[Git][security-tracker-team/security-tracker][master] 3 commits: Remove entries for smb4k for bookworm (removed)
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Jul 11 20:20:21 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f4750da9 by Salvatore Bonaccorso at 2026-07-11T21:16:01+02:00
Remove entries for smb4k for bookworm (removed)
- - - - -
e478e4e3 by Salvatore Bonaccorso at 2026-07-11T21:17:01+02:00
Merge changes for updates with CVEs via bookworm 12.15
- - - - -
aed8860e by Salvatore Bonaccorso at 2026-07-11T21:20:15+02:00
Merge branch 'bookworm-12.15' into 'master'
Merge changes accepted for bookworm 12.15 release
See merge request security-tracker-team/security-tracker!312
- - - - -
2 changed files:
- data/CVE/list
- data/next-oldstable-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -8912,7 +8912,7 @@ CVE-2026-53325 (In the Linux kernel, the following vulnerability has been resolv
CVE-2026-58302 (rtapi_app in linuxcnc-uspace in LinuxCNC before 2.9.9 allows privilege ...)
- linuxcnc 1:2.9.9-1 (bug #1140943)
[trixie] - linuxcnc 1:2.9.4-2+deb13u1
- [bookworm] - linuxcnc <no-dsa> (Will be fixed via point release)
+ [bookworm] - linuxcnc 2.9.0~pre1+git20230208.f1270d6ed7-1+deb12u2
NOTE: https://github.com/LinuxCNC/linuxcnc/commit/00d534c87464a3ed446656998aa02b8abc74b391 (v2.9.9)
CVE-2026-49048 (The Joomla extension JoomCCK exposes a front-end controller task, that ...)
NOT-FOR-US: Joomla
@@ -10049,7 +10049,7 @@ CVE-2026-11702 (Bytes::Random::Secure::Tiny versions through 1.011 for Perl shar
CVE-2026-11625 (Bytes::Random::Secure versions through 0.29 for Perl share internal st ...)
- libbytes-random-secure-perl 0.29-4
[trixie] - libbytes-random-secure-perl 0.29-4~deb13u1
- [bookworm] - libbytes-random-secure-perl <no-dsa> (Minor issue; will be fixed via point release)
+ [bookworm] - libbytes-random-secure-perl 0.29-4~deb13u1~deb12u1
[bullseye] - libbytes-random-secure-perl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41305966/
NOTE: https://github.com/daoswald/Bytes-Random-Secure/issues/3
@@ -14061,7 +14061,7 @@ CVE-2026-56114 (dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-b
- dhcpcd 1:10.3.2-4 (bug #1140767)
[trixie] - dhcpcd 1:10.1.0-11+deb13u3
- dhcpcd5 <removed>
- [bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point release)
+ [bookworm] - dhcpcd5 9.4.1-24~deb12u5
[bullseye] - dhcpcd5 <postponed> (Minor issue; needs non-default IA_PD config + adjacent DHCPv6 server; 1-byte OOB, availability-only)
NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029
CVE-2026-56113 (dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-af ...)
@@ -15068,6 +15068,7 @@ CVE-2026-12806 (A vulnerability has been found in Edimax BR-6478AC V2 1.23. The
CVE-2026-12805 (A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element ...)
- dcmtk 3.7.0+really3.7.0-6 (bug #1140562)
[trixie] - dcmtk 3.6.9-5+deb13u2
+ [bookworm] - dcmtk 3.6.7-9~deb12u4
NOTE: https://support.dcmtk.org/redmine/issues/1208
NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=1d4b3815c0987840a983160bfc671fef63a3105b
CVE-2026-11748 (A vulnerability has been identified in centraldogma-server-auth-shiro ...)
@@ -19071,7 +19072,7 @@ CVE-2025-70102 (A NULL pointer dereference occurs in Roy Marples NetworkConfigur
- dhcpcd 1:10.3.1-1
[trixie] - dhcpcd 1:10.1.0-11+deb13u3
- dhcpcd5 <removed>
- [bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point release)
+ [bookworm] - dhcpcd5 9.4.1-24~deb12u5
[bullseye] - dhcpcd5 <postponed> (Minor issue; NULL deref only via malformed local dhcpcd.conf; not network-reachable)
NOTE: https://github.com/NetworkConfiguration/dhcpcd/issues/567
NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/117742d755b591764036dd4218f314f748a3d2b7 (v10.3.1)
@@ -19775,11 +19776,13 @@ CVE-2026-XXXX [RUSTSEC-2026-0177]
CVE-2026-9641 (Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default al ...)
- libcrypt-pbkdf2-perl 0.261630-1 (bug #1139867)
[trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
+ [bookworm] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1~deb12u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40933040/
NOTE: Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/320db2451c42916ce787479de8a0bb1fb37a6700 (0.261630)
CVE-2026-9638 (Crypt::PBKDF2 versions before 0.261630 for Perl generate insecure rand ...)
- libcrypt-pbkdf2-perl 0.261630-1 (bug #1139867)
[trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
+ [bookworm] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1~deb12u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40932643/
NOTE: Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/1d0a1ad8474fd3dddfd10a04ea6837951f6e6519 (0.261630)
CVE-2026-9266 (A Missing Required Cryptographic Step vulnerability has been identifie ...)
@@ -20107,6 +20110,7 @@ CVE-2026-10557 (The Yarbo Android and iOS applications contain hard-coded MQTT b
CVE-2017-20240 (Crypt::PBKDF2 versions before 0.261630 for Perl are vulnerable to timi ...)
- libcrypt-pbkdf2-perl 0.261630-1 (bug #1139867)
[trixie] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1
+ [bookworm] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1~deb12u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40929601/
NOTE: Fixed by: https://github.com/arodland/Crypt-PBKDF2/commit/ac5aac7c8c0e411165a6665a9c1f449b745f2629 (0.261630)
CVE-2026-50012
@@ -23342,7 +23346,7 @@ CVE-2026-48913 (Use After Free vulnerability in Apache HTTP Server module mod_ht
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-48913
NOTE: Fixed by jumbo patch: https://github.com/apache/httpd/commit/dbf1cc4dd62b681a0066271720994a047a3329ca (2.4.68-rc1-candidate)
NOTE: Fixed by: https://github.com/icing/mod_h2/commit/e6a28242f23084f6dbae32090121148e99fdda78 (v2.0.42)
@@ -23389,28 +23393,28 @@ CVE-2026-44631 (Buffer Underwrite vulnerability in Apache HTTP Server on crafted
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44631
NOTE: Fixed by: https://github.com/apache/httpd/commit/7d9f3cfb10b0fe70df7358d26d7b1f374ea1a0cb (2.4.68-rc1-candidate)
CVE-2026-44186 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44186
NOTE: Fixed by: https://github.com/apache/httpd/commit/414de374a06549b2c6710cbcff81c3821379f75c (2.4.68-rc1-candidate)
CVE-2026-44185 (Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44185
NOTE: Fixed by: https://github.com/apache/httpd/commit/32b7e2e66477020ba75b78ab43fb8890ec292ad2 (2.4.68-rc1-candidate)
CVE-2026-44119 (Improper Privilege Management vulnerability in Apache HTTP Server 2.4. ...)
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-44119
NOTE: Fixed by: https://github.com/apache/httpd/commit/f63f26aff6aa747357b84b5bd09c45325fa7f9ba (2.4.68-rc1-candidate)
CVE-2026-43974 (Unexpected Status Code or Return Value vulnerability in ninenines gun ...)
@@ -23429,7 +23433,7 @@ CVE-2026-43951 (Out-of-bounds Read vulnerability in Apache HTTP Server with mod_
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-43951
NOTE: Fixed by: https://github.com/apache/httpd/commit/6ff9dc2fdbe7ffd2f8a6c9ffe9ec801d53c760ba (2.4.68-rc1-candidate)
CVE-2026-42863 (Flowise is a drag & drop user interface to build a customized large la ...)
@@ -23442,7 +23446,7 @@ CVE-2026-42536 (Heap-based Buffer Overflow vulnerability in Apache HTTP Server w
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42536
NOTE: Fixed by: https://github.com/apache/httpd/commit/fa5d85bbc832a587c3c5bca7c19fb21df96b5df0 (trunk)
NOTE: Fixed by: https://github.com/apache/httpd/commit/cb1f79c0ce66393c48657b19df754f16b79af543 (2.4.68-rc1-candidate)
@@ -23450,7 +23454,7 @@ CVE-2026-42535 (A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-42535
NOTE: Fixed by: https://github.com/apache/httpd/commit/7e871beec56d41fe098f48f5a5bcb1525c448d77 (trunk)
NOTE: Fixed by: https://github.com/apache/httpd/commit/56bfb128432a38e2e6bc5448122914bb271b1252 (2.4.68-rc1-candidate)
@@ -23476,7 +23480,7 @@ CVE-2026-34356 (Heap-based Buffer Overflow vulnerability in Apache HTTP Server w
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-34356
NOTE: Fixed by: https://github.com/apache/httpd/commit/403269396d24404e2576a9b20f96cd0b10574048 (2.4.68-rc1-candidate)
NOTE: Fixed by: https://github.com/apache/httpd/commit/a70753d294292e8c9f68758cfe3550d83f812129 (trunk)
@@ -23484,7 +23488,7 @@ CVE-2026-34355 (A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-34355
NOTE: Fixed by: https://github.com/apache/httpd/commit/d62fc375281486c6036b007ac349b25d4e6edb4a (2.4.68-rc1-candidate)
CVE-2026-34194 (Software installed and run as a non-privileged user may conduct improp ...)
