[Git][security-tracker-team/security-tracker][master] 17 commits: lts/dla-needed: target vim in Bookworm as well
Daniel Leidert (@dleidert)
dleidert at debian.org
Mon Jul 6 04:22:02 BST 2026
Daniel Leidert pushed to branch master at Debian Security Tracker / security-tracker
Commits:
edd18ffc by Daniel Leidert at 2026-07-06T04:22:58+02:00
lts/dla-needed: target vim in Bookworm as well
Lee offered updates for Stable; maybe this did also include Bookworm?
- - - - -
6dd0c20a by Daniel Leidert at 2026-07-06T04:23:09+02:00
lts/dla-needed: fix xrdp in Bookworm as well
Bookworm and Bullseye share the same version already
- - - - -
60de5c55 by Daniel Leidert at 2026-07-06T04:23:39+02:00
lts/dla-needed: fix jetty9 in Bullseye and Bookworm
- - - - -
57739dab by Daniel Leidert at 2026-07-06T04:27:52+02:00
lts: add EOL marks for CVE-2026-4360 and CVE-2026-11972 in jython and python2.7
- - - - -
4639d204 by Daniel Leidert at 2026-07-06T04:30:46+02:00
lts: add EOL marks for open CVEs for libreswan in Bullseye
- - - - -
5def0ade by Daniel Leidert at 2026-07-06T04:32:08+02:00
lts/dla-needed: fix kamailio in Bookworm as well
- - - - -
22e5d092 by Daniel Leidert at 2026-07-06T04:33:35+02:00
lts/dla-needed: fix netty in Bookworm as well
- - - - -
18227976 by Daniel Leidert at 2026-07-06T04:34:42+02:00
lts/dla-needed: fix perl in Bookworm as well
- - - - -
3e01d0bf by Daniel Leidert at 2026-07-06T04:45:28+02:00
lts/dla-needed: add redis
- - - - -
e8db0218 by Daniel Leidert at 2026-07-06T04:46:59+02:00
lts/dla-needed: fix ruby-rack in Bookworm as well
- - - - -
ce379ad4 by Daniel Leidert at 2026-07-06T04:48:35+02:00
lts/dla-needed: handle runc in Bookworm as well
- - - - -
fc89818d by Daniel Leidert at 2026-07-06T04:56:18+02:00
Mark CVE-2025-71385/netdata as not affecting any distribution
The vulnerable ilove endpoint is not part of any release in Debian.
- - - - -
1427ada6 by Daniel Leidert at 2026-07-06T05:04:54+02:00
lts: mark CVE-2026-27953/ormar as postponed
popcon numbers <10
- - - - -
364877a8 by Daniel Leidert at 2026-07-06T05:08:58+02:00
lts: mark CVE-2025-26240/pdfkit as postponed in Bookworm and Bullseye
- - - - -
55ce04d8 by Daniel Leidert at 2026-07-06T05:13:28+02:00
lts: ignore CVE-2024-29370/python-jose in Bookworm
The description is the same as CVE-2024-29370, which is already ignored.
- - - - -
0ffa3766 by Daniel Leidert at 2026-07-06T05:17:09+02:00
lts: ignore CVE-2015-1554/kgb-bot
It has been ignored for the past >10 years
- - - - -
ee844765 by Daniel Leidert at 2026-07-06T05:20:39+02:00
lts: mark CVE-2026-44587/ruby-carrierwave as postponed
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -784,10 +784,12 @@ CVE-2026-52187 (Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-21091
NOT-FOR-US: UTT
CVE-2026-50722 (Libreswan, via the function RSA_authenticate_hash_signature_pkcs1_1_5_ ...)
- libreswan <unfixed> (bug #1141390)
+ [bullseye] - libreswan <end-of-life> (EOL in bullseye LTS)
NOTE: https://libreswan.org/security/CVE-2026-50722/CVE-2026-50722.txt
NOTE: Patches: https://libreswan.org/security/CVE-2026-50722/
CVE-2026-50721 (Libreswan, via the function RSA_authenticate_hash_signature_raw_rsa(), ...)
