[Git][security-tracker-team/security-tracker][master] 11 commits: lts: libcatalyst-plugin-authentication-perl postponed in bookworm/bullseye

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Sun Jul 26 00:17:47 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
84aa106a by Utkarsh Gupta at 2026-07-25T22:40:17+05:30
lts: libcatalyst-plugin-authentication-perl postponed in bookworm/bullseye

- - - - -
3a1e172a by Utkarsh Gupta at 2026-07-25T22:44:27+05:30
lts: libcrypt-dsa-perl postponed in bookworm/bullseye

- - - - -
d03d86f5 by Utkarsh Gupta at 2026-07-25T22:52:37+05:30
lts: triage libcss-minifier-xs-perl in bookworm/bullseye

- - - - -
08ae8a9e by Utkarsh Gupta at 2026-07-25T22:55:52+05:30
lts: libhttp-tiny-perl postponed in bookworm

- - - - -
6bfeb6ae by Utkarsh Gupta at 2026-07-25T23:03:02+05:30
lts: libimager-perl postponed in bookworm/bullseye

- - - - -
d6519904 by Utkarsh Gupta at 2026-07-25T23:07:12+05:30
lts: triage libjavascript-minifier-xs-perl in bookworm/bullseye

- - - - -
e772a58a by Utkarsh Gupta at 2026-07-25T23:15:52+05:30
lts: liblist-someutils-xs-perl postponed in bookworm/bullseye

- - - - -
b06e0017 by Utkarsh Gupta at 2026-07-25T23:21:02+05:30
lts: libnet-statsd-perl postponed in bookworm/bullseye

- - - - -
18f8a442 by Utkarsh Gupta at 2026-07-25T23:29:02+05:30
lts: libsocket-perl postponed in bookworm/bullseye

- - - - -
34a53631 by Utkarsh Gupta at 2026-07-25T23:39:02+05:30
lts: libstring-util-perl postponed in bookworm