@@ -23493,7 +23497,7 @@ CVE-2026-29170 (A cross-site scripting vulnerability exists in mod_proxy_ftp's H
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29170
NOTE: Fixed by: https://github.com/apache/httpd/commit/e86bf540f166b3a322f7e7f9cd4aad4cd44deee6 (trunk)
NOTE: Fixed by: https://github.com/apache/httpd/commit/04641bce75a2734ad8150f9a6bc84fc5205e852b (2.4.68-rc1-candidate)
@@ -23501,7 +23505,7 @@ CVE-2026-29167 (Use After Free vulnerability in Apache HTTP Server with mod_ldap
{DLA-4629-1}
- apache2 2.4.68-1 (bug #1139340)
[trixie] - apache2 2.4.68-1~deb13u1
- [bookworm] - apache2 <no-dsa> (Minor issue)
+ [bookworm] - apache2 2.4.68-1~deb12u1
NOTE: https://httpd.apache.org/security/vulnerabilities_24.html#CVE-2026-29167
NOTE: Fixed by: https://github.com/apache/httpd/commit/354a94ee7fd4bd34bfe3e776e3b32d3344f435c7 (trunk)
NOTE: Fixed by: https://github.com/apache/httpd/commit/2cf9b3f393633f43746047e779fdf265a1ad8016 (2.4.68-rc1-candidate)
@@ -23861,7 +23865,7 @@ CVE-2026-47895
CVE-2026-48977
- openslide 3.4.1+dfsg-9 (bug #1140003)
[trixie] - openslide 3.4.1+dfsg-7+deb13u1
- [bookworm] - openslide <no-dsa> (Minor issue)
+ [bookworm] - openslide 3.4.1+dfsg-6+deb12u1
[bullseye] - openslide <postponed> (Minor issue; can be fixed in next update)
NOTE: https://github.com/openslide/openslide/security/advisories/GHSA-mxg2-48g7-fmwc
CVE-2026-11495 (A vulnerability was detected in CodeAstro Ingredients Stock Management ...)
@@ -23991,18 +23995,21 @@ CVE-2026-11447 (A security flaw has been discovered in GL.iNet GL-MT3000 up to 4
CVE-2026-44173 (MariaDB server is a community developed fork of MySQL server. From ver ...)
- mariadb 1:11.8.8-1
[trixie] - mariadb <no-dsa> (Will be fixed via point release)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7
NOTE: https://github.com/MariaDB/server/security/advisories/GHSA-667j-m53j-wpmc
NOTE: https://jira.mariadb.org/browse/MDEV-39493
CVE-2026-44172 (MariaDB server is a community developed fork of MySQL server. In versi ...)
- mariadb 1:11.8.8-1
[trixie] - mariadb <no-dsa> (Will be fixed via point release)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7
NOTE: https://github.com/MariaDB/server/security/advisories/GHSA-pv9p-5w55-55jm
NOTE: https://jira.mariadb.org/browse/CONC-819
CVE-2026-44171 (MariaDB server is a community developed fork of MySQL server. From ver ...)
- mariadb 1:11.8.8-1
[trixie] - mariadb <no-dsa> (Will be fixed via point release)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7
NOTE: https://github.com/MariaDB/server/security/advisories/GHSA-9pjh-5hhw-65v9
NOTE: https://jira.mariadb.org/browse/MDEV-39408
@@ -24020,30 +24027,34 @@ CVE-2026-44169 (MariaDB server is a community developed fork of MySQL server. Fr
CVE-2026-44168 (MariaDB server is a community developed fork of MySQL server. From ver ...)
- mariadb 1:11.8.8-1
[trixie] - mariadb <no-dsa> (Will be fixed via point release)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7
NOTE: https://github.com/MariaDB/server/security/advisories/GHSA-vwf7-w26c-9w5h
NOTE: https://jira.mariadb.org/browse/MDEV-39413
CVE-2026-48165 (MariaDB server is a community developed fork of MySQL server. From ver ...)
- mariadb 1:11.8.8-1
[trixie] - mariadb <no-dsa> (Will be fixed via point release)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8
NOTE: https://github.com/MariaDB/server/security/advisories/GHSA-7v3p-h23x-8hwv
NOTE: https://jira.mariadb.org/browse/MDEV-39676
CVE-2026-48163 (MariaDB server is a community developed fork of MySQL server. From ver ...)
- mariadb 1:11.8.8-1
[trixie] - mariadb <no-dsa> (Will be fixed via point release)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8
NOTE: https://github.com/MariaDB/server/security/advisories/GHSA-rpgv-q6gv-684r
NOTE: https://jira.mariadb.org/browse/MDEV-39648
CVE-2026-49261 (MariaDB server is a community developed fork of MySQL server. Versions ...)
- mariadb 1:11.8.8-1
[trixie] - mariadb <no-dsa> (Will be fixed via point release)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: https://mariadb.com/docs/release-notes/community-server/11.8/11.8.8
NOTE: https://github.com/MariaDB/server/security/advisories/GHSA-3p3m-4x7c-p4pw
NOTE: https://jira.mariadb.org/browse/MDEV-39721
CVE-2025-15646 (HTML::Gumbo versions before 0.19 for Perl disclose heap memory via typ ...)
- libhtml-gumbo-perl 0.18-5 (bug #1104789)
- [bookworm] - libhtml-gumbo-perl <no-dsa> (Minor issue; to be fixed in point release)
+ [bookworm] - libhtml-gumbo-perl 0.18-3+deb12u1
[bullseye] - libhtml-gumbo-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41446255/
NOTE: https://github.com/ruz/HTML-Gumbo/issues/6
@@ -26241,7 +26252,7 @@ CVE-2023-5502 (On affected platforms running Arista EOS with 802.1x authenticati
CVE-2026-50593 (Graphite before 1.3.15 has an integer underflow and resultant out-of-b ...)
- graphite2 1.3.15-2
[trixie] - graphite2 1.3.14-2+deb13u1
- [bookworm] - graphite2 <no-dsa> (Minor issue; can be fixed via point release)
+ [bookworm] - graphite2 1.3.14-1+deb12u1
[bullseye] - graphite2 <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/silnrsi/graphite/commit/ad78c6b7319909e1540c1b134e115ced03417866 (1.3.15)
CVE-2026-49837
@@ -26369,14 +26380,14 @@ CVE-2026-47320 (Access of uninitialized pointer, Uncontrolled Recursion vulnerab
{DLA-4675-1}
- rlottie 0.1+dfsg-5 (bug #1138920)
[trixie] - rlottie 0.1+dfsg-4.2+deb13u2
- [bookworm] - rlottie <no-dsa> (Minor issue)
+ [bookworm] - rlottie 0.1+dfsg-4+deb12u2
NOTE: https://github.com/Samsung/rlottie/pull/593
NOTE: https://github.com/Samsung/rlottie/commit/bf689b72b8482c5ea674235854bd11b6d1b42588
CVE-2026-47319 (Memory allocation with excessive size value vulnerability in Samsung O ...)
{DLA-4675-1}
- rlottie 0.1+dfsg-5 (bug #1138919)
[trixie] - rlottie 0.1+dfsg-4.2+deb13u2
- [bookworm] - rlottie <no-dsa> (Minor issue)
+ [bookworm] - rlottie 0.1+dfsg-4+deb12u2
NOTE: https://github.com/Samsung/rlottie/pull/588
NOTE: https://github.com/Samsung/rlottie/commit/5def9f402b1cb5b09f52655e414f0afba4ffd959
CVE-2026-47318 (Stack-based buffer overflow vulnerability in Samsung Open Source rlott ...)
@@ -26587,7 +26598,7 @@ CVE-2026-10305 (Out-of-bounds read vulnerability in Samsung Open Source rlottie
{DLA-4675-1}
- rlottie 0.1+dfsg-5 (bug #1139179)
[trixie] - rlottie 0.1+dfsg-4.2+deb13u2
- [bookworm] - rlottie <no-dsa> (Minor issue)
+ [bookworm] - rlottie 0.1+dfsg-4+deb12u2
NOTE: https://github.com/Samsung/rlottie/pull/587
NOTE: https://github.com/Samsung/rlottie/commit/b4f5101a4d1a8da60cc14cfd05608551b3448c77
CVE-2025-71316 (SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Wi ...)
@@ -26686,7 +26697,7 @@ CVE-2026-8829 (HTML::Entities versions before 3.84 for Perl read freed heap memo
{DLA-4655-1}
- libhtml-parser-perl 3.83-2
[trixie] - libhtml-parser-perl 3.83-2~deb13u1
- [bookworm] - libhtml-parser-perl <no-dsa> (Minor issue)
+ [bookworm] - libhtml-parser-perl 3.81-1+deb12u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40702610/
NOTE: https://github.com/libwww-perl/HTML-Parser/pull/56
NOTE: Fixed by: https://github.com/libwww-perl/HTML-Parser/commit/6922552b0778c90a9587a3894e248be4d3a25e1c (3.84)
@@ -27006,7 +27017,7 @@ CVE-2026-44393 (An issue was discovered in OpenStack oslo.messaging 1.0.0 throug
CVE-2026-55748 (OpenStack Horizon before 25.7.4 produces scripts for OpenStack RC file ...)
- horizon 3:25.7.3-2 (bug #1138845)
[trixie] - horizon 3:25.3.0-3+deb13u1
- [bookworm] - horizon <no-dsa> (Minor issue)
+ [bookworm] - horizon 3:23.0.0-5+deb12u2
[bullseye] - horizon <postponed> (Minor issue; can be fixed in next update)
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0097
NOTE: https://launchpad.net/bugs/2152240
@@ -28812,7 +28823,7 @@ CVE-2026-49489 (OpenCATS through 0.9.7.4 contains a sql injection vulnerability
CVE-2026-10194 (A weakness has been identified in OFFIS DCMTK 3.7.0. This affects the ...)
- dcmtk 3.7.0+really3.7.0-5 (bug #1139181)
[trixie] - dcmtk 3.6.9-5+deb13u1
- [bookworm] - dcmtk <no-dsa> (Minor issue)
+ [bookworm] - dcmtk 3.6.7-9~deb12u4
[bullseye] - dcmtk <no-dsa> (Minor issue)
NOTE: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=0f78a4ef6f645ea5530166e445e5436a5de58e75
CVE-2026-10193 (A security flaw has been discovered in OFCMS up to 1.1.3. The impacted ...)
