[Git][security-tracker-team/security-tracker][master] 2 commits: Merge changes for updates with CVEs via trixie 13.6
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Jul 11 20:00:20 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fbdefc27 by Salvatore Bonaccorso at 2026-07-10T20:34:27+02:00
Merge changes for updates with CVEs via trixie 13.6
- - - - -
f558d026 by Salvatore Bonaccorso at 2026-07-11T21:00:12+02:00
Merge branch 'trixie-13.6' into 'master'
Merge changes accepted for trixie 13.6 release
See merge request security-tracker-team/security-tracker!311
- - - - -
2 changed files:
- data/CVE/list
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1362,7 +1362,7 @@ CVE-2026-54423 (In OpenStack Ironic before 37.0.1, an Ironic user with the abili
NOTE: https://security.openstack.org/ossa/OSSA-2026-025.html
CVE-2026-3886 [virtio-gpu: fix overflow check when allocating 2d image]
- qemu 1:11.0.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/9462ff4695aa0d086fd63f7f2efafe5a05f2a243 (v8.1.0-rc0)
@@ -8861,7 +8861,7 @@ CVE-2026-53325 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/b08472db93b1ccff84a7adec5779d47f0e9d3a30 (7.2-rc1)
CVE-2026-58302 (rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege ...)
- linuxcnc 1:2.9.9-1 (bug #1140943)
- [trixie] - linuxcnc <no-dsa> (Will be fixed via point release)
+ [trixie] - linuxcnc 1:2.9.4-2+deb13u1
[bookworm] - linuxcnc <no-dsa> (Will be fixed via point release)
NOTE: https://github.com/LinuxCNC/linuxcnc/commit/00d534c87464a3ed446656998aa02b8abc74b391 (v2.9.9)
CVE-2026-49048 (The Joomla extension JoomCCK exposes a front-end controller task, that ...)
@@ -8961,32 +8961,32 @@ CVE-2026-10593 (The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-48002
- qemu 1:11.0.2+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.11+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/00589953cc263ed8098fa9c0a007a9b04d470f85 (v11.0.2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/52155a6affd077f7e50fd0aca99a391d6e9e7066 (v11.0.2)
CVE-2026-48003
- qemu 1:11.0.2+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.11+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/5228799f15b28c0780375701236098d7c07261d4 (v11.0.2)
CVE-2026-48004
- qemu 1:11.0.2+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.11+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/c394949ff2ec8db218e2a1a2b592d7f8efde68c7 (v11.0.2)
CVE-2026-48915
- qemu 1:11.0.2+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.11+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/12058948abdf7eed8364aee79add66b40002fd5b (v10.0.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/41d5a45d24ed3e18605d3f6569d9446dad3ebf65 (v11.0.2)
CVE-2026-6425
- qemu 1:11.0.2+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.11+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/92d7bb038e011e76b631a6213807469c6b5edd51 (v11.0.2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/cb326591b3da050fa676cf06a6d5346a976d3844 (v11.0.2)
CVE-2026-8343
- qemu 1:11.0.2+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.11+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/bccd2c7d602d17d6786872a8aa0706855c07e684 (v11.0.2)
CVE-2026-XXXX [TROVE-2026-020]
- tor 0.4.9.9-1
@@ -9109,7 +9109,7 @@ CVE-2026-XXXX [GHSA-5gf7-wjfm-vmvm: Out-of-bounds bit clears for negative Matros
NOTE: https://github.com/libass/libass/issues/937
CVE-2026-XXXX [GHSA-pjjp-65r7-ppgm: Out-of-bounds read and write in wrap_lines_measure]
- libass 1:0.17.5-1
- [trixie] - libass <no-dsa> (Minor issue, will be fixed via point release)
+ [trixie] - libass 1:0.17.3-1+deb13u1
NOTE: https://github.com/libass/libass/security/advisories/GHSA-pjjp-65r7-ppgm
NOTE: https://github.com/libass/libass/commit/f2ef59755292bc4bb950ef22710e18a5487c399d (0.17.5)
CVE-2026-9677 (The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 ...)
@@ -9998,7 +9998,7 @@ CVE-2026-11702 (Bytes::Random::Secure::Tiny versions through 1.011 for Perl shar
NOT-FOR-US: Bytes::Random::Secure::Tiny Perl module
CVE-2026-11625 (Bytes::Random::Secure versions through 0.29 for Perl share internal st ...)
- libbytes-random-secure-perl 0.29-4
- [trixie] - libbytes-random-secure-perl <no-dsa> (Minor issue; will be fixed via point release)
+ [trixie] - libbytes-random-secure-perl 0.29-4~deb13u1
[bookworm] - libbytes-random-secure-perl <no-dsa> (Minor issue; will be fixed via point release)
[bullseye] - libbytes-random-secure-perl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41305966/
@@ -13476,7 +13476,7 @@ CVE-2026-9612 (The WhatsOrder \u2013 Instant Checkout for WooCommerce plugin for
NOT-FOR-US: WordPress plugin
CVE-2026-9539 (An out-of-bounds heap read and integer underflow in the TCP urgent dat ...)
- libslirp 4.9.2-1
- [trixie] - libslirp <no-dsa> (Minor issue)
+ [trixie] - libslirp 4.8.0-1+deb13u1
NOTE: https://gitlab.freedesktop.org/slirp/libslirp/-/work_items/93
NOTE: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/927bca7344e31fd58e2f7afaca784aad4400eb84 (v4.9.2)
CVE-2026-9184 (The 24liveblog - live blog tool plugin for WordPress is vulnerable to ...)
@@ -13999,24 +13999,24 @@ CVE-2026-56222 (Capgo before 12.128.2 contains an authorization bypass vulnerabi
NOT-FOR-US: Cap-go
CVE-2026-56117 (dhcpcd through 10.3.2, fixed in commit 78ea09e, contains a heap use-af ...)
- dhcpcd 1:10.3.2-4 (bug #1140767)
- [trixie] - dhcpcd <no-dsa> (Minor issue)
+ [trixie] - dhcpcd 1:10.1.0-11+deb13u3
NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/78ea09ed1633a583dbcde6e7bab9df4639ec8a34
CVE-2026-56116 (dhcpcd through 10.3.2, fixed in commit 708b4a5, contains a memory leak ...)
- dhcpcd 1:10.3.2-4 (bug #1140767)
- [trixie] - dhcpcd <no-dsa> (Minor issue)
+ [trixie] - dhcpcd 1:10.1.0-11+deb13u3
NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/708b4a56bae080a5b18c2e0c4c6fbe103131a2b0
CVE-2026-56115 (Bootimus through 0.1.70 contains a broken access control vulnerability ...)
NOT-FOR-US: Bootimus
CVE-2026-56114 (dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-byte st ...)
- dhcpcd 1:10.3.2-4 (bug #1140767)
- [trixie] - dhcpcd <no-dsa> (Minor issue)
+ [trixie] - dhcpcd 1:10.1.0-11+deb13u3
- dhcpcd5 <removed>
[bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point release)
[bullseye] - dhcpcd5 <postponed> (Minor issue; needs non-default IA_PD config + adjacent DHCPv6 server; 1-byte OOB, availability-only)
NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029
CVE-2026-56113 (dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-af ...)
- dhcpcd 1:10.3.2-4 (bug #1140767)
- [trixie] - dhcpcd <no-dsa> (Minor issue)
+ [trixie] - dhcpcd 1:10.1.0-11+deb13u3
NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/5733d3c59a5651f64357ac11c98b4f39895c8d25
CVE-2026-55736 (Improperly Controlled Modification of Dynamically-Determined Object At ...)
NOT-FOR-US: ash-project ash
@@ -14527,7 +14527,7 @@ CVE-2026-45034 (PhpSpreadsheet is a pure PHP library for reading and writing spr
NOT-FOR-US: PhpSpreadsheet
CVE-2026-44889 (WebOb provides objects for HTTP requests and responses. Prior to 1.8.1 ...)
- python-webob 1:1.8.10-1
- [trixie] - python-webob <no-dsa> (Minor issue)
+ [trixie] - python-webob 1:1.8.10-0+deb13u1
NOTE: https://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95
CVE-2026-44727 (Jupyter Server is the backend for Jupyter web applications. Prior to 2 ...)
- jupyter-server 2.20.0-1
@@ -15017,7 +15017,7 @@ CVE-2026-12806 (A vulnerability has been found in Edimax BR-6478AC V2 1.23. The
NOT-FOR-US: Edimax
CVE-2026-12805 (A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element ...)
- dcmtk 3.7.0+really3.7.0-6 (bug #1140562)
- [trixie] - dcmtk <no-dsa> (Minor issue)
+ [trixie] - dcmtk 3.6.9-5+deb13u2
NOTE: https://support.dcmtk.org/redmine/issues/1208
NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=1d4b3815c0987840a983160bfc671fef63a3105b
CVE-2026-11748 (A vulnerability has been identified in centraldogma-server-auth-shiro ...)
@@ -18114,7 +18114,7 @@ CVE-2026-12319 (Denial-of-service in the Audio/Video: Playback component. This v
CVE-2026-12318 (Incorrect boundary conditions in the Libraries component in NSS. This ...)
- firefox <unfixed>
- nss 2:3.124-1
- [trixie] - nss <no-dsa> (Minor issue)
+ [trixie] - nss 2:3.110-1+deb13u3
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-57/#CVE-2026-12318
NOTE: https://hg-edge.mozilla.org/projects/nss/rev/bd0c42028c8eae5b9cbdb4f5b0ee59bc07cba2de
CVE-2026-12317 (Memory safety bug fixed in Firefox 152. This vulnerability was fixed i ...)
@@ -19019,7 +19019,7 @@ CVE-2026-10635 (On Xtensa targets with CONFIG_USERSPACE and CONFIG_XTENSA_MMU, t
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2025-70102 (A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/ ...)
- dhcpcd 1:10.3.1-1
- [trixie] - dhcpcd <no-dsa> (Minor issue)
+ [trixie] - dhcpcd 1:10.1.0-11+deb13u3
- dhcpcd5 <removed>
[bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point release)
[bullseye] - dhcpcd5 <postponed> (Minor issue; NULL deref only via malformed local dhcpcd.conf; not network-reachable)
@@ -19724,12 +19724,12 @@ CVE-2026-XXXX [RUSTSEC-2026-0177]
NOTE: https://github.com/PyO3/pyo3/pull/6096
CVE-2026-9641 (Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default al ...)
- libcrypt-pbkdf2-perl 0.261630-1 (bug #1139867)
- [trixie] - libcrypt-pbkdf2-perl <no-dsa> (Minor issue)
+ [trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40933040/
NOTE: Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/320db2451c42916ce787479de8a0bb1fb37a6700 (0.261630)
CVE-2026-9638 (Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure rand ...)
- libcrypt-pbkdf2-perl 0.261630-1 (bug #1139867)
- [trixie] - libcrypt-pbkdf2-perl <no-dsa> (Minor issue)
+ [trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40932643/
NOTE: Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/1d0a1ad8474fd3dddfd10a04ea6837951f6e6519 (0.261630)
CVE-2026-9266 (A Missing Required Cryptographic Step vulnerability has been identifie ...)
@@ -19863,7 +19863,7 @@ CVE-2026-49347 (Quest Bot is an opensource Discord Bot. Prior to version 1.1.8,
NOT-FOR-US: Quest Bot
CVE-2026-48914 (A flaw was found in QEMU's virtio-blk device. The issue arises because ...)
- qemu 1:11.0.2+ds-1 (bug #1139923)
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.11+ds-0+deb13u1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2488283
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/f34e73cd69bdbdb9b1d56b288c5e14d6fff58165 (v1.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/f5e2c6906cad9a84140e232f2e3eb7a46bf07f62 (v11.0.2)
@@ -20056,7 +20056,7 @@ CVE-2026-10557 (The Yarbo Android and iOS applications contain hard-coded MQTT b
NOT-FOR-US: Yarbo
CVE-2017-20240 (Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timi ...)
- libcrypt-pbkdf2-perl 0.261630-1 (bug #1139867)
- [trixie] - libcrypt-pbkdf2-perl <no-dsa> (Minor issue)
+ [trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40929601/
NOTE: Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/ac5aac7c8c0e411165a6665a9c1f449b745f2629 (0.261630)
CVE-2026-50012
@@ -21115,13 +21115,13 @@ CVE-2026-XXXX [OnionShare Receive mode writes uploaded files even when file uplo
NOTE: https://github.com/onionshare/onionshare/security/advisories/GHSA-v833-3823-cmhp
CVE-2026-11853 (Debusine is an integrated solution to build, distribute and maintain a ...)
- debusine 0.14.9
- [trixie] - debusine <no-dsa> (Will be fixed via point release)
+ [trixie] - debusine 0.11.3+deb13u1
NOTE: https://salsa.debian.org/freexian-team/debusine/-/work_items/1484
NOTE: https://salsa.debian.org/freexian-team/debusine/-/merge_requests/3103
NOTE: https://salsa.debian.org/freexian-team/debusine/-/commit/c24cdc49fb258714767546bdec5b09f8065d414e
CVE-2026-11852 (Debusine is an integrated solution to build, distribute and maintain a ...)
- debusine 0.14.6
- [trixie] - debusine <no-dsa> (Will be fixed via point release)
+ [trixie] - debusine 0.11.3+deb13u1
NOTE: https://salsa.debian.org/freexian-team/debusine/-/work_items/1499
NOTE: https://salsa.debian.org/freexian-team/debusine/-/merge_requests/2836
NOTE: https://salsa.debian.org/freexian-team/debusine/-/commit/98104f46dc546a27a0326d5ef728ac7f426c430a
@@ -23246,7 +23246,7 @@ CVE-2026-11701 (Inappropriate implementation in Guest View in Google Chrome prio
CVE-2026-9669 (bz2.BZ2Decompressor objects could be reused after a decompression erro ...)
