[Git][security-tracker-team/security-tracker][master] 17 commits: lts: golang-1.19 not-affected in bookworm (CVE-2026-42505, CVE-2026-39822)
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sun Jul 12 04:13:12 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
03cd64c4 by Utkarsh Gupta at 2026-07-12T08:25:06+05:30
lts: golang-1.19 not-affected in bookworm (CVE-2026-42505, CVE-2026-39822)
- - - - -
efd20b4a by Utkarsh Gupta at 2026-07-12T08:25:07+05:30
lts: golang-github-cli-go-gh postponed in bookworm (CVE-2026-48501)
- - - - -
07e8df86 by Utkarsh Gupta at 2026-07-12T08:25:08+05:30
lts: golang-github-go-git-go-billy postponed in bookworm (CVE-2026-44973, CVE-2026-44740)
- - - - -
39dea7f8 by Utkarsh Gupta at 2026-07-12T08:25:09+05:30
lts: golang-github-go-git-go-git postponed in bookworm (CVE-2026-45571, CVE-2026-45570, CVE-2026-45022, CVE-2026-41506)
- - - - -
cc0effdd by Utkarsh Gupta at 2026-07-12T08:25:10+05:30
lts: golang-github-labstack-echo postponed in bookworm (CVE-2026-55677)
- - - - -
fb31396d by Utkarsh Gupta at 2026-07-12T08:25:11+05:30
lts: golang-github-pion-dtls.v2 postponed in bookworm (CVE-2026-54908)
- - - - -
e44a7125 by Utkarsh Gupta at 2026-07-12T08:25:12+05:30
lts: golang-golang-x-image postponed in bookworm (CVE-2026-42500)
- - - - -
1e381bdc by Utkarsh Gupta at 2026-07-12T08:25:13+05:30
lts: golang-golang-x-net postponed in bookworm (6 CVEs)
- - - - -
a311f4f7 by Utkarsh Gupta at 2026-07-12T08:25:14+05:30
lts: golang-go.crypto postponed in bookworm (13 CVEs)
- - - - -
9dc1d322 by Utkarsh Gupta at 2026-07-12T08:25:30+05:30
lts: jython not-affected in bookworm (CVE-2026-4360)
- - - - -
f3a799d9 by Utkarsh Gupta at 2026-07-12T08:25:31+05:30
lts: rust-tar postponed in bookworm (CVE-2026-33056, CVE-2026-33055)
- - - - -
65907e9b by Utkarsh Gupta at 2026-07-12T08:25:33+05:30
lts: rustc postponed in bookworm (CVE-2026-33056, CVE-2026-33055)
- - - - -
e30029b6 by Utkarsh Gupta at 2026-07-12T08:32:08+05:30
lts: rust RUSTSEC issues postponed in bookworm (14 entries)
- - - - -
6284fc7f by Utkarsh Gupta at 2026-07-12T08:32:25+05:30
lts: lxd end-of-life in bookworm (28 CVEs)
- - - - -
d5f0aa12 by Utkarsh Gupta at 2026-07-12T08:32:27+05:30
lts: wolfssl end-of-life in bookworm (24 CVEs)
- - - - -
c17cb4f3 by Utkarsh Gupta at 2026-07-12T08:32:30+05:30
lts: php-horde-imp end-of-life in bookworm (CVE-2026-58451)
- - - - -
ae5ec562 by Utkarsh Gupta at 2026-07-12T08:32:32+05:30
lts: php-horde-vfs end-of-life in bookworm (CVE-2026-60102)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1868,6 +1868,7 @@ CVE-2026-60124 (An authorization bypass in MISP\u2019s EventsController::importM
NOT-FOR-US: MISP
CVE-2026-60102 (Horde Virtual File System (VFS) API before 3.0.1 contains an OS comman ...)
- php-horde-vfs <unfixed>
+ [bookworm] - php-horde-vfs <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/horde/Vfs/pull/10
NOTE: https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361 (v3.0.1)
CVE-2026-60092 (AVideo (Meet plugin) through commit e8d6119f3cb1b849149906efeb0a41fc02 ...)