@@ -29052,7 +29063,7 @@ CVE-2026-8594 (Text::LineFold versions through 2019.001 for Perl duplicate the o
CVE-2026-48711
- sshfs-fuse 3.7.3-1.2 (bug #1138293)
[trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
- [bookworm] - sshfs-fuse <no-dsa> (Minor issue)
+ [bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
[bullseye] - sshfs-fuse <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/30/3
NOTE: https://github.com/libfuse/sshfs/security/advisories/GHSA-mm85-q63v-4476
@@ -29061,7 +29072,7 @@ CVE-2026-48711
CVE-2026-47187
- sshfs-fuse 3.7.3-1.2 (bug #1138293)
[trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
- [bookworm] - sshfs-fuse <no-dsa> (Minor issue)
+ [bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
[bullseye] - sshfs-fuse <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/30/3
NOTE: https://github.com/libfuse/sshfs/security/advisories/GHSA-pjv6-2c3f-r357
@@ -29084,6 +29095,7 @@ CVE-2026-9334 (Cpanel::JSON::XS versions before 4.41 for Perl allow type confusi
CVE-2026-50538 [Attacker-controlled heap out-of-bounds write in libvncclient Tight decoder]
- libvncserver 0.9.15+dfsg-6 (bug #1138253)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
+ [bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
NOTE: https://github.com/LibVNC/libvncserver/security/advisories/GHSA-v9pm-47h4-jcq8
CVE-2026-9831 (A race condition in the shared Extreme Platform ONE IAM Gateway API-ke ...)
NOT-FOR-US: Extreme Networks
@@ -29638,13 +29650,13 @@ CVE-2024-13745
CVE-2026-49214 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
- php-guzzlehttp-psr7 2.10.3-1 (bug #1138265)
[trixie] - php-guzzlehttp-psr7 2.7.1-1+deb13u1
- [bookworm] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+ [bookworm] - php-guzzlehttp-psr7 2.4.5-1+deb12u1
[bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue)
NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-hq7v-mx3g-29hw
CVE-2026-48998 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
- php-guzzlehttp-psr7 2.10.3-1 (bug #1138265)
[trixie] - php-guzzlehttp-psr7 2.7.1-1+deb13u1
- [bookworm] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+ [bookworm] - php-guzzlehttp-psr7 2.4.5-1+deb12u1
[bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue)
NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-34xg-wgjx-8xph
CVE-2026-9999 (Inappropriate implementation in ANGLE in Google Chrome on Mac prior to ...)
@@ -31806,13 +31818,14 @@ CVE-2026-21785 (A misconfigured Content Security Policy (CSP) in HCL BigFix Remo
CVE-2026-48112 (7-Zip is a file archiver with a high compression ratio. Versions 9.18 ...)
- 7zip 26.01+dfsg-1
[trixie] - 7zip <no-dsa> (Minor issue)
- [bookworm] - 7zip <no-dsa> (Minor issue)
+ [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
- p7zip 16.02+transitional.1
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
NOTE: https://securitylab.github.com/advisories/GHSL-2026-115_GHSL-2026-122_7-zip/
CVE-2026-48111 (7-Zip is a file archiver with a high compression ratio. Versions 9.21 ...)
- 7zip 26.01+dfsg-1 (unimportant)
+ [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
- p7zip 16.02+transitional.1 (unimportant)
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
@@ -31820,6 +31833,7 @@ CVE-2026-48111 (7-Zip is a file archiver with a high compression ratio. Versions
NOTE: Crash in CLI tool, no security impact
CVE-2026-48104 (7-Zip is a file archiver with a high compression ratio. Versions 9.18 ...)
- 7zip 26.01+dfsg-1 (unimportant)
+ [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
- p7zip 16.02+transitional.1 (unimportant)
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
@@ -31827,6 +31841,7 @@ CVE-2026-48104 (7-Zip is a file archiver with a high compression ratio. Versions
NOTE: Crash in CLI tool, no security impact
CVE-2026-48103 (7-Zip is a file archiver with a high compression ratio. Versions 9.34 ...)
- 7zip 26.01+dfsg-1 (unimportant)
+ [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
- p7zip 16.02+transitional.1 (unimportant)
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
@@ -31834,6 +31849,7 @@ CVE-2026-48103 (7-Zip is a file archiver with a high compression ratio. Versions
NOTE: Crash in CLI tool, no security impact
CVE-2026-48102 (7-Zip is a file archiver with a high compression ratio. Versions 9.11 ...)
- 7zip 26.01+dfsg-1 (unimportant)
+ [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
- p7zip 16.02+transitional.1 (unimportant)
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
@@ -31841,6 +31857,7 @@ CVE-2026-48102 (7-Zip is a file archiver with a high compression ratio. Versions
NOTE: Crash in CLI tool, no security impact
CVE-2026-48101 (7-Zip is a file archiver with a high compression ratio. Versions 9.21 ...)
- 7zip 26.01+dfsg-1 (unimportant)
+ [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
- p7zip 16.02+transitional.1 (unimportant)
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
@@ -31848,6 +31865,7 @@ CVE-2026-48101 (7-Zip is a file archiver with a high compression ratio. Versions
NOTE: Crash in CLI tool, no security impact
CVE-2026-48092 (7-Zip is a file archiver with a high compression ratio. Versions 9.34 ...)
- 7zip 26.01+dfsg-1 (unimportant)
+ [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
- p7zip 16.02+transitional.1 (unimportant)
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
@@ -31856,6 +31874,7 @@ CVE-2026-48092 (7-Zip is a file archiver with a high compression ratio. Versions
CVE-2026-48095 (7-Zip is a file archiver with a high compression ratio. Versions 26.00 ...)
- 7zip 26.01+dfsg-1
[trixie] - 7zip <no-dsa> (Minor issue)
+ [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
- p7zip 16.02+transitional.1
NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only a empty source package
NOTE: depending on 7zip. Mark this version as fixed version.
@@ -32107,6 +32126,7 @@ CVE-2026-45022 (go-git is an extensible git implementation library written in pu
CVE-2026-44988 (LibVNCClient is a library for easy implementation of a VNC client. In ...)
- libvncserver 0.9.15+dfsg-5 (bug #1138174)
[trixie] - libvncserver 0.9.15+dfsg-1+deb13u2
+ [bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
NOTE: https://github.com/LibVNC/libvncserver/security/advisories/GHSA-jcc5-8wj4-7c58
NOTE: https://github.com/LibVNC/libvncserver/commit/5b270544b85233668b98161323297d418a8f5fd1
CVE-2026-44972 (GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 ...)
@@ -37754,7 +37774,7 @@ CVE-2026-43620 (Rsync version3.4.2 and prior contain a receiver-side out-of-boun
CVE-2026-45232 (Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack ...)
- rsync 3.4.3+ds1-1
[trixie] - rsync 3.4.1+ds1-5+deb13u4
- [bookworm] - rsync <no-dsa> (Minor issue)
+ [bookworm] - rsync 3.2.7-1+deb12u6
[bullseye] - rsync <postponed> (Minor issue, 1-byte zero OOB write)
NOTE: https://download.samba.org/pub/rsync/NEWS#3.4.3
NOTE: https://www.openwall.com/lists/oss-security/2026/05/20/6
@@ -38889,7 +38909,7 @@ CVE-2026-8454 (Imager::File::GIF versions through 1.002 for Perl allow a heap ou
CVE-2026-8503 (Apache::Session::Generate::SHA256 versions before 1.3.19 for Perl crea ...)
- libapache-session-browseable-perl 1.3.19-1
[trixie] - libapache-session-browseable-perl 1.3.16-1+deb13u1
- [bookworm] - libapache-session-browseable-perl <no-dsa> (Minor issue)
+ [bookworm] - libapache-session-browseable-perl 1.3.11-3+deb12u1
[bullseye] - libapache-session-browseable-perl <postponed> (Minor issue, hard to exploit)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40079348/
NOTE: https://github.com/LemonLDAPNG/Apache-Session-Browseable/commit/cc915cbbd266776eec3dd8bf4748b15fa827dbd0 (v1.3.19)
@@ -39740,7 +39760,7 @@ CVE-2026-44348 (PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before
CVE-2026-44312 (css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Pa ...)
- ruby-css-parser 2.1.0-1
[trixie] - ruby-css-parser 1.19.0-1+deb13u1
- [bookworm] - ruby-css-parser <no-dsa> (Minor issue)
+ [bookworm] - ruby-css-parser 1.6.0-2+deb12u1
[bullseye] - ruby-css-parser <postponed> (Minor issue)
NOTE: https://github.com/premailer/css_parser/security/advisories/GHSA-ff6c-w6qf-7xqc
NOTE: https://github.com/premailer/css_parser/issues/185
@@ -39977,7 +39997,7 @@ CVE-2026-6637 (Stack buffer overflow in PostgreSQL module "refint" allows an unp
CVE-2026-45793 [Github Actions issued GITHUB_TOKEN disclosure in GitHub Actions logs]
- composer 0.9.1+dfsg-1
[trixie] - composer 2.8.8-1+deb13u3
- [bookworm] - composer <no-dsa> (Minor issue)
+ [bookworm] - composer 2.5.5-1+deb12u5
NOTE: https://github.com/composer/composer/security/advisories/GHSA-f9f8-rm49-7jv2
CVE-2026-8496 (A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, vers ...)
{DSA-6366-1 DLA-4657-1}
@@ -42338,7 +42358,7 @@ CVE-2026-42188 (Geyser is a bridge between Minecraft: Bedrock Edition and Minecr
CVE-2026-42046 (libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an ...)
