[Git][security-tracker-team/security-tracker][master] 3 commits: lts: curl not-affected/postponed in bullseye/bookworm (9 CVEs)
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sun Jul 12 02:24:20 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
78e637f1 by Utkarsh Gupta at 2026-07-12T06:45:13+05:30
lts: curl not-affected/postponed in bullseye/bookworm (9 CVEs)
- - - - -
2987309f by Utkarsh Gupta at 2026-07-12T06:46:29+05:30
lts: glib2.0 postponed in bullseye/bookworm (CVE-2026-58010 to CVE-2026-58016)
- - - - -
30119240 by Utkarsh Gupta at 2026-07-12T06:47:55+05:30
lts: lmdb postponed in bullseye/bookworm (CVE-2019-16224 to CVE-2019-16228)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7961,29 +7961,39 @@ CVE-2026-58116 (LLaMA-Factory through 0.9.5 contains a remote code execution vul
CVE-2026-58016 (A flaw was found in GLib. A state confusion issue exists in g_dbus_nod ...)
- glib2.0 <unfixed> (bug #1141316)
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; GDBus introspection-XML OOB-read DoS; no upstream fix yet)
+ [bullseye] - glib2.0 <postponed> (Minor issue; GDBus introspection-XML OOB-read DoS; no upstream fix yet)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3932
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5156 (2.89.0)
CVE-2026-58015 (A flaw was found in GLib. The D-Bus client-side implementation of the ...)
- glib2.0 2.88.1-2
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; DBUS_COOKIE_SHA1 client path traversal, needs malicious D-Bus server)
+ [bullseye] - glib2.0 <postponed> (Minor issue; DBUS_COOKIE_SHA1 client path traversal, needs malicious D-Bus server)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3931
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5172 (2.89.0)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
CVE-2026-58014 (A flaw was found in GLib. An off-by-one error can occur in the g_key_f ...)
- glib2.0 2.88.1-2
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; GKeyFile off-by-one 1-byte OOB, reachability-gated)
+ [bullseye] - glib2.0 <postponed> (Minor issue; GKeyFile off-by-one 1-byte OOB, reachability-gated)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3930
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5171 (2.89.0)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
CVE-2026-58013 (A flaw was found in GLib. A buffer over-read can occur in g_io_channel ...)
- glib2.0 2.88.1-2
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; GIOChannel custom-terminator over-read, reachability-gated)
+ [bullseye] - glib2.0 <postponed> (Minor issue; GIOChannel custom-terminator over-read, reachability-gated)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3925
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5170 (2.89.0)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
CVE-2026-58012 (A flaw was found in GLib. A buffer over-read can occur in the g_regex_ ...)
- glib2.0 2.88.1-2
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; g_regex_replace raw-mode over-read, needs G_REGEX_RAW)
+ [bullseye] - glib2.0 <postponed> (Minor issue; g_regex_replace raw-mode over-read, needs G_REGEX_RAW)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3918
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5132 (2.89.0)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5134 (2.88.1)
@@ -7991,6 +8001,8 @@ CVE-2026-58012 (A flaw was found in GLib. A buffer over-read can occur in the g_
CVE-2026-58011 (A flaw was found in GLib. An out-of-bounds read of only 2 bytes can oc ...)
- glib2.0 2.88.1-2
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; GDateTime 2-byte over-read, reachability-gated)
+ [bullseye] - glib2.0 <postponed> (Minor issue; GDateTime 2-byte over-read, reachability-gated)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3917
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5131 (2.89.0)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5134 (2.88.1)
@@ -7998,6 +8010,8 @@ CVE-2026-58011 (A flaw was found in GLib. An out-of-bounds read of only 2 bytes
CVE-2026-58010 (A flaw was found in GLib. An off-by-one error can occur in the gvs_tup ...)
- glib2.0 2.88.1-2
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; GVariant deserialiser 1-byte over-read, reachability-gated)
+ [bullseye] - glib2.0 <postponed> (Minor issue; GVariant deserialiser 1-byte over-read, reachability-gated)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3915
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5129 (2.89.0)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/commit/8338414f6560216efe67d3cbf549e32f8630252a (2.89.0)
@@ -13874,18 +13888,24 @@ CVE-2025-64105 (FOSSBilling is a billing and client management system that autom
CVE-2026-8286 (A vulnerability exists where a new transfer that uses STARTTLS to upgr ...)
- curl 8.21.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <postponed> (Minor issue; STARTTLS connection reuse config mismatch)
+ [bullseye] - curl <postponed> (Minor issue; STARTTLS connection reuse config mismatch)
NOTE: https://curl.se/docs/CVE-2026-8286.html
NOTE: Introduced with: https://github.com/curl/curl/commit/a1701eea289fe7ea80651f801cf992838a491dde (curl-7_30_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/a86efdd7ca5433de9231e650f18247de8319ad16 (rc-8_21_0-1, curl-8_21_0)
CVE-2026-8458 (libcurl might in some circumstances reuse the wrong connection when as ...)
