[Git][security-tracker-team/security-tracker][master] 11 commits: lts: triage fastdds in bookworm/bullseye

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Fri Jul 24 23:40:01 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
25be8f09 by Utkarsh Gupta at 2026-07-24T23:18:25+05:30
lts: triage fastdds in bookworm/bullseye

- - - - -
d3f09ca9 by Utkarsh Gupta at 2026-07-24T23:21:40+05:30
lts: triage jupyterhub in bookworm

- - - - -
f8c98d54 by Utkarsh Gupta at 2026-07-24T23:25:02+05:30
lts: kas postponed in bookworm/bullseye (CVE-2026-54548)

- - - - -
6eb64cfe by Utkarsh Gupta at 2026-07-24T23:28:20+05:30
lts: kcoreaddons postponed in bookworm/bullseye (CVE-2026-41526)

- - - - -
4101c104 by Utkarsh Gupta at 2026-07-24T23:31:45+05:30
lts: ldns postponed in bookworm/bullseye (CVE-2026-10846)

- - - - -
84b28e5a by Utkarsh Gupta at 2026-07-24T23:35:10+05:30
lts: lemonldap-ng postponed in bookworm/bullseye (CVE-2026-12804)

- - - - -
4169488c by Utkarsh Gupta at 2026-07-24T23:38:30+05:30
lts: triage liboauth2 in bookworm/bullseye

- - - - -
c9d29434 by Utkarsh Gupta at 2026-07-24T23:41:55+05:30
lts: triage libzypp in bookworm/bullseye

- - - - -
27067676 by Utkarsh Gupta at 2026-07-24T23:45:20+05:30
lts: triage mistune in bookworm/bullseye

- - - - -
f1f7eebd by Utkarsh Gupta at 2026-07-24T23:48:50+05:30
lts: neovim not-affected in bookworm/bullseye (CVE-2026-11487)