- - - - -
e1aad7da by Utkarsh Gupta at 2026-07-25T23:47:12+05:30
lts: libxml-bare-perl postponed in bookworm/bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11029,12 +11029,16 @@ CVE-2026-62318
 CVE-2026-57074 (XML::Bare versions through 0.53 for Perl have an unbounded character l ...)
 	- libxml-bare-perl 0.53-5 (bug #1142227)
 	[trixie] - libxml-bare-perl <no-dsa> (Minor issue)
+	[bookworm] - libxml-bare-perl <postponed> (Minor issue; heap OOB read on truncated XML input)
+	[bullseye] - libxml-bare-perl <postponed> (Minor issue; heap OOB read on truncated XML input)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41876806/
 	NOTE: https://github.com/nanoscopic/perl-XML-Bare/pull/1
 	NOTE: https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-57074-r1.patch
 CVE-2026-13401 (XML::Bare versions through 0.53 for Perl will hang in an infinite loop ...)
 	- libxml-bare-perl 0.53-5 (bug #1142227)
 	[trixie] - libxml-bare-perl <no-dsa> (Minor issue)
+	[bookworm] - libxml-bare-perl <postponed> (Minor issue; infinite loop on malformed attributes, CPU-pinning DoS)
+	[bullseye] - libxml-bare-perl <postponed> (Minor issue; infinite loop on malformed attributes, CPU-pinning DoS)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41876829/
 	NOTE: https://github.com/nanoscopic/perl-XML-Bare/pull/2
 	NOTE: https://security.metacpan.org/patches/X/XML-Bare/0.53/CVE-2026-13401-r1.patch
@@ -17310,6 +17314,8 @@ CVE-2026-58388
 CVE-2026-14454 (Imager versions before 1.033 for Perl treat unsigned EXIF IFD entry co ...)
 	- libimager-perl 1.033+dfsg-1 (bug #1141959)
 	[trixie] - libimager-perl <no-dsa> (Minor issue)
+	[bookworm] - libimager-perl <postponed> (Minor issue; crafted EXIF data can kill the process via a failed huge allocation)
+	[bullseye] - libimager-perl <postponed> (Minor issue; crafted EXIF data can kill the process via a failed huge allocation)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41637674/
 	NOTE: Fixed by: https://github.com/tonycoz/imager/commit/06f01a5d0fd591259aeba589370d6888384a6b6d (v1.033)
 CVE-2026-9842 (The Backstage - Customizer Demo Access plugin for WordPress is vulnera ...)
@@ -17738,6 +17744,7 @@ CVE-2026-55999 (Local attackers with a X connection able to provide PCX fonts to
 CVE-2026-14895 (String::Util versions before 1.36 for Perl are susceptible to a regula ...)
 	- libstring-util-perl 1.36-1
 	[trixie] - libstring-util-perl <no-dsa> (Minor issue; will be fixed via point release)
+	[bookworm] - libstring-util-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625636/
 	NOTE: Fixed by: https://github.com/scottchiefbaker/String-Util/commit/f8150867aaeb8f57c59601aefb2193f2caed8745 (v1.36)
 CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code injection vi ...)
@@ -17889,6 +17896,7 @@ CVE-2011-10043 (Module::Load versions before 0.22 for Perl allow arbitrary modul
 CVE-2026-7017 (HTTP::Tiny versions before 0.095 for Perl forward credential headers t ...)
 	- libhttp-tiny-perl 0.096-1 (bug #1141638)
 	[trixie] - libhttp-tiny-perl <no-dsa> (Minor issue)
+	[bookworm] - libhttp-tiny-perl <postponed> (Minor issue; leak requires caller-supplied credential headers and an attacker-influenced redirect)
 	- perl <unfixed> (bug #1141639)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41618211/
 	NOTE: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36
@@ -18565,11 +18573,15 @@ CVE-2026-XXXX [RUSTSEC-2026-0194]
 CVE-2026-13708 (Imager::File::JPEG versions before 1.003 for Perl leak heap memory whe ...)
 	- libimager-perl 1.032+dfsg-1 (bug #1141587)
 	[trixie] - libimager-perl <no-dsa> (Minor issue)
+	[bookworm] - libimager-perl <postponed> (Minor issue; memory leak reading JPEGs with repeated APP13 markers, DoS only in long-lived readers)
+	[bullseye] - libimager-perl <postponed> (Minor issue; memory leak reading JPEGs with repeated APP13 markers, DoS only in long-lived readers)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41572486/
 	NOTE: Fixed by: https://github.com/tonycoz/imager/commit/9f1c485ca3ee15dc261549e11afb356866552c3a (v1.032)
 CVE-2026-13705 (Imager versions before 1.032 for Perl have a heap out-of-bounds read i ...)
 	- libimager-perl 1.032+dfsg-1 (bug #1141587)
 	[trixie] - libimager-perl <no-dsa> (Minor issue)
+	[bookworm] - libimager-perl <postponed> (Minor issue; heap over-read crash on a crafted SGI image)
+	[bullseye] - libimager-perl <postponed> (Minor issue; heap over-read crash on a crafted SGI image)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41572386/
 	NOTE: Fixed by: https://github.com/tonycoz/imager/commit/f28de02770dfc26ffbdc32048970ed84babbf730 (v1.032)
 CVE-2026-XXXX [RUSTSEC-2026-0195]
@@ -18910,6 +18922,8 @@ CVE-2024-1248 (The silent Just-In-Time (JIT) provisioning feature in federated a
 CVE-2026-14570 (Crypt::DSA versions before 1.22 for Perl draw the DSA signing nonce an ...)
 	- libcrypt-dsa-perl <removed>
 	[trixie] - libcrypt-dsa-perl <no-dsa> (Minor issue)
+	[bookworm] - libcrypt-dsa-perl <postponed> (Minor issue; biased makerandom nonce/key generation; obsolete leaf module, removed from sid)
+	[bullseye] - libcrypt-dsa-perl <postponed> (Minor issue; biased makerandom nonce/key generation; obsolete leaf module, removed from sid)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41542402/
 CVE-2026-14647 (A weakness has been identified in onnx up to 1.21.x. This vulnerabilit ...)
 	- onnx <unfixed>
@@ -23884,15 +23898,21 @@ CVE-2026-13758 (CryptX versions before 0.088_001 for Perl compare AEAD authentic
