[Git][security-tracker-team/security-tracker][master] 7 commits: lts: ack postponed in bullseye/bookworm (CVE-2026-49145)
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sun Jul 12 01:44:58 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
64405243 by Utkarsh Gupta at 2026-07-12T06:14:26+05:30
lts: ack postponed in bullseye/bookworm (CVE-2026-49145)
- - - - -
a5f045f4 by Utkarsh Gupta at 2026-07-12T06:14:27+05:30
lts: acl postponed in bullseye/bookworm (CVE-2026-54369, CVE-2026-54370)
- - - - -
4ba3df32 by Utkarsh Gupta at 2026-07-12T06:14:29+05:30
lts: angular.js postponed in bullseye/bookworm (CVE-2026-11998)
- - - - -
fd8bef76 by Utkarsh Gupta at 2026-07-12T06:14:30+05:30
lts: assimp postponed in bullseye/bookworm (CVE-2026-14610, CVE-2026-14604, CVE-2025-15666)
- - - - -
e6b822be by Utkarsh Gupta at 2026-07-12T06:14:32+05:30
lts: attr postponed in bullseye/bookworm (CVE-2026-54371)
- - - - -
a8b14913 by Utkarsh Gupta at 2026-07-12T06:14:33+05:30
lts: botan postponed in bullseye/bookworm (CVE-2026-32884, CVE-2026-32877)
- - - - -
0fb5f7c0 by Utkarsh Gupta at 2026-07-12T06:14:35+05:30
lts: note v3.10.0 only partially fixes CVE-2026-49145/ack
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2181,8 +2181,11 @@ CVE-2026-49146 (App::Ack versions before 3.10.0 for Perl allow memory exhaustion
CVE-2026-49145 (App::Ack versions through 3.10.0 for Perl read arbitrary files via --f ...)
- ack <unfixed>
[trixie] - ack <no-dsa> (Minor issue)
+ [bookworm] - ack <postponed> (Minor issue; local-only, needs untrusted project .ackrc; --files-from still unfixed upstream)
+ [bullseye] - ack <postponed> (Minor issue; local-only, needs untrusted project .ackrc; --files-from still unfixed upstream)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41643327/
NOTE: Fixed by: https://github.com/beyondgrep/ack3/commit/45ff5fe77dbd96f7332f31943102291f878f30b8 (v3.10.0)
+ NOTE: 45ff5fe (v3.10.0) is only a partial fix: it adds --follow to the project .ackrc blocklist but --files-from remains accepted, so arbitrary file read via --files-from is still unfixed upstream.
CVE-2026-44840 (Dgraph is an open source distributed GraphQL database. Prior to versio ...)
TODO: check
CVE-2026-41122 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, LTS2026 r ...)
@@ -4058,6 +4061,8 @@ CVE-2026-14611 (A vulnerability has been found in DeepMyst Mysti up to 0.4.0. Th
CVE-2026-14610 (A flaw has been found in Open Asset Import Library Assimp up to 6.0.5. ...)
- assimp <unfixed> (bug #1141496)
[trixie] - assimp <no-dsa> (Minor issue)
+ [bookworm] - assimp <postponed> (Minor issue)
+ [bullseye] - assimp <postponed> (Minor issue)
NOTE: https://github.com/assimp/assimp/issues/6622
NOTE: https://github.com/assimp/assimp/pull/6649
NOTE: https://github.com/assimp/assimp/commit/eb84eec580d3f4ba2f0fd87409b7d0744620f11e
@@ -4260,6 +4265,8 @@ CVE-2026-14612 (Two off-by-one errors in the FreeIPA ipa-otpd daemon's OAuth2 de
CVE-2026-14604 (A vulnerability was determined in Open Asset Import Library Assimp up ...)
- assimp <unfixed> (bug #1141494)
[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+ [bullseye] - assimp <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/assimp/assimp/issues/6620
CVE-2026-14544 (A flaw was found in HPLIP (HP Linux Imaging and Printing Software). Th ...)
- hplip <unfixed>
@@ -6330,6 +6337,8 @@ CVE-2025-36319 (IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could a
CVE-2025-15666 (A security vulnerability has been detected in Open Asset Import Librar ...)
- assimp <unfixed> (bug #1141389)
[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+ [bullseye] - assimp <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/assimp/assimp/issues/6079
CVE-2025-12530 (IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 through patch ...)
NOT-FOR-US: IBM
@@ -8813,6 +8822,8 @@ CVE-2026-11720 (A path traversal vulnerability exists in the HTTP tool URL build
CVE-2026-54371 (attr before version 2.6.0 contains a symlink traversal vulnerability i ...)
- attr 1:2.6.0-1 (bug #1141107)
[trixie] - attr <no-dsa> (Will be fixed first in unstable, then point release update; not to be backported by individual patches)
+ [bookworm] - attr <postponed> (Minor issue; local symlink-traversal in recursive getfattr/setfattr; fix is a complete walk_tree rewrite, high regression risk)
+ [bullseye] - attr <postponed> (Minor issue; local symlink-traversal in recursive getfattr/setfattr; fix is a complete walk_tree rewrite, high regression risk)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
NOTE: Fixed by: https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=641ea6fcc556c1f34b77efb9cd3f876dff0a0a07 (v2.6.0)
NOTE: Fixed by: https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=3fb06b9ba314d37035d0877e6de313de754f1ac8 (v2.6.0)
@@ -8820,6 +8831,8 @@ CVE-2026-54371 (attr before version 2.6.0 contains a symlink traversal vulnerabi
CVE-2026-54370 (acl before version 2.4.0 contains a time-of-check to time-of-use (TOCT ...)
