[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2026-59203/pillow: bookworm,bullseye not-affected + introductory commit

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Wed Jul 15 20:01:42 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8185b132 by Sylvain Beucler at 2026-07-15T20:58:08+02:00
CVE-2026-59203/pillow: bookworm,bullseye not-affected + introductory commit

- - - - -
96ff55ff by Sylvain Beucler at 2026-07-15T21:01:20+02:00
CVE-2026-49981/php-twig: replicate bookworm triage from CVE-2026-46636

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -155,9 +155,12 @@ CVE-2026-59204 (Pillow is a Python imaging library. From 8.2.0 through 12.2.0, s
 CVE-2026-59203 (Pillow is a Python imaging library. From 12.0.0 through 12.2.0, Pillow ...)
 	- pillow <unfixed>
 	[trixie] - pillow <not-affected> (Vulnerable code not present)
+	[bookworm] - pillow <not-affected> (BeginBinary support introduced in v12.0.0)
+	[bullseye] - pillow <not-affected> (BeginBinary support introduced in v12.0.0)
 	NOTE: https://github.com/python-pillow/Pillow/security/advisories/GHSA-pg7v-jwj7-p798
 	NOTE: https://github.com/python-pillow/Pillow/pull/9708
 	NOTE: Fixed by: https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83 (12.3.0)
+	NOTE: Introduced by: https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83 (12.0.0)
 CVE-2026-59200 (Pillow is a Python imaging library. From 5.1.0 until 12.3.0, PdfParser ...)
 	- pillow <unfixed>
 	NOTE: https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565
@@ -1236,6 +1239,7 @@ CVE-2026-4017 (Buffer Overflow in the entry handler of the TraceEvent() system c
 CVE-2026-49981 (Twig is a template language for PHP. Prior to 3.27.0, the per-template ...)
 	- php-twig 3.27.0-1
 	[trixie] - php-twig 3.27.0-0+deb13u1
+	[bookworm] - php-twig <ignored> (Minor issue, too intrusive to backport)
 	NOTE: https://github.com/twigphp/Twig/security/advisories/GHSA-529h-vh3j-85hq
 	NOTE: https://github.com/twigphp/Twig/commit/23eb6eb1267cb0d303b91eb5cff9b0c559c538a4 (v3.27.0)
 	NOTE: Duplicate of CVE-2026-46636



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37b8b4c376bc5858cccca75b0ddb9cd55a780f7d...96ff55ff9cca090e536d65595331ea2e02f5f1cf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37b8b4c376bc5858cccca75b0ddb9cd55a780f7d...96ff55ff9cca090e536d65595331ea2e02f5f1cf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260715/6f54a471/attachment.htm>


More information about the debian-security-tracker-commits mailing list