- curl 8.21.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <postponed> (Minor issue; needs HTTP Negotiate auth with differing service names)
+ [bullseye] - curl <postponed> (Minor issue; needs HTTP Negotiate auth with differing service names)
NOTE: https://curl.se/docs/CVE-2026-8458.html
NOTE: Introduced with: https://github.com/curl/curl/commit/97c272e5d173ad5f706443e2477f0a84f0044edd (curl-7_43_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/5e99b73cf441d9c369768b9cd48b5389b9a2503d (rc-8_21_0-1, curl-8_21_0)
CVE-2026-8924 (A flaw in curl\u2019s cookie parsing logic allows a malicious HTTP ser ...)
- curl 8.21.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <postponed> (Minor issue; trailing-dot super cookie; PSL-enabled build mitigates)
+ [bullseye] - curl <postponed> (Minor issue; trailing-dot super cookie; PSL-enabled build mitigates)
NOTE: https://curl.se/docs/CVE-2026-8924.html
NOTE: Introduced with: https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 (curl-7_46_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/51beed175dbfc37da3113f6acce60c630c070ce8 (rc-8_21_0-1, curl-8_21_0)
@@ -13908,12 +13928,16 @@ CVE-2026-8926 (When asking curl to use a `.netrc` file to find credentials and a
CVE-2026-8927 (When reusing a libcurl handle for sequential transfers driven by envir ...)
- curl 8.21.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <postponed> (Minor issue; libcurl env-proxy Digest auth handle reuse)
+ [bullseye] - curl <postponed> (Minor issue; libcurl env-proxy Digest auth handle reuse)
NOTE: https://curl.se/docs/CVE-2026-8927.html
NOTE: Introduced with: https://github.com/curl/curl/commit/fc6eff13b5414caf6edf22d73a3239e074a04216 (curl-7_12_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/5c225384b8d52c67ce8259c6e4203bc57aacb567 (rc-8_21_0-1, curl-8_21_0)
CVE-2026-8932 (libcurl would reuse a previously created connection even when some mTL ...)
- curl 8.21.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <postponed> (Minor issue; libcurl mTLS handle-reuse config mismatch)
+ [bullseye] - curl <postponed> (Minor issue; libcurl mTLS handle-reuse config mismatch)
NOTE: https://curl.se/docs/CVE-2026-8932.html
NOTE: Introduced with: https://github.com/curl/curl/commit/a1d6ad26100bc493c7b04f1301b1634b7f5aa8b4 (curl-7_7)
NOTE: Fixed by: https://github.com/curl/curl/commit/7541ae569d82fb308a5e2d94916027da4fa3ba3e (rc-8_21_0-1, curl-8_21_0)
@@ -13952,12 +13976,16 @@ CVE-2026-9546 (A vulnerability in libcurl caused the HTTP `Referer:` header to p
CVE-2026-9547 (When a libcurl-based application performs transfers via `SCP://` or `S ...)
- curl 8.21.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <not-affected> (Debian builds --without-libssh --with-libssh2; flaw only affects the libssh backend)
+ [bullseye] - curl <not-affected> (Debian builds curl with libssh2, not the libssh backend the flaw requires)
NOTE: https://curl.se/docs/CVE-2026-9547.html
NOTE: Introduced with: https://github.com/curl/curl/commit/507cf6a13db0375eadd4655b4c64710db29e9cf2 (curl-7_69_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/0b8dbbc63c98777e4584cb9fbd71df3464008ad1 (rc-8_21_0-1, curl-8_21_0)
CVE-2026-10536 (A use-after-free vulnerability exists in libcurl when an application c ...)
- curl 8.21.0~rc2-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <postponed> (Minor issue; needs rare CURLOPT_STREAM_DEPENDS + reset/cleanup)
+ [bullseye] - curl <not-affected> (Vulnerable code introduced in 7.88.0; bullseye ships 7.74.0)
NOTE: https://curl.se/docs/CVE-2026-10536.html
NOTE: Introduced with: https://github.com/curl/curl/commit/71b7e0161032927cdfb4e75ea40f65b8898b3956 (curl-7_88_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/bfbff7852f050232edd3e5ca5c6bf2021c340f5a (rc-8_21_0-1, curl-8_21_0)
@@ -13988,12 +14016,16 @@ CVE-2026-11586 (By default, curl automatically responds to WebSocket PING frames
CVE-2026-11856 (Successfully using libcurl to do a transfer to a specific HTTP origin ...)