- python3.14 3.14.6-1
- python3.13 3.13.14-1
- [trixie] - python3.13 <no-dsa> (Minor issue, will be fixed via pu)
+ [trixie] - python3.13 3.13.5-2+deb13u3
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
@@ -23291,7 +23291,7 @@ CVE-2026-49232 (Routinator exits on any error when accepting incoming HTTP or RT
CVE-2026-48913 (Use After Free vulnerability in Apache HTTP Server module mod_http2 wh ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-48913
NOTE: Fixed by jumbo patch: https://github.com/apache/httpd/commit/dbf1cc4dd62b681a0066271720994a047a3329ca (2.4.68-rc1-candidate)
@@ -23338,28 +23338,28 @@ CVE-2026-45581 (fabric-chaincode-java is a Java based implementation of Hyperled
CVE-2026-44631 (Buffer Underwrite vulnerability in Apache HTTP Server on crafted regul ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44631
NOTE: Fixed by: https://github.com/apache/httpd/commit/7d9f3cfb10b0fe70df7358d26d7b1f374ea1a0cb (2.4.68-rc1-candidate)
CVE-2026-44186 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44186
NOTE: Fixed by: https://github.com/apache/httpd/commit/414de374a06549b2c6710cbcff81c3821379f75c (2.4.68-rc1-candidate)
CVE-2026-44185 (Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44185
NOTE: Fixed by: https://github.com/apache/httpd/commit/32b7e2e66477020ba75b78ab43fb8890ec292ad2 (2.4.68-rc1-candidate)
CVE-2026-44119 (Improper Privilege Management vulnerability in Apache HTTP Server 2.4. ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44119
NOTE: Fixed by: https://github.com/apache/httpd/commit/f63f26aff6aa747357b84b5bd09c45325fa7f9ba (2.4.68-rc1-candidate)
@@ -23378,7 +23378,7 @@ CVE-2026-43966 (Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP
CVE-2026-43951 (Out-of-bounds Read vulnerability in Apache HTTP Server with mod_header ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-43951
NOTE: Fixed by: https://github.com/apache/httpd/commit/6ff9dc2fdbe7ffd2f8a6c9ffe9ec801d53c760ba (2.4.68-rc1-candidate)
@@ -23391,7 +23391,7 @@ CVE-2026-42861 (Flowise is a drag & drop user interface to build a customized la
CVE-2026-42536 (Heap-based Buffer Overflow vulnerability in Apache HTTP Server withmod ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42536
NOTE: Fixed by: https://github.com/apache/httpd/commit/fa5d85bbc832a587c3c5bca7c19fb21df96b5df0 (trunk)
@@ -23399,7 +23399,7 @@ CVE-2026-42536 (Heap-based Buffer Overflow vulnerability in Apache HTTP Server w
CVE-2026-42535 (A path handling issue in mod_dav_fs in Apache 2.4.67 and earlierallows ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42535
NOTE: Fixed by: https://github.com/apache/httpd/commit/7e871beec56d41fe098f48f5a5bcb1525c448d77 (trunk)
@@ -23425,7 +23425,7 @@ CVE-2026-36786 (Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was disc
CVE-2026-34356 (Heap-based Buffer Overflow vulnerability in Apache HTTP Server with ma ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-34356
NOTE: Fixed by: https://github.com/apache/httpd/commit/403269396d24404e2576a9b20f96cd0b10574048 (2.4.68-rc1-candidate)
@@ -23433,7 +23433,7 @@ CVE-2026-34356 (Heap-based Buffer Overflow vulnerability in Apache HTTP Server w
CVE-2026-34355 (A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and e ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-34355
NOTE: Fixed by: https://github.com/apache/httpd/commit/d62fc375281486c6036b007ac349b25d4e6edb4a (2.4.68-rc1-candidate)
@@ -23442,7 +23442,7 @@ CVE-2026-34194 (Software installed and run as a non-privileged user may conduct
CVE-2026-29170 (A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML di ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29170
NOTE: Fixed by: https://github.com/apache/httpd/commit/e86bf540f166b3a322f7e7f9cd4aad4cd44deee6 (trunk)
@@ -23450,7 +23450,7 @@ CVE-2026-29170 (A cross-site scripting vulnerability exists in mod_proxy_ftp's H
CVE-2026-29167 (Use After Free vulnerability in Apache HTTP Server with mod_ldap in pe ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
- [trixie] - apache2 <no-dsa> (Minor issue)
+ [trixie] - apache2 2.4.68-1~deb13u1
[bookworm] - apache2 <no-dsa> (Minor issue)
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29167
NOTE: Fixed by: https://github.com/apache/httpd/commit/354a94ee7fd4bd34bfe3e776e3b32d3344f435c7 (trunk)
@@ -23810,7 +23810,7 @@ CVE-2026-47895
NOTE: https://www.strongswan.org/blog/2026/06/08/strongswan-vulnerability-(cve-2026-47895).html
CVE-2026-48977
- openslide 3.4.1+dfsg-9 (bug #1140003)
- [trixie] - openslide <no-dsa> (Minor issue)
+ [trixie] - openslide 3.4.1+dfsg-7+deb13u1
[bookworm] - openslide <no-dsa> (Minor issue)
[bullseye] - openslide <postponed> (Minor issue; can be fixed in next update)
NOTE: https://github.com/openslide/openslide/security/advisories/GHSA-mxg2-48g7-fmwc
@@ -24122,7 +24122,7 @@ CVE-2026-45758 (Guardrails AI is a Python framework that helps build AI applicat
NOT-FOR-US: Guardrails AI
CVE-2026-45409 (Internationalized Domain Names in Applications (IDNA) for Python provi ...)
- python-idna 3.11-1.1 (bug #1139164)
- [trixie] - python-idna <no-dsa> (Minor issue)
+ [trixie] - python-idna 3.10-1+deb13u1
[bookworm] - python-idna <no-dsa> (Minor issue)
[bullseye] - python-idna <no-dsa> (Minor issue)
NOTE: https://github.com/kjd/idna/security/advisories/GHSA-65pc-fj4g-8rjx
@@ -26190,7 +26190,7 @@ CVE-2023-5502 (On affected platforms running Arista EOS with 802.1x authenticati
NOT-FOR-US: Arista Networks
CVE-2026-50593 (Graphite before 1.3.15 has an integer underflow and resultant out-of-b ...)
- graphite2 1.3.15-2
- [trixie] - graphite2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - graphite2 1.3.14-2+deb13u1
[bookworm] - graphite2 <no-dsa> (Minor issue; can be fixed via point release)
[bullseye] - graphite2 <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/silnrsi/graphite/commit/ad78c6b7319909e1540c1b134e115ced03417866 (1.3.15)
@@ -26216,7 +26216,7 @@ CVE-2026-8037 (OS Command Injection Remote Code Execution Vulnerability in API i
CVE-2026-7774 (tarfile.data_filter could be bypassed using crafted link entries, incl ...)
- python3.14 3.14.6-1
- python3.13 3.13.14-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u3
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
@@ -26318,14 +26318,14 @@ CVE-2026-47706 (Strawberry GraphQL is a library for creating GraphQL APIs. In ve
CVE-2026-47320 (Access of uninitialized pointer, Uncontrolled Recursion vulnerability ...)
{DLA-4675-1}
- rlottie 0.1+dfsg-5 (bug #1138920)
- [trixie] - rlottie <no-dsa> (Minor issue)
+ [trixie] - rlottie 0.1+dfsg-4.2+deb13u2
[bookworm] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/593
NOTE: https://github.com/Samsung/rlottie/commit/bf689b72b8482c5ea674235854bd11b6d1b42588
CVE-2026-47319 (Memory allocation with excessive size value vulnerability in Samsung O ...)
{DLA-4675-1}
- rlottie 0.1+dfsg-5 (bug #1138919)
- [trixie] - rlottie <no-dsa> (Minor issue)
+ [trixie] - rlottie 0.1+dfsg-4.2+deb13u2
[bookworm] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/588
NOTE: https://github.com/Samsung/rlottie/commit/5def9f402b1cb5b09f52655e414f0afba4ffd959
@@ -26536,7 +26536,7 @@ CVE-2026-10597 (OMICARD EDM developed by ITPison has a Insecure Direct Object Re
CVE-2026-10305 (Out-of-bounds read vulnerability in Samsung Open Source rlottie allows ...)
{DLA-4675-1}
- rlottie 0.1+dfsg-5 (bug #1139179)
- [trixie] - rlottie <no-dsa> (Minor issue)
+ [trixie] - rlottie 0.1+dfsg-4.2+deb13u2
[bookworm] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/587
NOTE: https://github.com/Samsung/rlottie/commit/b4f5101a4d1a8da60cc14cfd05608551b3448c77
@@ -26635,7 +26635,7 @@ CVE-2026-50219 (libexpat before 2.8.2 lacks handler call depth tracking for call
CVE-2026-8829 (HTML::Entities versions before 3.84 for Perl read freed heap memory in ...)
{DLA-4655-1}
- libhtml-parser-perl 3.83-2
- [trixie] - libhtml-parser-perl <no-dsa> (Minor issue)
+ [trixie] - libhtml-parser-perl 3.83-2~deb13u1
[bookworm] - libhtml-parser-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40702610/
NOTE: https://github.com/libwww-perl/HTML-Parser/pull/56
@@ -26756,13 +26756,13 @@ CVE-2026-45614 (OP-TEE is a Trusted Execution Environment (TEE) designed as comp
NOTE: https://github.com/OP-TEE/optee_os/security/advisories/GHSA-g6qf-hwf7-mg9h
CVE-2026-44546 (daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's par ...)
- python-daphne 4.2.2-0.1 (bug #1138864)
- [trixie] - python-daphne <no-dsa> (Minor issue)
+ [trixie] - python-daphne 4.1.2-2+deb13u1
[bookworm] - python-daphne <no-dsa> (Minor issue)
[bullseye] - python-daphne <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/django/daphne/commit/2628b7b2e6a196afff58defee3d77671a28de631 (4.2.2)
CVE-2026-44545 (daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayl ...)
- python-daphne 4.2.2-0.1 (bug #1138864)
- [trixie] - python-daphne <no-dsa> (Minor issue)
+ [trixie] - python-daphne 4.1.2-2+deb13u1
[bookworm] - python-daphne <no-dsa> (Minor issue)
[bullseye] - python-daphne <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/django/daphne/commit/32f8be0fb0bf2a441085cb45e0e8f45455f0793e (4.2.2)
@@ -26928,7 +26928,7 @@ CVE-2019-25720 (Dr\xe4ger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000,
CVE-2026-3276 (unicodedata.normalize() can take excessive CPU time when processing sp ...)
- python3.14 3.14.6-1
- python3.13 3.13.14-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u3
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
@@ -26955,7 +26955,7 @@ CVE-2026-44393 (An issue was discovered in OpenStack oslo.messaging 1.0.0 throug
NOTE: https://launchpad.net/bugs/2150316
CVE-2026-55748 (OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file ...)
- horizon 3:25.7.3-2 (bug #1138845)
- [trixie] - horizon <no-dsa> (Minor issue)
+ [trixie] - horizon 3:25.3.0-3+deb13u1
[bookworm] - horizon <no-dsa> (Minor issue)
[bullseye] - horizon <postponed> (Minor issue; can be fixed in next update)
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0097
@@ -28682,49 +28682,49 @@ CVE-2026-47191
NOTE: Fixed by: https://github.com/siemens/kas/commit/4cb4a3d01122ffaec9feaae768a5814092f6f9b5 (5.3)
CVE-2026-8341
- qemu 1:11.0.1+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/f1488fac0584cc095865e4d4d987f01f4e97fbe5 (v10.0.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6a15005290ee1187f8ae9aa44e99b40cae07be45 (v11.0.1)
CVE-2026-41435
- qemu 1:11.0.1+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/db1ecfb473ac58f2bd065ca6f2a50c6294ff9169 (v10.0.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/4c6e8882e4915ee9afe4116e4eaa7857912f18cb (v11.0.1)
CVE-2026-41436
- qemu 1:11.0.1+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/90ca4e03c27dc8ac821a2e1686e705ae9a93d301 (v10.0.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/023f87ab68cea5c08c73bd79545149fe77dc3f0c (v11.0.1)
CVE-2026-41437
- qemu 1:11.0.1+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/1ebc319c8ca7ad8af350026662ae18fdcb8b0dac (v10.0.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/5c358eabe637699c9b1bf852931b58a78c681ff0 (v11.0.1)
CVE-2026-41438
- qemu 1:11.0.1+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/db1ecfb473ac58f2bd065ca6f2a50c6294ff9169 (v10.0.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/2c4c582f3f179b2508ca259fda9e722adc973b40 (v11.0.1)
CVE-2026-41439
- qemu 1:11.0.1+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/02b593d4dccbb4a9684720d9ef07f0ac8d6da716 (v10.0.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/02b593d4dccbb4a9684720d9ef07f0ac8d6da716 (v11.0.1)
CVE-2026-41440
- qemu 1:11.0.1+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/f1488fac0584cc095865e4d4d987f01f4e97fbe5 (v10.0.0-rc0)
@@ -28761,7 +28761,7 @@ CVE-2026-49489 (OpenCATS through 0.9.7.4 contains a sql injection vulnerability
NOT-FOR-US: OpenCATS
CVE-2026-10194 (A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the ...)