@@ -2712,6 +2713,7 @@ CVE-2026-39822 (On Unix systems, opening a file in an os.Root improperly follows
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
+ [bookworm] - golang-1.19 <not-affected> (os.Root API introduced in Go 1.24; absent in 1.19)
- golang-1.15 <not-affected> (Vulnerable code introduced later)
NOTE: golang-1.15: os.Root API introduced in Go 1.24 (go.dev/doc/go1.24); absent in 1.15
NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
@@ -2725,6 +2727,7 @@ CVE-2026-42505 (Handshakes which used Encrypted Client Hello could be de-anonymi
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
+ [bookworm] - golang-1.19 <not-affected> (crypto/tls client ECH introduced in Go 1.23; absent in 1.19)
- golang-1.15 <not-affected> (Vulnerable code introduced later)
NOTE: golang-1.15: crypto/tls client Encrypted Client Hello introduced in Go 1.23 (issue #63369); absent in 1.15
NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
@@ -3430,15 +3433,18 @@ CVE-2024-6228 (The Notifications for Forms & WordPress Actions WordPress plugin
CVE-2026-XXXX [RUSTSEC-2026-0190]
- rust-anyhow <unfixed> (bug #1141593)
[trixie] - rust-anyhow <no-dsa> (Minor issue)
+ [bookworm] - rust-anyhow <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0190.html
NOTE: https://github.com/dtolnay/anyhow/issues/451
CVE-2026-XXXX [RUSTSEC-2026-0193]
- rust-ammonia <unfixed> (bug #1141594)
[trixie] - rust-ammonia <no-dsa> (Minor issue)
+ [bookworm] - rust-ammonia <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0193.html
CVE-2026-XXXX [RUSTSEC-2026-0194]
- rust-quick-xml <unfixed> (bug #1141595)
[trixie] - rust-quick-xml <no-dsa> (Minor issue)
+ [bookworm] - rust-quick-xml <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0194.html
NOTE: https://github.com/tafia/quick-xml/issues/969
NOTE: https://github.com/tafia/quick-xml/pull/971
@@ -3456,6 +3462,7 @@ CVE-2026-13705 (Imager versions before 1.032 for Perl have a heap out-of-bounds
CVE-2026-XXXX [RUSTSEC-2026-0195]
- rust-quick-xml <unfixed> (bug #1141588)
[trixie] - rust-quick-xml <no-dsa> (Minor issue)
+ [bookworm] - rust-quick-xml <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0195.html
NOTE: https://github.com/tafia/quick-xml/issues/970
NOTE: https://github.com/tafia/quick-xml/commit/7ca25266e94987210daa864889ab15c9332c8a2a (v0.41.0)
@@ -3470,11 +3477,13 @@ CVE-2026-XXXX [RUSTSEC-2026-0199]
CVE-2026-XXXX [RUSTSEC-2026-0202]
- rust-cxx <unfixed> (bug #1141591)
[trixie] - rust-cxx <no-dsa> (Minor issue)
+ [bookworm] - rust-cxx <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0202.html
NOTE: https://github.com/dtolnay/cxx/issues/1729
CVE-2026-XXXX [RUSTSEC-2026-0166]
- rust-stackvector <unfixed> (bug #1141592)
[trixie] - rust-stackvector <no-dsa> (Minor issue)
+ [bookworm] - rust-stackvector <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0166.html
NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/3
NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/5
@@ -3842,6 +3851,7 @@ CVE-2025-13475 (In multi-tenanted deployments, the application consent managemen
CVE-2026-XXXX [RUSTSEC-2026-0185]
- rust-quinn-proto <unfixed> (bug #1141481)
[trixie] - rust-quinn-proto <no-dsa> (Minor issue)
+ [bookworm] - rust-quinn-proto <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0185.html
NOTE: https://github.com/quinn-rs/quinn/pull/2694
CVE-2026-XXXX [RUSTSEC-2026-0187]
@@ -3854,6 +3864,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0187]
CVE-2026-XXXX [RUSTSEC-2026-0186]
- rust-memmap2 <unfixed> (bug #1141479)
[trixie] - rust-memmap2 <no-dsa> (Minor issue)
+ [bookworm] - rust-memmap2 <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0186.html
NOTE: https://github.com/RazrFalcon/memmap2-rs/commit/cee7cf03a9ee095982a3c37b7aac8e3f68f1a00c (v0.9.11)
CVE-2026-53360 (In the Linux kernel, the following vulnerability has been resolved: K ...)
@@ -4986,6 +4997,7 @@ CVE-2026-55153 (mchange-commons-java is a Java library of shared utility classes
CVE-2026-54908 (Pion DTLS is a Go implementation of Datagram Transport Layer Security. ...)
