[Git][security-tracker-team/security-tracker][master] Fix order of releases

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 10 07:38:18 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
da86ccd5 by Salvatore Bonaccorso at 2026-07-10T08:37:49+02:00
Fix order of releases

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2068,8 +2068,8 @@ CVE-2026-45094
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104 (v3.6.2)
 CVE-2026-59089 (A flaw was found in GIMP. The PlayStation TIM loader, responsible for  ...)
 	- gimp <unfixed>
-	[bullseye] - gimp <not-affected> (PlayStation TIM loader plug-ins/common/file-tim.c added in GIMP 3.x; 2.10 has no such loader)
 	[bookworm] - gimp <not-affected> (PlayStation TIM loader plug-ins/common/file-tim.c added in GIMP 3.x; 2.10 has no such loader)
+	[bullseye] - gimp <not-affected> (PlayStation TIM loader plug-ins/common/file-tim.c added in GIMP 3.x; 2.10 has no such loader)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16493
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/53cdb27fa2b1676d11e9677c9975b5ad7b61b2ee
 CVE-2026-XXXX [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via unvalidated DNS header record counts]
@@ -12476,8 +12476,8 @@ CVE-2026-54555 (rtk filters and compresses command outputs before they reach you
 	NOT-FOR-US: rtk-ai rtk
 CVE-2026-54518 (jackson-databind contains the general-purpose data-binding functionali ...)
 	- jackson-databind <unfixed>
-	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	[bookworm] - jackson-databind <not-affected> (introduced in 2.21.0; bookworm ships 2.14)
+	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-rcqc-6cw3-h962
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5971
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5973
@@ -12485,8 +12485,8 @@ CVE-2026-54518 (jackson-databind contains the general-purpose data-binding funct
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/d633bc038f200c1397c07f1a2b46f58e72c91eea (jackson-databind-3.1.4)
 CVE-2026-54517 (jackson-databind contains the general-purpose data-binding functionali ...)
 	- jackson-databind <unfixed>
-	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	[bookworm] - jackson-databind <not-affected> (introduced in 2.21.0; bookworm ships 2.14)
+	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-5hh8-q8hv-fr38
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5969
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5970
@@ -12494,8 +12494,8 @@ CVE-2026-54517 (jackson-databind contains the general-purpose data-binding funct
 	NOTE: https://github.com/FasterXML/jackson-databind/commit/5bf23edb4221f7dd2ec8e71ff6d26c61640f261d (jackson-databind-3.1.4)
 CVE-2026-54516 (jackson-databind contains the general-purpose data-binding functionali ...)
 	- jackson-databind <unfixed>
-	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	[bookworm] - jackson-databind <not-affected> (introduced in 2.21.0; bookworm ships 2.14)
+	[bullseye] - jackson-databind <not-affected> (introduced in 2.21.0; bullseye ships 2.12)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-9fxm-vc8v-hj55
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5967
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/5968



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da86ccd5bb15b0c134ceb5207b66c1d6eab40dfe

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da86ccd5bb15b0c134ceb5207b66c1d6eab40dfe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260710/910c181d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list