- dcmtk 3.7.0+really3.7.0-5 (bug #1139181)
- [trixie] - dcmtk <no-dsa> (Minor issue)
+ [trixie] - dcmtk 3.6.9-5+deb13u1
[bookworm] - dcmtk <no-dsa> (Minor issue)
[bullseye] - dcmtk <no-dsa> (Minor issue)
NOTE: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=0f78a4ef6f645ea5530166e445e5436a5de58e75
@@ -29001,7 +29001,7 @@ CVE-2026-8594 (Text::LineFold versions through 2019.001 for Perl duplicate the o
NOTE: Patch: https://security.metacpan.org/patches/U/Unicode-LineBreak/2019.001/CVE-2026-8594-r1.patch
CVE-2026-48711
- sshfs-fuse 3.7.3-1.2 (bug #1138293)
- [trixie] - sshfs-fuse <no-dsa> (Minor issue)
+ [trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
[bookworm] - sshfs-fuse <no-dsa> (Minor issue)
[bullseye] - sshfs-fuse <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/30/3
@@ -29010,7 +29010,7 @@ CVE-2026-48711
NOTE: Fixed by: https://github.com/libfuse/sshfs/commit/6678accb85ea4aec15dae9961b92af8d12501a66 (sshfs-3.7.6)
CVE-2026-47187
- sshfs-fuse 3.7.3-1.2 (bug #1138293)
- [trixie] - sshfs-fuse <no-dsa> (Minor issue)
+ [trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
[bookworm] - sshfs-fuse <no-dsa> (Minor issue)
[bullseye] - sshfs-fuse <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/30/3
@@ -29033,7 +29033,7 @@ CVE-2026-9334 (Cpanel::JSON::XS versions before 4.41 for Perl allow type confusi
NOTE: Fixed by: https://github.com/rurban/Cpanel-JSON-XS/commit/11a7c550a0d8fac2f84414f24d5df9b2bfe346e2 (4.41)
CVE-2026-50538 [Attacker-controlled heap out-of-bounds write in libvncclient Tight decoder]
- libvncserver 0.9.15+dfsg-6 (bug #1138253)
- [trixie] - libvncserver <no-dsa> (Minor issue)
+ [trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
NOTE: https://github.com/LibVNC/libvncserver/security/advisories/GHSA-v9pm-47h4-jcq8
CVE-2026-9831 (A race condition in the shared Extreme Platform ONE IAM Gateway API-ke ...)
NOT-FOR-US: Extreme Networks
@@ -29587,13 +29587,13 @@ CVE-2024-13745
NOTE: https://www.openwall.com/lists/oss-security/2026/05/29/2
CVE-2026-49214 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
- php-guzzlehttp-psr7 2.10.3-1 (bug #1138265)
- [trixie] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+ [trixie] - php-guzzlehttp-psr7 2.7.1-1+deb13u1
[bookworm] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
[bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue)
NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-hq7v-mx3g-29hw
CVE-2026-48998 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
- php-guzzlehttp-psr7 2.10.3-1 (bug #1138265)
- [trixie] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+ [trixie] - php-guzzlehttp-psr7 2.7.1-1+deb13u1
[bookworm] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
[bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue)
NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-34xg-wgjx-8xph
@@ -30164,7 +30164,7 @@ CVE-2026-5343 (Improper Check for Unusual or Exceptional Conditions vulnerabilit
NOT-FOR-US: Drupal core and addons
CVE-2026-49299 (In OpenStack Neutron before 28.0.1, the tagging controller enforces pl ...)
- neutron 2:28.0.0-4 (bug #1138172)
- [trixie] - neutron <no-dsa> (Minor issue)
+ [trixie] - neutron 2:26.0.0-9+deb13u1
[bookworm] - neutron <no-dsa> (Minor issue)
[bullseye] - neutron <postponed> (Minor issue; can be fixed with next upload)
NOTE: https://security.openstack.org/ossa/OSSA-2026-016.html
@@ -32056,7 +32056,7 @@ CVE-2026-45022 (go-git is an extensible git implementation library written in pu
NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp
CVE-2026-44988 (LibVNCClient is a library for easy implementation of a VNC client. In ...)
- libvncserver 0.9.15+dfsg-5 (bug #1138174)
- [trixie] - libvncserver <no-dsa> (Minor issue)
+ [trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
NOTE: https://github.com/LibVNC/libvncserver/security/advisories/GHSA-jcc5-8wj4-7c58
NOTE: https://github.com/LibVNC/libvncserver/commit/5b270544b85233668b98161323297d418a8f5fd1
CVE-2026-44972 (GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 ...)
@@ -36760,7 +36760,7 @@ CVE-2026-1543 (The Avada (Fusion) Builder plugin for WordPress is vulnerable to
NOT-FOR-US: WordPress plugin
CVE-2026-9759 (ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to ...)
- wireshark 4.6.6-1
- [trixie] - wireshark <postponed> (Minor issue, fix along with future update)
+ [trixie] - wireshark 4.4.16-0+deb13u1
[bookworm] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-51.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21243
@@ -37703,7 +37703,7 @@ CVE-2026-43620 (Rsync version3.4.2 and prior contain a receiver-side out-of-boun
NOTE: https://github.com/RsyncProject/rsync/security/advisories/GHSA-28pw-r563-rxvm
CVE-2026-45232 (Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack ...)
- rsync 3.4.3+ds1-1
- [trixie] - rsync <no-dsa> (Minor issue)
+ [trixie] - rsync 3.4.1+ds1-5+deb13u4
[bookworm] - rsync <no-dsa> (Minor issue)
[bullseye] - rsync <postponed> (Minor issue, 1-byte zero OOB write)
NOTE: https://download.samba.org/pub/rsync/NEWS#3.4.3
@@ -38838,7 +38838,7 @@ CVE-2026-8454 (Imager::File::GIF versions through 1.002 for Perl allow a heap ou
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40079077/
CVE-2026-8503 (Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl crea ...)
- libapache-session-browseable-perl 1.3.19-1
- [trixie] - libapache-session-browseable-perl <no-dsa> (Minor issue)
+ [trixie] - libapache-session-browseable-perl 1.3.16-1+deb13u1
[bookworm] - libapache-session-browseable-perl <no-dsa> (Minor issue)
[bullseye] - libapache-session-browseable-perl <postponed> (Minor issue, hard to exploit)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40079348/
@@ -39689,7 +39689,7 @@ CVE-2026-44348 (PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before
NOTE: Fixed by: https://github.com/podofo/podofo/commit/696d765c3a71ef224d4abffe1f174fef11292d7e (1.0.4)
CVE-2026-44312 (css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Pa ...)
- ruby-css-parser 2.1.0-1
- [trixie] - ruby-css-parser <no-dsa> (Minor issue)
+ [trixie] - ruby-css-parser 1.19.0-1+deb13u1
[bookworm] - ruby-css-parser <no-dsa> (Minor issue)
[bullseye] - ruby-css-parser <postponed> (Minor issue)
NOTE: https://github.com/premailer/css_parser/security/advisories/GHSA-ff6c-w6qf-7xqc
@@ -39926,7 +39926,7 @@ CVE-2026-6637 (Stack buffer overflow in PostgreSQL module "refint" allows an unp
NOTE: https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/
CVE-2026-45793 [Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs]
- composer 0.9.1+dfsg-1
- [trixie] - composer <no-dsa> (Minor issue)
+ [trixie] - composer 2.8.8-1+deb13u3
[bookworm] - composer <no-dsa> (Minor issue)
NOTE: https://github.com/composer/composer/security/advisories/GHSA-f9f8-rm49-7jv2
CVE-2026-8496 (A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, vers ...)
@@ -39952,7 +39952,7 @@ CVE-2026-8367 (aria2c accepts a server certificate with incorrect Extended Key U
CVE-2026-8328 (The ftpcp() function in Lib/ftplib.py was not updated when CVE-2021-4 ...)
- python3.14 3.14.6-1
- python3.13 3.13.14-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u3
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
@@ -40042,11 +40042,13 @@ CVE-2026-4524 (GitLab has remediated an issue in GitLab CE/EE affecting all vers
CVE-2026-46446 (SOGo before 5.12.7, when PostgreSQL or MariaDB is used, and cleartext ...)
{DSA-6366-1 DLA-4657-1}
- sogo 5.12.7-1
+ [trixie] - sogo 5.12.1-3+deb13u2
[bullseye] - sogo <ignored> (Invasive to patch; Debian maintainer recommends against backport)
NOTE: https://github.com/Alinto/sogo/commit/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21 (SOGo-5.12.7)
CVE-2026-46445 (SOGo before 5.12.7, when PostgreSQL is used, allows SQL injection.)
{DSA-6366-1 DLA-4657-1}
- sogo 5.12.7-1
+ [trixie] - sogo 5.12.1-3+deb13u2
[bullseye] - sogo <ignored> (Invasive to patch; Debian maintainer recommends against backport)
NOTE: https://github.com/Alinto/sogo/commit/1f7e5d2b2c2047c44a6a9e05f73c36491cb96d21 (SOGo-5.12.7)
CVE-2026-46419 (Yubico webauthn-server-core (aka java-webauthn-server) 2.8.0 before 2. ...)
@@ -42285,7 +42287,7 @@ CVE-2026-42188 (Geyser is a bridge between Minecraft: Bedrock Edition and Minecr
NOT-FOR-US: Geyser
CVE-2026-42046 (libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an ...)
- libcaca 0.99.beta20-7 (bug #1136952)
- [trixie] - libcaca <no-dsa> (Minor issue)
+ [trixie] - libcaca 0.99.beta20-5+deb13u1
[bookworm] - libcaca <no-dsa> (Minor issue)
NOTE: https://github.com/cacalabs/libcaca/security/advisories/GHSA-4vvg-vrqv-m56w
NOTE: https://github.com/cacalabs/libcaca/issues/86
@@ -43027,7 +43029,7 @@ CVE-2026-8248 (A vulnerability was detected in Open5GS up to 2.7.7. The affected
- open5gs <itp> (bug #1094791)
CVE-2026-8177 (XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap m ...)
- libxml-libxml-perl 2.0207+dfsg+really+2.0134-8 (bug #1136300)
- [trixie] - libxml-libxml-perl <no-dsa> (Minor issue; will be fixed via point release)
+ [trixie] - libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+deb13u1
[bookworm] - libxml-libxml-perl <no-dsa> (Minor issue; will be fixed via point release)
[bullseye] - libxml-libxml-perl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/39920366/
@@ -43040,7 +43042,7 @@ CVE-2026-45192 (A bug in the GET `/api/v2/connections/{connection_id}` REST API
- airflow <itp> (bug #819700)
CVE-2026-45191 (Net::CIDR::Lite versions before 0.24 for Perl does not properly consid ...)
- libnet-cidr-lite-perl 0.24-1
- [trixie] - libnet-cidr-lite-perl <no-dsa> (Minor issue; will be fixed via point release)
+ [trixie] - libnet-cidr-lite-perl 0.22-3~deb13u2
[bookworm] - libnet-cidr-lite-perl <no-dsa> (Minor issue; will be fixed via point release)
[bullseye] - libnet-cidr-lite-perl <postponed> (Minor issue, validation)
NOTE: https://github.com/stigtsp/Net-CIDR-Lite/commit/24e2c439ec405e5256024b9acefd4f7008c5ed0c (0.24)
@@ -43048,7 +43050,7 @@ CVE-2026-45191 (Net::CIDR::Lite versions before 0.24 for Perl does not properly
NOTE: https://lists.security.metacpan.org/cve-announce/msg/39920370/
CVE-2026-45190 (Net::CIDR::Lite versions before 0.24 for Perl does not properly valida ...)
- libnet-cidr-lite-perl 0.24-1
- [trixie] - libnet-cidr-lite-perl <no-dsa> (Minor issue; will be fixed via point release)
+ [trixie] - libnet-cidr-lite-perl 0.22-3~deb13u2
[bookworm] - libnet-cidr-lite-perl <no-dsa> (Minor issue; will be fixed via point release)
[bullseye] - libnet-cidr-lite-perl <postponed> (Minor issue, validation)
NOTE: https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692 (0.24)
@@ -48073,13 +48075,13 @@ CVE-2026-31195 (OS command injection vulnerability in the ping diagnostic handle
NOT-FOR-US: ALTICE
CVE-2026-42268 (ModSecurity is an open source, cross platform web application firewall ...)
- modsecurity 3.0.15-1
- [trixie] - modsecurity <no-dsa> (Proposed via point release update)
+ [trixie] - modsecurity 3.0.14-1+deb13u1
[bookworm] - modsecurity <no-dsa> (Proposed via point release update)
[bullseye] - modsecurity <postponed> (Minor issue, DoS)
NOTE: https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-vwr3-7x7g-7p9w
CVE-2026-30923 (ModSecurity is an open source, cross platform web application firewall ...)
- modsecurity 3.0.15-1
- [trixie] - modsecurity <no-dsa> (Proposed via point release update)
+ [trixie] - modsecurity 3.0.14-1+deb13u1
[bookworm] - modsecurity <no-dsa> (Proposed via point release update)
[bullseye] - modsecurity <postponed> (Minor issue, DoS)
NOTE: https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-qrjc-3jpc-3h2g
@@ -48244,7 +48246,7 @@ CVE-2026-43060 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/36eae0956f659e48d5366d9b083d9417f3263ddc (7.0-rc5)
CVE-2026-6502
- qemu 1:11.0.0+ds-2
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (Vulnerable code not present)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/7c092f17cceef10258ed23006b40e19b14996471 (v9.2.0-rc0)
@@ -48537,7 +48539,7 @@ CVE-2026-42075 (Evolver is a GEP-powered self-evolving engine for AI agents. Pri
CVE-2026-42052 (Beets is the media library management system. Prior to version 2.10.0, ...)
{DLA-4641-1}
- beets 2.11.0-1 (bug #1135779)
- [trixie] - beets <no-dsa> (Minor issue)
+ [trixie] - beets 2.2.0-3+deb13u1
[bookworm] - beets <no-dsa> (Minor issue)
NOTE: https://github.com/beetbox/beets/security/advisories/GHSA-3gxm-wfjx-m847
CVE-2026-42027 (Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP Ext ...)