- golang-github-pion-dtls.v2 <unfixed> (bug #1141306)
[trixie] - golang-github-pion-dtls.v2 <no-dsa> (Minor issue)
+ [bookworm] - golang-github-pion-dtls.v2 <postponed> (Minor issue; remote DoS via crafted ServerKeyExchange)
- golang-github-pion-dtls-v3 <unfixed> (bug #1141307)
NOTE: https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j
NOTE: https://github.com/pion/dtls/pull/839
@@ -5376,6 +5388,7 @@ CVE-2026-58452 (JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.5770
CVE-2026-58451 (Horde IMP before 7.0.1 contains a path traversal vulnerability in lib/ ...)
- horde3 <removed>
- php-horde-imp <unfixed> (bug #1141341)
+ [bookworm] - php-horde-imp <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/horde/imp/pull/85
NOTE: Fixed by: https://github.com/horde/imp/commit/fba972fab72ee6871e5d56e6390bee38593085de (v7.0.1)
CVE-2026-58399 (@acastellon/auth is an authentication control system for microservices ...)
@@ -8062,6 +8075,7 @@ CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not pa
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- jython <unfixed>
[trixie] - jython <no-dsa> (Minor issue)
+ [bookworm] - jython <not-affected> (extraction filters/PEP 706 absent in bundled python2.7 stdlib; tarfile.extract() has no filter parameter)
[bullseye] - jython <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed> (bug #1141531)
[trixie] - pypy3 <no-dsa> (Minor issue)
@@ -9623,6 +9637,7 @@ CVE-2026-9699 (Mattermost Plugins versions <=11.6 10.18.11 11.3.6 11.6.5.0 fail
CVE-2026-9640 (A privilege escalation vulnerability exists in LXD from 6.0 before 6.9 ...)
{DSA-6373-1}
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-ppq7-4492-5552
NOTE: https://github.com/canonical/lxd/pull/18301
NOTE: https://github.com/canonical/lxd/pull/18303
@@ -9630,6 +9645,7 @@ CVE-2026-9640 (A privilege escalation vulnerability exists in LXD from 6.0 befor
CVE-2026-9639 (Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to v ...)
{DSA-6373-1}
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-j93m-3j9p-m5m8
NOTE: https://github.com/canonical/lxd/pull/18320
NOTE: https://github.com/canonical/lxd/pull/18390
@@ -9913,6 +9929,7 @@ CVE-2026-55686 (Podman is a tool for managing OCI containers and pods. From 3.0.
CVE-2026-55677 (Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router a ...)
- golang-github-labstack-echo <unfixed> (bug #1141444)
[trixie] - golang-github-labstack-echo <no-dsa> (Minor issue)
+ [bookworm] - golang-github-labstack-echo <postponed> (Minor issue; encoded-slash %2F static route bypass)
- golang-github-labstack-echo.v3 <removed>
[bullseye] - golang-github-labstack-echo.v3 <postponed> (Minor issue; limited/case-by-case golang support, no upstream v3 fix)
- golang-github-labstack-echo.v2 <removed>
@@ -10033,6 +10050,7 @@ CVE-2026-2053 (The WSO2 API Manager's message flow component, when processing WS
CVE-2026-28385 (In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forg ...)
- lxd <removed>
[trixie] - lxd <postponed> (Fix along in future DSA)
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-3gq2-x4qg-p4g6
NOTE: https://github.com/canonical/lxd/pull/18462
CVE-2026-24547 (Unauthenticated Broken Access Control in SiteGround Email Marketing <= ...)
@@ -10121,6 +10139,7 @@ CVE-2026-8797 (An access control deficiency vulnerability exists in ExpressUpdat
CVE-2026-8720 (wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message when t ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10447 (v5.9.2-stable)
CVE-2026-8661 (Server-Side Cross-Site Scripting and Server-Side Request Forgery vulne ...)
NOT-FOR-US: Rapid7
@@ -10129,58 +10148,72 @@ CVE-2026-8380 (The Frontend File Manager Plugin WordPress plugin through 23.6 do
CVE-2026-7532 (iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is not defi ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10354 (v5.9.2-stable)
CVE-2026-7531 (Use-after-free in PQC hybrid key-share handling. This is an incomplete ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10327 (v5.9.2-stable)
CVE-2026-7511 (PKCS7_verify signer confusion allows forged signatures, where the sign ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6731 (X.509 name constraint bypass via the Subject Common Name when treated ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10223 (v5.9.2-stable)
CVE-2026-6681 (The PKCS#7 decode path ignores the caller-supplied output buffer size ...)
- wolfssl 5.9.2-1
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
CVE-2026-6679 (A heap buffer overflow could occur in the DTLS 1.3 ACK serialization p ...)
