[Git][security-tracker-team/security-tracker][master] trixie/bookworm triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Jan 19 11:56:58 GMT 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5ccf6207 by Moritz Muehlenhoff at 2026-01-19T12:55:44+01:00
trixie/bookworm triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -719,7 +719,9 @@ CVE-2025-61731 [cmd/go: bypass of flag sanitization can lead to arbitrary code e
CVE-2025-68121 [crypto/tls: Config.Clone copies automatically generated session ticket keys, session resumption does not account for the expiration of full certificate chain]
- golang-1.25 <unfixed> (bug #1125916)
- golang-1.24 <unfixed> (bug #1125917)
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
+ [bookworm] - golang-1.19 <no-dsa> (Minor issue)
- golang-1.15 <removed>
NOTE: https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
NOTE: https://github.com/golang/go/issues/77113
@@ -728,7 +730,9 @@ CVE-2025-68121 [crypto/tls: Config.Clone copies automatically generated session
CVE-2025-61726 [net/http: memory exhaustion in Request.ParseForm]
- golang-1.25 <unfixed> (bug #1125916)
- golang-1.24 <unfixed> (bug #1125917)
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
+ [bookworm] - golang-1.19 <no-dsa> (Minor issue)
- golang-1.15 <removed>
NOTE: https://groups.google.com/g/golang-announce/c/Vd2tYVM8eUc
NOTE: https://github.com/golang/go/issues/77101
@@ -1194,6 +1198,8 @@ CVE-2026-22211 (TinyOS versions up to and including 2.1.2 contain a global buffe
NOT-FOR-US: TinyOS
CVE-2026-22036 (Undici is an HTTP/1.1 client for Node.js. Prior to 7.18.0 and 6.23.0, ...)
- node-undici 7.18.2+dfsg+~cs3.2.0-1 (bug #1125679)
+ [trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <no-dsa> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-g9mf-h72j-4rw9
NOTE: Fixed by: https://github.com/nodejs/undici/commit/b04e3cbb569c1596f86c108e9b52c79d8475dcb3 (v7.18.2)
CVE-2026-21889 (Weblate is a web based localization tool. Prior to 5.15.2, the screens ...)
@@ -89023,7 +89029,7 @@ CVE-2025-37730 (Improper certificate validation in Logstash's TCP output could l
- logstash <itp> (bug #664841)
CVE-2025-32022 (Finit provides fast init for Linux systems. Finit's urandom plugin has ...)
- finit 4.12-1 (bug #1104932)
- [bookworm] - finit <no-dsa> (Minor issue)
+ [bookworm] - finit <ignored> (Minor issue)
NOTE: https://github.com/troglobit/finit/security/advisories/GHSA-fv6v-vw8h-9x79
NOTE: Fixed by: https://github.com/troglobit/finit/commit/3feff37ba51fa0a6a0a06f59682a0918aa5b04de (4.12)
CVE-2025-30165 (vLLM is an inference and serving engine for large language models. In ...)
@@ -91884,7 +91890,7 @@ CVE-2025-30202 (vLLM is a high-throughput and memory-efficient inference and ser
- vllm <itp> (bug #1095237)
CVE-2025-29906 (Finit is a fast init for Linux systems. Versions starting from 3.0-rc1 ...)
- finit 4.11-1
- [bookworm] - finit <no-dsa> (Minor issue)
+ [bookworm] - finit <ignored> (Minor issue)
NOTE: https://github.com/troglobit/finit/security/advisories/GHSA-563g-p98j-mc9q
NOTE: https://github.com/troglobit/finit/commit/6528628b5c771c25ffa0cb1a46c6c89d9d0d69e0 (4.11-rc1)
CVE-2025-25962 (An issue in Coresmartcontracts Uniswap v.3.0 and fixed in v.4.0 allows ...)
@@ -247893,7 +247899,7 @@ CVE-2023-44487 (The HTTP/2 protocol allows a denial of service (server resource
- jetty9 9.4.53-1
- netty 1:4.1.48-8 (bug #1054234)
- dnsdist 1.8.2-2
- [bookworm] - dnsdist <no-dsa> (Minor issue)
+ [bookworm] - dnsdist <end-of-life> (See #1119290)
[bullseye] - dnsdist <no-dsa> (Minor issue)
[buster] - dnsdist <not-affected> (HTTP/2 support was added later)
- varnish 7.5.0-1 (bug #1056156)
=====================================
data/dsa-needed.txt
=====================================
@@ -43,6 +43,8 @@ mbedtls/oldstable
netty
Bastien Roucaries proposing an update
--
+nodejs
+--
opennds/oldstable
pinged maintainer, but no reply yet. should most probably be bumped to 10.x
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ccf6207c88303850e03d199b14360e0be083c5e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ccf6207c88303850e03d199b14360e0be083c5e
You're receiving this email because of your account on salsa.debian.org.
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260119/af2c1e4b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list