@@ -48888,37 +48890,37 @@ CVE-2026-5335 (The Magic Export & Import WordPress plugin before 1.2.0 stores ex
NOT-FOR-US: WordPress plugin
CVE-2026-43864 (mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.)
- mutt 2.3.2-1 (bug #1135699)
- [trixie] - mutt <no-dsa> (Minor issue)
+ [trixie] - mutt 2.2.13-1+deb13u1
[bookworm] - mutt <no-dsa> (Minor issue)
[bullseye] - mutt <postponed> (Minor issue, DoS)
NOTE: Fixed by: https://gitlab.com/muttmua/mutt/-/commit/ebfa2969042d89303d15334193fcc32866c8a8df (mutt-2-3-2-rel)
CVE-2026-43863 (mutt before 2.3.2 has an infinite loop in data_object_to_stream in cry ...)
- mutt 2.3.2-1 (bug #1135699)
- [trixie] - mutt <no-dsa> (Minor issue)
+ [trixie] - mutt 2.2.13-1+deb13u1
[bookworm] - mutt <no-dsa> (Minor issue)
[bullseye] - mutt <postponed> (Minor issue, DoS)
NOTE: Fixed by: https://gitlab.com/muttmua/mutt/-/commit/fdc04a171777327218a1e78db504926c388b48c4 (mutt-2-3-2-rel)
CVE-2026-43862 (In mutt before 2.3.2, the imap_auth_gss security level is mishandled.)
- mutt 2.3.2-1 (bug #1135699)
- [trixie] - mutt <no-dsa> (Minor issue)
+ [trixie] - mutt 2.2.13-1+deb13u1
[bookworm] - mutt <no-dsa> (Minor issue)
[bullseye] - mutt <postponed> (Minor issue)
NOTE: Fixed by: https://gitlab.com/muttmua/mutt/-/commit/f547a849cdacb512800a5f477c27de217e1c8151 (mutt-2-3-2-rel)
CVE-2026-43861 (mutt before 2.3.2 does not check for '\0' in url_pct_decode.)
- mutt 2.3.2-1 (bug #1135699)
- [trixie] - mutt <no-dsa> (Minor issue)
+ [trixie] - mutt 2.2.13-1+deb13u1
[bookworm] - mutt <no-dsa> (Minor issue)
[bullseye] - mutt <postponed> (Minor issue, URL validation)
NOTE: Fixed by: https://gitlab.com/muttmua/mutt/-/commit/12f54fe3b61f761c096fe95e95d5e3072af00ed2 (mutt-2-3-2-rel)
CVE-2026-43860 (mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for ...)
- mutt 2.3.2-1 (bug #1135699)
- [trixie] - mutt <no-dsa> (Minor issue)
+ [trixie] - mutt 2.2.13-1+deb13u1
[bookworm] - mutt <no-dsa> (Minor issue)
[bullseye] - mutt <postponed> (Minor issue, failed authentication in corner case, no security impact)
NOTE: Fixed by: https://gitlab.com/muttmua/mutt/-/commit/834c5a2ed0479e51e8662a31caed129f136f4805 (mutt-2-3-2-rel)
CVE-2026-43859 (mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMA ...)
- mutt 2.3.2-1 (bug #1135699)
- [trixie] - mutt <no-dsa> (Minor issue)
+ [trixie] - mutt 2.2.13-1+deb13u1
[bookworm] - mutt <no-dsa> (Minor issue)
[bullseye] - mutt <postponed> (Minor issue, failed authentication in corner case, no security impact)
NOTE: Fixed by: https://gitlab.com/muttmua/mutt/-/commit/834c5a2ed0479e51e8662a31caed129f136f4805 (mutt-2-3-2-rel)
@@ -51304,7 +51306,7 @@ CVE-2026-7111 (Text::CSV_XS versions before 1.62 for Perl have a use-after-free
NOTE: Fixed by: https://github.com/cpan-authors/Text-CSV_XS/commit/c17f31a5f2bf36674748eb4b6e25672f0571a224
CVE-2026-7168 (Successfully using libcurl to do a transfer over a specific HTTP proxy ...)
- curl 8.20.0-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-7168.html
@@ -51315,7 +51317,7 @@ CVE-2026-7009 (When curl is told to use the Certificate Status Request TLS exten
NOTE: https://curl.se/docs/CVE-2026-7009.html
CVE-2026-6429 (When asked to both use a `.netrc` file for credentials and to follow H ...)
- curl 8.20.0~rc3-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-6429.html
@@ -51323,7 +51325,7 @@ CVE-2026-6429 (When asked to both use a `.netrc` file for credentials and to fol
NOTE: Fixed by: https://github.com/curl/curl/commit/b4024bf808bd558026fdc6096e8457f199ace306 (rc-8_20_0-3)
CVE-2026-6253 (curl might erroneously pass on credentials for a first proxy to a seco ...)
- curl 8.20.0~rc3-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-6253.html
@@ -51336,7 +51338,7 @@ CVE-2026-42198 (pgjdbc is an open source postgresql JDBC Driver. From version 42
NOTE: https://github.com/pgjdbc/pgjdbc/commit/c9d41d1332a7426fcef19ff89f2e6b1116429143 (REL42.7.11)
CVE-2026-5773 (libcurl might in some circumstances reuse the wrong connection for SMB ...)
- curl 8.20.0~rc2-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-5773.html
@@ -51344,7 +51346,7 @@ CVE-2026-5773 (libcurl might in some circumstances reuse the wrong connection fo
NOTE: Fixed by: https://github.com/curl/curl/commit/74a169575d6412dc0ff532acdf94de35a6c2a571 (rc-8_20_0-2)
CVE-2026-5545 (libcurl might in some circumstances reuse the wrong connection when as ...)
- curl 8.20.0~rc2-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-5545.html
@@ -51352,7 +51354,7 @@ CVE-2026-5545 (libcurl might in some circumstances reuse the wrong connection wh
NOTE: Fixed by: https://github.com/curl/curl/commit/33e43985b8f3b9e66691d06e70be0395849856cd (rc-8_20_0-1)
CVE-2026-4873 (A vulnerability exists where a connection requiring TLS incorrectly re ...)
- curl 8.20.0~rc2-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-4873.html
@@ -51360,7 +51362,7 @@ CVE-2026-4873 (A vulnerability exists where a connection requiring TLS incorrect
NOTE: Fixed by: https://github.com/curl/curl/commit/507e7be573b0a76fca597b75ff7cb27a66e7d865 (rc-8_20_0-1)
CVE-2026-6276 (Using libcurl, when a custom `Host:` header is first set for an HTTP r ...)
- curl 8.20.0~rc3-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-6276.html
@@ -51664,7 +51666,7 @@ CVE-2026-7355 (Use after free in Media in Google Chrome prior to 147.0.7727.138
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-40560 (Starman versions before 0.4018 for Perl allows HTTP Request Smuggling ...)
- starman 0.4018-1 (bug #1135229)
- [trixie] - starman <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - starman 0.4018-0+deb13u1
[bookworm] - starman <no-dsa> (Minor issue; can be fixed via point release)
[bullseye] - starman <postponed> (Minor issue; can be fixed in next update)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/39426182/
@@ -51842,7 +51844,7 @@ CVE-2026-41526 (In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to
NOTE: Fixed by: https://invent.kde.org/frameworks/kcoreaddons/-/commit/447250fb061d6a866eeef9ae3c21b627244b198a (v6.25.0)
CVE-2026-41525 (KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with A ...)
- dolphin 4:26.04.0-1
- [trixie] - dolphin <no-dsa> (Minor issue)
+ [trixie] - dolphin 4:25.04.3-1+deb13u1
[bookworm] - dolphin <no-dsa> (Minor issue)
[bullseye] - dolphin <no-dsa> (Minor issue)
NOTE: https://kde.org/info/security/advisory-20260427-2.txt
@@ -52411,7 +52413,7 @@ CVE-2026-25710 (The new upstream added a privileged D-Bus helper called plasmalo
NOT-FOR-US: plasma-login-manager
CVE-2026-41682 (pupnp is an SDK for development of UPnP device and control point appli ...)
- pupnp 1:1.14.31-1
- [trixie] - pupnp <no-dsa> (Minor issue)
+ [trixie] - pupnp 1:1.14.20-1+deb13u1
NOTE: https://github.com/pupnp/pupnp/security/advisories/GHSA-q522-6w45-4j58
NOTE: https://github.com/pupnp/pupnp/commit/58021a7600876c77403e2e06eb19d21efc196d21 (release-1.14.31)
CVE-2026-7106 (The Highland Software Custom Role Manager plugin for WordPress is vuln ...)
@@ -54449,26 +54451,26 @@ CVE-2026-35058 (Improper validation of packet length during tls-crypt-v2 key ext
NOTE: Fixed by: https://github.com/OpenVPN/openvpn/commit/607e2fcb9cbcff785abfa372c7a59029767b5ed9 (v2.7.2)
CVE-2026-5744 [hw/uefi: heap overflow]
- qemu 1:11.0.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code introduced later)
[bullseye] - qemu <not-affected> (Vulnerable code introduced later)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/90ca4e03c27dc8ac821a2e1686e705ae9a93d301 (v10.0.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/af74c9e46bb55e2da042315a0c65666f59c61686 (v11.0.0-rc3)
CVE-2026-5761 [virtio-blk: zone report buffer out-of-memory]
- qemu 1:11.0.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code introduced later)
[bullseye] - qemu <not-affected> (Vulnerable code introduced later)
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/4f7366506a96c862c796d4ea1913110d9c341e7d (v8.1.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/4913ae36f9796c55d434dcbfa6bdb9ebb3e5e4b1 (v11.0.0-rc4)
CVE-2026-5763 [virtio-scsi request size mismatch]
- qemu 1:11.0.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/79971302935472232a68073faddb085177e3ca54 (v11.0.0-rc3)
CVE-2026-3890 [hcd-ohci: infinite loop]
- qemu 1:11.0.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/129922c2bc398b656a9180150e667f98fdf0d402 (v11.0.0-rc1)
CVE-2026-6862 (A flaw was found in libefiboot, a component of efivar. The device path ...)
@@ -55683,7 +55685,7 @@ CVE-2026-41651 (PackageKit is a a D-Bus abstraction layer that allows the user t
NOTE: Fixed by: https://github.com/PackageKit/PackageKit/commit/76cfb675fb31acc3ad5595d4380bfff56d2a8697 (v1.3.5)
CVE-2026-4367 (A flaw was found in libXpm. A local user with low privileges could exp ...)
- libxpm 1:3.5.19-1 (bug #1134690)
- [trixie] - libxpm <no-dsa> (Minor issue)
+ [trixie] - libxpm 1:3.5.17-1+deb13u1
[bookworm] - libxpm <no-dsa> (Minor issue)
[bullseye] - libxpm <postponed> (Minor issue; can be fixed in next update)
NOTE: https://www.openwall.com/lists/oss-security/2026/04/21/3
@@ -56471,14 +56473,14 @@ CVE-2026-39386 (Neko is a a self-hosted virtual browser that runs in Docker and
NOT-FOR-US: Neko
CVE-2026-39378 (The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to v ...)
- nbconvert 7.17.1-1 (bug #1134890)
- [trixie] - nbconvert <no-dsa> (Minor issue)
+ [trixie] - nbconvert 7.16.6-1+deb13u1
[bookworm] - nbconvert <no-dsa> (Minor issue)
[bullseye] - nbconvert <no-dsa> (Minor issue)
NOTE: https://github.com/jupyter/nbconvert/security/advisories/GHSA-7jqv-fw35-gmx9
NOTE: Fixed by: https://github.com/jupyter/nbconvert/commit/0e6b8ccabf2aca6c18fac8c574f22b7155f441fb (v7.17.1)
CVE-2026-39377 (The nbconvert tool, jupyter nbconvert, converts Jupyter notebooks to v ...)
- nbconvert 7.17.1-1 (bug #1134889)
- [trixie] - nbconvert <no-dsa> (Minor issue)
+ [trixie] - nbconvert 7.16.6-1+deb13u1
[bookworm] - nbconvert <not-affected> (Vulnerable code introduced later)
[bullseye] - nbconvert <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/jupyter/nbconvert/security/advisories/GHSA-4c99-qj7h-p3vg
@@ -57296,7 +57298,7 @@ CVE-2026-6048 (The Flipbox Addon for Elementor plugin for WordPress is vulnerabl
NOT-FOR-US: WordPress plugin
CVE-2026-5720 (miniupnpd contains an integer underflow vulnerability in SOAPAction he ...)
- miniupnpd 2.3.10-1 (bug #1134334)
- [trixie] - miniupnpd <no-dsa> (Minor issue)
+ [trixie] - miniupnpd 2.3.9-2+deb13u1
[bookworm] - miniupnpd <no-dsa> (Minor issue)
[bullseye] - miniupnpd <postponed> (Minor issue; DoS)
NOTE: Fixed by: https://github.com/miniupnp/miniupnp/commit/f56bd09b2f2650126b832c5f30a65a09e28167fa (miniupnpd_2_3_10)
@@ -57343,7 +57345,7 @@ CVE-2026-40492 (SAIL is a cross-platform library for loading and saving images w
NOTE: Fixed by: https://github.com/HappySeaFox/sail/commit/36aa5c7ec8a2bb35f6fb867a1177a6f141156b02
CVE-2026-40491 (gdown is a Google Drive public file/folder downloader. Versions prior ...)
- gdown 6.0.0+dfsg-1
- [trixie] - gdown <no-dsa> (Minor issue)
+ [trixie] - gdown 5.2.0+dfsg-2+deb13u1
NOTE: https://github.com/wkentaro/gdown/security/advisories/GHSA-76hw-p97h-883f
NOTE: Fixed by: https://github.com/wkentaro/gdown/commit/af569fc6ed300b7974dee66dc51e9f01b57b4dff (v5.2.2)
CVE-2026-40490 (The AsyncHttpClient (AHC) library allows Java applications to easily e ...)
