[Git][security-tracker-team/security-tracker][master] Reserve DLA-4686-1 for dhcpcd5

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Wed Jul 15 14:45:54 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4a5ade44 by Sylvain Beucler at 2026-07-15T15:45:39+02:00
Reserve DLA-4686-1 for dhcpcd5

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -17308,7 +17308,6 @@ CVE-2026-56114 (dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-b
 	[trixie] - dhcpcd 1:10.1.0-11+deb13u3
 	- dhcpcd5 <removed>
 	[bookworm] - dhcpcd5 9.4.1-24~deb12u5
-	[bullseye] - dhcpcd5 <postponed> (Minor issue; needs non-default IA_PD config + adjacent DHCPv6 server; 1-byte OOB, availability-only)
 	NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029
 CVE-2026-56113 (dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-af ...)
 	- dhcpcd 1:10.3.2-4 (bug #1140767)
@@ -22386,7 +22385,6 @@ CVE-2025-70102 (A NULL pointer dereference occurs in Roy Marples NetworkConfigur
 	[trixie] - dhcpcd 1:10.1.0-11+deb13u3
 	- dhcpcd5 <removed>
 	[bookworm] - dhcpcd5 9.4.1-24~deb12u5
-	[bullseye] - dhcpcd5 <postponed> (Minor issue; NULL deref only via malformed local dhcpcd.conf; not network-reachable)
 	NOTE: https://github.com/NetworkConfiguration/dhcpcd/issues/567
 	NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/117742d755b591764036dd4218f314f748a3d2b7 (v10.3.1)
 CVE-2025-69332 (Subscriber Broken Access Control in Bookify <= 1.1.1 versions.)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[15 Jul 2026] DLA-4686-1 dhcpcd5 - security update
+	{CVE-2025-70102 CVE-2026-56114}
+	[bullseye] - dhcpcd5 7.1.0-2+deb11u1
 [15 Jul 2026] DLA-4685-1 grub2 - security update
 	{CVE-2024-45774 CVE-2024-45775 CVE-2024-45776 CVE-2024-45777 CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45781 CVE-2024-45782 CVE-2024-45783 CVE-2025-0622 CVE-2025-0624 CVE-2025-0677 CVE-2025-0678 CVE-2025-0684 CVE-2025-0685 CVE-2025-0686 CVE-2025-0689 CVE-2025-0690 CVE-2025-1118 CVE-2025-1125}
 	[bullseye] - grub2 2.06-3~deb11u7


=====================================
data/dla-needed.txt
=====================================
@@ -134,11 +134,6 @@ cups (Thorsten Alteholz)
   NOTE: 20260615: bookworm also need the same fixes as bullseye. (charles)
   NOTE: 20260705: still trying to find a solution to fix a CVE without changing the functionality of lpadmin
 --
-dhcpcd5/bullseye (Sylvain Beucler)
-  NOTE: 20260715: Added by Front-Desk (Beuc)
-  NOTE: 20260715: Maintainer proposed an update (Beuc/front-desk)
-  NOTE: 20260715: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140767#42
---
 docker-registry/bullseye
   NOTE: 20260419: Added by Front-Desk (rouca)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4a5ade447aea94d550208934fc0446f4454041bb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4a5ade447aea94d550208934fc0446f4454041bb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260715/e7f8a653/attachment.htm>


More information about the debian-security-tracker-commits mailing list