- libreswan <unfixed> (bug #1141390)
+ [bullseye] - libreswan <end-of-life> (EOL in bullseye LTS)
NOTE: https://libreswan.org/security/CVE-2026-50721/CVE-2026-50721.txt
NOTE: Patches: https://libreswan.org/security/CVE-2026-50721/
CVE-2026-4967 (In IMS, there is a possible out of bounds read due to a missing bounds ...)
@@ -866,12 +868,15 @@ CVE-2026-12557 (The Ninja Forms - File Uploads plugin for WordPress is vulnerabl
NOT-FOR-US: WordPress plugin
CVE-2026-12413 (An invalidly formatted IKEv2 fragment causes the Libreswan pluto daemo ...)
- libreswan <unfixed> (bug #1141390)
+ [bullseye] - libreswan <end-of-life> (EOL in bullseye LTS)
NOTE: https://libreswan.org/security/CVE-2026-12413/CVE-2026-12413.txt
NOTE: Patches: https://libreswan.org/security/CVE-2026-12413/
CVE-2026-11397 (The WP Import Export Lite plugin for WordPress is vulnerable to Server ...)
NOT-FOR-US: WordPress plugin
CVE-2025-71385 (Netdata before 2.3.1 reflects the user-supplied love query parameter o ...)
- netdata <removed>
+ [bookworm] - netdata <not-affected> (Vulnerable endpoint not existent)
+ [bullseye] - netdata <not-affected> (Vulnerable endpoint not existent)
NOTE: https://github.com/netdata/netdata/commit/f82554fe9b21b5ae51a8663a3f4ddce84cac16af (v2.4.0)
NOTE: https://github.com/netdata/netdata/pull/19919
CVE-2022-4990 (** UNSUPPORTED WHEN ASSIGNED ** Improper Validation of Specified Quant ...)
@@ -4405,7 +4410,9 @@ CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not pa
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
+ [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- jython <unfixed>
+ [bullseye] - jython <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed> (bug #1141531)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/TWZW2PC2AZOV6FENIHFSRC63OM7MBGSB/
NOTE: https://github.com/python/cpython/issues/151987
@@ -10133,6 +10140,7 @@ CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming
- python3.9 <removed>
[bullseye] - python3.9 <postponed> (Minor issue)
- python2.7 <removed>
+ [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed> (bug #1141534)
[trixie] - pypy3 <no-dsa> (Minor issue)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/AXPSKKTSRKXTTJULW3XSIC74WZNAAPPB/
@@ -13238,6 +13246,8 @@ CVE-2025-31013 (Improper Neutralization of Input During Web Page Generation ('Cr
NOT-FOR-US: WordPress plugin or theme
CVE-2025-26240 (In JazzCore python-pdfkit 1.0.0, the from_string method enables the ex ...)
- pdfkit <removed>
+ [bookworm] - pdfkit <postponed> (Minor issue; revisit when fixed upstream)
+ [bullseye] - pdfkit <postponed> (Minor issue; revisit when fixed upstream)
NOTE: https://habuon.github.io/2025/03/12/pdfkit-vulnerability-%28CVE-2025-26240%29.html
CVE-2025-15657 (Unauthenticated Insecure Direct Object References (IDOR) in School Man ...)
NOT-FOR-US: WordPress plugin or theme
@@ -13689,6 +13699,7 @@ CVE-2026-46765 (Vulnerability in the Oracle WebCenter Portal product of Oracle F
NOT-FOR-US: Oracle
CVE-2026-44587 (CarrierWave is a framework to upload files from Ruby applications. In ...)
- ruby-carrierwave <removed>
+ [bookworm] - ruby-carrierwave <postponed> (Minor issue)
NOTE: https://github.com/carrierwaveuploader/carrierwave/security/advisories/GHSA-7g26-2qgj-chfg
NOTE: https://github.com/carrierwaveuploader/carrierwave/commit/4c4a005775a436c5165df014dc9b1874c227d86c (v2.2.7)
CVE-2026-40761 (Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.)
@@ -44402,6 +44413,7 @@ CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of r
CVE-2026-23479 (Redis is an in-memory data structure store. In redis-server from 7.2.0 ...)