- - - - -
7e4a890e by Utkarsh Gupta at 2026-07-24T23:52:11+05:30
lts: nix not-affected in bookworm (CVE-2026-39860)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15453,47 +15453,65 @@ CVE-2026-59937 (pypdf is a free and open-source pure-python PDF library. Prior t
 CVE-2026-59930 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <postponed> (Minor issue)
+	[bullseye] - mistune <not-affected> (Directive system introduced after 0.8.4)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/c4093c4742ed0d10d9332fb8edb455869b7b581b (v3.3.0)
 CVE-2026-59929 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <postponed> (Minor issue)
+	[bullseye] - mistune <postponed> (Minor issue)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-qfrw-5rxm-mhh2
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc (v3.3.0)
 CVE-2026-59928 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
+	[bullseye] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69 (v3.3.0)
 CVE-2026-59927 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <postponed> (Minor issue)
+	[bullseye] - mistune <not-affected> (Directive system introduced after 0.8.4)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-8mpj-m6qm-5qr8
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993 (v3.3.0)
 CVE-2026-59926 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <not-affected> (Admonition :class: option introduced in 3.x)
+	[bullseye] - mistune <not-affected> (Admonition :class: option introduced in 3.x)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-g97x-gvcm-x72h
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2 (v3.2.1)
 CVE-2026-59925 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
+	[bullseye] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f (v3.3.0)
 CVE-2026-59924 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <postponed> (Minor issue)
+	[bullseye] - mistune <not-affected> (Directive system introduced after 0.8.4)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993 (v3.3.0)
 CVE-2026-59923 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <postponed> (Minor issue)
+	[bullseye] - mistune <postponed> (Minor issue)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc (v3.3.0)
 CVE-2026-59922 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
+	[bullseye] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq
 	NOTE: Fixed by: https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7 (v3.3.0)
 CVE-2026-59897 (Hono is a Web application framework that provides support for any Java ...)
@@ -16787,46 +16805,68 @@ CVE-2024-56141 (Minosoft is an open-source, multi-version Minecraft Java Edition
 CVE-2026-49861
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-53589
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <not-affected> (RTPSEndpointQos deserializer introduced upstream in 3.2)
+	[bullseye] - fastdds <not-affected> (RTPSEndpointQos deserializer introduced upstream in 3.2)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-45098
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-49862
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <not-affected> (regex-based IPLocator::isIPv4 introduced after 2.1.0)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-55063
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-49863
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-53588
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-53590
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-45096
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104 (v3.6.2)
 CVE-2026-45095
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104 (v3.6.2)
 CVE-2026-45094
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104 (v3.6.2)
 CVE-2026-59089 (A flaw was found in GIMP. The PlayStation TIM loader, responsible for  ...)
 	- gimp <unfixed>
@@ -18442,10 +18482,14 @@ CVE-2026-54886 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerabi
 CVE-2026-54431 (In liboauth2 the Demonstrating Proof-of-Possession (DPoP) verifier acc ...)
 	- liboauth2 2.3.0-1
 	[trixie] - liboauth2 <no-dsa> (Minor issue)
+	[bookworm] - liboauth2 <postponed> (Minor issue)
+	[bullseye] - liboauth2 <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/OpenIDC/liboauth2/commit/c0b57152ed6a0af33aeb04a60bd7f5bff5ab8800 (v2.3.0)
 CVE-2026-54430 (liboauth2 is vulnerable to Server-Side Request Forgery inoauth2_jose_j ...)
 	- liboauth2 2.3.0-1
 	[trixie] - liboauth2 <no-dsa> (Minor issue)
+	[bookworm] - liboauth2 <not-affected> (Vulnerable code introduced in 2.1.0)
+	[bullseye] - liboauth2 <not-affected> (Vulnerable code introduced in 2.1.0)
 	NOTE: Fixed by: https://github.com/OpenIDC/liboauth2/commit/347507ac5b51f48c2933bbe49b2ee07c2af4712b (v2.3.0)