- curl 8.21.0~rc3-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <postponed> (Minor issue; needs Digest auth + libcurl handle reuse across origins)
+ [bullseye] - curl <postponed> (Minor issue; needs Digest auth + libcurl handle reuse across origins)
NOTE: https://curl.se/docs/CVE-2026-11856.html
NOTE: Introduced with: https://github.com/curl/curl/commit/334d78cd18a7310144383929bdcef34ffbf6159b (curl-7_10_6)
NOTE: Fixed by: https://github.com/curl/curl/commit/5c6b4880357ab3e72967c1c45cae0f96ffabc535 (rc-8_21_0-3, curl-8_21_0)
CVE-2026-12064 (When a user invokes curl using a schemeless URL combined with `--proto ...)
- curl 8.21.0~rc3-1
[trixie] - curl <no-dsa> (Minor issue)
+ [bookworm] - curl <postponed> (Minor issue; needs schemeless URL with --proto-default sftp/scp)
+ [bullseye] - curl <not-affected> (Vulnerable code introduced in 7.81.0; bullseye ships 7.74.0)
NOTE: https://curl.se/docs/CVE-2026-12064.html
NOTE: Introduced with: https://github.com/curl/curl/commit/18270893abdb19f0ca170c118f8a2847dbd304be (curl-7_81_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/ab3bb8cd8be8f9d4acb97da0418abc279182041e (rc-8_21_0-3, curl-8_21_0)
@@ -642739,6 +642771,8 @@ CVE-2019-16229 (drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5
CVE-2019-16228 (An issue was discovered in py-lmdb 0.97. There is a divide-by-zero err ...)
- lmdb <unfixed> (bug #1141312)
[trixie] - lmdb <no-dsa> (Minor issue)
+ [bookworm] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
+ [bullseye] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
- py-lmdb <unfixed> (bug #1132719; unimportant)
NOTE: src:py-lmdb uses system version of liblmdb
NOTE: https://github.com/jnwatson/py-lmdb/issues/210
@@ -642746,6 +642780,8 @@ CVE-2019-16228 (An issue was discovered in py-lmdb 0.97. There is a divide-by-ze
CVE-2019-16227 (An issue was discovered in py-lmdb 0.97. For certain values of mn_flag ...)
- lmdb <unfixed> (bug #1141312)
[trixie] - lmdb <no-dsa> (Minor issue)
+ [bookworm] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
+ [bullseye] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
- py-lmdb <unfixed> (bug #1132719; unimportant)
NOTE: src:py-lmdb uses system version of liblmdb
NOTE: https://github.com/jnwatson/py-lmdb/issues/210
@@ -642753,6 +642789,8 @@ CVE-2019-16227 (An issue was discovered in py-lmdb 0.97. For certain values of m
CVE-2019-16226 (An issue was discovered in py-lmdb 0.97. mdb_node_del does not validat ...)
- lmdb <unfixed> (bug #1141312)
[trixie] - lmdb <no-dsa> (Minor issue)
+ [bookworm] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
+ [bullseye] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
- py-lmdb <unfixed> (bug #1132719; unimportant)
NOTE: src:py-lmdb uses system version of liblmdb
NOTE: https://github.com/jnwatson/py-lmdb/issues/210
@@ -642760,6 +642798,8 @@ CVE-2019-16226 (An issue was discovered in py-lmdb 0.97. mdb_node_del does not v
CVE-2019-16225 (An issue was discovered in py-lmdb 0.97. For certain values of mp_flag ...)
- lmdb <unfixed> (bug #1141312)
[trixie] - lmdb <no-dsa> (Minor issue)
+ [bookworm] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
+ [bullseye] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
- py-lmdb <unfixed> (bug #1132719; unimportant)
NOTE: src:py-lmdb uses system version of liblmdb
NOTE: https://github.com/jnwatson/py-lmdb/issues/210
@@ -642767,6 +642807,8 @@ CVE-2019-16225 (An issue was discovered in py-lmdb 0.97. For certain values of m
CVE-2019-16224 (An issue was discovered in py-lmdb 0.97. For certain values of md_flag ...)
- lmdb <unfixed> (bug #1141312)
[trixie] - lmdb <no-dsa> (Minor issue)
+ [bookworm] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
+ [bullseye] - lmdb <postponed> (Minor issue; only reachable via attacker-supplied/corrupted LMDB database file; unfixed upstream)
- py-lmdb <unfixed> (bug #1132719; unimportant)
NOTE: src:py-lmdb uses system version of liblmdb
NOTE: https://github.com/jnwatson/py-lmdb/issues/210
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0fb5f7c0d4bcd97009727268e60dcca34420c93d...30119240530fdc8251accb8664553efeeaae3ddf
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0fb5f7c0d4bcd97009727268e60dcca34420c93d...30119240530fdc8251accb8664553efeeaae3ddf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260712/098877cf/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list