[Git][security-tracker-team/security-tracker][master] 3 commits: lts: rsyslog postponed in bookworm/bullseye (CVE-2026-61548)
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Wed Jul 22 00:02:12 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dcfa620c by Utkarsh Gupta at 2026-07-22T03:56:14+05:30
lts: rsyslog postponed in bookworm/bullseye (CVE-2026-61548)
- - - - -
e1689d24 by Utkarsh Gupta at 2026-07-22T04:12:14+05:30
lts: hdf5 postponed in bookworm/bullseye (CVE-2026-26199)
- - - - -
ed71dc8d by Utkarsh Gupta at 2026-07-22T04:16:21+05:30
dla-needed: extend python-tornado to bullseye
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -814,6 +814,8 @@ CVE-2026-56452 (Path traversal in the sshd-scp component of Apache MINA SSHD.Apa
CVE-2026-61548 [rsyslog mmpstrucdata stack overflow]
- rsyslog 8.2606.0-4
[trixie] - rsyslog <no-dsa> (Minor issue; can be fixed in a point release)
+ [bookworm] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs module loaded + oversized RFC5424 structured-data)
+ [bullseye] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs module loaded + oversized RFC5424 structured-data)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/1
NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-8qmr-c66f-g368
NOTE: Fixed in major cleanup and refactoring of mmpstrucdata:
@@ -1111,6 +1113,8 @@ CVE-2026-26483 (Mettle SendPortal 3.0.1 and earlier contains a stored cross-site
CVE-2026-26199 (HDF5 is a high-performance library and a file format specification tha ...)
- hdf5 <unfixed>
[trixie] - hdf5 <no-dsa> (Minor issue)
+ [bookworm] - hdf5 <postponed> (Minor issue; H5G_get_name buffer underflow only when caller passes size=0 to H5Iget_name)
+ [bullseye] - hdf5 <postponed> (Minor issue; H5G_get_name buffer underflow only when caller passes size=0 to H5Iget_name)
NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
TODO: isolate fixing commit
CVE-2026-26197 (HDF5 is a high-performance library and a file format specification tha ...)
=====================================
data/dla-needed.txt
=====================================
@@ -655,9 +655,11 @@ python-msgpack
python-oslo.messaging/bullseye
NOTE: 20260612: Added by Front-Desk (rouca)
--
-python-tornado/bookworm
+python-tornado
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: See also https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/322 (Beuc/front-desk)
+ NOTE: 20260722: Extend to bullseye; CVE-2026-49853/49854/49855 in 6.1.0 too,
+ NOTE: 20260722: shared with bookworm; fix in 6.5.6 (utkarsh/front-desk)
--
qemu
NOTE: 20260520: Added by Front-Desk (Beuc)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4ed36ba85c92dcf239b24ea7978088f20ba6b8f5...ed71dc8d1e276c85073517681853bffe23860a06
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4ed36ba85c92dcf239b24ea7978088f20ba6b8f5...ed71dc8d1e276c85073517681853bffe23860a06
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/67d8b7c8/attachment.htm>
More information about the debian-security-tracker-commits
mailing list