- libcaca 0.99.beta20-7 (bug #1136952)
[trixie] - libcaca 0.99.beta20-5+deb13u1
- [bookworm] - libcaca <no-dsa> (Minor issue)
+ [bookworm] - libcaca 0.99.beta20-3+deb12u1
NOTE: https://github.com/cacalabs/libcaca/security/advisories/GHSA-4vvg-vrqv-m56w
NOTE: https://github.com/cacalabs/libcaca/issues/86
NOTE: Fixed by: https://github.com/cacalabs/libcaca/commit/fb77acff9ba6bb01d53940da34fb10f20b156a23
@@ -43080,7 +43100,7 @@ CVE-2026-8248 (A vulnerability was detected in Open5GS up to 2.7.7. The affected
CVE-2026-8177 (XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap m ...)
- libxml-libxml-perl 2.0207+dfsg+really+2.0134-8 (bug #1136300)
[trixie] - libxml-libxml-perl 2.0207+dfsg+really+2.0134-5+deb13u1
- [bookworm] - libxml-libxml-perl <no-dsa> (Minor issue; will be fixed via point release)
+ [bookworm] - libxml-libxml-perl 2.0207+dfsg+really+2.0134-1+deb12u1
[bullseye] - libxml-libxml-perl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/39920366/
NOTE: https://github.com/cpan-authors/XML-LibXML/issues/146
@@ -43093,7 +43113,7 @@ CVE-2026-45192 (A bug in the GET `/api/v2/connections/{connection_id}` REST API
CVE-2026-45191 (Net::CIDR::Lite versions before 0.24 for Perl does not properly consid ...)
- libnet-cidr-lite-perl 0.24-1
[trixie] - libnet-cidr-lite-perl 0.22-3~deb13u2
- [bookworm] - libnet-cidr-lite-perl <no-dsa> (Minor issue; will be fixed via point release)
+ [bookworm] - libnet-cidr-lite-perl 0.22-3~deb12u2
[bullseye] - libnet-cidr-lite-perl <postponed> (Minor issue, validation)
NOTE: https://github.com/stigtsp/Net-CIDR-Lite/commit/24e2c439ec405e5256024b9acefd4f7008c5ed0c (0.24)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/10/7
@@ -43101,7 +43121,7 @@ CVE-2026-45191 (Net::CIDR::Lite versions before 0.24 for Perl does not properly
CVE-2026-45190 (Net::CIDR::Lite versions before 0.24 for Perl does not properly valida ...)
- libnet-cidr-lite-perl 0.24-1
[trixie] - libnet-cidr-lite-perl 0.22-3~deb13u2
- [bookworm] - libnet-cidr-lite-perl <no-dsa> (Minor issue; will be fixed via point release)
+ [bookworm] - libnet-cidr-lite-perl 0.22-3~deb12u2
[bullseye] - libnet-cidr-lite-perl <postponed> (Minor issue, validation)
NOTE: https://github.com/stigtsp/Net-CIDR-Lite/commit/ca9542adec87110556601d7ce48381ea8d13e692 (0.24)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/10/6
@@ -48126,13 +48146,13 @@ CVE-2026-31195 (OS command injection vulnerability in the ping diagnostic handle
CVE-2026-42268 (ModSecurity is an open source, cross platform web application firewall ...)
- modsecurity 3.0.15-1
[trixie] - modsecurity 3.0.14-1+deb13u1
- [bookworm] - modsecurity <no-dsa> (Proposed via point release update)
+ [bookworm] - modsecurity 3.0.9-1+deb12u2
[bullseye] - modsecurity <postponed> (Minor issue, DoS)
NOTE: https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-vwr3-7x7g-7p9w
CVE-2026-30923 (ModSecurity is an open source, cross platform web application firewall ...)
- modsecurity 3.0.15-1
[trixie] - modsecurity 3.0.14-1+deb13u1
- [bookworm] - modsecurity <no-dsa> (Proposed via point release update)
+ [bookworm] - modsecurity 3.0.9-1+deb12u2
[bullseye] - modsecurity <postponed> (Minor issue, DoS)
NOTE: https://github.com/owasp-modsecurity/ModSecurity/security/advisories/GHSA-qrjc-3jpc-3h2g
CVE-2026-30246 (Fiber is a web framework for Go. In github.com/gofiber/fiber/v3 versio ...)
@@ -48590,7 +48610,7 @@ CVE-2026-42052 (Beets is the media library management system. Prior to version 2
{DLA-4641-1}
- beets 2.11.0-1 (bug #1135779)
[trixie] - beets 2.2.0-3+deb13u1
- [bookworm] - beets <no-dsa> (Minor issue)
+ [bookworm] - beets 1.6.0-4+deb12u1
NOTE: https://github.com/beetbox/beets/security/advisories/GHSA-3gxm-wfjx-m847
CVE-2026-42027 (Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP Ext ...)
- apache-opennlp 2.5.9-1 (bug #1135782)
@@ -51357,7 +51377,7 @@ CVE-2026-7111 (Text::CSV_XS versions before 1.62 for Perl have a use-after-free
CVE-2026-7168 (Successfully using libcurl to do a transfer over a specific HTTP proxy ...)
- curl 8.20.0-1
[trixie] - curl 8.14.1-2+deb13u4
- [bookworm] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl 7.88.1-10+deb12u15
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-7168.html
NOTE: Introduced by: https://github.com/curl/curl/commit/fc6eff13b5414caf6edf22d73a3239e074a04216 (curl-7_12_0)
@@ -51389,7 +51409,7 @@ CVE-2026-42198 (pgjdbc is an open source postgresql JDBC Driver. From version 42
CVE-2026-5773 (libcurl might in some circumstances reuse the wrong connection for SMB ...)
- curl 8.20.0~rc2-1
[trixie] - curl 8.14.1-2+deb13u4
- [bookworm] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl 7.88.1-10+deb12u15
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2026-5773.html
NOTE: Introduced by: https://github.com/curl/curl/commit/aec2e865f06669b9cb5d26cc1148d70bc418b163 (curl-7_40_0)
@@ -56081,6 +56101,7 @@ CVE-2026-34303 (Vulnerability in the MySQL Server product of Oracle MySQL (compo
- mysql-8.0 8.0.46-1 (bug #1134614)
- mariadb 1:11.8.6-1
[trixie] - mariadb 1:11.8.6-0+deb13u1
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: Fixed in MariaDB: 12.2.2, 11.8.6, 11.4.10, 10.11.16
CVE-2026-34302 (Vulnerability in the Oracle Workflow product of Oracle E-Business Suit ...)
NOT-FOR-US: Oracle
@@ -57954,7 +57975,7 @@ CVE-2026-6410 (@fastify/static versions 8.0.0 through 9.1.0 allow path traversal
CVE-2026-6409 (A Denial of Service (DoS) vulnerability exists in the Protobuf PHP lib ...)
- protobuf 3.21.12-16 (bug #1134895)
[trixie] - protobuf 3.21.12-11+deb13u1
- [bookworm] - protobuf <no-dsa> (Minor issue)
+ [bookworm] - protobuf 3.21.12-3+deb12u1
[bullseye] - protobuf <postponed> (minor issue)
NOTE: https://github.com/protocolbuffers/protobuf/security/advisories/GHSA-p2gh-cfq4-4wjc
NOTE: https://github.com/protocolbuffers/protobuf/issues/24159
@@ -59899,7 +59920,7 @@ CVE-2026-6100 (Use-after-free (UAF) was possible in the `lzma.LZMADecompressor`,
- python3.13 3.13.14-1
[trixie] - python3.13 3.13.5-2+deb13u2
- python3.11 <removed>
- [bookworm] - python3.11 <no-dsa> (Minor issue)
+ [bookworm] - python3.11 3.11.2-6+deb12u8
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (not supported in bullseye)
@@ -60310,7 +60331,7 @@ CVE-2026-6121 (A flaw has been found in Tenda F451 1.0.0.7. Affected by this vul
CVE-2026-40393 (In Mesa before 25.3.6 and 26 before 26.0.1, out-of-bounds memory acces ...)
- mesa 26.0.1-1
[trixie] - mesa 25.0.7-2+deb13u1
- [bookworm] - mesa <ignored> (Minor issue, too intrusive to backport)
+ [bookworm] - mesa 22.3.6-1+deb12u2
NOTE: https://lists.freedesktop.org/archives/mesa-dev/2026-February/226597.html
NOTE: https://gitlab.freedesktop.org/mesa/mesa/-/merge_requests/39866
NOTE: Fixed by: https://gitlab.freedesktop.org/mesa/mesa/-/commit/978fd42b4b7d1e9c0435ffa7e1a4d339cba9b76e (mesa-26.0.1)
@@ -64178,7 +64199,7 @@ CVE-2026-5664
CVE-2026-5663 (A security flaw has been discovered in OFFIS DCMTK up to 3.7.0. This i ...)
- dcmtk 3.7.0+really3.7.0-3 (bug #1133001)
[trixie] - dcmtk 3.6.9-5+deb13u1
- [bookworm] - dcmtk <no-dsa> (Minor issue)
+ [bookworm] - dcmtk 3.6.7-9~deb12u4
[bullseye] - dcmtk <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/edbb085e45788dccaf0e64d71534cfca925784b8
CVE-2026-5661 (A vulnerability was identified in Free5GC 4.2.0. This affects an unkno ...)
@@ -67670,7 +67691,7 @@ CVE-2026-5292 (Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7
CVE-2026-34743 (XZ Utils provide a general-purpose data-compression library plus comma ...)
- xz-utils 5.8.3-1 (bug #1132497)
[trixie] - xz-utils 5.8.1-1+deb13u1
- [bookworm] - xz-utils <no-dsa> (Minor issue)
+ [bookworm] - xz-utils 5.4.1-2+deb12u1
[bullseye] - xz-utils <postponed> (Minor issue)
NOTE: https://tukaani.org/xz/index-append-overflow.html
NOTE: Fixed by: https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 (v5.8.3)
@@ -68240,7 +68261,7 @@ CVE-2026-5041 (A vulnerability was identified in code-projects Chamber of Commer
CVE-2026-5037 (A vulnerability was determined in mxml up to 4.0.4. This issue affects ...)