@@ -57901,7 +57903,7 @@ CVE-2026-6410 (@fastify/static versions 8.0.0 through 9.1.0 allow path traversal
NOT-FOR-US: fastify/static
CVE-2026-6409 (A Denial of Service (DoS) vulnerability exists in the Protobuf PHP lib ...)
- protobuf 3.21.12-16 (bug #1134895)
- [trixie] - protobuf <no-dsa> (Minor issue)
+ [trixie] - protobuf 3.21.12-11+deb13u1
[bookworm] - protobuf <no-dsa> (Minor issue)
[bullseye] - protobuf <postponed> (minor issue)
NOTE: https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-p2gh-cfq4-4wjc
@@ -58502,7 +58504,7 @@ CVE-2026-40916 (A flaw was found in GIMP. A stack buffer overflow vulnerability
NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/d5cdeb96e868308fa529916edbf3034981a664f3 (GIMP_3_1_2)
CVE-2026-40915 (A flaw was found in GIMP. A remote attacker could exploit an integer o ...)
- gimp 3.2.2-1
- [trixie] - gimp <no-dsa> (Minor issue, fix along with future DSA)
+ [trixie] - gimp 3.0.4-3+deb13u9
[bookworm] - gimp <no-dsa> (Minor issue, fix along with future DSA)
[bullseye] - gimp <postponed> (Minor issue; can be fixed in next update)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/16051
@@ -60257,7 +60259,7 @@ CVE-2026-6121 (A flaw has been found in Tenda F451 1.0.0.7. Affected by this vul
NOT-FOR-US: Tenda
CVE-2026-40393 (In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory acces ...)
- mesa 26.0.1-1
- [trixie] - mesa <ignored> (Minor issue, too intrusive to backport)
+ [trixie] - mesa 25.0.7-2+deb13u1
[bookworm] - mesa <ignored> (Minor issue, too intrusive to backport)
NOTE: https://lists.freedesktop.org/archives/mesa-dev/2026-February/226597.html
NOTE: https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/39866
@@ -60406,7 +60408,7 @@ CVE-2026-4155 (ChargePoint Home Flex Inclusion of Sensitive Information in Sourc
NOT-FOR-US: ChargePoint Home Flex
CVE-2026-4154 (GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
- gimp 3.2.0-1
- [trixie] - gimp <no-dsa> (Minor issue)
+ [trixie] - gimp 3.0.4-3+deb13u9
[bookworm] - gimp <no-dsa> (Minor issue)
[bullseye] - gimp <postponed> (Minor issue; can be fixed in next update)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-221/
@@ -60869,7 +60871,7 @@ CVE-2026-22560 (An open redirect vulnerability in Rocket.Chat versions prior to
CVE-2026-1502 (CR/LF bytes were not rejected by HTTP client proxy tunnel headers or h ...)
- python3.14 3.14.5-1
- python3.13 3.13.14-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u3
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
@@ -63049,7 +63051,7 @@ CVE-2026-39374 (Plane is an an open-source project management tool. Prior to 1.3
NOT-FOR-US: Plane
CVE-2026-39373 (JWCrypto implements JWK, JWS, and JWE specifications using python-cryp ...)
- python-jwcrypto 1.5.6-1.1 (bug #1133006)
- [trixie] - python-jwcrypto <no-dsa> (Minor issue)
+ [trixie] - python-jwcrypto 1.5.6-1.1~deb13u1
[bookworm] - python-jwcrypto <no-dsa> (Minor issue)
[bullseye] - python-jwcrypto <postponed> (minor issue; limited memory DoS)
NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-fjrm-76x2-c4q4
@@ -64125,7 +64127,7 @@ CVE-2026-5664
REJECTED
CVE-2026-5663 (A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This i ...)
- dcmtk 3.7.0+really3.7.0-3 (bug #1133001)
- [trixie] - dcmtk <no-dsa> (Minor issue)
+ [trixie] - dcmtk 3.6.9-5+deb13u1
[bookworm] - dcmtk <no-dsa> (Minor issue)
[bullseye] - dcmtk <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8
@@ -66083,7 +66085,7 @@ CVE-2026-34593 (Ash Framework is a declarative, extensible framework for buildin
NOT-FOR-US: Ash Framework
CVE-2026-34591 (Poetry is a dependency manager for Python. From version 1.4.0 to befor ...)
- poetry 2.3.4-0.1 (bug #1132609)
- [trixie] - poetry <no-dsa> (Minor issue)
+ [trixie] - poetry 2.1.2+dfsg-1+deb13u1
[bookworm] - poetry <no-dsa> (Minor issue)
NOTE: https://github.com/python-poetry/poetry/security/advisories/GHSA-2599-h6xx-hpxp
NOTE: https://github.com/python-poetry/poetry/pull/10792
@@ -67324,7 +67326,7 @@ CVE-2026-34156 (NocoBase is an AI-powered no-code/low-code platform for building
NOT-FOR-US: NocoBase
CVE-2026-34155 (RAUC controls the update process on embedded Linux systems. Prior to v ...)
- rauc 1.15.2-1
- [trixie] - rauc <no-dsa> (Minor issue)
+ [trixie] - rauc 1.13-3+deb13u1
[bookworm] - rauc <no-dsa> (Minor issue)
[bullseye] - rauc <postponed> (Minor issue)
NOTE: https://github.com/rauc/rauc/security/advisories/GHSA-6hj7-q844-m2hx
@@ -67617,7 +67619,7 @@ CVE-2026-5292 (Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-34743 (XZ Utils provide a general-purpose data-compression library plus comma ...)
- xz-utils 5.8.3-1 (bug #1132497)
- [trixie] - xz-utils <no-dsa> (Minor issue)
+ [trixie] - xz-utils 5.8.1-1+deb13u1
[bookworm] - xz-utils <no-dsa> (Minor issue)
[bullseye] - xz-utils <postponed> (Minor issue)
NOTE: https://tukaani.org/xz/index-append-overflow.html
@@ -68187,7 +68189,7 @@ CVE-2026-5041 (A vulnerability was identified in code-projects Chamber of Commer
NOT-FOR-US: code-projects
CVE-2026-5037 (A vulnerability was determined in mxml up to 4.0.4. This issue affects ...)
- mxml 4.0.4-4 (bug #1132328)
- [trixie] - mxml <no-dsa> (Minor issue)
+ [trixie] - mxml 3.3.1-1+deb13u1
[bookworm] - mxml <no-dsa> (Minor issue)
[bullseye] - mxml <postponed> (Minor issue)
NOTE: https://github.com/michaelrsweet/mxml/issues/350
@@ -68573,7 +68575,7 @@ CVE-2026-34353 (In OCaml through 4.14.3, Bigarray.reshape allows an integer over
NOTE: Backport for 4.13.y series: https://github.com/ocaml/ocaml/pull/14691
CVE-2026-34352 (In TigerVNC before 1.16.2, Image.cxx in x0vncserver allows other users ...)
- tigervnc 1.15.0+dfsg-2.1 (bug #1132166)
- [trixie] - tigervnc <no-dsa> (Minor issue)
+ [trixie] - tigervnc 1.15.0+dfsg-2.1~deb13u1
[bookworm] - tigervnc <no-dsa> (Minor issue)
[bullseye] - tigervnc <postponed> (Minor issue)
NOTE: https://groups.google.com/g/tigervnc-announce/c/anHL9WLshLI
@@ -68894,12 +68896,12 @@ CVE-2026-33280 (Hidden functionality issue exists in BUFFALO Wi-Fi router produc
NOT-FOR-US: BUFFALO
CVE-2026-33206 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
- calibre 9.6.0+ds+~0.10.5-1
- [trixie] - calibre <no-dsa> (Minor issue)
+ [trixie] - calibre 8.5.0+ds-1+deb13u3
[bookworm] - calibre <no-dsa> (Minor issue)
NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-h3p4-m74f-43g6
CVE-2026-33205 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
- calibre 9.6.0+ds+~0.10.5-1
- [trixie] - calibre <no-dsa> (Minor issue)
+ [trixie] - calibre 8.5.0+ds-1+deb13u3
[bookworm] - calibre <no-dsa> (Minor issue)
NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4926-v9px-wv7v
CVE-2026-33045 (Home Assistant is open source home automation software that puts local ...)
@@ -70690,7 +70692,7 @@ CVE-2026-3591 (A use-after-return vulnerability exists in the `named` server whe
NOTE: https://gitlab.isc.org/isc-projects/bind9/-/commit/4a2048ea7f98b7ad9528463a045abc9d224a0f43 (v9.20.21)
CVE-2026-3608 (Sending a maliciously crafted message to the kea-ctrl-agent, kea-dhcp- ...)
- isc-kea 3.0.3-1
- [trixie] - isc-kea <no-dsa> (Minor issue)
+ [trixie] - isc-kea 2.6.3-1+deb13u1
NOTE: https://kb.isc.org/docs/cve-2026-3608
CVE-2026-33515 (Squid is a caching proxy for the Web. Prior to version 7.5, due to imp ...)
{DSA-6360-1}
@@ -73511,14 +73513,14 @@ CVE-2026-33156 (ScreenToGif is a screen recording tool. In versions from 2.42.1
NOT-FOR-US: ScreenToGif
CVE-2026-33155 (DeepDiff is a project focused on Deep Difference and search of any Pyt ...)
- deepdiff 9.0.0-1 (bug #1131472)
- [trixie] - deepdiff <no-dsa> (Minor issue)
+ [trixie] - deepdiff 8.1.1-4+deb13u1
[bookworm] - deepdiff <no-dsa> (Minor issue)
[bullseye] - deepdiff <not-affected> (Vulnerable code introduced in 5.0.0)
NOTE: https://github.com/qlustered/deepdiff/security/advisories/GHSA-54jj-px8x-5w5q
NOTE: Fixed by: https://github.com/qlustered/deepdiff/commit/0d07ec21d12b46ef4e489383b363eadc22d990fb (8.6.2)
CVE-2026-33154 (dynaconf is a configuration management tool for Python. Prior to versi ...)
- python-dynaconf 3.2.13-1 (bug #1131476)
- [trixie] - python-dynaconf <no-dsa> (Minor issue)
+ [trixie] - python-dynaconf 3.1.7-2+deb13u1
NOTE: https://github.com/dynaconf/dynaconf/security/advisories/GHSA-pxrr-hq57-q35p
NOTE: Fixed by: https://github.com/dynaconf/dynaconf/commit/2fbb45ee36b8c0caa5b924fe19f3c1a5e8603fa7 (3.2.13)
CVE-2026-33151 (Socket.IO is an open source, real-time, bidirectional, event-based, co ...)
@@ -74726,7 +74728,7 @@ CVE-2026-34881 (OpenStack Glance before 29.1.1, 30.x before 30.1.1, and 31.0.0 i
NOTE: https://security.openstack.org/ossa/OSSA-2026-004.html
CVE-2026-3842
- qemu 1:10.2.2+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <no-dsa> (Minor issue)
[bullseye] - qemu <not-affected> (Synthetic Debugging introduced in v7.1.0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/85af4e937016ed2f20122eb116597d1abb30c5c0 (v10.2.2)
@@ -74970,7 +74972,7 @@ CVE-2026-32723 (SandboxJS is a JavaScript sandboxing library. Prior to 0.8.35, S
NOT-FOR-US: SandboxJS Node module
CVE-2026-32722 (Memray is a memory profiler for Python. Prior to Memray 1.19.2, Memray ...)
- python-memray 1.19.3+dfsg-1 (bug #1131372)
- [trixie] - python-memray <no-dsa> (Minor issue)
+ [trixie] - python-memray 1.17.0+dfsg-1+deb13u1
NOTE: https://github.com/bloomberg/memray/security/advisories/GHSA-r5pr-887v-m2w9
NOTE: https://github.com/bloomberg/memray/commit/ba6e4e2e9930f9641bed7adfdf43c8e2545ce249 (v1.19.2)
CVE-2026-32703 (OpenProject is an open-source, web-based project management software. ...)
@@ -75278,7 +75280,7 @@ CVE-2026-26945 (Dell Integrated Dell Remote Access Controller 9, 14G versions pr
CVE-2026-26740 (Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote attack ...)
{DLA-4650-1}
- giflib 6.1.3-1 (bug #1131368)
- [trixie] - giflib <no-dsa> (Minor issue)
+ [trixie] - giflib 5.2.2-1+deb13u1
[bookworm] - giflib <no-dsa> (Minor issue)
NOTE: https://github.com/zakkanijia/POC/blob/main/giflib/giftool/giflib_giftool_gce_len_heap_oobwrite_disclosure.md
NOTE: https://sourceforge.net/p/giflib/bugs/199/
@@ -75702,14 +75704,14 @@ CVE-2026-27522 (OpenClaw versions prior to 2026.2.24 contain a local media root
NOT-FOR-US: OpenClaw
CVE-2026-27459 (pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...)
- pyopenssl 26.0.0-1
- [trixie] - pyopenssl <no-dsa> (Minor issue)
+ [trixie] - pyopenssl 25.0.0-1+deb13u1
[bookworm] - pyopenssl <no-dsa> (Minor issue)
[bullseye] - pyopenssl <not-affected> (set_cookie_generate_callback introduced in v22.0.0)
NOTE: https://github.com/pyca/pyopenssl/security/advisories/GHSA-5pwr-322w-8jr4
NOTE: https://github.com/pyca/pyopenssl/commit/57f09bb4bb051d3bc2a1abd36e9525313d5cd408 (26.0.0)
CVE-2026-27448 (pyOpenSSL is a Python wrapper around the OpenSSL library. Starting in ...)
