[Git][security-tracker-team/security-tracker][master] 2 commits: lts: pymdown-extensions postponed in bookworm (CVE-2023-32309)

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Tue Jul 21 17:11:41 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8a24c600 by Utkarsh Gupta at 2026-07-21T21:32:59+05:30
lts: pymdown-extensions postponed in bookworm (CVE-2023-32309)

- - - - -
c2736976 by Utkarsh Gupta at 2026-07-21T21:32:59+05:30
dla-needed: add chromium

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -377815,6 +377815,7 @@ CVE-2023-32955 (Improper neutralization of special elements used in an OS comman
 	NOT-FOR-US: Synology
 CVE-2023-32309 (PyMdown Extensions is a set of extensions for the `Python-Markdown` ma ...)
 	- pymdown-extensions 10.8.1-1
+	[bookworm] - pymdown-extensions <postponed> (pymdownx.snippets path traversal reachable only when Snippets is enabled on untrusted Markdown, discouraged upstream)
 	NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-jh85-wwv9-24hv
 	NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/b7bb4878d6017c03c8dc97c42d8d3bb6ee81db9d (10.0)
 CVE-2023-32308 (anuko timetracker is an open source time tracking system. Boolean-base ...)


=====================================
data/dla-needed.txt
=====================================
@@ -114,6 +114,10 @@ calibre/bullseye
   NOTE: 20260429: partial update (abhijith)
   NOTE: 20260430: Revisit when rest of the CVEs are fixed upstream (abhijith)
 --
+chromium/bookworm
+  NOTE: 20260721: Added by Front-Desk (utkarsh)
+  NOTE: 20260721: CVE-2026-15899 to CVE-2026-15905 fixed in 150.0.7871.128; bookworm at .124 (DLA-4687-1). Rebase.
+--
 ckeditor/bullseye
   NOTE: 20241002: Added by Front-Desk (Beuc)
   NOTE: 20241002: Multiple CVEs have been piling up (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5c8bc28d40b4bcbb1031364a6d56a4fd80bdc089...c27369762b4a154700c27452a3c29a6982cd87b4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/5c8bc28d40b4bcbb1031364a6d56a4fd80bdc089...c27369762b4a154700c27452a3c29a6982cd87b4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/ad3c8d1c/attachment.htm>


More information about the debian-security-tracker-commits mailing list