e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6051fd7faaa16a6277f7173c75d2974b00102187...d49be00d7ed927c177ef77388c70b3f75c84038e
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260205/8fee0a6e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list