- pyopenssl 26.0.0-1
- [trixie] - pyopenssl <no-dsa> (Minor issue)
+ [trixie] - pyopenssl 25.0.0-1+deb13u1
[bookworm] - pyopenssl <no-dsa> (Minor issue)
[bullseye] - pyopenssl <postponed> (Minor issue, requires buggy app callback)
NOTE: https://github.com/pyca/pyopenssl/security/advisories/GHSA-vp96-hxj8-p424
@@ -77132,7 +77134,7 @@ CVE-2026-30914 (SFTPGo is an open source, event-driven file transfer solution. I
- sftpgo <itp> (bug #1050829)
CVE-2026-30853 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
- calibre 9.5.0+ds+~0.10.5-1
- [trixie] - calibre <no-dsa> (Minor issue)
+ [trixie] - calibre 8.5.0+ds-1+deb13u3
[bookworm] - calibre <no-dsa> (Minor issue)
NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-7mp7-rfrg-542x
CVE-2026-2888 (The Formidable Forms plugin for WordPress is vulnerable to an authoriz ...)
@@ -78794,7 +78796,7 @@ CVE-2024-14024 (An improper certificate validation vulnerability has been report
NOT-FOR-US: QNAP
CVE-2026-3805 (When doing a second SMB request to the same host again, curl would wro ...)
- curl 8.19.0-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <not-affected> (Vulnerable code introduced later)
[bullseye] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2026-3805.html
@@ -78802,7 +78804,7 @@ CVE-2026-3805 (When doing a second SMB request to the same host again, curl woul
NOTE: Fixed by: https://github.com/curl/curl/commit/e090be9f73a7a71459ef678c7cc4b1f75e3ea883 (curl-8_19_0)
CVE-2026-3784 (curl would wrongly reuse an existing HTTP proxy connection doing CONNE ...)
- curl 8.19.0-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-3784.html
@@ -78810,7 +78812,7 @@ CVE-2026-3784 (curl would wrongly reuse an existing HTTP proxy connection doing
NOTE: Fixed by: https://github.com/curl/curl/commit/5f13a7645e565c5c1a06f3ef86e97afb856fb364 (curl-8_19_0)
CVE-2026-3783 (When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...)
- curl 8.19.0-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-3783.html
@@ -78818,7 +78820,7 @@ CVE-2026-3783 (When an OAuth2 bearer token is used for an HTTP(S) transfer, and
NOTE: Fixed by: https://github.com/curl/curl/commit/e3d7401a32a46516c9e5ee877e613e62ed35bddc (curl-8_19_0)
CVE-2026-1965 (libcurl can in some circumstances reuse the wrong connection when aske ...)
- curl 8.19.0~rc3-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-1965.html
@@ -79185,7 +79187,7 @@ CVE-2026-23907 (This issue affects the ExtractEmbeddedFiles example inApache PD
CVE-2026-23868 (Giflib contains a double-free vulnerability that is the result of a sh ...)
{DLA-4650-1}
- giflib 6.1.3-1 (bug #1130495)
- [trixie] - giflib <no-dsa> (Minor issue)
+ [trixie] - giflib 5.2.2-1+deb13u1
[bookworm] - giflib <no-dsa> (Minor issue)
NOTE: https://www.facebook.com/security/advisories/cve-2026-23868
NOTE: https://sourceforge.net/p/giflib/code/ci/f5b7267aed3665ef025c13823e454170d031c106/tree/gifalloc.c?diff=5146815377b7395944cb683a08c43eee3f631eb7
@@ -81101,14 +81103,14 @@ CVE-2026-28353 (Trivy Vulnerability Scanner is a VS Code extension that helps fi
CVE-2026-28350 (lxml_html_clean is a project for HTML cleaning functionalities copied ...)
- lxml 5.2.0-1
- lxml-html-clean 0.4.4-1
- [trixie] - lxml-html-clean <no-dsa> (Minor issue)
+ [trixie] - lxml-html-clean 0.4.4-1~deb13u1
NOTE: https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-xvp8-3mhv-424c
NOTE: Fixed by: https://github.com/fedora-python/lxml_html_clean/commit/9c5612ca33b941eec4178abf8a5294b103403f34 (0.4.4)
NOTE: lxml-html-clean was split out of lxml in 5.2.0
CVE-2026-28348 (lxml_html_clean is a project for HTML cleaning functionalities copied ...)
- lxml 5.2.0-1
- lxml-html-clean 0.4.4-1
- [trixie] - lxml-html-clean <no-dsa> (Minor issue)
+ [trixie] - lxml-html-clean 0.4.4-1~deb13u1
NOTE: https://github.com/fedora-python/lxml_html_clean/security/advisories/GHSA-hw26-mmpg-fqfg
NOTE: Fixed by: https://github.com/fedora-python/lxml_html_clean/commit/2ef732667ddbc74ea59847bcf24b75809aaeed3b (0.4.4)
NOTE: lxml-html-clean was split out of lxml in 5.2.0
@@ -83612,7 +83614,7 @@ CVE-2026-2428 (The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerab
NOT-FOR-US: WordPress plugin
CVE-2026-28370 (In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0 ...)
- vitrage 15.0.1-1 (bug #1139452)
- [trixie] - vitrage <no-dsa> (Minor issue)
+ [trixie] - vitrage 14.0.0-4+deb13u1
[bookworm] - vitrage <no-dsa> (Minor issue)
NOTE: https://storyboard.openstack.org/#!/story/2011539
NOTE: Fixed by: https://github.com/openstack/vitrage/commit/5b57e2b32a6d02992a28d9a671ebba5e308fd141 (master)
@@ -84119,7 +84121,7 @@ CVE-2026-27812 (Sub2API is an AI API gateway platform designed to distribute and
NOT-FOR-US: Sub2API
CVE-2026-27809 (psd-tools is a Python package for working with Adobe Photoshop PSD fil ...)
- psd-tools 1.14.2+dfsg.1-1 (bug #1129098)
- [trixie] - psd-tools <no-dsa> (Minor issue)
+ [trixie] - psd-tools 1.10.7+dfsg.1-1+deb13u1
[bookworm] - psd-tools <no-dsa> (Minor issue)
NOTE: https://github.com/psd-tools/psd-tools/security/advisories/GHSA-24p2-j2jr-386w
NOTE: Fixed by: https://github.com/psd-tools/psd-tools/commit/6c0a78f195b5942757886a1863793fd5946c1fb1 (v1.12.2)
@@ -87237,7 +87239,7 @@ CVE-2026-2274 (A SSRF and Arbitrary File Read vulnerability in AppSheet Core in
NOT-FOR-US: Google AppSheet
CVE-2026-2243 (A flaw was found in QEMU. A specially crafted VMDK image could trigger ...)
- qemu 1:10.2.2+ds-1 (bug #1128478)
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <no-dsa> (Minor issue)
[bullseye] - qemu <postponed> (Minor issue)
NOTE: https://lore.kernel.org/qemu-devel/CAJ9qJssSwxkmEVethg57-Ph6maEfButSaV-r07ma9_x1sp6wYg@mail.gmail.com/
@@ -88846,7 +88848,7 @@ CVE-2026-2574
NOTE: OpenSSL backend disabled by default upstream and in Debian
CVE-2026-2474 (Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable t ...)
- libcrypt-urandom-perl 0.55-1
- [trixie] - libcrypt-urandom-perl <no-dsa> (Minor issue)
+ [trixie] - libcrypt-urandom-perl 0.54-1+deb13u1
[bookworm] - libcrypt-urandom-perl <not-affected> (Vulnerable code introduced later in 0.41)
[bullseye] - libcrypt-urandom-perl <not-affected> (Vulnerable code introduced later in 0.41)
NOTE: Fixed by: https://github.com/david-dick/crypt-urandom/commit/124e2c2d32bfd637fd06f81f832fa8a4627cdc2b
@@ -92983,7 +92985,7 @@ CVE-2019-25266 (Wondershare Application Framework Service 2.4.3.231 contains an
NOT-FOR-US: Wondershare Application Framework Service
CVE-2026-25727 (time provides date and time handling in Rust. From 0.3.6 to before 0.3 ...)
- rust-time 0.3.47-1
- [trixie] - rust-time <no-dsa> (Minor issue)
+ [trixie] - rust-time 0.3.37-1+deb13u1
[bookworm] - rust-time <no-dsa> (Minor issue)
[bullseye] - rust-time <not-affected> (rfc2822 parsing introduced in v0.3.6)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0009.html
@@ -94940,6 +94942,7 @@ CVE-2026-1760 (A flaw was found in SoupServer. This HTTP request smuggling vulne
CVE-2026-1757 (A flaw was identified in the interactive shell of the xmllint utility, ...)
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (unimportant)
+ [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/160c8a43ba37dfb07ebe6446fbad9d0973d9279d
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/5446460ad3229579c91506317fb80ab333d44414 (v2.15.2)
@@ -97205,7 +97208,7 @@ CVE-2016-15057 (** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Speci
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-1425 (A security flaw has been discovered in pymumu SmartDNS up to 47.1. Thi ...)
- smartdns 46.1+dfsg-1.1 (bug #1126538)
- [trixie] - smartdns <no-dsa> (Minor issue)
+ [trixie] - smartdns 46.1+dfsg-1.1~deb13u1
[bookworm] - smartdns <no-dsa> (Minor issue)
[bullseye] - smartdns <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/pymumu/smartdns/commit/2d57c4b4e1add9b4537aeb403f794a084727e1c8
@@ -97800,7 +97803,7 @@ CVE-2026-1299 (The email module, specifically the "BytesGenerator" class, didn\
CVE-2026-0994 (A denial-of-service (DoS) vulnerability exists in google.protobuf.json ...)
[experimental] - protobuf 3.25.7-1
- protobuf 3.21.12-16 (bug #1126302)
- [trixie] - protobuf <no-dsa> (Minor issue)
+ [trixie] - protobuf 3.21.12-11+deb13u1
[bookworm] - protobuf <no-dsa> (Minor issue)
[bullseye] - protobuf <postponed> (Minor issue)
NOTE: https://github.com/protocolbuffers/protobuf/issues/25070
@@ -100485,7 +100488,7 @@ CVE-2025-15537 (A security vulnerability has been detected in Mapnik up to 4.2.0
NOTE: https://github.com/mapnik/mapnik/issues/4543
CVE-2025-15536 (A weakness has been identified in BYVoid OpenCC up to 1.1.9. This vuln ...)
- opencc 1.1.9+ds1-4 (bug #1126286)
- [trixie] - opencc <no-dsa> (Minor issue)
+ [trixie] - opencc 1.1.9+ds1-1+deb13u1
[bookworm] - opencc <no-dsa> (Minor issue)
[bullseye] - opencc <postponed> (Minor issue)
NOTE: https://github.com/BYVoid/OpenCC/issues/997
@@ -101308,7 +101311,7 @@ CVE-2026-20047 (A vulnerability in the web-based management interface of Cisco I
CVE-2026-0992 (A flaw was found in the libxml2 library. This uncontrolled resource co ...)
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (bug #1125696)
- [trixie] - libxml2 <no-dsa> (Minor issue)
+ [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
[bookworm] - libxml2 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/f75abfcaa419a740a3191e56c60400f3ff18988d
@@ -101320,7 +101323,7 @@ CVE-2026-0992 (A flaw was found in the libxml2 library. This uncontrolled resour
CVE-2026-0990 (A flaw was found in libxml2, an XML parsing library. This uncontrolled ...)
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (bug #1125695)
- [trixie] - libxml2 <no-dsa> (Minor issue)
+ [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
[bookworm] - libxml2 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/1961208e958ca22f80a0b4e4c9d71cfa050aa982
@@ -101330,7 +101333,7 @@ CVE-2026-0990 (A flaw was found in libxml2, an XML parsing library. This uncontr
CVE-2026-0989 (A flaw was identified in the RelaxNG parser of libxml2 related to how ...)
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (bug #1125691)
- [trixie] - libxml2 <no-dsa> (Minor issue)
+ [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
[bookworm] - libxml2 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/998
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374
@@ -103514,7 +103517,7 @@ CVE-2026-22033 (Label Studio is a multi-type data labeling and annotation tool.
NOT-FOR-US: Label Studio
CVE-2025-71063 (Errands before 46.2.10 does not verify TLS certificates for CalDAV ser ...)
- errands 46.2.10-1 (bug #1123738)
- [trixie] - errands <no-dsa> (Minor issue)
+ [trixie] - errands 46.2.8-1+deb13u1
NOTE: https://github.com/mrvladus/Errands/issues/401
NOTE: https://github.com/mrvladus/Errands/commit/04e567b432083fc798ea2249363ea6c83ff01099 (46.2.10)
CVE-2025-68657 (Espressif ESP-IDF USB Host HID (Human Interface Device) Driver allows ...)
@@ -103726,7 +103729,7 @@ CVE-2026-22703 (Cosign provides code signing and transparency for containers and
NOTE: Fixed by: https://github.com/sigstore/cosign/commit/3ade80c5f77cefc904f8c994e88618e5892e8f1c (v2.6.2)
CVE-2026-22702 (virtualenv is a tool for creating isolated virtual python environments ...)
- python-virtualenv 20.36.1+ds-1 (bug #1125191)
- [trixie] - python-virtualenv <no-dsa> (Minor issue)
+ [trixie] - python-virtualenv 20.31.2+ds-1+deb13u1
[bookworm] - python-virtualenv <no-dsa> (Minor issue)
[bullseye] - python-virtualenv <postponed> (Minor issue, affected directories normally not in world-writable locations)
NOTE: https://github.com/pypa/virtualenv/security/advisories/GHSA-597g-3phw-6986
@@ -104658,7 +104661,7 @@ CVE-2025-13679 (The Tutor LMS \u2013 eLearning and online course solution plugin
CVE-2025-13151 (Stack-based buffer overflow in libtasn1 version: v4.20.0. The function ...)