- mxml 4.0.4-4 (bug #1132328)
[trixie] - mxml 3.3.1-1+deb13u1
- [bookworm] - mxml <no-dsa> (Minor issue)
+ [bookworm] - mxml 3.3.1-1+deb13u1~deb12u1
[bullseye] - mxml <postponed> (Minor issue)
NOTE: https://github.com/michaelrsweet/mxml/issues/350
NOTE: Fixed by: https://github.com/michaelrsweet/mxml/commit/6e27354466092a1ac65601e01ce6708710bb9fa5
@@ -68947,12 +68968,12 @@ CVE-2026-33280 (Hidden functionality issue exists in BUFFALO Wi-Fi router produc
CVE-2026-33206 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
- calibre 9.6.0+ds+~0.10.5-1
[trixie] - calibre 8.5.0+ds-1+deb13u3
- [bookworm] - calibre <no-dsa> (Minor issue)
+ [bookworm] - calibre 6.13.0+repack-2+deb12u8
NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-h3p4-m74f-43g6
CVE-2026-33205 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
- calibre 9.6.0+ds+~0.10.5-1
[trixie] - calibre 8.5.0+ds-1+deb13u3
- [bookworm] - calibre <no-dsa> (Minor issue)
+ [bookworm] - calibre 6.13.0+repack-2+deb12u9
NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4926-v9px-wv7v
CVE-2026-33045 (Home Assistant is open source home automation software that puts local ...)
NOT-FOR-US: Home Assistant
@@ -69136,7 +69157,7 @@ CVE-2026-4948 (A flaw was found in firewalld. A local unprivileged user can expl
{DLA-4585-1}
- firewalld 2.4.0-2
[trixie] - firewalld 2.3.1-1+deb13u1
- [bookworm] - firewalld <no-dsa> (Minor issue)
+ [bookworm] - firewalld 1.3.3-1~deb12u2
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2452086
NOTE: Fixed by: https://github.com/firewalld/firewalld/commit/5fb3914ad830feff6cb2b0670457c60a323c6c6c
CVE-2026-27855 (Dovecot OTP authentication is vulnerable to replay attack under specif ...)
@@ -73809,7 +73830,7 @@ CVE-2026-4519 (The webbrowser.open() API would accept leading dashes in the URL
- python3.13 3.13.14-1
[trixie] - python3.13 3.13.5-2+deb13u2
- python3.11 <removed>
- [bookworm] - python3.11 <no-dsa> (Minor issue)
+ [bookworm] - python3.11 3.11.2-6+deb12u8
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
@@ -75331,7 +75352,7 @@ CVE-2026-26740 (Buffer Overflow vulnerability in giflib v.5.2.2 allows a remote
{DLA-4650-1}
- giflib 6.1.3-1 (bug #1131368)
[trixie] - giflib 5.2.2-1+deb13u1
- [bookworm] - giflib <no-dsa> (Minor issue)
+ [bookworm] - giflib 5.2.1-2.5+deb12u1
NOTE: https://github.com/zakkanijia/POC/blob/main/giflib/giftool/giflib_giftool_gce_len_heap_oobwrite_disclosure.md
NOTE: https://sourceforge.net/p/giflib/bugs/199/
NOTE: https://sourceforge.net/p/giflib/bugs/201/
@@ -76153,7 +76174,7 @@ CVE-2026-4224 (When an Expat parser with a registered ElementDeclHandler parses
- python3.13 3.13.14-1
[trixie] - python3.13 3.13.5-2+deb13u2
- python3.11 <removed>
- [bookworm] - python3.11 <no-dsa> (Minor issue)
+ [bookworm] - python3.11 3.11.2-6+deb12u8
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
@@ -77185,7 +77206,7 @@ CVE-2026-30914 (SFTPGo is an open source, event-driven file transfer solution. I
CVE-2026-30853 (calibre is a cross-platform e-book manager for viewing, converting, ed ...)
- calibre 9.5.0+ds+~0.10.5-1
[trixie] - calibre 8.5.0+ds-1+deb13u3
- [bookworm] - calibre <no-dsa> (Minor issue)
+ [bookworm] - calibre 6.13.0+repack-2+deb12u8
NOTE: https://github.com/kovidgoyal/calibre/security/advisories/GHSA-7mp7-rfrg-542x
CVE-2026-2888 (The Formidable Forms plugin for WordPress is vulnerable to an authoriz ...)
NOT-FOR-US: WordPress plugin
@@ -77680,7 +77701,7 @@ CVE-2025-13462 (The "tarfile" module would still apply normalization of AREGTYPE
- python3.13 3.13.14-1
[trixie] - python3.13 3.13.5-2+deb13u1
- python3.11 <removed>
- [bookworm] - python3.11 <no-dsa> (Minor issue)
+ [bookworm] - python3.11 3.11.2-6+deb12u8
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
@@ -78855,7 +78876,7 @@ CVE-2026-3805 (When doing a second SMB request to the same host again, curl woul
CVE-2026-3784 (curl would wrongly reuse an existing HTTP proxy connection doing CONNE ...)
- curl 8.19.0-1
[trixie] - curl 8.14.1-2+deb13u4
- [bookworm] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl 7.88.1-10+deb12u15
[bullseye] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-3784.html
NOTE: Introduced with: https://github.com/curl/curl/commit/a1d6ad26100bc493c7b04f1301b1634b7f5aa8b4 (curl-7_7_alpha2)
@@ -78863,7 +78884,7 @@ CVE-2026-3784 (curl would wrongly reuse an existing HTTP proxy connection doing
CVE-2026-3783 (When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...)
- curl 8.19.0-1
[trixie] - curl 8.14.1-2+deb13u4
- [bookworm] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl 7.88.1-10+deb12u15
[bullseye] - curl <postponed> (Minor issue)
NOTE: https://curl.se/docs/CVE-2026-3783.html
NOTE: Introduced with: https://github.com/curl/curl/commit/06c1bea72faabb6fad4b7ef818aafaa336c9a7aa (curl-7_33_0)
@@ -79238,7 +79259,7 @@ CVE-2026-23868 (Giflib contains a double-free vulnerability that is the result o
{DLA-4650-1}
- giflib 6.1.3-1 (bug #1130495)
[trixie] - giflib 5.2.2-1+deb13u1
- [bookworm] - giflib <no-dsa> (Minor issue)
+ [bookworm] - giflib 5.2.1-2.5+deb12u1
NOTE: https://www.facebook.com/security/advisories/cve-2026-23868
NOTE: https://sourceforge.net/p/giflib/code/ci/f5b7267aed3665ef025c13823e454170d031c106/tree/gifalloc.c?diff=5146815377b7395944cb683a08c43eee3f631eb7
CVE-2026-23674 (Improper resolution of path equivalence in Windows MapUrlToZone allows ...)
@@ -81321,7 +81342,7 @@ CVE-2026-2297 (The import hook in CPython that handles legacy *.pyc files (Sourc
- python3.13 3.13.14-1
[trixie] - python3.13 3.13.5-2+deb13u1
- python3.11 <removed>
- [bookworm] - python3.11 <no-dsa> (Minor issue)
+ [bookworm] - python3.11 3.11.2-6+deb12u8
- python3.9 <removed>
- pypy3 7.3.22+dfsg-1
[trixie] - pypy3 <no-dsa> (Minor issue)
@@ -82536,6 +82557,7 @@ CVE-2026-2376 (A flaw was found in mirror-registry where an authenticated user c
CVE-2026-3494 (In MariaDB server version through 11.8.5, when server audit plugin is ...)
- mariadb 1:11.8.6-1
[trixie] - mariadb 1:11.8.6-0+deb13u1
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
NOTE: https://github.com/MariaDB/server/commit/635559a2ad68a5a6d1a354e8209c58323dba0261
NOTE: Fixed in MariaDB: 12.3.1, 12.2.2, 11.8.6, 11.4.10, 10.11.16, 10.6.25
CVE-2026-3484 (A vulnerability was detected in PhialsBasement nmap-mcp-server up to b ...)
@@ -83665,7 +83687,7 @@ CVE-2026-2428 (The Fluent Forms Pro Add On Pack plugin for WordPress is vulnerab
CVE-2026-28370 (In the query parser in OpenStack Vitrage before 12.0.1, 13.0.0, 14.0.0 ...)
- vitrage 15.0.1-1 (bug #1139452)
[trixie] - vitrage 14.0.0-4+deb13u1
- [bookworm] - vitrage <no-dsa> (Minor issue)
+ [bookworm] - vitrage 9.0.0-3+deb12u1
NOTE: https://storyboard.openstack.org/#!/story/2011539
NOTE: Fixed by: https://github.com/openstack/vitrage/commit/5b57e2b32a6d02992a28d9a671ebba5e308fd141 (master)
NOTE: Fixed by: https://github.com/openstack/vitrage/commit/89df4bd2ffda1a5ddea66cd828438a6a171a3b11 (15.0.1)
@@ -93036,7 +93058,7 @@ CVE-2019-25266 (Wondershare Application Framework Service 2.4.3.231 contains an
CVE-2026-25727 (time provides date and time handling in Rust. From 0.3.6 to before 0.3 ...)
