[Git][security-tracker-team/security-tracker][master] trixie/bookworm triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Jan 19 11:56:58 GMT 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5ccf6207 by Moritz Muehlenhoff at 2026-01-19T12:55:44+01:00
trixie/bookworm triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -719,7 +719,9 @@ CVE-2025-61731 [cmd/go: bypass of flag sanitization can lead to arbitrary code e
 CVE-2025-68121 [crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain]
 	- golang-1.25 <unfixed> (bug #1125916)
 	- golang-1.24 <unfixed> (bug #1125917)
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <no-dsa> (Minor issue)
 	- golang-1.15 <removed>
 	NOTE: https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
 	NOTE: https://github.com/golang/go/issues/77113
@@ -728,7 +730,9 @@ CVE-2025-68121 [crypto/tls: Config.Clone copies automatically generated session
 CVE-2025-61726 [net/http: memory exhaustion in Request.ParseForm]
 	- golang-1.25 <unfixed> (bug #1125916)
 	- golang-1.24 <unfixed> (bug #1125917)
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
+	[bookworm] - golang-1.19 <no-dsa> (Minor issue)
 	- golang-1.15 <removed>
 	NOTE: https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
 	NOTE: https://github.com/golang/go/issues/77101
@@ -1194,6 +1198,8 @@ CVE-2026-22211 (TinyOS versions up to and including 2.1.2 contain a global buffe
 	NOT-FOR-US: TinyOS
 CVE-2026-22036 (Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0,  ...)
 	- node-undici 7.18.2+dfsg+~cs3.2.0-1 (bug #1125679)
+	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9
 	NOTE: Fixed by: https://github.com/nodejs/undici/commit/b04e3cbb569c1596f86c108e9b52c79d8475dcb3 (v7.18.2)
 CVE-2026-21889 (Weblate is a web based localization tool. Prior to 5.15.2, the screens ...)
@@ -89023,7 +89029,7 @@ CVE-2025-37730 (Improper certificate validation in Logstash's TCP output could l
 	- logstash <itp> (bug #664841)
 CVE-2025-32022 (Finit provides fast init for Linux systems. Finit's urandom plugin has ...)
 	- finit 4.12-1 (bug #1104932)
-	[bookworm] - finit <no-dsa> (Minor issue)
+	[bookworm] - finit <ignored> (Minor issue)
 	NOTE: https://github.com/troglobit/finit/security/advisories/GHSA-fv6v-vw8h-9x79
 	NOTE: Fixed by: https://github.com/troglobit/finit/commit/3feff37ba51fa0a6a0a06f59682a0918aa5b04de (4.12)
 CVE-2025-30165 (vLLM is an inference and serving engine for large language models. In  ...)
@@ -91884,7 +91890,7 @@ CVE-2025-30202 (vLLM is a high-throughput and memory-efficient inference and ser
 	- vllm <itp> (bug #1095237)
 CVE-2025-29906 (Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 ...)
 	- finit 4.11-1
-	[bookworm] - finit <no-dsa> (Minor issue)
+	[bookworm] - finit <ignored> (Minor issue)
 	NOTE: https://github.com/troglobit/finit/security/advisories/GHSA-563g-p98j-mc9q
 	NOTE: https://github.com/troglobit/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0 (4.11-rc1)
 CVE-2025-25962 (An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows ...)
@@ -247893,7 +247899,7 @@ CVE-2023-44487 (The HTTP/2 protocol allows a denial of service (server resource
 	- jetty9 9.4.53-1
 	- netty 1:4.1.48-8 (bug #1054234)
 	- dnsdist 1.8.2-2
-	[bookworm] - dnsdist <no-dsa> (Minor issue)
+	[bookworm] - dnsdist <end-of-life> (See #1119290)
 	[bullseye] - dnsdist <no-dsa> (Minor issue)
 	[buster] - dnsdist <not-affected> (HTTP/2 support was added later)
 	- varnish 7.5.0-1 (bug #1056156)


=====================================
data/dsa-needed.txt
=====================================
@@ -43,6 +43,8 @@ mbedtls/oldstable
 netty
   Bastien Roucaries proposing an update
 --
+nodejs
+--
 opennds/oldstable
   pinged maintainer, but no reply yet. should most probably be bumped to 10.x
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ccf6207c88303850e03d199b14360e0be083c5e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ccf6207c88303850e03d199b14360e0be083c5e
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260119/af2c1e4b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list