[experimental] - libtasn1-6 4.21.0-1
- libtasn1-6 4.21.0-2 (bug #1125063)
- [trixie] - libtasn1-6 <no-dsa> (Minor issue)
+ [trixie] - libtasn1-6 4.20.0-2+deb13u1
[bookworm] - libtasn1-6 <no-dsa> (Minor issue)
[bullseye] - libtasn1-6 <postponed> (Minor issue, unlikely scenario)
NOTE: https://gitlab.com/gnutls/libtasn1/-/issues/55
@@ -105171,7 +105174,7 @@ CVE-2025-15079 (When doing SSH-based transfers using either SCP or SFTP, and set
NOTE: Debian builds with libssh2 for SSH backend
CVE-2025-14819 (When doing TLS related transfers with reused easy or multi handles and ...)
- curl 8.18.0~rc3-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2025-14819.html
@@ -105179,7 +105182,7 @@ CVE-2025-14819 (When doing TLS related transfers with reused easy or multi handl
NOTE: Fixed by: https://github.com/curl/curl/commit/cd046f6c93b39d673a58c18648d8906e954c4f5d (rc-8_18_0-3, curl-8_18_0)
CVE-2025-14524 (When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...)
- curl 8.18.0~rc2-1
- [trixie] - curl <no-dsa> (Minor issue)
+ [trixie] - curl 8.14.1-2+deb13u4
[bookworm] - curl <no-dsa> (Minor issue)
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2025-14524.html
@@ -112495,7 +112498,7 @@ CVE-2025-68614 (LibreNMS is an auto-discovering PHP/MySQL/SNMP based network mon
NOT-FOR-US: LibreNMS
CVE-2025-68480 (Marshmallow is a lightweight library for converting complex objects to ...)
- python-marshmallow 3.26.2-0.1 (bug #1123888)
- [trixie] - python-marshmallow <no-dsa> (Minor issue)
+ [trixie] - python-marshmallow 3.26.2-0+deb13u1
[bookworm] - python-marshmallow <no-dsa> (Minor issue)
[bullseye] - python-marshmallow <postponed> (Minor issue)
NOTE: https://github.com/marshmallow-code/marshmallow/security/advisories/GHSA-428g-f7cq-pgp5
@@ -113230,7 +113233,7 @@ CVE-2025-34451 (rofl0r/proxychains-ng versions up to and including 4.17 and prio
NOTE: Doesn't cross any security boundary
CVE-2025-34450 (merbanan/rtl_433 versions up to and including 25.02 and prior to commi ...)
- rtl-433 25.12-1 (bug #1126178)
- [trixie] - rtl-433 <no-dsa> (Minor issue)
+ [trixie] - rtl-433 25.02-1+deb13u1
[bookworm] - rtl-433 <no-dsa> (Minor issue)
[bullseye] - rtl-433 <postponed> (Minor issue)
NOTE: https://github.com/merbanan/rtl_433/issues/3375
@@ -114138,7 +114141,7 @@ CVE-2025-14841 (A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted e
{DLA-4443-1}
[experimental] - dcmtk 3.7.0+really3.7.0-0+exp1
- dcmtk 3.7.0+really3.7.0-1 (bug #1123584)
- [trixie] - dcmtk <no-dsa> (Minor issue)
+ [trixie] - dcmtk 3.6.9-5+deb13u1
[bookworm] - dcmtk <no-dsa> (Minor issue)
NOTE: https://support.dcmtk.org/redmine/issues/1183
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/ffb1a4a37d2c876e3feeb31df4930f2aed7fa030 (DCMTK-3.7.0)
@@ -115398,7 +115401,7 @@ CVE-2025-68146 (filelock is a platform-independent file lock for Python. In vers
NOTE: Fixed by: https://github.com/tox-dev/filelock/commit/4724d7f8c3393ec1f048c93933e6e3e6ec321f0e (3.20.1)
CVE-2025-68142 (PyMdown Extensions is a set of extensions for the `Python-Markdown` ma ...)
- pymdown-extensions 10.13-4 (bug #1123672)
- [trixie] - pymdown-extensions <no-dsa> (Minor issue)
+ [trixie] - pymdown-extensions 10.13-1+deb13u1
[bookworm] - pymdown-extensions <not-affected> (Vulnerable code not present)
NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-r6h4-mm7h-8pmq
NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/b50d15a56850ed1408a284bba81cc019c6bd72e8 (10.16.1)
@@ -115984,7 +115987,7 @@ CVE-2025-14439
NOT-FOR-US: OpenUSD
CVE-2025-68920 (C-Kermit (aka ckermit) through 10.0 Beta.12 (aka 416-beta12) before 24 ...)
- ckermit 416~beta12-5 (bug #1123025)
- [trixie] - ckermit <no-dsa> (Minor issue; documented; can be fixed via point release)
+ [trixie] - ckermit 416~beta12-1+deb13u1
[bookworm] - ckermit <no-dsa> (Minor issue; documented; can be fixed via point release)
[bullseye] - ckermit <postponed> (Minor issue; documented)
NOTE: https://github.com/KermitProject/ckermit/pull/20
@@ -116337,7 +116340,7 @@ CVE-2025-14607 (A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affecte
{DLA-4443-1}
[experimental] - dcmtk 3.7.0+really3.7.0-0+exp1
- dcmtk 3.7.0+really3.7.0-1 (bug #1122926)
- [trixie] - dcmtk <no-dsa> (Minor issue)
+ [trixie] - dcmtk 3.6.9-5+deb13u1
[bookworm] - dcmtk <no-dsa> (Minor issue)
NOTE: https://support.dcmtk.org/redmine/issues/1184
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/4c0e5c10079392c594d6a7abd95dd78ac0aa556a (DCMTK-3.7.0)
@@ -122028,7 +122031,7 @@ CVE-2025-66478
REJECTED
CVE-2025-66453 (Rhino is an open-source implementation of JavaScript written entirely ...)
- rhino 1.7.15.1-0.1 (bug #1121953)
- [trixie] - rhino <no-dsa> (Minor issue)
+ [trixie] - rhino 1.7.15.1-0.1~deb13u1
[bookworm] - rhino <no-dsa> (Minor issue)
[bullseye] - rhino <postponed> (Minor issue)
NOTE: https://github.com/mozilla/rhino/security/advisories/GHSA-3w8q-xq97-5j7x
@@ -123750,7 +123753,7 @@ CVE-2025-58360 (GeoServer is an open source server that allows users to share an
NOT-FOR-US: GeoServer
CVE-2025-55174 (In KDE Skanpage before 25.08.0, an attempt at file overwrite can resul ...)
- skanpage 25.12.3-1 (bug #1121443)
- [trixie] - skanpage <no-dsa> (Minor issue)
+ [trixie] - skanpage 25.04.2-1+deb13u1
[bookworm] - skanpage <no-dsa> (Minor issue)
NOTE: https://kde.org/info/security/advisory-20250811-1.txt
NOTE: https://commits.kde.org/skanpage/19308900da27b46739f2360426b91479e7179a2f (v25.07.90)
@@ -152007,7 +152010,7 @@ CVE-2025-58369 (fs2 is a compositional, streaming I/O library for Scala. Version
NOT-FOR-US: fs2 compositional, streaming I/O library for Scala
CVE-2025-58367 (DeepDiff is a project focused on Deep Difference and search of any Pyt ...)
- deepdiff 8.6.1-1
- [trixie] - deepdiff <no-dsa> (Minor issue)
+ [trixie] - deepdiff 8.1.1-4+deb13u1
[bookworm] - deepdiff <no-dsa> (Minor issue)
[bullseye] - deepdiff <not-affected> (Vulnerable code introduced in 5.0.0)
NOTE: https://github.com/qlustered/deepdiff/security/advisories/GHSA-mw26-5g2v-hqw3
@@ -154155,7 +154158,7 @@ CVE-2025-9769 (A security flaw has been discovered in D-Link DI-7400G+ 19.12.25A
CVE-2025-9375 (XML Injection vulnerability in xmltodict allows Input Data Manipulatio ...)
[experimental] - python-xmltodict 1.0.3-1
- python-xmltodict 0.13.0-1.1 (bug #1113825)
- [trixie] - python-xmltodict <no-dsa> (Minor issue)
+ [trixie] - python-xmltodict 0.13.0-1.1~deb13u1
[bookworm] - python-xmltodict <no-dsa> (Minor issue)
[bullseye] - python-xmltodict <postponed> (Minor issue)
NOTE: https://github.com/martinblech/xmltodict/issues/377
@@ -154295,7 +154298,7 @@ CVE-2025-9733 (A security flaw has been discovered in code-projects Human Resour
CVE-2025-9732 (A vulnerability was identified in DCMTK up to 3.6.9. This affects an u ...)
{DLA-4363-1}
- dcmtk 3.6.9-6 (bug #1113993)
- [trixie] - dcmtk <no-dsa> (Minor issue)
+ [trixie] - dcmtk 3.6.9-5+deb13u1
[bookworm] - dcmtk <no-dsa> (Minor issue)
NOTE: https://github.com/DCMTK/dcmtk/commit/7ad81d69b19714936e18ea5fc74edaeb9f021ce7
NOTE: https://github.com/DCMTK/dcmtk/commit/3de96da6cd66b1af7224561c568bc3de50cd1398
@@ -161486,6 +161489,7 @@ CVE-2025-8733
CVE-2025-8732 (A vulnerability was found in libxml2 up to 2.14.5. It has been declare ...)
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (unimportant)
+ [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/958
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/958#note_2505853
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/3425dece47c8db600f8d7328ae2d7ddfaa0d7b2d (v2.15.2)
@@ -175307,7 +175311,7 @@ CVE-2025-6393 (A vulnerability was found in TOTOLINK A702R, A3002R, A3002RU and
CVE-2025-6375 (A vulnerability was found in poco up to 1.14.1. It has been rated as p ...)
[experimental] - poco 1.14.2-1
- poco 1.14.2-2 (bug #1108157)
- [trixie] - poco <no-dsa> (Minor issue)
+ [trixie] - poco 1.13.0-6+deb13u1
[bookworm] - poco <no-dsa> (Minor issue)
[bullseye] - poco <postponed> (Minor issue)
NOTE: https://github.com/pocoproject/poco/issues/4915
@@ -178141,7 +178145,7 @@ CVE-2025-4748 (Improper Limitation of a Pathname to a Restricted Directory ('Pat
NOTE: https://github.com/erlang/otp/commit/10608879c81332af2d3c00db61ee173c93c1ea4e (OTP-26.2.5.13, OTP-27.3.4.1)
CVE-2025-4565 (Any project that uses Protobuf Pure-Python backendto parse untrusted P ...)
- protobuf 3.21.12-12 (bug #1108057)
- [trixie] - protobuf <no-dsa> (Minor issue)
+ [trixie] - protobuf 3.21.12-11+deb13u1
[bookworm] - protobuf <no-dsa> (Minor issue)
[bullseye] - protobuf <postponed> (Minor issue; can be fixed in next update)
NOTE: https://github.com/protocolbuffers/protobuf/commit/17838beda2943d08b8a9d4df5b68f5f04f26d901
@@ -256451,7 +256455,7 @@ CVE-2024-49193 (Zendesk before 2024-07-02 allows remote attackers to read ticket
NOT-FOR-US: Zendesk
CVE-2024-6519 (A use-after-free vulnerability was found in the QEMU LSI53C895A SCSI H ...)
- qemu 1:11.0.0+ds-1 (bug #1085299)
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <no-dsa> (Minor issue)
[bullseye] - qemu <postponed> (Minor issue; can be fixed in next update)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2292089
@@ -261064,7 +261068,7 @@ CVE-2024-8364 (The WP Custom Fields Search plugin for WordPress is vulnerable to
NOT-FOR-US: WordPress plugin
CVE-2024-7254 (Any project that parses untrusted Protocol Buffers datacontaining an a ...)
- protobuf 3.21.12-12 (bug #1082381)
- [trixie] - protobuf <no-dsa> (Minor issue)
+ [trixie] - protobuf 3.21.12-11+deb13u1
[bookworm] - protobuf <no-dsa> (Minor issue)
[bullseye] - protobuf <postponed> (Minor issue)
NOTE: https://github.com/protocolbuffers/protobuf/commit/b7044987de77f1dc368fee558636d0b56d7e75e1 (v3.25.5)
@@ -270090,7 +270094,7 @@ CVE-2024-20082 (In Modem, there is a possible memory corruption due to a missing
NOT-FOR-US: Mediatek
CVE-2026-3196 (An integer overflow vulnerability was found in the virtio-snd device v ...)
- qemu 1:10.2.2+ds-1 (bug #1129605)
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Vulnerable code not present)
[bullseye] - qemu <not-affected> (VirtIO sound device introduced in v8.2.0)
NOTE: https://lore.kernel.org/qemu-devel/20260220-virtio-snd-series-v1-0-207c4f7200a2@linaro.org/
@@ -270098,7 +270102,7 @@ CVE-2026-3196 (An integer overflow vulnerability was found in the virtio-snd dev
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d84fbf241d0322f19adfbe466c60bed5f50de262 (v10.2.2)
CVE-2026-3195 (A flaw was found in QEMU. When reading input audio in the virtio-snd d ...)
- qemu 1:10.2.2+ds-1 (bug #1129604)
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.10+ds-0+deb13u1
[bookworm] - qemu <not-affected> (Incomplete fix for CVE-2024-7730 not applied)
[bullseye] - qemu <not-affected> (Incomplete fix for CVE-2024-7730 not applied)
NOTE: CVE exists for an incomplete fix for CVE-2024-7730
@@ -496195,7 +496199,7 @@ CVE-2021-41557 (Sofico Miles RIA 2020.2 Build 127964T is affected by Stored Cros
NOT-FOR-US: Sofico
CVE-2021-41556 (sqclass.cpp in Squirrel through 2.2.5 and 3.x through 3.1 allows an ou ...)
