[Git][security-tracker-team/security-tracker][master] 6 commits: dla-needed: extend docker-registry to bookworm
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sat Jul 25 00:25:41 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
91725139 by Utkarsh Gupta at 2026-07-25T04:53:24+05:30
dla-needed: extend docker-registry to bookworm
- - - - -
11f13ecd by Utkarsh Gupta at 2026-07-25T04:53:24+05:30
dla-needed: extend ldap-account-manager to bookworm
- - - - -
e037e9df by Utkarsh Gupta at 2026-07-25T04:53:24+05:30
dla-needed: extend libcryptx-perl to bookworm
- - - - -
037bdc60 by Utkarsh Gupta at 2026-07-25T04:53:24+05:30
dla-needed: add lrzip for bookworm
- - - - -
e5468e54 by Utkarsh Gupta at 2026-07-25T04:53:24+05:30
dla-needed: add python-geopandas for bookworm
- - - - -
1397cb3f by Utkarsh Gupta at 2026-07-25T04:53:25+05:30
lts: libretro-snes9x ignored in bookworm/bullseye (CVE-2026-39199)
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -30876,6 +30876,8 @@ CVE-2026-39442 (Unauthenticated PHP Object Injection in PressMart <= 1.2.26 vers
CVE-2026-39199 (snes9x 1.63 allows an out-of-bounds write and denial of service via a ...)
- libretro-snes9x 1.63+dfsg-2 (bug #1140481)
[trixie] - libretro-snes9x <no-dsa> (non-free not supported)
+ [bookworm] - libretro-snes9x <ignored> (Non-free not supported)
+ [bullseye] - libretro-snes9x <ignored> (Non-free not supported)
NOTE: https://karansaini.com/snes9x-oob-write/
NOTE: https://github.com/snes9xgit/snes9x/issues/1035
NOTE: https://github.com/snes9xgit/snes9x/commit/96b366100172723f6314c40e237b370f4f7b59f4
=====================================
data/dla-needed.txt
=====================================
@@ -153,8 +153,11 @@ cyrus-imapd
NOTE: 20260717: Added by Front-Desk (Beuc)
NOTE: 20260717: Upcoming DSA (Beuc/front-desk)
--
-docker-registry/bullseye
+docker-registry
NOTE: 20260419: Added by Front-Desk (rouca)
+ NOTE: 20260725: Also add for bookworm (2.8.2); CVE-2026-33540 proxyauth.go
+ NOTE: 20260725: realm handling identical to bullseye. CVE-2026-41888 is
+ NOTE: 20260725: not-affected there (tag-delete code is 3.0.0+). (utkarsh/front-desk)
--
docker.io
NOTE: 20250805: Added by Front-Desk (rouca)
@@ -327,8 +330,10 @@ knot-resolver/bullseye
NOTE: 20250104: still waiting to hear back. will upload to debusine for extra pipelines to run. (utkarsh)
NOTE: 20250119: still waiting to hear back. (utkarsh)
--
-ldap-account-manager/bullseye
+ldap-account-manager
NOTE: 20260418: Added by Front-Desk (rouca)
+ NOTE: 20260725: Also add for bookworm (8.3); CVE-2026-27894 PDF-export LFI,
+ NOTE: 20260725: unvalidated pdf_structure/pdf_font identical to bullseye. (utkarsh/front-desk)
--
libass
NOTE: 20260712: Added by Front-Desk (utkarsh)
@@ -343,8 +348,11 @@ libcrypt-pbkdf2-perl
NOTE: 20260612: Added by Front-Desk (rouca)
NOTE: 20260613: you MUST follow #1139897 and coordinate (rouca/FD)
--
-libcryptx-perl/bullseye
+libcryptx-perl
NOTE: 20260531: Added by Front-Desk (dleidert)
+ NOTE: 20260725: Also add for bookworm (0.077); CVE-2026-41565 unclamped AEAD
+ NOTE: 20260725: tag Copy and CVE-2026-13758 memNE both present. Sponsored in
+ NOTE: 20260725: both suites. (utkarsh/front-desk)
--
libde265
NOTE: 20260709: Added by Front-Desk (utkarsh)
@@ -438,6 +446,13 @@ libxslt/bullseye
linux (Ben Hutchings)
NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
--
+lrzip/bookworm
+ NOTE: 20260725: Added by Front-Desk (utkarsh)
+ NOTE: 20260725: CVE-2025-15570; fixed in bullseye via DLA-4567-1. bookworm
+ NOTE: 20260725: 0.651-2 has the same UAF (thread_count guard absent); fix is
+ NOTE: 20260725: upstream 96931e70 (0.660). Should be fixed for trixie too,
+ NOTE: 20260725: which still ships an affected 0.651-3. (utkarsh/front-desk)
+--
lxml
NOTE: 20260614: Added by Front-Desk (rouca)
--
@@ -645,6 +660,14 @@ python-eventlet/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
--
+python-geopandas/bookworm
+ NOTE: 20260725: Added by Front-Desk (utkarsh)
+ NOTE: 20260725: CVE-2025-69662; fixed in bullseye via DLA-4523-1. bookworm
+ NOTE: 20260725: 0.12.2-1 still builds the Find_SRID query with .format(); fix
+ NOTE: 20260725: is upstream 81214bf9 (1.1.2), one hunk in geopandas/io/sql.py.
+ NOTE: 20260725: Should be fixed for trixie too, which still ships an
+ NOTE: 20260725: affected 1.0.1-2. (utkarsh/front-desk)
+--
python-httplib2 (eamanu)
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-59939 (fixed 0.32.0); Debian <=0.20.4 affected.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a4120670cdefdb7889db04e07ec9cec7bc95b125...1397cb3fcbd8f3f4b22c57851c60ee7d6b5fed56
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/a4120670cdefdb7889db04e07ec9cec7bc95b125...1397cb3fcbd8f3f4b22c57851c60ee7d6b5fed56
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/b0cc9854/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list