 CVE-2026-54409 (A malicious actor with access to the network and under certain conditi ...)
 	NOT-FOR-US: UniFi
@@ -18496,7 +18540,10 @@ CVE-2026-49779 (Customer Path Traversal in Tax Exempt for WooCommerce <= 1.9.3 v
 CVE-2026-44941 (A relative path traversal in the "keyhint" option in repomd.xml parsin ...)
 	- libzypp 17.38.12-1
 	[trixie] - libzypp <no-dsa> (Minor issue)
+	[bookworm] - libzypp <not-affected> (keyhint support introduced in 17.26.0; absent in 17.25.7)
+	[bullseye] - libzypp <not-affected> (keyhint support introduced in 17.26.0; absent in 17.25.7)
 	NOTE: Fixed by: https://github.com/openSUSE/libzypp/commit/294b1bad442d089ca671c5c03adc8031e3b29e04 (17.38.12)
+	NOTE: Introduced with: https://github.com/openSUSE/libzypp/commit/beb0e764a86e7effc13cde04ff3db652c5c758a4 (17.26.0)
 CVE-2026-44935 (Missing validation of "valuesFrom" references in Helm Deployer of SUSE ...)
 	NOT-FOR-US: Rancher Fleet
 CVE-2026-42382 (Unauthenticated Local File Inclusion in Audrey <= 1.5 versions.)
@@ -22587,6 +22634,8 @@ CVE-2026-36848 (Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traver
 CVE-2026-25707 (A relative path traversal bug problem when processing repository metad ...)
 	- libzypp 17.38.11-1
 	[trixie] - libzypp <no-dsa> (Minor issue)
+	[bookworm] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized metadata paths present in 17.25.7)
+	[bullseye] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized metadata paths present in 17.25.7)
 	NOTE: https://github.com/openSUSE/libzypp/commit/f09feda7fca03c941218aab0bb161cc82b185b6b (17.38.10)
 CVE-2026-22078 (Because O+ Connect's IPC service does not authenticate clients, extern ...)
 	NOT-FOR-US: Oppo
@@ -25769,6 +25818,8 @@ CVE-2026-53131 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2026-54548
 	- kas 5.4-1
 	[trixie] - kas <no-dsa> (Minor issue)
+	[bookworm] - kas <postponed> (Minor issue)
+	[bullseye] - kas <postponed> (Minor issue)
 	NOTE: https://github.com/siemens/kas/security/advisories/GHSA-mv8m-v9v6-5f94
 CVE-2026-9787 (Quest NetVault Backup NVBULogDaemon Command Injection Remote Code Exec ...)
 	NOT-FOR-US: Quest
@@ -26379,6 +26430,8 @@ CVE-2026-49980 (Rclone is a command-line program to sync files and directories t
 CVE-2026-49851 (Mistune is a Python Markdown parser with renderers and plugins. Prior  ...)
 	- mistune <unfixed> (bug #1141770)
 	[trixie] - mistune <no-dsa> (Minor issue)
+	[bookworm] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
+	[bullseye] - mistune <not-affected> (Vulnerable parser construct introduced in 3.x rewrite)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p
 CVE-2026-49269 (Apple M1 GPUs retain register file data between compute shader dispatc ...)
 	NOT-FOR-US: Apple Silicon HW issue
@@ -29315,6 +29368,8 @@ CVE-2026-56229 (Capgo before 12.128.2 contains an authorization bypass vulnerabi
 CVE-2026-12804 (A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is ...)
 	- lemonldap-ng <unfixed>
 	[trixie] - lemonldap-ng <no-dsa> (Minor issue)
+	[bookworm] - lemonldap-ng <postponed> (Minor issue; open redirect in rarely-used SAML CDC endpoint; fix in 2.23.1)
+	[bullseye] - lemonldap-ng <postponed> (Minor issue; open redirect in rarely-used SAML CDC endpoint; fix in 2.23.1)
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3619
 	NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/979
 CVE-2026-12799 (A security vulnerability has been detected in BerriAI litellm up to 1. ...)
@@ -30229,6 +30284,8 @@ CVE-2026-46580 (In Eclipse Theia versions prior to 1.71.0, files matching the pa
 CVE-2026-44942 (A path traversal in handling the "path" component of .repo files proce ...)
 	- libzypp 17.38.13-1
 	[trixie] - libzypp <no-dsa> (Minor issue)
+	[bookworm] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized .repo path= handling present in 17.25.7)
+	[bullseye] - libzypp <postponed> (Minor issue; requires attacker-controlled repo; unsanitized .repo path= handling present in 17.25.7)
 	NOTE: https://bugzilla.suse.com/show_bug.cgi?id=1267874
 CVE-2026-44691 (In Eclipse Theia versions prior to 1.69.0, custom task definitions in  ...)
 	NOT-FOR-US: Eclipse
@@ -35718,6 +35775,8 @@ CVE-2026-11799 (UXSS in Focus for iOS / Klar Webkit navigation. This vulnerabili
 CVE-2026-10846 (NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in ...)
 	- ldns 1.9.2-1 (bug #1139627)
 	[trixie] - ldns <no-dsa> (Minor issue)
+	[bookworm] - ldns <postponed> (Minor issue; off-path response spoofing only for apps using ldns as UDP stub resolver, e.g. drill; no addr/port/ID matching in ldns_udp_send_from)
+	[bullseye] - ldns <postponed> (Minor issue; off-path response spoofing only for apps using ldns as UDP stub resolver, e.g. drill; no addr/port/ID matching in ldns_udp_send_from)