- squirrel3 3.1-8.5 (bug #1016212)
- [trixie] - squirrel3 <no-dsa> (Minor issue)
+ [trixie] - squirrel3 3.1-8.2+deb13u1
[bullseye] - squirrel3 <no-dsa> (Minor issue)
[buster] - squirrel3 <no-dsa> (Minor issue)
NOTE: https://github.com/albertodemichelis/squirrel/commit/23a0620658714b996d20da3d4dd1a0dcf9b0bd98 (v3.2)
=====================================
data/next-point-update.txt
=====================================
@@ -1,283 +1,3 @@
-CVE-2026-25727
- [trixie] - rust-time 0.3.37-1+deb13u1
-CVE-2025-68920
- [trixie] - ckermit 416~beta12-1+deb13u1
-CVE-2025-14524
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2025-14819
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-1965
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-3783
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-3784
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-3805
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-4873
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-5545
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-5773
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-6253
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-6276
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-6429
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-7168
- [trixie] - curl 8.14.1-2+deb13u4
-CVE-2026-45793
- [trixie] - composer 2.8.8-1+deb13u3
-CVE-2026-42052
- [trixie] - beets 2.2.0-3+deb13u1
-CVE-2026-8503
- [trixie] - libapache-session-browseable-perl 1.3.16-1+deb13u1
-CVE-2026-46445
- [trixie] - sogo 5.12.1-3+deb13u2
-CVE-2026-46446
- [trixie] - sogo 5.12.1-3+deb13u2
-CVE-2025-71063
- [trixie] - errands 46.2.8-1+deb13u1
-CVE-2026-42268
- [trixie] - modsecurity 3.0.14-1+deb13u1
-CVE-2026-30923
- [trixie] - modsecurity 3.0.14-1+deb13u1
-CVE-2026-30853
- [trixie] - calibre 8.5.0+ds-1+deb13u3
-CVE-2026-33205
- [trixie] - calibre 8.5.0+ds-1+deb13u3
-CVE-2026-33206
- [trixie] - calibre 8.5.0+ds-1+deb13u3
-CVE-2026-42046
- [trixie] - libcaca 0.99.beta20-5+deb13u1
-CVE-2026-49299
- [trixie] - neutron 2:26.0.0-9+deb13u1
-CVE-2026-45232
- [trixie] - rsync 3.4.1+ds1-5+deb13u4
-CVE-2026-47187
- [trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
-CVE-2026-48711
- [trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
-CVE-2026-50593
- [trixie] - graphite2 1.3.14-2+deb13u1
-CVE-2026-44312
- [trixie] - ruby-css-parser 1.19.0-1+deb13u1
-CVE-2026-0989
- [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
-CVE-2026-0990
- [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
-CVE-2026-0992
- [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
-CVE-2025-8732
- [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
-CVE-2026-1757
- [trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
-CVE-2026-49214
- [trixie] - php-guzzlehttp-psr7 2.7.1-1+deb13u1
-CVE-2026-48998
- [trixie] - php-guzzlehttp-psr7 2.7.1-1+deb13u1
-CVE-2026-40491
- [trixie] - gdown 5.2.0+dfsg-2+deb13u1
-CVE-2026-4367
- [trixie] - libxpm 1:3.5.17-1+deb13u1
-CVE-2026-1502
- [trixie] - python3.13 3.13.5-2+deb13u3
-CVE-2026-3276
- [trixie] - python3.13 3.13.5-2+deb13u3
-CVE-2026-7774
- [trixie] - python3.13 3.13.5-2+deb13u3
-CVE-2026-8328
- [trixie] - python3.13 3.13.5-2+deb13u3
-CVE-2026-9669
- [trixie] - python3.13 3.13.5-2+deb13u3
-CVE-2026-4154
- [trixie] - gimp 3.0.4-3+deb13u9
-CVE-2026-40915
- [trixie] - gimp 3.0.4-3+deb13u9
-CVE-2026-28370
- [trixie] - vitrage 14.0.0-4+deb13u1
-CVE-2026-55748
- [trixie] - horizon 3:25.3.0-3+deb13u1
-CVE-2025-55174
- [trixie] - skanpage 25.04.2-1+deb13u1
-CVE-2026-8341
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-41440
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-41439
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-41438
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-41437
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-41436
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-41435
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-6502
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-5761
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-5744
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-5763
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2024-6519
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-3890
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-3886
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-3842
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-2243
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-3195
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-3195
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-3196
- [trixie] - qemu 1:10.0.10+ds-0+deb13u1
-CVE-2026-2474
- [trixie] - libcrypt-urandom-perl 0.54-1+deb13u1
-CVE-2026-29167
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-29170
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-34355
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-34356
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-42535
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-42536
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-43951
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-44119
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-44185
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-44186
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-44631
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2026-48913
- [trixie] - apache2 2.4.68-1~deb13u1
-CVE-2025-9732
- [trixie] - dcmtk 3.6.9-5+deb13u1
-CVE-2025-14607
- [trixie] - dcmtk 3.6.9-5+deb13u1
-CVE-2026-5663
- [trixie] - dcmtk 3.6.9-5+deb13u1
-CVE-2025-14841
- [trixie] - dcmtk 3.6.9-5+deb13u1
-CVE-2026-10194
- [trixie] - dcmtk 3.6.9-5+deb13u1
-CVE-2026-12805
- [trixie] - dcmtk 3.6.9-5+deb13u2
-CVE-2026-9641
- [trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
-CVE-2026-9638
- [trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
-CVE-2017-20240
- [trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
-CVE-2026-8829
- [trixie] - libhtml-parser-perl 3.83-2~deb13u1
-CVE-2026-43859
- [trixie] - mutt 2.2.13-1+deb13u1
-CVE-2026-43860
- [trixie] - mutt 2.2.13-1+deb13u1
-CVE-2026-43861
- [trixie] - mutt 2.2.13-1+deb13u1
-CVE-2026-43862
- [trixie] - mutt 2.2.13-1+deb13u1
-CVE-2026-43863
- [trixie] - mutt 2.2.13-1+deb13u1
-CVE-2026-43864
- [trixie] - mutt 2.2.13-1+deb13u1
-CVE-2026-3608
- [trixie] - isc-kea 2.6.3-1+deb13u1
-CVE-2026-11852
- [trixie] - debusine 0.11.3+deb13u1
-CVE-2026-11853
- [trixie] - debusine 0.11.3+deb13u1
-CVE-2026-23868
- [trixie] - giflib 5.2.2-1+deb13u1
-CVE-2026-26740
- [trixie] - giflib 5.2.2-1+deb13u1
-CVE-2026-44988
- [trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
-CVE-2026-50538
- [trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
-CVE-2025-13151
- [trixie] - libtasn1-6 4.20.0-2+deb13u1
-CVE-2021-41556
- [trixie] - squirrel3 3.1-8.2+deb13u1
-CVE-2026-5037
- [trixie] - mxml 3.3.1-1+deb13u1
-CVE-2026-28350
- [trixie] - lxml-html-clean 0.4.4-1~deb13u1
-CVE-2026-28348
- [trixie] - lxml-html-clean 0.4.4-1~deb13u1
-CVE-2026-5720
- [trixie] - miniupnpd 2.3.9-2+deb13u1
-CVE-2026-39377
- [trixie] - nbconvert 7.16.6-1+deb13u1
-CVE-2026-39378
- [trixie] - nbconvert 7.16.6-1+deb13u1
-CVE-2025-15536
- [trixie] - opencc 1.1.9+ds1-1+deb13u1
-CVE-2025-6375
- [trixie] - poco 1.13.0-6+deb13u1
-CVE-2026-40393
- [trixie] - mesa 25.0.7-2+deb13u1
-CVE-2026-48977
- [trixie] - openslide 3.4.1+dfsg-7+deb13u1
-CVE-2026-27809
- [trixie] - psd-tools 1.10.7+dfsg.1-1+deb13u1
-CVE-2026-41682
- [trixie] - pupnp 1:1.14.20-1+deb13u1
-CVE-2025-68142
- [trixie] - pymdown-extensions 10.13-1+deb13u1
-CVE-2026-27448
- [trixie] - pyopenssl 25.0.0-1+deb13u1
-CVE-2026-27459
- [trixie] - pyopenssl 25.0.0-1+deb13u1
-CVE-2026-33154
- [trixie] - python-dynaconf 3.1.7-2+deb13u1
-CVE-2026-32722
- [trixie] - python-memray 1.17.0+dfsg-1+deb13u1
-CVE-2026-11625
- [trixie] - libbytes-random-secure-perl 0.29-4~deb13u1
-CVE-2026-9539
- [trixie] - libslirp 4.8.0-1+deb13u1
-CVE-2026-45190
- [trixie] - libnet-cidr-lite-perl 0.22-3~deb13u2
-CVE-2026-45191
- [trixie] - libnet-cidr-lite-perl 0.22-3~deb13u2
-CVE-2026-8177
- [trixie] - libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+deb13u1
-CVE-2025-70102
- [trixie] - dhcpcd 1:10.1.0-11+deb13u3
-CVE-2026-56113
- [trixie] - dhcpcd 1:10.1.0-11+deb13u3
-CVE-2026-56114
- [trixie] - dhcpcd 1:10.1.0-11+deb13u3
-CVE-2026-56116
- [trixie] - dhcpcd 1:10.1.0-11+deb13u3
-CVE-2026-56117
- [trixie] - dhcpcd 1:10.1.0-11+deb13u3
-CVE-2026-34743
- [trixie] - xz-utils 5.8.1-1+deb13u1
-CVE-2026-45409
- [trixie] - python-idna 3.10-1+deb13u1
-CVE-2026-39373
- [trixie] - python-jwcrypto 1.5.6-1.1~deb13u1
-CVE-2026-XXXX [GHSA-pjjp-65r7-ppgm]
- [trixie] - libass 1:0.17.3-1+deb13u1
CVE-2026-44173
[trixie] - mariadb 1:11.8.8-0+deb13u1
CVE-2026-44172
@@ -292,72 +12,6 @@ CVE-2026-48165
[trixie] - mariadb 1:11.8.8-0+deb13u1
CVE-2026-48163
[trixie] - mariadb 1:11.8.8-0+deb13u1
-CVE-2025-68480
- [trixie] - python-marshmallow 3.26.2-0+deb13u1
-CVE-2026-6425
- [trixie] - qemu 1:10.0.11+ds-0+deb13u1
-CVE-2026-8343
- [trixie] - qemu 1:10.0.11+ds-0+deb13u1
-CVE-2026-48002
- [trixie] - qemu 1:10.0.11+ds-0+deb13u1
-CVE-2026-48003
- [trixie] - qemu 1:10.0.11+ds-0+deb13u1
-CVE-2026-48004
- [trixie] - qemu 1:10.0.11+ds-0+deb13u1
-CVE-2026-48914
- [trixie] - qemu 1:10.0.11+ds-0+deb13u1
-CVE-2026-48915
- [trixie] - qemu 1:10.0.11+ds-0+deb13u1
-CVE-2026-22702
- [trixie] - python-virtualenv 20.31.2+ds-1+deb13u1
-CVE-2026-34155
- [trixie] - rauc 1.13-3+deb13u1
-CVE-2026-58302
- [trixie] - linuxcnc 1:2.9.4-2+deb13u1
-CVE-2025-34450
- [trixie] - rtl-433 25.02-1+deb13u1
-CVE-2026-9759
- [trixie] - wireshark 4.4.16-0+deb13u1
-CVE-2026-12318
- [trixie] - nss 2:3.110-1+deb13u3
-CVE-2025-58367
- [trixie] - deepdiff 8.1.1-4+deb13u1
-CVE-2026-33155
- [trixie] - deepdiff 8.1.1-4+deb13u1
-CVE-2026-41525
- [trixie] - dolphin 4:25.04.3-1+deb13u1
-CVE-2026-0994
- [trixie] - protobuf 3.21.12-11+deb13u1
-CVE-2026-6409
- [trixie] - protobuf 3.21.12-11+deb13u1
-CVE-2025-4565
- [trixie] - protobuf 3.21.12-11+deb13u1
-CVE-2024-7254
- [trixie] - protobuf 3.21.12-11+deb13u1
-CVE-2025-66453
- [trixie] - rhino 1.7.15.1-0.1~deb13u1
-CVE-2026-1425
- [trixie] - smartdns 46.1+dfsg-1.1~deb13u1
-CVE-2025-9375
- [trixie] - python-xmltodict 0.13.0-1.1~deb13u1
-CVE-2026-34591
- [trixie] - poetry 2.1.2+dfsg-1+deb13u1
-CVE-2026-34352
- [trixie] - tigervnc 1.15.0+dfsg-2.1~deb13u1
-CVE-2026-44889
- [trixie] - python-webob 1:1.8.10-0+deb13u1
-CVE-2026-44545
- [trixie] - python-daphne 4.1.2-2+deb13u1
-CVE-2026-44546
- [trixie] - python-daphne 4.1.2-2+deb13u1
-CVE-2026-47319
- [trixie] - rlottie 0.1+dfsg-4.2+deb13u2
-CVE-2026-47320
- [trixie] - rlottie 0.1+dfsg-4.2+deb13u2
-CVE-2026-10305
- [trixie] - rlottie 0.1+dfsg-4.2+deb13u2
-CVE-2026-40560
- [trixie] - starman 0.4018-0+deb13u1
CVE-2026-11822
[trixie] - sqlite3 3.46.1-7+deb13u2
CVE-2026-11824
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/da16882f025b41a73217bcda41d11c8507bb52b0...f558d0269343919c4e5eed13c142f95f430f7025
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/da16882f025b41a73217bcda41d11c8507bb52b0...f558d0269343919c4e5eed13c142f95f430f7025
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260711/7d9354ed/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list