- rust-time 0.3.47-1
[trixie] - rust-time 0.3.37-1+deb13u1
- [bookworm] - rust-time <no-dsa> (Minor issue)
+ [bookworm] - rust-time 0.3.9-1+deb12u1
[bullseye] - rust-time <not-affected> (rfc2822 parsing introduced in v0.3.6)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0009.html
NOTE: https://github.com/advisories/GHSA-r6v5-fh4h-64xc
@@ -94993,6 +95015,7 @@ CVE-2026-1757 (A flaw was identified in the interactive shell of the xmllint uti
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (unimportant)
[trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
+ [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1009
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/160c8a43ba37dfb07ebe6446fbad9d0973d9279d
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/5446460ad3229579c91506317fb80ab333d44414 (v2.15.2)
@@ -96447,7 +96470,7 @@ CVE-2026-24765 (PHPUnit is a testing framework for PHP. A vulnerability has been
{DLA-4470-1}
- phpunit 12.5.8-1
[trixie] - phpunit 11.5.19-1+deb13u1
- [bookworm] - phpunit <no-dsa> (Minor issue; can be fixed via point release)
+ [bookworm] - phpunit 9.6.7-1+deb12u1
NOTE: https://github.com/sebastianbergmann/phpunit/security/advisories/GHSA-vvj3-c3rp-c85p
NOTE: Fixed by: https://github.com/sebastianbergmann/phpunit/commit/3141742e00620e2968d3d2e732d320de76685fda (12.5.8, 11.5.50, 10.5.62, 9.6.33, 8.5.52)
CVE-2026-24748 (Kargo manages and automates the promotion of software artifacts. Prior ...)
@@ -97854,7 +97877,7 @@ CVE-2026-0994 (A denial-of-service (DoS) vulnerability exists in google.protobuf
[experimental] - protobuf 3.25.7-1
- protobuf 3.21.12-16 (bug #1126302)
[trixie] - protobuf 3.21.12-11+deb13u1
- [bookworm] - protobuf <no-dsa> (Minor issue)
+ [bookworm] - protobuf 3.21.12-3+deb12u1
[bullseye] - protobuf <postponed> (Minor issue)
NOTE: https://github.com/protocolbuffers/protobuf/issues/25070
NOTE: https://github.com/protocolbuffers/protobuf/pull/25239
@@ -99581,7 +99604,7 @@ CVE-2026-21968 (Vulnerability in the MySQL Server product of Oracle MySQL (compo
- mysql-8.0 8.0.45-1 (bug #1126115)
- mariadb 1:11.8.5-1
[trixie] - mariadb 11.8.6-0+deb13u1
- [bookworm] - mariadb <no-dsa> (Minor issue)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
CVE-2026-21967 (Vulnerability in the Oracle Hospitality OPERA 5 product of Oracle Hosp ...)
NOT-FOR-US: Oracle
CVE-2026-21966 (Vulnerability in the Oracle Hospitality OPERA 5 Property Services prod ...)
@@ -101362,7 +101385,7 @@ CVE-2026-0992 (A flaw was found in the libxml2 library. This uncontrolled resour
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (bug #1125696)
[trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
- [bookworm] - libxml2 <no-dsa> (Minor issue)
+ [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1019
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/f75abfcaa419a740a3191e56c60400f3ff18988d
NOTE: Follow-up: https://gitlab.gnome.org/GNOME/libxml2/-/commit/deed3b7873dff30b7f87f7f33154c9932a772522
@@ -101374,7 +101397,7 @@ CVE-2026-0990 (A flaw was found in libxml2, an XML parsing library. This uncontr
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (bug #1125695)
[trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
- [bookworm] - libxml2 <no-dsa> (Minor issue)
+ [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/1018
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/1961208e958ca22f80a0b4e4c9d71cfa050aa982
NOTE: Tests: https://gitlab.gnome.org/GNOME/libxml2/-/commit/f8399e62a31095bf1ced01827c33f9b29494046f
@@ -101384,7 +101407,7 @@ CVE-2026-0989 (A flaw was identified in the RelaxNG parser of libxml2 related to
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (bug #1125691)
[trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
- [bookworm] - libxml2 <no-dsa> (Minor issue)
+ [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/998
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/374
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/66c52b3ac6c32ab112ec2a3bf41e6c30948be113 (v2.15.2)
@@ -103788,7 +103811,7 @@ CVE-2026-22702 (virtualenv is a tool for creating isolated virtual python enviro
CVE-2026-22701 (filelock is a platform-independent file lock for Python. Prior to vers ...)
- python-filelock 3.20.3-1 (bug #1125190)
[trixie] - python-filelock <no-dsa> (Minor issue)
- [bookworm] - python-filelock <no-dsa> (Minor issue)
+ [bookworm] - python-filelock 3.9.0-1+deb12u1
[bullseye] - python-filelock <postponed> (Minor issue, limited/DoS impact)
NOTE: https://github.com/tox-dev/filelock/security/advisories/GHSA-qmgc-5h2g-mvrw
NOTE: Fixed by: https://github.com/tox-dev/filelock/commit/41b42dd2c72aecf7da83dbda5903b8087dddc4d5 (3.20.3)
@@ -105225,7 +105248,7 @@ CVE-2025-15079 (When doing SSH-based transfers using either SCP or SFTP, and set
CVE-2025-14819 (When doing TLS related transfers with reused easy or multi handles and ...)
- curl 8.18.0~rc3-1
[trixie] - curl 8.14.1-2+deb13u4
- [bookworm] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl 7.88.1-10+deb12u15
[bullseye] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2025-14819.html
NOTE: Introduced with: https://github.com/curl/curl/commit/3c16697ebd796f799227be293e8689aec5f8190d (curl-7_87_0)
@@ -105233,7 +105256,7 @@ CVE-2025-14819 (When doing TLS related transfers with reused easy or multi handl
CVE-2025-14524 (When an OAuth2 bearer token is used for an HTTP(S) transfer, and that ...)
- curl 8.18.0~rc2-1
[trixie] - curl 8.14.1-2+deb13u4
- [bookworm] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl 7.88.1-10+deb12u15
[bullseye] - curl <postponed> (Minor issue; can be fixed in next update)
NOTE: https://curl.se/docs/CVE-2025-14524.html
NOTE: Introduced with: https://github.com/curl/curl/commit/06c1bea72faabb6fad4b7ef818aafaa336c9a7aa (curl-7_33_0)
@@ -114192,7 +114215,7 @@ CVE-2025-14841 (A flaw has been found in OFFIS DCMTK up to 3.6.9. The impacted e
[experimental] - dcmtk 3.7.0+really3.7.0-0+exp1
- dcmtk 3.7.0+really3.7.0-1 (bug #1123584)
[trixie] - dcmtk 3.6.9-5+deb13u1
- [bookworm] - dcmtk <no-dsa> (Minor issue)
+ [bookworm] - dcmtk 3.6.7-9~deb12u4
NOTE: https://support.dcmtk.org/redmine/issues/1183
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/ffb1a4a37d2c876e3feeb31df4930f2aed7fa030 (DCMTK-3.7.0)
NOTE: Originally fixed with 3.7.0-1 (but reverted via the 3.7.0+really3.6.9-1 upload)
@@ -115444,7 +115467,7 @@ CVE-2025-68150 (Parse Server is an open source backend that can be deployed to a
CVE-2025-68146 (filelock is a platform-independent file lock for Python. In versions p ...)
- python-filelock 3.20.2-1 (bug #1123510)
[trixie] - python-filelock 3.18.0-1+deb13u1
- [bookworm] - python-filelock <no-dsa> (Minor issue)
+ [bookworm] - python-filelock 3.9.0-1+deb12u1
[bullseye] - python-filelock <postponed> (Minor issue)
NOTE: https://github.com/tox-dev/filelock/security/advisories/GHSA-w853-jp5j-5j7f
NOTE: https://github.com/tox-dev/filelock/pull/461
@@ -116391,7 +116414,7 @@ CVE-2025-14607 (A vulnerability was detected in OFFIS DCMTK up to 3.6.9. Affecte
[experimental] - dcmtk 3.7.0+really3.7.0-0+exp1
- dcmtk 3.7.0+really3.7.0-1 (bug #1122926)
[trixie] - dcmtk 3.6.9-5+deb13u1
- [bookworm] - dcmtk <no-dsa> (Minor issue)
+ [bookworm] - dcmtk 3.6.7-9~deb12u4
NOTE: https://support.dcmtk.org/redmine/issues/1184
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/4c0e5c10079392c594d6a7abd95dd78ac0aa556a (DCMTK-3.7.0)
NOTE: Originally fixed with 3.7.0-1 (but reverted via the 3.7.0+really3.6.9-1 upload)
@@ -118204,7 +118227,6 @@ CVE-2024-2104 (Due to improper BLE security configurations on the device's GATT
CVE-2025-66003 (An External Control of File Name or Path vulnerability in smb4k allows ...)
{DSA-6092-1}
- smb4k 4.0.5-1 (bug #1122381)
- [bookworm] - smb4k <ignored> (Will be removed in final Bookworm point release)
NOTE: https://www.openwall.com/lists/oss-security/2025/12/10/6
NOTE: Fixed by: https://invent.kde.org/network/smb4k/-/commit/0dea60194ab6eb8f6e34ca2e6cb0f97b90c46f1e
NOTE: Fixed by: https://invent.kde.org/network/smb4k/-/commit/0aeabfa9d0f041479589dd855cbfe7cdebedfdb6 (4.0.5)
@@ -118214,7 +118236,6 @@ CVE-2025-66003 (An External Control of File Name or Path vulnerability in smb4k
CVE-2025-66002 (An Improper Neutralization of Argument Delimiters in a Command ('Argu ...)
{DSA-6092-1}
- smb4k 4.0.5-1 (bug #1122381)
- [bookworm] - smb4k <ignored> (Will be removed in final Bookworm point release)
NOTE: https://www.openwall.com/lists/oss-security/2025/12/10/6
NOTE: Fixed by: https://invent.kde.org/network/smb4k/-/commit/0dea60194ab6eb8f6e34ca2e6cb0f97b90c46f1e
NOTE: Fixed by: https://invent.kde.org/network/smb4k/-/commit/0aeabfa9d0f041479589dd855cbfe7cdebedfdb6 (4.0.5)
@@ -122082,7 +122103,7 @@ CVE-2025-66478
CVE-2025-66453 (Rhino is an open-source implementation of JavaScript written entirely ...)
