[Git][security-tracker-team/security-tracker][master] 2 commits: lts: add git-lfs/bookworm libwebsockets/bookworm python-eventlet/bookworm

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Sat Jul 18 11:24:01 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ade9de80 by Sylvain Beucler at 2026-07-18T12:19:07+02:00
lts: add git-lfs/bookworm libwebsockets/bookworm python-eventlet/bookworm

- - - - -
7e63c070 by Sylvain Beucler at 2026-07-18T12:23:22+02:00
CVE-2026-55599/*phpseclib*: bookworm,bullseye postponed

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -19737,10 +19737,15 @@ CVE-2026-55599 (phpseclib is a PHP secure communications library. From 0.1.1 unt
 	{DLA-4670-1}
 	- php-phpseclib3 3.0.55-1
 	[trixie] - php-phpseclib3 <no-dsa> (Minor issue)
+	[bookworm] - php-phpseclib3 <postponed> (Minor issue, SSRF)
 	- php-phpseclib 2.0.55-1
 	[trixie] - php-phpseclib <no-dsa> (Minor issue)
+	[bookworm] - php-phpseclib <postponed> (Minor issue, SSRF)
+	[bullseye] - php-phpseclib <postponed> (Minor issue, SSRF)
 	- phpseclib 1.0.30-1
 	[trixie] - phpseclib <no-dsa> (Minor issue)
+	[bookworm] - phpseclib <postponed> (Minor issue, SSRF)
+	[bullseye] - phpseclib <postponed> (Minor issue, SSRF)
 	NOTE: https://github.com/phpseclib/phpseclib/security/advisories/GHSA-m557-wrgg-6rp4
 	NOTE: Fixed by: https://github.com/phpseclib/phpseclib/commit/0987dd98832b20fcdc223148c35e22de0f521de9 (3.0.54, 2.0.55, 1.0.30)
 CVE-2026-55409 (Filament is a collection of full-stack components for accelerated Lara ...)


=====================================
data/dla-needed.txt
=====================================
@@ -219,6 +219,10 @@ gimp
   NOTE: 20260709: PSP/PNM/PSD parser overflows CVE-2026-58379..58388 (crafted image); TIM-loader
   NOTE: 20260709: CVE-2026-59089 not-affected (GIMP 3.x-only).
 --
+git-lfs/bookworm
+  NOTE: 20260718: Added by Front-Desk (Beuc)
+  NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
+--
 glances/bullseye
   NOTE: 20260518: Added by Front-Desk (Beuc)
   NOTE: 20260518: Many postponed vulnerabilities piled-up (Beuc/front-desk)
@@ -403,6 +407,10 @@ libstb/bullseye
 libvncserver
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
+libwebsockets/bookworm
+  NOTE: 20260718: Added by Front-Desk (Beuc)
+  NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
+--
 libxmltok/bullseye
   NOTE: 20250421: Added by Front-Desk (ta)
   NOTE: 20250421: Also review all other expat CVEs. (bunk)
@@ -609,6 +617,10 @@ python-authlib (andrewsh)
   NOTE: 20260709: CVE-2026-41479 (<1.6.10) + CVE-2026-44681 (<=1.6.11); Debian 0.15.4/1.2.0 in range.
   NOTE: 20260709: See also https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/330
 --
+python-eventlet/bookworm
+  NOTE: 20260718: Added by Front-Desk (Beuc)
+  NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
+--
 python-httplib2 (eamanu)
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: CVE-2026-59939 (fixed 0.32.0); Debian <=0.20.4 affected.



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/04dda5656129887271caa7cf6cb34c46213d2f5a...7e63c07066eaf1b4f7ef6b69e48ab14c7936140a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/04dda5656129887271caa7cf6cb34c46213d2f5a...7e63c07066eaf1b4f7ef6b69e48ab14c7936140a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260718/47525572/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list