[Git][security-tracker-team/security-tracker][master] 2 commits: lts: add freerdp2/bookworm
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Mon Jul 13 10:51:25 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f05be437 by Sylvain Beucler at 2026-07-13T11:38:37+02:00
lts: add freerdp2/bookworm
- - - - -
0b023903 by Sylvain Beucler at 2026-07-13T11:50:49+02:00
CVE-2026-34743/xz-utils: fix bookworm version
Error from initial OSPU, cf. https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140801#57
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -68265,7 +68265,7 @@ CVE-2026-5292 (Out of bounds read in WebCodecs in Google Chrome prior to 146.0.7
CVE-2026-34743 (XZ Utils provide a general-purpose data-compression library plus comma ...)
- xz-utils 5.8.3-1 (bug #1132497)
[trixie] - xz-utils 5.8.1-1+deb13u1
- [bookworm] - xz-utils 5.4.1-2+deb12u1
+ [bookworm] - xz-utils 5.4.1-1+deb12u1
[bullseye] - xz-utils <postponed> (Minor issue)
NOTE: https://tukaani.org/xz/index-append-overflow.html
NOTE: Fixed by: https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 (v5.8.3)
=====================================
data/dla-needed.txt
=====================================
@@ -179,9 +179,10 @@ flatpak/bullseye
fontforge/bullseye
NOTE: 20260216: Added by Front-Desk (rouca)
--
-freerdp2/bullseye
+freerdp2
NOTE: 20260127: Added by Front-Desk (Beuc)
NOTE: 20260127: Many CVEs fixed in 3.20.1 and 3.21, but missing fix commits (Beuc/front-desk)
+ NOTE: 20260713: Also add for bookworm-lts (Beuc/front-desk)
--
frr/bullseye
NOTE: 20251102: Added by Front-Desk (apo)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3251abe0549eac0ed8ea1b11f122e3195ea08643...0b023903790d4fad6e5815c4e21a9f292ff9b423
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3251abe0549eac0ed8ea1b11f122e3195ea08643...0b023903790d4fad6e5815c4e21a9f292ff9b423
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260713/c87817f1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list