- rhino 1.7.15.1-0.1 (bug #1121953)
[trixie] - rhino 1.7.15.1-0.1~deb13u1
- [bookworm] - rhino <no-dsa> (Minor issue)
+ [bookworm] - rhino 1.7.14.1-0+deb12u1
[bullseye] - rhino <postponed> (Minor issue)
NOTE: https://github.com/mozilla/rhino/security/advisories/GHSA-3w8q-xq97-5j7x
NOTE: Fixed by: https://github.com/mozilla/rhino/commit/b333c3ec7a86409d62b0aab315129584fe18cb9e (Rhino1_7_15_1_Release)
@@ -123147,7 +123168,7 @@ CVE-2025-6666 (A vulnerability was determined in motogadget mo.lock Ignition Loc
CVE-2025-13699 (MariaDB mariadb-dump Utility Directory Traversal Remote Code Execution ...)
- mariadb 1:11.8.5-1
[trixie] - mariadb 11.8.6-0+deb13u1
- [bookworm] - mariadb <no-dsa> (Minor issue; requires attacker to already have access to the database)
+ [bookworm] - mariadb 1:10.11.18-0+deb12u1
- mariadb-10.5 <removed>
[bullseye] - mariadb-10.5 <postponed> (Minor issue; requires attacker to already have access to the database)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2417693
@@ -134874,7 +134895,7 @@ CVE-2025-10020 (Zohocorp ManageEngine ADManager Plus version before 8024 are vul
CVE-2022-4981 (A vulnerability was detected in DCMTK up to 3.6.7. The impacted elemen ...)
{DLA-4363-1}
- dcmtk 3.6.8-5
- [bookworm] - dcmtk <no-dsa> (Minor issue)
+ [bookworm] - dcmtk 3.6.7-9~deb12u4
NOTE: https://support.dcmtk.org/redmine/issues/1026
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/957fb31e5d96f51ecf5cb3422c7dc2227f8e0423 (DCMTK-3.6.8)
CVE-2020-36855 (A security vulnerability has been detected in DCMTK up to 3.6.5. The a ...)
@@ -151031,7 +151052,7 @@ CVE-2025-9086 (1. A cookie is set using the `secure` keyword for `https://target
CVE-2025-10148 (curl's websocket code did not update the 32 bit mask pattern for each ...)
- curl 8.16.0-1
[trixie] - curl 8.14.1-2+deb13u1
- [bookworm] - curl <ignored> (Minor issue; WebSocket support considered experimental feature, only enabled in builds since 8.8.0-2)
+ [bookworm] - curl 7.88.1-10+deb12u15
[bullseye] - curl <not-affected> (WebSocket support introduced later)
NOTE: https://curl.se/docs/CVE-2025-10148.html
NOTE: Fixed by: https://github.com/curl/curl/commit/84db7a9eae8468c0445b15aa806fa7fa806fa0f2 (curl-8_16_0)
@@ -154209,7 +154230,7 @@ CVE-2025-9375 (XML Injection vulnerability in xmltodict allows Input Data Manipu
[experimental] - python-xmltodict 1.0.3-1
- python-xmltodict 0.13.0-1.1 (bug #1113825)
[trixie] - python-xmltodict 0.13.0-1.1~deb13u1
- [bookworm] - python-xmltodict <no-dsa> (Minor issue)
+ [bookworm] - python-xmltodict 0.13.0-1.1~deb12u1
[bullseye] - python-xmltodict <postponed> (Minor issue)
NOTE: https://github.com/martinblech/xmltodict/issues/377
NOTE: https://fluidattacks.com/advisories/mono
@@ -154349,7 +154370,7 @@ CVE-2025-9732 (A vulnerability was identified in DCMTK up to 3.6.9. This affects
{DLA-4363-1}
- dcmtk 3.6.9-6 (bug #1113993)
[trixie] - dcmtk 3.6.9-5+deb13u1
- [bookworm] - dcmtk <no-dsa> (Minor issue)
+ [bookworm] - dcmtk 3.6.7-9~deb12u4
NOTE: https://github.com/DCMTK/dcmtk/commit/7ad81d69b19714936e18ea5fc74edaeb9f021ce7
NOTE: https://github.com/DCMTK/dcmtk/commit/3de96da6cd66b1af7224561c568bc3de50cd1398
CVE-2025-9731 (A vulnerability was determined in Tenda AC9 15.03.05.19. The impacted ...)
@@ -161540,6 +161561,7 @@ CVE-2025-8732 (A vulnerability was found in libxml2 up to 2.14.5. It has been de
{DLA-4622-1}
- libxml2 2.15.2+dfsg-0.1 (unimportant)
[trixie] - libxml2 2.12.7+dfsg+really2.9.14-2.1+deb13u3
+ [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/958
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/issues/958#note_2505853
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/3425dece47c8db600f8d7328ae2d7ddfaa0d7b2d (v2.15.2)
@@ -178196,7 +178218,7 @@ CVE-2025-4748 (Improper Limitation of a Pathname to a Restricted Directory ('Pat
CVE-2025-4565 (Any project that uses Protobuf Pure-Python backendto parse untrusted P ...)
- protobuf 3.21.12-12 (bug #1108057)
[trixie] - protobuf 3.21.12-11+deb13u1
- [bookworm] - protobuf <no-dsa> (Minor issue)
+ [bookworm] - protobuf 3.21.12-3+deb12u1
[bullseye] - protobuf <postponed> (Minor issue; can be fixed in next update)
NOTE: https://github.com/protocolbuffers/protobuf/commit/17838beda2943d08b8a9d4df5b68f5f04f26d901
CVE-2025-49125 (Authentication Bypass Using an Alternate Path or Channel vulnerability ...)
@@ -207928,7 +207950,7 @@ CVE-2025-2358 (A vulnerability was found in Shenzhen Mingyuan Cloud Technology M
CVE-2025-2357 (A vulnerability was found in DCMTK 3.6.9. It has been declared as crit ...)
{DLA-4227-1}
- dcmtk 3.6.9-5 (bug #1100724)
- [bookworm] - dcmtk <no-dsa> (Minor issue)
+ [bookworm] - dcmtk 3.6.7-9~deb12u4
NOTE: https://support.dcmtk.org/redmine/issues/1155
NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=3239a791542e1ea433d23aaa9e0a05a532ffabff
CVE-2025-2356 (A vulnerability was found in BlackVue App 3.65 on Android. It has been ...)
@@ -261119,7 +261141,7 @@ CVE-2024-8364 (The WP Custom Fields Search plugin for WordPress is vulnerable to
CVE-2024-7254 (Any project that parses untrusted Protocol Buffers datacontaining an a ...)
- protobuf 3.21.12-12 (bug #1082381)
[trixie] - protobuf 3.21.12-11+deb13u1
- [bookworm] - protobuf <no-dsa> (Minor issue)
+ [bookworm] - protobuf 3.21.12-3+deb12u1
[bullseye] - protobuf <postponed> (Minor issue)
NOTE: https://github.com/protocolbuffers/protobuf/commit/b7044987de77f1dc368fee558636d0b56d7e75e1 (v3.25.5)
NOTE: https://github.com/protocolbuffers/protobuf/commit/850fcce9176e2c9070614dab53537760498c926b (v3.25.5)
@@ -276126,7 +276148,7 @@ CVE-2024-40648 (matrix-rust-sdk is an implementation of a Matrix client-server l
CVE-2024-40647 (sentry-sdk is the official Python SDK for Sentry.io. A bug in Sentry's ...)
{DLA-4612-1}
- sentry-python 2.16.0-1 (bug #1083189)
- [bookworm] - sentry-python <no-dsa> (Minor issue)
+ [bookworm] - sentry-python 1.9.10-2+deb12u1
NOTE: https://github.com/getsentry/sentry-python/security/advisories/GHSA-g92j-qhmh-64v2
NOTE: https://github.com/getsentry/sentry-python/pull/3251
NOTE: https://github.com/getsentry/sentry-python/commit/763e40aa4cb57ecced467f48f78f335c87e9bdff (2.8.0)
@@ -307497,7 +307519,7 @@ CVE-2024-3774 (aEnrich Technology a+HRD's functionality for front-end retrieval
NOT-FOR-US: aEnrich Technology
CVE-2024-3772 (Regular expression denial of service in Pydanic < 2.4.0, < 1.10.13 all ...)
- pydantic 1.10.13-0.1
- [bookworm] - pydantic <no-dsa> (Minor issue)
+ [bookworm] - pydantic 1.10.4-1+deb12u1
[bullseye] - pydantic <no-dsa> (Minor issue)
NOTE: https://github.com/pydantic/pydantic/pull/7360
NOTE: https://github.com/pydantic/pydantic/commit/e4393ae6145c4dadff739990bb0116c6dec3441b (v2.4.0)
@@ -355955,7 +355977,7 @@ CVE-2023-41080 (URL Redirection to Untrusted Site ('Open Redirect') vulnerabilit
NOTE: Starting with 9.0.70-2 Tomcat9 no longer ships the server stack, using that as the fixed version
CVE-2023-40587 (Pyramid is an open source Python web framework. A path traversal vulne ...)
- python-pyramid 2.0.2+dfsg-1 (bug #1050740)
- [bookworm] - python-pyramid <no-dsa> (Minor issue)
+ [bookworm] - python-pyramid 2.0+dfsg-2+deb12u1
[bullseye] - python-pyramid <not-affected> (Python version in Bullseye is not affected)
[buster] - python-pyramid <not-affected> (Python version in Buster is not affected)
NOTE: https://github.com/Pylons/pyramid/security/advisories/GHSA-j8g2-6fc7-q8f8
@@ -417694,7 +417716,7 @@ CVE-2022-42965 (An exponential ReDoS (Regular Expression Denial of Service) can
NOT-FOR-US: snowflake-connector-python
CVE-2022-42964 (An exponential ReDoS (Regular Expression Denial of Service) can be tri ...)