- wolfssl 5.9.2-1
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
CVE-2026-6678 (Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other R ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6450 (A CRL critical extension bypass exists in ParseCRL_Extensions where cr ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10239 (v5.9.2-stable)
CVE-2026-6412 (Certificate policy and RFC 8446 compliance concerns regarding the cont ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10222 (v5.9.2-stable)
CVE-2026-6331 (HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-le ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext comparison only compares half of the ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6329 (PKCS#12 MAC verification uses an attacker-controlled comparison length ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6325 (Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversiz ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10204 (v5.9.2-stable)
CVE-2026-6092 (When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fal ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10167 (v5.9.2-stable)
CVE-2026-57522 (Bitwarden Server before 2026.5.0 contains a JSON injection vulnerabili ...)
- bitwarden <itp> (bug #956836)
@@ -10193,18 +10226,22 @@ CVE-2026-56445 (The qrscp application's C-STORE handler uses a specific instance
CVE-2026-55964 (Chain intermediate CA:TRUE without keyCertSign accepted as a signing C ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55962 (TLS 1.3 post-handshake authentication (PHA) issue where a server could ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55960 (Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55958 (Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript buffer. In ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10705 (v5.9.2-stable)
CVE-2026-54479 (The WebSocket backend uses charging station identifiers to uniquely as ...)
NOT-FOR-US: Evoke
@@ -10368,18 +10405,21 @@ CVE-2026-48750
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-73hr-m85f-64v9
NOTE: https://github.com/canonical/lxd/pull/18590
CVE-2026-48751
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv
NOTE: https://github.com/canonical/lxd/pull/18604
CVE-2026-48752
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-vxp5-584q-c479
NOTE: https://github.com/lxc/incus/commit/cbefa31ae0da8fd96361178aed3a3c631e098fef (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18590
@@ -10387,6 +10427,7 @@ CVE-2026-48755
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-v6mj-8pf4-hhw4
NOTE: https://github.com/lxc/incus/commit/873a032a461df6b09b7586435b592873863a4e88 (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18597
@@ -10394,6 +10435,7 @@ CVE-2026-48769
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x
NOTE: https://github.com/lxc/incus/commit/46d6ef232186df5535c49ca9f3597cab381f9b86 (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18594
@@ -10401,6 +10443,7 @@ CVE-2026-55621
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-64f3-v33m-w89f
NOTE: https://github.com/lxc/incus/commit/2e01078366e2653712719dec82318e51c6d21b28 (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18603
@@ -10408,6 +10451,7 @@ CVE-2026-55622
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrg
NOTE: https://github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84eb (v7.2.0)
NOTE: https://github.com/canonical/lxd/pull/18603
@@ -10415,6 +10459,7 @@ CVE-2026-48749
{DSA-6373-1 DSA-6370-1}
- incus 7.0.0-5
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-2q3f-q5pq-g8wv
NOTE: https://github.com/canonical/lxd/pull/18590
CVE-2026-XXXX [ZSA-2026-12]
@@ -10454,14 +10499,17 @@ CVE-2026-6432 (Improper bounds validation in EmberZNet SDK versions 9.0.2 and ea
CVE-2026-6291 (Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypti ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6094 (Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing craf ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10128 (v5.9.2-stable)
CVE-2026-6091 (Partial-chain certificate verification may accept chains that terminat ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10170 (v5.9.2-stable)
CVE-2026-57700 (Unrestricted Upload of File with Dangerous Type vulnerability in Daan. ...)
NOT-FOR-US: WordPress plugin or theme
@@ -10628,10 +10676,12 @@ CVE-2026-56005 (Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.
CVE-2026-55967 (AES-GCM encryption/decryption with extremely large cumulative single m ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10709 (v5.9.2-stable)
CVE-2026-55961 (wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Minor issue)
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55895 (Vim is an open source, command line text editor. Prior to 9.2.0663, a ...)