- acl 2.4.0-1 (bug #1141110)
[trixie] - acl <no-dsa> (Will be fixed first in unstable, then point release update; not to be backported by individual patches)
+ [bookworm] - acl <postponed> (Minor issue; local TOCTOU in recursive setfacl/chacl; fix needs 2.4.0 acl_*_at() ABI + walk_tree rewrite, not individually backportable)
+ [bullseye] - acl <postponed> (Minor issue; local TOCTOU in recursive setfacl/chacl; fix needs 2.4.0 acl_*_at() ABI + walk_tree rewrite, not individually backportable)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
NOTE: Fixed by: https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=601cc884a548ae9e9d246ae749e54b3272e4b1d7 (v2.4.0)
NOTE: Fixed by: https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=54e14e9bc545f505b379d0792a2748d9baf88700 (v2.4.0)
@@ -8829,6 +8842,8 @@ CVE-2026-54370 (acl before version 2.4.0 contains a time-of-check to time-of-use
CVE-2026-54369 (acl before version 2.4.0 contains a symlink traversal vulnerability in ...)
- acl 2.4.0-1 (bug #1141110)
[trixie] - acl <no-dsa> (Will be fixed first in unstable, then point release update; not to be backported by individual patches)
+ [bookworm] - acl <postponed> (Minor issue; libacl acl_*_file() follow symlinks; fix adds new acl_*_at() ABI, not individually backportable)
+ [bullseye] - acl <postponed> (Minor issue; libacl acl_*_file() follow symlinks; fix adds new acl_*_at() ABI, not individually backportable)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
NOTE: Fixed by: https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=5906d2868ec8d3b08be556153696e6b1122eeeda (v2.4.0)
NOTE: Fixed by: https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=0071c6d1fea0a8a6270333baa85fb609be325c26 (v2.4.0)
@@ -12089,6 +12104,8 @@ CVE-2026-12053 (GitLab has remediated an issue in GitLab EE affecting all versio
CVE-2026-11998 (A flaw in AngularJS' Strict Contextual Escaping (SCE) logic allows byp ...)
- angular.js <unfixed> (bug #1141314)
[trixie] - angular.js <no-dsa> (Minor issue)
+ [bookworm] - angular.js <postponed> (Minor issue; EOL upstream, no fix available; only reachable with custom RegExp trustedResourceUrlList matchers using alternation)
+ [bullseye] - angular.js <postponed> (Minor issue; EOL upstream, no fix available; only reachable with custom RegExp trustedResourceUrlList matchers using alternation)
NOTE: https://www.herodevs.com/vulnerability-directory/cve-2026-11998?nes-for-angularjs
CVE-2026-11379 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
@@ -67894,6 +67911,8 @@ CVE-2026-32884 (Botan is a C++ cryptography library. Prior to version 3.11.0, du
- botan3 3.11.0+dfsg-2
- botan <removed>
[trixie] - botan <no-dsa> (Minor issue)
+ [bookworm] - botan <postponed> (Minor issue; case-sensitive CN fallback in DNS name-constraint check; fix only in 3.11.0)
+ [bullseye] - botan <postponed> (Minor issue; case-sensitive CN fallback in DNS name-constraint check; fix only in 3.11.0)
NOTE: https://github.com/randombit/botan/security/advisories/GHSA-7c3g-7763-ggj5
CVE-2026-32883 (Botan is a C++ cryptography library. From version 3.0.0 to before vers ...)
[experimental] - botan3 3.11.0+dfsg-1
@@ -67906,6 +67925,8 @@ CVE-2026-32877 (Botan is a C++ cryptography library. From version 2.3.0 to befor
- botan3 3.11.0+dfsg-2
- botan <removed>
[trixie] - botan <no-dsa> (Minor issue)
+ [bookworm] - botan <postponed> (Minor issue; SM2 C3 heap over-read; fix only in 3.11.0)
+ [bullseye] - botan <postponed> (Minor issue; SM2 C3 heap over-read; fix only in 3.11.0)
NOTE: https://github.com/randombit/botan/security/advisories/GHSA-7jj6-4r42-w9h6
NOTE: https://github.com/randombit/botan/commit/f3c31f96f58f1d1d482032d8f4286dc9ebbc6712 (3.11.0)
CVE-2026-32794 (Improper Certificate Validation vulnerability in Apache Airflow Provid ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3469ea93fa5284f9bf13d4eace8370296a721e02...0fb5f7c0d4bcd97009727268e60dcca34420c93d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3469ea93fa5284f9bf13d4eace8370296a721e02...0fb5f7c0d4bcd97009727268e60dcca34420c93d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260712/7f79f3a1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list