[experimental] - redis 5:8.6.3-1
- redis <unfixed>
+ [bookworm] - redis <not-affected> (Vulnerable code not present)
[bullseye] - redis <not-affected> (Vulnerable code not present)
NOTE: https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3
NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-23479-deep-dive
@@ -70785,6 +70797,7 @@ CVE-2026-28282 (Discourse is an open-source discussion platform. Versions prior
NOT-FOR-US: Discourse
CVE-2026-27953 (ormar is a async mini ORM for Python. Versions 0.23.0 and below are vu ...)
- ormar 0.23.1-1 (bug #1131494)
+ [bookworm] - ormar <postponed> (Low popcon)
NOTE: https://github.com/ormar-orm/ormar/security/advisories/GHSA-f964-whrq-44h8
NOTE: Fixed by: https://github.com/ormar-orm/ormar/commit/7f22aa21a7614b993970345b392dabb0ccde0ab3 (0.23.1)
CVE-2026-27936 (Discourse is an open-source discussion platform. Prior to versions 202 ...)
@@ -110560,6 +110573,7 @@ CVE-2024-29371 (In jose4j before 0.9.6, an attacker can cause a Denial-of-Servic
NOTE: Fixed by: https://bitbucket.org/b_c/jose4j/commits/19a90a64c47bb07c4aa5462f1316d5c293d81fcf
CVE-2024-29370 (In python-jose 3.3.0 (specifically jwe.decrypt), a vulnerability allow ...)
- python-jose <removed>
+ [bookworm] - python-jose <ignored> (Minor issue, similar to CVE-2024-33664)
NOTE: https://github.com/mpdavis/python-jose/issues/344
NOTE: https://github.com/mpdavis/python-jose/pull/352
NOTE: Fixed by: https://github.com/mpdavis/python-jose/commit/8e1f521a7588dd6bfe553c3d3f320ab7a55bba36 (3.4.0)
@@ -300076,7 +300090,7 @@ CVE-2024-33665 (angular-translate through 2.19.1 allows XSS via a crafted key th
NOT-FOR-US: angular-translate
CVE-2024-33664 (python-jose through 3.3.0 allows attackers to cause a denial of servic ...)
- python-jose <removed> (bug #1070375)
- [bookworm] - python-jose <ignored> (Minor issue)
+ [bookworm] - python-jose <ignored> (Minor issue, similar to CVE-2024-29370)
NOTE: https://github.com/mpdavis/python-jose/issues/344
NOTE: https://github.com/mpdavis/python-jose/pull/345
CVE-2024-33663 (python-jose through 3.3.0 has algorithm confusion with OpenSSH ECDSA k ...)
@@ -844865,6 +844879,7 @@ CVE-2015-1401 (Improper Authentication vulnerability in the "LDAP / SSO Authenti
NOT-FOR-US: typo3 extension
CVE-2015-1554 (kgb-bot 1.33-2 allows remote attackers to cause a denial of service (c ...)
- kgb-bot <undetermined> (low; bug #776424)
+ [bookworm] - kgb-bot <ignored> (Minor issue)
[bullseye] - kgb-bot <ignored> (Minor issue, not reproducible)
[buster] - kgb-bot <ignored> (Minor issue, not reproducible)
NOTE: 20190201: random crash still not reproducible
=====================================
data/dla-needed.txt
=====================================
@@ -273,14 +273,14 @@ isc-kea/bookworm
NOTE: 20260224: Added by Security Team (jmm)
NOTE: 20260611: bookworm LTS handover.