- vim 2:9.2.0782-1 (bug #1140775)
@@ -16219,11 +16269,13 @@ CVE-2026-9692 (Mojolicious::Sessions::Storable versions through 0.05 for Perl ge
CVE-2026-XXXX [RUSTSEC-2026-0183]
- rust-git2 <unfixed>
[trixie] - rust-git2 <no-dsa> (Minor issue)
+ [bookworm] - rust-git2 <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0183.html
NOTE: https://github.com/rust-lang/git2-rs/pull/1250
CVE-2026-XXXX [RUSTSEC-2026-0184]
- rust-git2 <unfixed>
[trixie] - rust-git2 <no-dsa> (Minor issue)
+ [bookworm] - rust-git2 <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0184.html
NOTE: https://github.com/rust-lang/git2-rs/pull/1254
CVE-2026-50190
@@ -19496,6 +19548,7 @@ CVE-2026-11527 (Config::IniFiles versions before 3.001000 for Perl allow OS comm
CVE-2026-XXXX [RUSTSEC-2026-0178]
- rust-tokio-postgres <unfixed> (bug #1140013)
[trixie] - rust-tokio-postgres <no-dsa> (Minor issue)
+ [bookworm] - rust-tokio-postgres <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0178.html
NOTE: https://github.com/rust-postgres/rust-postgres/commit/7a00ffa9ad4d951ec0a4564b52f1780fa9d353c1 (tokio-postgres-v0.7.18)
CVE-2026-XXXX [RUSTSEC-2026-0176]
@@ -19829,16 +19882,19 @@ CVE-2026-XXXX [RUSTSEC-2026-0172]
CVE-2026-XXXX [RUSTSEC-2026-0180]
- rust-postgres-protocol 0.6.12-1 (bug #1139876)
[trixie] - rust-postgres-protocol <no-dsa> (Minor issue)
+ [bookworm] - rust-postgres-protocol <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0180.html
NOTE: https://github.com/rust-postgres/rust-postgres/commit/a7cf84b5c46431cbca9d8ff50508c23f446efa7d (postgres-protocol-v0.6.12)
CVE-2026-XXXX [RUSTSEC-2026-0179]
- rust-postgres-protocol 0.6.12-1 (bug #1139876)
[trixie] - rust-postgres-protocol <no-dsa> (Minor issue)
+ [bookworm] - rust-postgres-protocol <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0179.html
NOTE: https://github.com/rust-postgres/rust-postgres/commit/d40097a36a85068ea50a3afbf0ce154ba439e7f0 (postgres-protocol-v0.6.12)
CVE-2026-XXXX [RUSTSEC-2026-0177]
- rust-pyo3 <unfixed> (bug #1139875)
[trixie] - rust-pyo3 <no-dsa> (Minor issue)
+ [bookworm] - rust-pyo3 <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0177.html
NOTE: https://github.com/PyO3/pyo3/pull/6096
CVE-2026-9641 (Crypt::PBKDF2 versions before 0.261630 for Perl have a weak default al ...)
@@ -28393,6 +28449,7 @@ CVE-2026-45131 (CloudPirates Open Source Helm Charts is a collection of Helm cha
CVE-2026-44740 (Billy is an interface filesystem abstraction for Go. Prior to versions ...)
- golang-github-go-git-go-billy <unfixed>
[trixie] - golang-github-go-git-go-billy <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-billy <postponed> (Limited support, minor issue; DoS on malformed input)
- golang-github-go-git-go-billy-v6 <unfixed>
NOTE: https://github.com/go-git/go-billy/security/advisories/GHSA-m3xc-h892-ggx6
CVE-2026-44211 (Cline is an autonomous coding agent as an SDK, IDE extension, or CLI a ...)
@@ -29250,6 +29307,7 @@ CVE-2026-44285 (FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1,
CVE-2026-42500 (Decoding a paletted BMP file with an out-of-range palette index result ...)
- golang-golang-x-image 0.42.0-1 (bug #1138257)
[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-image <postponed> (Limited support, minor issue; BMP OOB read)
[bullseye] - golang-golang-x-image <no-dsa> (Minor issue)
NOTE: https://github.com/golang/go/issues/79576
NOTE: https://go-review.googlesource.com/c/image/+/781500
@@ -29377,6 +29435,7 @@ CVE-2026-48501 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Pri
[trixie] - golang-github-cli-go-gh-v2 <no-dsa> (Minor issue)
- golang-github-cli-go-gh <unfixed>
[trixie] - golang-github-cli-go-gh <no-dsa> (Minor issue)
+ [bookworm] - golang-github-cli-go-gh <postponed> (Limited support, minor issue; token leak to sibling *.github.com hosts)
NOTE: https://github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9
CVE-2026-47745 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admi ...)
NOT-FOR-US: Shopper
@@ -30402,6 +30461,7 @@ CVE-2026-45023 (AutoGPT is a workflow automation platform for creating, deployin
CVE-2026-44973 (Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, m ...)
