[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2026-14266: bookworm,bullseye postponed

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Fri Jul 17 20:28:42 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5b1c8557 by Sylvain Beucler at 2026-07-17T21:28:34+02:00
CVE-2026-14266: bookworm,bullseye postponed

- - - - -
2473e6ea by Sylvain Beucler at 2026-07-17T21:28:35+02:00
lts: add cyrus-imapd

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -251,6 +251,8 @@ CVE-2024-23564 (HCL Aftermarket EPC is affected by Business Logic Vulnerability
 CVE-2026-14266
 	- 7zip 26.02+dfsg-1 (bug #1142293)
 	- p7zip 16.02+transitional.1
+	[bookworm] - p7zip <postponed> (Wait for 7zip-26.02/trixie SPU approval, then backport)
+	[bullseye] - p7zip <postponed> (Wait for 7zip-26.02/trixie SPU approval, then backport)
 	NOTE: Since p7zip/16.02+transitional.1 src:p7zip is only an empty source package
 	NOTE: depending on 7zip. Mark this version as fixed version.
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/


=====================================
data/dla-needed.txt
=====================================
@@ -131,6 +131,10 @@ cups (Thorsten Alteholz)
   NOTE: 20260615: bookworm also need the same fixes as bullseye. (charles)
   NOTE: 20260705: still trying to find a solution to fix a CVE without changing the functionality of lpadmin
 --
+cyrus-imapd
+  NOTE: 20260717: Added by Front-Desk (Beuc)
+  NOTE: 20260717: Upcoming DSA (Beuc/front-desk)
+--
 docker-registry/bullseye
   NOTE: 20260419: Added by Front-Desk (rouca)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/24f97375835402e2468ea7a46c4ba6b04dd4c653...2473e6ea366311c7686acc618bf75678217b618c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/24f97375835402e2468ea7a46c4ba6b04dd4c653...2473e6ea366311c7686acc618bf75678217b618c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260717/3b787012/attachment.htm>


More information about the debian-security-tracker-commits mailing list