--
-jetty9/bullseye
+jetty9
NOTE: 20260418: Added by Front-Desk. Fix CVE-2026-5795 maybe other (rouca)
--
jpeg-xl/bookworm
NOTE: 20260619: Added by Front-Desk (charles)
NOTE: 20260619: Follow DSA-6342-1 (charles)
--
-kamailio/bullseye
+kamailio
NOTE: 20260413: Added by Front-Desk (rouca)
--
kitty
@@ -444,7 +444,7 @@ netatalk/bullseye
NOTE: 20260518: ~low popcon, no sponsors, only fix if backporting the single
NOTE: 20260518: consolidated patch is straightforward enough (Beuc/front-desk)
--
-netty/bullseye (rouca)
+netty (rouca)
NOTE: 20250814: Added by Front-Desk (lamby)
NOTE: 20251115: Partial release for sid. Fix all CVEs except CVE-2025-58056 (rouca)
NOTE: 20251127: all CVEs fixed under sid (rouca)
@@ -510,7 +510,7 @@ pacemaker
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Package is in dsa-needed (charles)
--
-perl/bullseye
+perl
NOTE: 20260527: Added by Front-Desk (santiago)
NOTE: 20260527: wait for the DSA before releasing
--
@@ -567,6 +567,10 @@ rabbitmq-server/bullseye
NOTE: 20260504: Added by coordinator (santiago)
NOTE: 20260504: Added to address out-standing minor issues
--
+redis
+ NOTE: 20260706: Added by Front-Desk (dleidert)
+ NOTE: 20260706: Follow upcoming DSA and care about piled-up CVEs (dleidert/front-desk)
+--
request-tracker4/bullseye (Andrew Ruthven)
NOTE: 20260529: Added by Front-Desk (dleidert)
NOTE: 20260529: Follow DSA in preparation by maintainer (dleidert/front-desk)
@@ -577,15 +581,16 @@ rsync (Thorsten Alteholz)
NOTE: 20260615: Requested by Sylvain to track regressions, same as in dsa-needed. (charles)
NOTE: 20260705: making progress with updated patches
--
-ruby-rack/bullseye (Abhijith PA)
+ruby-rack (Abhijith PA)
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260608: https://people.debian.org/~abhijith/upload/rr/ (abhijith)
+ NOTE: 20260706: Please check Bookworm as well (dleidert/front-desk)
--
ruby2.7/bullseye (Abhijith PA)
NOTE: 20260419: Added by Front-Desk (rouca)
NOTE: 20260608: https://people.debian.org/~abhijith/upload/ruby2.7_patches/ (abhijith)
--
-runc/bullseye
+runc
NOTE: 20251105: Added by Front-Desk (Beuc)
NOTE: 20251105: 3 high-severity container breakouts. Used by docker.io.
NOTE: 20251105: This could be hard to backport so maybe check with the security team
@@ -597,6 +602,7 @@ runc/bullseye
NOTE: 20251203: The other option is to drop support as it is on limited support (written in Go) already. (jspricke)
NOTE: 20260212: Try to rebuild new upstream versions against Trixie, update #1120140 (arnaudr)
NOTE: 20260223: Updated #1120140 with some thoughts, asking for more opinions (kanashiro)
+ NOTE: 20260706: Please handle Bookworm as well (dleidert/front-desk)
--
rust-openssl/bullseye
NOTE: 20250209: Added by Front-Desk (apo)
@@ -676,11 +682,12 @@ util-linux (eamanu)
NOTE: 20260619: Added by Front-Desk (charles)
NOTE: 20260619: In dsa-needed, sync with secteam or follow DSA. (charles)
--
-vim/bullseye (lee)
+vim (lee)
NOTE: 20260217: Added by Front-Desk (rouca)
NOTE: 20260228: I enabled the salsa pipeline, there are (previously undetected)
NOTE: 20260228: test failures. Working on ignoring them so the pipeline will be
NOTE: 20260228: useful to spot regressions. (paride)
+ NOTE: 20260706: Fix Bookworm as well; was this already intended when offering the updates for stable/DSA? (dleidert/front-desk)
--
vips/bullseye
NOTE: 20260522: Added by Front-Desk (Beuc)
@@ -714,8 +721,9 @@ xorg-server/bullseye
NOTE: 20260522: Added by Front-Desk (Beuc)
NOTE: 20260522: Follow bookworm 12.14 (5 CVEs) (Beuc/front-desk)
--
-xrdp/bullseye (Abhijith PA)
+xrdp (Abhijith PA)
NOTE: 20260418: Added by Front-Desk (rouca)
+ NOTE: 20260706: Bookworm/Bullseye share the same version - fix in Bookworm first (dleidert/front-desk)
--
zabbix/bullseye
NOTE: 20260328: Added by Front-Desk (Beuc)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/01971b8219a94a84fb716adf90a194f6b79fe660...ee844765974e6221e285ee946cf73fc450a6f857
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/01971b8219a94a84fb716adf90a194f6b79fe660...ee844765974e6221e285ee946cf73fc450a6f857
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260706/e34e40e3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list