- golang-github-go-git-go-billy <unfixed>
[trixie] - golang-github-go-git-go-billy <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-billy <postponed> (Limited support, minor issue; path traversal)
- golang-github-go-git-go-billy-v6 <unfixed>
NOTE: https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2
CVE-2026-44885 (Portainer Community Edition is a lightweight service delivery platform ...)
@@ -32157,11 +32217,13 @@ CVE-2026-45571 (go-git is an extensible git implementation library written in pu
- golang-github-go-git-go-git-v6 6.0.0~alpha4-1
- golang-github-go-git-go-git 5.19.1-1
[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, minor issue; path traversal)
NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96
CVE-2026-45570 (go-git is an extensible git implementation library written in pure Go. ...)
- golang-github-go-git-go-git-v6 6.0.0~alpha4-1
- golang-github-go-git-go-git 5.19.1-1
[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, minor issue; SSH argument quoting)
NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-m7cr-m3pv-hgrp
CVE-2026-45548 (Budibase is an open-source low-code platform. Prior to 3.34.8, the pro ...)
NOT-FOR-US: Budibase
@@ -32189,6 +32251,7 @@ CVE-2026-45022 (go-git is an extensible git implementation library written in pu
- golang-github-go-git-go-git-v6 6.0.0~alpha4-1
- golang-github-go-git-go-git 5.19.1-1
[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, minor issue; signature-verification bypass)
NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp
CVE-2026-44988 (LibVNCClient is a library for easy implementation of a VNC client. In ...)
- libvncserver 0.9.15+dfsg-5 (bug #1138174)
@@ -35974,12 +36037,14 @@ CVE-2026-42626 (HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not prope
CVE-2026-42506 (Parsing arbitrary HTML which is then rendered using Render can result ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor issue; html.Render output)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79571
CVE-2026-42502 (Parsing arbitrary HTML which is then rendered using Render can result ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor issue; html.Render output)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79572
@@ -36008,6 +36073,7 @@ CVE-2026-39964 (TypeBot is a chatbot builder tool. In versions prior to 3.16.0,
CVE-2026-39821 (The ToASCII and ToUnicode functions incorrectly accept Punycode-encode ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor issue; IDNA Punycode validation)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/78760
@@ -36035,18 +36101,21 @@ CVE-2026-28444 (Typebot is a chatbot builder tool. In versions 3.15.2 and prior,
CVE-2026-27136 (Parsing arbitrary HTML which is then rendered using Render can result ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor issue; html.Render output)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79575
CVE-2026-25681 (Parsing arbitrary HTML which is then rendered using Render can result ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor issue; html.Render output)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79574
CVE-2026-25680 (Parsing arbitrary HTML can consume excessive CPU time, possibly leadin ...)
- golang-golang-x-net 1:0.55.0-1
[trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-net <postponed> (Limited support, minor issue; html parse CPU DoS)
[bullseye] - golang-golang-x-net <postponed> (Limited support, minor issue)
NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
NOTE: https://github.com/golang/go/issues/79573
@@ -36202,18 +36271,21 @@ CVE-2026-47101 (LiteLLM prior to 1.83.14 allows an authenticated internal_user t
CVE-2026-46598 (For certain crafted inputs, a 'ed25519.PrivateKey' was created by cast ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79596
CVE-2026-46597 (An incorrectly placed cast from bytes to int allowed for server-side p ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79561
CVE-2026-46595 (Previously, CVE-2024-45337 fixed an authorization bypass for misused s ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79570
@@ -36222,6 +36294,7 @@ CVE-2026-44409 (There is an an information disclosure vulnerability in ZTE MU525
CVE-2026-42508 (Previously, a revoked 'SignatureKey' belonging to a CA was not correct ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79568
@@ -36230,54 +36303,63 @@ CVE-2026-3481 (The WP Blockade plugin for WordPress is vulnerable to Reflected C
CVE-2026-39835 (SSH servers which use CertChecker as a public key callback without set ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79563
CVE-2026-39834 (When writing data larger than 4GB in a single Write call on an SSH cha ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79567
CVE-2026-39833 (The in-memory keyring returned by NewKeyring() silently accepted keys ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79436
CVE-2026-39832 (When adding a key to a remote agent constraint extensions such as rest ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79435
CVE-2026-39831 (The Verify() method for FIDO/U2F security key types (sk-ecdsa-sha2-nis ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79566
CVE-2026-39830 (A malicious SSH peer could send unsolicited global request responses t ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79564
CVE-2026-39829 (The RSA and DSA public key parsers did not enforce size limits on key ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79565
CVE-2026-39828 (When an SSH server authentication callback returned PartialSuccessErro ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/79562
CVE-2026-39827 (An authenticated SSH client that repeatedly opened channels which were ...)