 	NOTE: https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt
 CVE-2026-10238
 	REJECTED
@@ -38092,6 +38151,8 @@ CVE-2026-11488 (A vulnerability has been found in code-projects Simple Flight Ti
 CVE-2026-11487 (A flaw has been found in Neovim up to 0.12.2. Affected by this issue i ...)
 	- neovim 0.12.3-1 (bug #1139999)
 	[trixie] - neovim <no-dsa> (Minor issue)
+	[bookworm] - neovim <not-affected> (Vulnerable code not present; vim.secure added upstream in 0.9)
+	[bullseye] - neovim <not-affected> (Vulnerable code not present; vim.secure added upstream in 0.9)
 	NOTE: https://github.com/neovim/neovim/issues/39914
 	NOTE: https://github.com/neovim/neovim/pull/39918
 	NOTE: https://github.com/neovim/neovim/commit/f83e0dcaf8cf18de94828341b0a1a61a86c75baf (v0.12.3)
@@ -50027,6 +50088,7 @@ CVE-2026-41069 (libheif is a HEIF and AVIF file format decoder and encoder. In v
 CVE-2026-40864 (JupyterHub is software that allows users to create a multi-user server ...)
 	- jupyterhub <unfixed>
 	[trixie] - jupyterhub <no-dsa> (Minor issue)
+	[bookworm] - jupyterhub <not-affected> (Vulnerable Sec-Fetch-Mode handling introduced with the 4.1.0 XSRF rework)
 	NOTE: https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9
 	NOTE: Fixed by: https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117efa77bd941127 (5.4.5)
 CVE-2026-40610 (BentoML is a Python library for building online serving systems optimi ...)
@@ -66347,6 +66409,8 @@ CVE-2026-41602 (Integer Overflow or Wraparound vulnerability in Apache Thrift TF
 CVE-2026-41526 (In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safel ...)
 	- kcoreaddons 5.116.0-2 (bug #1135179)
 	[trixie] - kcoreaddons <no-dsa> (Minor issue)
+	[bookworm] - kcoreaddons <postponed> (Minor issue)
+	[bullseye] - kcoreaddons <postponed> (Minor issue)
 	- kf6-kcoreaddons 6.26.0-1 (bug #1135178)
 	[trixie] - kf6-kcoreaddons <no-dsa> (Minor issue)
 	NOTE: https://kde.org/info/security/advisory-20260427-1.txt
@@ -77815,6 +77879,7 @@ CVE-2025-14732 (The Elementor Website Builder \u2013 More Than Just a Page Build
 CVE-2026-39860 (Nix is a package manager for Linux and other Unix systems. A bug in th ...)
 	- nix 2.34.6+dfsg-1 (bug #1133004)
 	[trixie] - nix <no-dsa> (Minor issue)
+	[bookworm] - nix <not-affected> (Vulnerable code introduced by the CVE-2024-27297 fix in 2.21; that fix was never applied to 2.8.0)
 	[bullseye] - nix <postponed> (regresssion of postponed CVE-2024-27297; revisit when fixing CVE-2024-27297)
 	NOTE: https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj
 	NOTE: Introduced with: https://github.com/NixOS/nix/commit/a3163b9eabb952b4aa96e376dea95ebcca97b31a (2.21.0)
@@ -79567,6 +79632,7 @@ CVE-2026-34052 (LTI JupyterHub Authenticator is a JupyterHub authenticator for L
 CVE-2026-33709 (JupyterHub is software that allows one to create a multi-user server f ...)
 	- jupyterhub <unfixed> (bug #1132715)
 	[trixie] - jupyterhub <no-dsa> (Minor issue)
+	[bookworm] - jupyterhub <postponed> (Minor issue; open redirect requiring user interaction)
 	NOTE: https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-3vff-hjqv-m7h8
 CVE-2026-33184 (nimiq/core-rs-albatross is a Rust implementation of the Nimiq Proof-of ...)
 	NOT-FOR-US: nimiq/core-rs-albatross
@@ -126891,18 +126957,26 @@ CVE-2025-66845 (A reflected Cross-Site Scripting (XSS) vulnerability has been id
 CVE-2026-45097
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <not-affected> (xtypes DynamicDataImpl introduced in 3.0; 2.x ships legacy dynamic-types)
+	[bullseye] - fastdds <not-affected> (xtypes DynamicDataImpl introduced in 3.0; 2.x ships legacy dynamic-types)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284 (v3.6.2)
 CVE-2026-45092
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284 (v3.6.2)
 CVE-2026-45093
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284 (v3.6.2)
 CVE-2025-65865 (An integer overflow in eProsima Fast-DDS v3.3 allows attackers to caus ...)
 	- fastdds <unfixed> (bug #1141768)
 	[trixie] - fastdds <no-dsa> (Minor issue)
+	[bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
+	[bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, vulnerable code present)
 	NOTE: Fixed by: https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284 (v3.6.2)
 CVE-2025-65713 (Home Assistant Core before v2025.8.0 is vulnerable to Directory Traver ...)
 	NOT-FOR-US: Home Assistant Core



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee0457739c13ffbf0086719cc26a5f2225dbe7e3...7e4a890e49fd3b4131a905d5e5fd29b02e3115f7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee0457739c13ffbf0086719cc26a5f2225dbe7e3...7e4a890e49fd3b4131a905d5e5fd29b02e3115f7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/314abd11/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list