 CVE-2026-13593 (CSS::Minifier::XS versions before 0.14 for Perl have a memory leak whe ...)
 	- libcss-minifier-xs-perl 0.14-1
 	[trixie] - libcss-minifier-xs-perl <no-dsa> (Minor issue)
+	[bookworm] - libcss-minifier-xs-perl <postponed> (Minor issue)
+	[bullseye] - libcss-minifier-xs-perl <not-affected> (Vulnerable code introduced in 0.13's NodeSet arena rewrite; 0.11 frees nodes individually when pruned)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41396070/
 CVE-2026-56018 (JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on  ...)
 	- libjavascript-minifier-xs-perl 0.16-1
 	[trixie] - libjavascript-minifier-xs-perl <no-dsa> (Minor issue)
+	[bookworm] - libjavascript-minifier-xs-perl <postponed> (Minor issue; unbounded memory-leak DoS in JS minifier, fixed upstream in 0.16)
+	[bullseye] - libjavascript-minifier-xs-perl <not-affected> (Vulnerable code introduced in 0.14 bulk-Node-allocation rework; 0.13 frees all node contents via JsFreeNodeList/JsFreeNode)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41396069/
 	NOTE: https://github.com/bleargh45/JavaScript-Minifier-XS/issues/10
 CVE-2026-56017 (JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NU ...)
 	- libjavascript-minifier-xs-perl 0.16-1
 	[trixie] - libjavascript-minifier-xs-perl <no-dsa> (Minor issue)
+	[bookworm] - libjavascript-minifier-xs-perl <postponed> (Minor issue; crash-only DoS in JS minifier, fixed upstream in 0.16)
+	[bullseye] - libjavascript-minifier-xs-perl <postponed> (Minor issue; crash-only DoS in JS minifier, fixed upstream in 0.16)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41396063/
 CVE-2026-9267 (Eclipse tinydtls before commitb3efd41ad111a4920f599f51ffa4f5e9f1e72221 ...)
 	NOT-FOR-US: Eclipse
@@ -26355,6 +26375,8 @@ CVE-2026-11999 (X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL
 CVE-2026-12844 (List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer o ...)
 	- liblist-someutils-xs-perl 0.59-1
 	[trixie] - liblist-someutils-xs-perl <no-dsa> (Minor issue)
+	[bookworm] - liblist-someutils-xs-perl <postponed> (Minor issue)
+	[bullseye] - liblist-someutils-xs-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41398142/
 	NOTE: Fixed by: https://github.com/houseabsolute/List-SomeUtils-XS/commit/22549f78669b780d6aa338a2d2e49a3dedfffaa6 (v0.59)
 CVE-2026-40211 (An attacker can send crafted DNS over HTTP/3 queries, triggering an ex ...)
@@ -34819,6 +34841,8 @@ CVE-2026-53705 (A flaw was found in GStreamer's WavPack audio decoder in gst-plu
 CVE-2026-12087 (Socket versions before 2.041 for Perl have an out-of-bounds heap read. ...)
 	- libsocket-perl 2.041-1
 	[trixie] - libsocket-perl <no-dsa> (Minor issue)
+	[bookworm] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
+	[bullseye] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
 	- perl <unfixed> (bug #1140152)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41020451/
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb (v5.43.11)
@@ -34985,6 +35009,8 @@ CVE-2016-20066 (WordPress CP Polls 1.0.8 contains a persistent cross-site script
 CVE-2026-12205 (Crypt::DSA versions before 1.21 for Perl reused the nonce across signa ...)
 	- libcrypt-dsa-perl 1.21-1 (bug #1140105)
 	[trixie] - libcrypt-dsa-perl <no-dsa> (Minor issue)
+	[bookworm] - libcrypt-dsa-perl <postponed> (Minor issue; sign() reuses cached nonce across signatures; obsolete leaf module, removed from sid)
+	[bullseye] - libcrypt-dsa-perl <postponed> (Minor issue; sign() reuses cached nonce across signatures; obsolete leaf module, removed from sid)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41004653/
 CVE-2026-XXXX [SSLMate go-pkcs12: Authentication bypass in Decode functions]
 	- golang-sslmate-src-go-pkcs12 0.7.2-1
@@ -38462,6 +38488,8 @@ CVE-2026-49818 (The Apache Airflow Samba provider's `GCSToSambaOperator` joined
 CVE-2009-10007 (Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is  ...)
 	- libcatalyst-plugin-authentication-perl <unfixed> (bug #1139461)
 	[trixie] - libcatalyst-plugin-authentication-perl <no-dsa> (Minor issue)
+	[bookworm] - libcatalyst-plugin-authentication-perl <postponed> (Minor issue)
+	[bullseye] - libcatalyst-plugin-authentication-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40832427/
 	NOTE: Fixed by: https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b1385ea87a2491b64f33169222af19982d0acce3 (v0.10_027)
 CVE-2026-9662 (The Recover Exit For WooCommerce plugin for WordPress is vulnerable to ...)
@@ -42363,6 +42391,8 @@ CVE-2026-46741 (Etsy::StatsD versions through 1.002002 for Perl allow metric inj
 CVE-2026-46739 (Net::Statsd versions before 0.13 for Perl allow metric injections.  Th ...)
 	- libnet-statsd-perl 0.13-1 (bug #1139163)
 	[trixie] - libnet-statsd-perl <no-dsa> (Minor issue)
+	[bookworm] - libnet-statsd-perl <postponed> (Minor issue)
+	[bullseye] - libnet-statsd-perl <postponed> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/40702251/
 	NOTE: https://github.com/cosimo/perl5-net-statsd/pull/10
 	NOTE: Fixed by: https://github.com/cosimo/perl5-net-statsd/commit/a10b10173d6751991b7ade14b86dd272439d2283 (0.13)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/43503c2386d518d1407645d6225bc5226ce28039...e1aad7da9ec1bca2cd27b29e4c04cf5b76cf29c2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/43503c2386d518d1407645d6225bc5226ce28039...e1aad7da9ec1bca2cd27b29e4c04cf5b76cf29c2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260725/c569d3c3/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list