- golang-go.crypto 1:0.52.0-1 (bug #1137516)
[trixie] - golang-go.crypto <no-dsa> (Minor issue)
+ [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
[bullseye] - golang-go.crypto <postponed> (Limited support, follow bookworm DSAs/point-releases)
NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
NOTE: https://github.com/golang/go/issues/35127
@@ -43824,6 +43906,7 @@ CVE-2026-41506 (go-git is an extensible git implementation library written in pu
- golang-github-go-git-go-git-v6 6.0.0~alpha4-1
- golang-github-go-git-go-git 5.19.1-1 (bug #1136095)
[trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+ [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, minor issue; credential leak on cross-host redirect)
NOTE: https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963
NOTE: Fixed by: https://github.com/go-git/go-git/commit/bcd20a9c525826081262a06a9ed9c3167abfcd53 (v5.18.0)
CVE-2026-41497 (PraisonAI is a multi-agent teams system. Prior to version 4.6.9, the f ...)
@@ -49618,18 +49701,21 @@ CVE-2026-41685 (Incus is a system container and virtual machine manager. Prior t
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-98vh-x9cx-9cfp
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-41684 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-x5r6-jr56-89pv
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-41648 (Incus is a system container and virtual machine manager. Prior to vers ...)
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-67wx-r9xr-x75x
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-41647 (Incus is a system container and virtual machine manager. Prior to vers ...)
@@ -49641,6 +49727,7 @@ CVE-2026-40251 (Incus is a system container and virtual machine manager. In vers
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-4m88-wxj4-9qj6
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-40243 (Incus is a system container and virtual machine manager. In versions b ...)
@@ -49652,6 +49739,7 @@ CVE-2026-40197 (Incus is a system container and virtual machine manager. In vers
{DSA-6247-1 DSA-6244-1}
- incus 7.0.0-1 (bug #1135644)
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-r7w7-mmxr-47r9
NOTE: https://github.com/lxc/incus/pull/3273
CVE-2026-35527 (Incus is an open source container and virtual machine manager. In vers ...)
@@ -61860,6 +61948,7 @@ CVE-2026-34179 (In Canonical LXD versions 4.12 through 6.7, the doCertificateUpd
{DSA-6213-1 DSA-6212-1}
- incus 6.0.6-3
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-c3h3-89qf-jqm5
NOTE: https://github.com/canonical/lxd/pull/17936
NOTE: https://github.com/canonical/lxd/commit/8c0c8dcc0f7b6ef59524bfeae198b6081248a88d
@@ -61878,6 +61967,7 @@ CVE-2026-34177 (Canonical LXD versions 4.12 through 6.7 contain an incomplete de
{DSA-6213-1}
- incus 6.0.2-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-fm2x-c5qw-4h6f
NOTE: https://github.com/canonical/lxd/pull/17909
NOTE: https://github.com/canonical/lxd/commit/2f85d3ec0a6f9c9de8c003b81591ec173d489914
@@ -69340,6 +69430,7 @@ CVE-2026-33542 (Incus is a system container and virtual machine manager. Prior t
{DSA-6188-1 DSA-6184-1}
- incus 6.0.6-2
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/pull/3092
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-p8mm-23gg-jc9r
CVE-2026-33711 (Incus is a system container and virtual machine manager. Incus provide ...)
@@ -69358,6 +69449,7 @@ CVE-2026-33897 (Incus is a system container and virtual machine manager. Prior t
{DSA-6188-1 DSA-6184-1}
- incus 6.0.6-2
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/pull/3092
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-83xr-5xxr-mh92
CVE-2026-33898 (Incus is a system container and virtual machine manager. Prior to vers ...)
@@ -74344,9 +74436,11 @@ CVE-2026-33057 (Mesop is a Python-based UI framework that allows users to build
CVE-2026-33056 (tar-rs is a tar archive reading/writing library for Rust. In versions ...)
- rustc 1.92.0+dfsg1-2
[trixie] - rustc <no-dsa> (Minor issue)
+ [bookworm] - rustc <postponed> (Minor issue, parsing inconsistencies among tar libraries, requires recompiling rdeps)
[bullseye] - rustc <postponed> (Minor issue, parsing inconsistencies among tar libraries, requires recompiling rdeps)
- rust-tar 0.4.45-1 (bug #1131481)
[trixie] - rust-tar <no-dsa> (Minor issue)
+ [bookworm] - rust-tar <postponed> (Minor issue, parsing inconsistencies among tar libraries, requires recompiling rdeps)
[bullseye] - rust-tar <postponed> (Minor issue, parsing inconsistencies among tar libraries, requires recompiling rdeps)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0067.html
NOTE: https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph
@@ -74354,9 +74448,11 @@ CVE-2026-33056 (tar-rs is a tar archive reading/writing library for Rust. In ver
CVE-2026-33055 (tar-rs is a tar archive reading/writing library for Rust. Versions 0.4 ...)
