[Git][security-tracker-team/security-tracker][master] 2 commits: data/dla-needed.txt: Claim rtpengine/bookworm.

Chris Lamb (@lamby) lamby at debian.org
Mon Jul 20 21:13:58 BST 2026



Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b0c929fc by Chris Lamb at 2026-07-20T13:11:44-07:00
data/dla-needed.txt: Claim rtpengine/bookworm.

- - - - -
b99c747d by Chris Lamb at 2026-07-20T13:11:46-07:00
Reserve DLA-4690-1 for xz-utils

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -76411,7 +76411,6 @@ CVE-2026-34743 (XZ Utils provide a general-purpose data-compression library plus
 	- xz-utils 5.8.3-1 (bug #1132497)
 	[trixie] - xz-utils 5.8.1-1+deb13u1
 	[bookworm] - xz-utils 5.4.1-1+deb12u1
-	[bullseye] - xz-utils <postponed> (Minor issue)
 	NOTE: https://tukaani.org/xz/index-append-overflow.html
 	NOTE: Fixed by: https://github.com/tukaani-project/xz/commit/c8c22869e780ff57c96b46939c3d79ff99395f87 (v5.8.3)
 CVE-2026-5087 (PAGI::Middleware::Session::Store::Cookie versions through 0.001003 for ...)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[20 Jul 2026] DLA-4690-1 xz-utils - security update
+	{CVE-2026-34743}
+	[bullseye] - xz-utils 5.2.5-2.1~deb11u2
 [19 Jul 2026] DLA-4689-1 libnfs - security update
 	{CVE-2026-53689}
 	[bullseye] - libnfs 4.0.0-1+deb11u1


=====================================
data/dla-needed.txt
=====================================
@@ -676,7 +676,7 @@ rsync (Thorsten Alteholz)
   NOTE: 20260615: Requested by Sylvain to track regressions, same as in dsa-needed. (charles)
   NOTE: 20260705: making progress with updated patches
 --
-rtpengine/bookworm
+rtpengine/bookworm (Chris Lamb)
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
@@ -864,10 +864,6 @@ xrdp (Abhijith PA)
   NOTE: 20260418: Added by Front-Desk (rouca)
   NOTE: 20260706: Bookworm/Bullseye share the same version - fix in Bookworm first (dleidert/front-desk)
 --
-xz-utils/bullseye (Chris Lamb)
-  NOTE: 20260713: Added by Front-Desk (Beuc)
-  NOTE: 20260713: Follow bookworm 12.15 (CVE-2026-34743) (Beuc/front-desk)
---
 zabbix/bullseye
   NOTE: 20260328: Added by Front-Desk (Beuc)
   NOTE: 20260328: CVE-2026-23919->24 appear to be in supported scope (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4b7c689d140a0867938fa54498c6288679661f41...b99c747d76399afdd1ac1e3d949560e2259ea37b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4b7c689d140a0867938fa54498c6288679661f41...b99c747d76399afdd1ac1e3d949560e2259ea37b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/d09c2fca/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list