[Git][security-tracker-team/security-tracker][master] 3 commits: lts: rsyslog postponed in bookworm/bullseye (CVE-2026-61548)

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Wed Jul 22 00:02:12 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dcfa620c by Utkarsh Gupta at 2026-07-22T03:56:14+05:30
lts: rsyslog postponed in bookworm/bullseye (CVE-2026-61548)

- - - - -
e1689d24 by Utkarsh Gupta at 2026-07-22T04:12:14+05:30
lts: hdf5 postponed in bookworm/bullseye (CVE-2026-26199)

- - - - -
ed71dc8d by Utkarsh Gupta at 2026-07-22T04:16:21+05:30
dla-needed: extend python-tornado to bullseye

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -814,6 +814,8 @@ CVE-2026-56452 (Path traversal in the sshd-scp component of Apache MINA SSHD.Apa
 CVE-2026-61548 [rsyslog mmpstrucdata stack overflow]
 	- rsyslog 8.2606.0-4
 	[trixie] - rsyslog <no-dsa> (Minor issue; can be fixed in a point release)
+	[bookworm] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs module loaded + oversized RFC5424 structured-data)
+	[bullseye] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs module loaded + oversized RFC5424 structured-data)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/1
 	NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-8qmr-c66f-g368
 	NOTE: Fixed in major cleanup and refactoring of mmpstrucdata:
@@ -1111,6 +1113,8 @@ CVE-2026-26483 (Mettle SendPortal 3.0.1 and earlier contains a stored cross-site
 CVE-2026-26199 (HDF5 is a high-performance library and a file format specification tha ...)
 	- hdf5 <unfixed>
 	[trixie] - hdf5 <no-dsa> (Minor issue)
+	[bookworm] - hdf5 <postponed> (Minor issue; H5G_get_name buffer underflow only when caller passes size=0 to H5Iget_name)
+	[bullseye] - hdf5 <postponed> (Minor issue; H5G_get_name buffer underflow only when caller passes size=0 to H5Iget_name)
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
 	TODO: isolate fixing commit
 CVE-2026-26197 (HDF5 is a high-performance library and a file format specification tha ...)


=====================================
data/dla-needed.txt
=====================================
@@ -655,9 +655,11 @@ python-msgpack
 python-oslo.messaging/bullseye
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
-python-tornado/bookworm
+python-tornado
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: See also https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/322 (Beuc/front-desk)
+  NOTE: 20260722: Extend to bullseye; CVE-2026-49853/49854/49855 in 6.1.0 too,
+  NOTE: 20260722: shared with bookworm; fix in 6.5.6 (utkarsh/front-desk)
 --
 qemu
   NOTE: 20260520: Added by Front-Desk (Beuc)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4ed36ba85c92dcf239b24ea7978088f20ba6b8f5...ed71dc8d1e276c85073517681853bffe23860a06

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4ed36ba85c92dcf239b24ea7978088f20ba6b8f5...ed71dc8d1e276c85073517681853bffe23860a06
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260721/67d8b7c8/attachment.htm>


More information about the debian-security-tracker-commits mailing list