- rustc 1.92.0+dfsg1-2 (bug #1135225)
[trixie] - rustc <no-dsa> (Minor issue)
+ [bookworm] - rustc <postponed> (Minor issue, path traversal, requires recompiling rdeps)
[bullseye] - rustc <postponed> (Minor issue, path traversal, requires recompiling rdeps)
- rust-tar 0.4.45-1 (bug #1131480)
[trixie] - rust-tar <no-dsa> (Minor issue)
+ [bookworm] - rust-tar <postponed> (Minor issue, path traversal, requires recompiling rdeps)
[bullseye] - rust-tar <postponed> (Minor issue, path traversal, requires recompiling rdeps)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0068.html
NOTE: https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-gchp-q4r4-x4ff
@@ -77695,6 +77791,7 @@ CVE-2026-28384 (An improper sanitization of the compression_algorithm parameter
{DSA-6188-1 DSA-6184-1}
- incus 6.0.6-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-4rmf-rcp8-2r9g
NOTE: https://github.com/canonical/lxd/pull/17820
NOTE: https://github.com/lxc/incus/pull/2972
@@ -99376,12 +99473,14 @@ CVE-2026-23954 (Incus is a system container and virtual machine manager. Version
{DSA-6153-1 DSA-6109-1}
- incus 6.0.5-8
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-7f67-crqm-jgh7
NOTE: https://github.com/canonical/lxd/commit/9a80e47b358e56fb2c9f7abad61b1d0ac654b6fa (lxd-5.0.6)
CVE-2026-23953 (Incus is a system container and virtual machine manager. In versions 6 ...)
{DSA-6153-1 DSA-6109-1}
- incus 6.0.5-8
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-x6jc-phwx-hp32
NOTE: https://github.com/canonical/lxd/commit/6343c2cb0c2c5d4057821f05094671bff032ede8 (lxd-5.0.6)
CVE-2024-31884
@@ -128690,6 +128789,7 @@ CVE-2025-64507 (Incus is a system container and virtual machine manager. An issu
- incus 6.0.5-4
- lxd <removed>
[trixie] - lxd 5.0.2+git20231211.1364ae4-9+deb13u2
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-56mx-8g9f-5crf
NOTE: https://github.com/lxc/incus/issues/2641
NOTE: Fixed by: https://github.com/lxc/incus/pull/2642
@@ -141458,6 +141558,7 @@ CVE-2025-54293 (Path Traversal in the log file retrieval function in Canonical L
{DSA-6028-1 DSA-6027-1}
- incus 6.0.5-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-472f-vmf2-pr3h
CVE-2025-54292 (Path traversal in Canonical LXD LXD-UI versions before 6.5 and 5.21.4 ...)
NOT-FOR-US: Canonical LXD LXD-UI (not bundled in src:lxd or src:incus)
@@ -141487,16 +141588,19 @@ CVE-2025-54288 (Information Spoofing in devLXD Server in Canonical LXD versions
{DSA-6028-1 DSA-6027-1}
- incus 6.0.5-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-7232-97c6-j525
CVE-2025-54287 (Template Injection in instance snapshot creation component in Canonica ...)
{DSA-6028-1 DSA-6027-1}
- incus 6.0.5-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-w2hg-2v4p-vmh6
CVE-2025-54286 (Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD versions ...)
{DSA-6028-1 DSA-6027-1}
- incus 6.0.5-1
- lxd <removed>
+ [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE: https://github.com/canonical/lxd/security/advisories/GHSA-p8hw-rfjg-689h
CVE-2025-54086 (CVE-2025-54086 is an excess permissions vulnerability in the Warehouse ...)
NOT-FOR-US: Absolute Software
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e4fd8128c65e1a07bd26a91d0df6d8871cefbef8...ae5ec5623d3865db6e731e5c7c511a9b413ddb2b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e4fd8128c65e1a07bd26a91d0df6d8871cefbef8...ae5ec5623d3865db6e731e5c7c511a9b413ddb2b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260712/22d9ad67/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list