- pymatgen 2023.06.23+dfsg1-1 (bug #1024017)
- [bookworm] - pymatgen <no-dsa> (Minor issue)
+ [bookworm] - pymatgen 2022.11.7+dfsg1-11+deb12u2
NOTE: https://research.jfrog.com/vulnerabilities/pymatgen-redos-xray-257184/
NOTE: https://github.com/materialsproject/pymatgen/issues/2755
CVE-2022-3520 (Heap-based Buffer Overflow in GitHub repository vim/vim prior to 9.0.0 ...)
@@ -506136,7 +506158,7 @@ CVE-2021-37746 (textview_uri_security_check in textview.c in Claws Mail before 3
[stretch] - claws-mail <no-dsa> (Minor issue)
- sylpheed <removed> (bug #991723)
[trixie] - sylpheed 3.8.0~beta1-2+deb13u1
- [bookworm] - sylpheed <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - sylpheed 3.8.0~beta1-1+deb12u1
[bullseye] - sylpheed <no-dsa> (Minor issue)
[buster] - sylpheed <no-dsa> (Minor issue)
[stretch] - sylpheed <no-dsa> (Minor issue)
=====================================
data/next-oldstable-point-update.txt
=====================================
@@ -1,229 +1,3 @@
-CVE-2025-13462
- [bookworm] - python3.11 3.11.2-6+deb12u8
-CVE-2026-2297
- [bookworm] - python3.11 3.11.2-6+deb12u8
-CVE-2026-4224
- [bookworm] - python3.11 3.11.2-6+deb12u8
-CVE-2026-4519
- [bookworm] - python3.11 3.11.2-6+deb12u8
-CVE-2026-6100
- [bookworm] - python3.11 3.11.2-6+deb12u8
-CVE-2026-24765
- [bookworm] - phpunit 9.6.7-1+deb12u1
-CVE-2026-25727
- [bookworm] - rust-time 0.3.9-1+deb12u1
-CVE-2021-37746
- [bookworm] - sylpheed 3.8.0~beta1-1+deb12u1
-CVE-2025-10148
- [bookworm] - curl 7.88.1-10+deb12u15
-CVE-2025-14524
- [bookworm] - curl 7.88.1-10+deb12u15
-CVE-2025-14819
- [bookworm] - curl 7.88.1-10+deb12u15
-CVE-2026-3783
- [bookworm] - curl 7.88.1-10+deb12u15
-CVE-2026-3784
- [bookworm] - curl 7.88.1-10+deb12u15
-CVE-2026-5773
- [bookworm] - curl 7.88.1-10+deb12u15
-CVE-2026-7168
- [bookworm] - curl 7.88.1-10+deb12u15
-CVE-2026-45793
- [bookworm] - composer 2.5.5-1+deb12u5
-CVE-2026-8503
- [bookworm] - libapache-session-browseable-perl 1.3.11-3+deb12u1
-CVE-2026-42052
- [bookworm] - beets 1.6.0-4+deb12u1
-CVE-2026-4948
- [bookworm] - firewalld 1.3.3-1~deb12u2
-CVE-2026-42268
- [bookworm] - modsecurity 3.0.9-1+deb12u2
-CVE-2026-30923
- [bookworm] - modsecurity 3.0.9-1+deb12u2
-CVE-2026-30853
- [bookworm] - calibre 6.13.0+repack-2+deb12u8
-CVE-2026-33206
- [bookworm] - calibre 6.13.0+repack-2+deb12u8
-CVE-2026-33205
- [bookworm] - calibre 6.13.0+repack-2+deb12u9
-CVE-2024-40647
- [bookworm] - sentry-python 1.9.10-2+deb12u1
-CVE-2024-3772
- [bookworm] - pydantic 1.10.4-1+deb12u1
-CVE-2026-42046
- [bookworm] - libcaca 0.99.beta20-3+deb12u1
-CVE-2026-45232
- [bookworm] - rsync 3.2.7-1+deb12u6
-CVE-2022-42964
- [bookworm] - pymatgen 2022.11.7+dfsg1-11+deb12u2
-CVE-2026-48112
- [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
-CVE-2026-48111
- [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
-CVE-2026-48104
- [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
-CVE-2026-48103
- [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
-CVE-2026-48102
- [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
-CVE-2026-48101
- [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
-CVE-2026-48095
- [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
-CVE-2026-48092
- [bookworm] - 7zip 22.01+really26.01+dfsg-0+deb12u1
-CVE-2025-68146
- [bookworm] - python-filelock 3.9.0-1+deb12u1
-CVE-2026-22701
- [bookworm] - python-filelock 3.9.0-1+deb12u1
-CVE-2026-47187
- [bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
-CVE-2026-48711
- [bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
-CVE-2026-50593
- [bookworm] - graphite2 1.3.14-1+deb12u1
-CVE-2026-44312
- [bookworm] - ruby-css-parser 1.6.0-2+deb12u1
-CVE-2026-0989
- [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
-CVE-2026-0990
- [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
-CVE-2026-0992
- [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
-CVE-2025-8732
- [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
-CVE-2026-1757
- [bookworm] - libxml2 2.9.14+dfsg-1.3~deb12u6
-CVE-2026-49214
- [bookworm] - php-guzzlehttp-psr7 2.4.5-1+deb12u1
-CVE-2026-48998
- [bookworm] - php-guzzlehttp-psr7 2.4.5-1+deb12u1
-CVE-2026-28370
- [bookworm] - vitrage 9.0.0-3+deb12u1
-CVE-2026-55748
- [bookworm] - horizon 3:23.0.0-5+deb12u2
-CVE-2026-29167
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-29170
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-34355
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-34356
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-42535
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-42536
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-43951
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-44119
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-44185
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-44186
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-44631
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-48913
- [bookworm] - apache2 2.4.68-1~deb12u1
-CVE-2026-9641
- [bookworm] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1~deb12u1
-CVE-2026-9638
- [bookworm] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1~deb12u1
-CVE-2017-20240
- [bookworm] - libcrypt-pbkdf2-perl 0.261630-1~deb13u1~deb12u1
-CVE-2026-8829
- [bookworm] - libhtml-parser-perl 3.81-1+deb12u1
-CVE-2022-4981
- [bookworm] - dcmtk 3.6.7-9~deb12u4
-CVE-2026-12805
- [bookworm] - dcmtk 3.6.7-9~deb12u4
-CVE-2025-2357
- [bookworm] - dcmtk 3.6.7-9~deb12u4
-CVE-2025-9732
- [bookworm] - dcmtk 3.6.7-9~deb12u4
-CVE-2025-14607
- [bookworm] - dcmtk 3.6.7-9~deb12u4
-CVE-2025-14841
- [bookworm] - dcmtk 3.6.7-9~deb12u4
-CVE-2026-5663
- [bookworm] - dcmtk 3.6.7-9~deb12u4
-CVE-2026-10194
- [bookworm] - dcmtk 3.6.7-9~deb12u4
-CVE-2026-44988
- [bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
-CVE-2026-50538
- [bookworm] - libvncserver 0.9.14+dfsg-1+deb12u2
-CVE-2026-5037
- [bookworm] - mxml 3.3.1-1+deb13u1~deb12u1
-CVE-2026-48977
- [bookworm] - openslide 3.4.1+dfsg-6+deb12u1
-CVE-2026-40393
- [bookworm] - mesa 22.3.6-1+deb12u2
-CVE-2023-40587
- [bookworm] - python-pyramid 2.0+dfsg-2+deb12u1
-CVE-2026-11625
- [bookworm] - libbytes-random-secure-perl 0.29-4~deb13u1~deb12u1
-CVE-2026-45190
- [bookworm] - libnet-cidr-lite-perl 0.22-3~deb12u2
-CVE-2026-45191
- [bookworm] - libnet-cidr-lite-perl 0.22-3~deb12u2
-CVE-2026-8177
- [bookworm] - libxml-libxml-perl 2.0207+dfsg+really+2.0134-1+deb12u1
-CVE-2026-34743
- [bookworm] - xz-utils 5.4.1-2+deb12u1
-CVE-2026-26740
- [bookworm] - giflib 5.2.1-2.5+deb12u1
-CVE-2026-23868
- [bookworm] - giflib 5.2.1-2.5+deb12u1
-CVE-2026-49261
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-48165
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-48163
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-44173
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-44172
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-44171
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-44168
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-3494
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-34303
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-21968
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2025-13699
- [bookworm] - mariadb 1:10.11.18-0+deb12u1
-CVE-2026-58302
- [bookworm] - linuxcnc 2.9.0~pre1+git20230208.f1270d6ed7-1+deb12u2
-CVE-2025-15646
- [bookworm] - libhtml-gumbo-perl 0.18-3+deb12u1
-CVE-2026-0994
- [bookworm] - protobuf 3.21.12-3+deb12u1
-CVE-2026-6409
- [bookworm] - protobuf 3.21.12-3+deb12u1
-CVE-2024-7254
- [bookworm] - protobuf 3.21.12-3+deb12u1
-CVE-2025-4565
- [bookworm] - protobuf 3.21.12-3+deb12u1
-CVE-2025-66453
- [bookworm] - rhino 1.7.14.1-0+deb12u1
-CVE-2026-47319
- [bookworm] - rlottie 0.1+dfsg-4+deb12u2
-CVE-2026-47320
- [bookworm] - rlottie 0.1+dfsg-4+deb12u2
-CVE-2026-10305
- [bookworm] - rlottie 0.1+dfsg-4+deb12u2
-CVE-2025-9375
- [bookworm] - python-xmltodict 0.13.0-1.1~deb12u1
-CVE-2025-70102
- [bookworm] - dhcpcd5 9.4.1-24~deb12u5
-CVE-2026-56114
- [bookworm] - dhcpcd5 9.4.1-24~deb12u5
CVE-2025-13465
[bookworm] - node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9+deb12u1
CVE-2026-2950
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/648491a4ef4ebb7c74857c7d2af668b4e7bb3e37...aed8860e080f8e559d89f0a980f56e0f8df13951
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/648491a4ef4ebb7c74857c7d2af668b4e7bb3e37...aed8860e080f8e559d89f0a980f56e0f8df13951
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260711/aa5bb501/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list