[Git][security-tracker-team/security-tracker][master] 6 commits: lts: nova postponed in bookworm/bullseye
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sun Jul 26 01:19:58 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
aa717ab4 by Utkarsh Gupta at 2026-07-26T03:21:54+05:30
lts: nova postponed in bookworm/bullseye
- - - - -
825abbc2 by Utkarsh Gupta at 2026-07-26T03:28:54+05:30
lts: triage onionshare in bookworm/bullseye
- - - - -
8c581fec by Utkarsh Gupta at 2026-07-26T03:41:54+05:30
lts: onnx postponed in bookworm/bullseye
- - - - -
f1f9e53e by Utkarsh Gupta at 2026-07-26T03:50:24+05:30
lts: ovn postponed in bookworm
- - - - -
a75ebb5a by Utkarsh Gupta at 2026-07-26T04:01:54+05:30
lts: triage opencolorio in bookworm/bullseye
- - - - -
41a05316 by Utkarsh Gupta at 2026-07-26T04:12:21+05:30
lts: python-protego postponed in bookworm/bullseye
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18938,6 +18938,8 @@ CVE-2026-14570 (Crypt::DSA versions before 1.22 for Perl draw the DSA signing no
CVE-2026-14647 (A weakness has been identified in onnx up to 1.21.x. This vulnerabilit ...)
- onnx <unfixed>
[trixie] - onnx <no-dsa> (Minor issue)
+ [bookworm] - onnx <postponed> (Minor issue; OOB read in Conv shape inference when parsing a crafted model)
+ [bullseye] - onnx <postponed> (Minor issue; OOB read in Conv shape inference when parsing a crafted model)
NOTE: https://github.com/onnx/onnx/issues/8036
NOTE: https://github.com/onnx/onnx/pull/8051
NOTE: Fixed by: https://github.com/onnx/onnx/commit/a7bf3a0f1d18bb62575236ef6e4944980c40e045
@@ -25906,6 +25908,8 @@ CVE-2026-XXXX [ZSA-2026-12]
CVE-2026-55520
- python-protego 0.6.2+dfsg-1
[trixie] - python-protego <no-dsa> (Minor issue)
+ [bookworm] - python-protego <postponed> (Minor issue)
+ [bullseye] - python-protego <postponed> (Minor issue)
NOTE: https://github.com/scrapy/protego/security/advisories/GHSA-wjmf-p669-5m5p
NOTE: Fixed by: https://github.com/scrapy/protego/commit/785940181659bf440ba82f1da148fade5087e858 (0.6.2)
CVE-2026-9800 (A flaw was found in Keycloak Policy Enforcer. This vulnerability allow ...)
@@ -27924,6 +27928,8 @@ CVE-2026-44016 (Docling simplifies document processing by parsing diverse format
CVE-2026-42450 (OpenColorIO is a color management framework for visual effects and ani ...)
- opencolorio <unfixed> (bug #1141498)
[trixie] - opencolorio <no-dsa> (Minor issue)
+ [bookworm] - opencolorio <postponed> (Minor issue)
+ [bullseye] - opencolorio <not-affected> (Vulnerable code introduced in 2.x rewrite; 1.1.1 Spi3D parser scans %f directly, no %s into stack buffers)
NOTE: https://github.com/AcademySoftwareFoundation/OpenColorIO/security/advisories/GHSA-rxp3-rrgx-f547
CVE-2026-35025 (ProFTPD through 1.3.9b and 1.3.10rc2 contains an access control bypass ...)
- proftpd-dfsg <unfixed>
@@ -34145,6 +34151,8 @@ CVE-2026-57053 (GNU libidn before 1.44 is prone to out-of-bounds reads ofuniniti
CVE-2026-46448 (In OpenStack Nova before 33.0.2, the server create API does not strip ...)
- nova 2:33.0.1-4 (bug #1140149)
[trixie] - nova <no-dsa> (Minor issue)
+ [bookworm] - nova <postponed> (Minor issue)
+ [bullseye] - nova <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/16/5
NOTE: https://launchpad.net/bugs/2151252
CVE-2026-10649 (A flaw was found in Pacemaker. An unauthenticated remote attacker can ...)
@@ -36895,10 +36903,14 @@ CVE-2024-58350 (Ghidra before 11.2 contains a use after free vulnerability in th
CVE-2026-54706 [OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files]
- onionshare 2.6.4-1 (bug #1139717)
[trixie] - onionshare <no-dsa> (Minor issue)
+ [bookworm] - onionshare <postponed> (Minor issue; requires sharing a directory containing untrusted symlinks)
+ [bullseye] - onionshare <postponed> (Minor issue; requires sharing a directory containing untrusted symlinks)
NOTE: https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf
CVE-2026-54707 [OnionShare Receive mode writes uploaded files even when file uploads are disabled]
- onionshare 2.6.4-1 (bug #1139716)
[trixie] - onionshare <no-dsa> (Minor issue)
+ [bookworm] - onionshare <postponed> (Minor issue; policy bypass by a peer who already holds the onion address and key)
+ [bullseye] - onionshare <not-affected> (disable_files setting introduced in 2.6; 2.2 has no file-upload-disable feature to bypass)
NOTE: https://github.com/onionshare/onionshare/security/advisories/GHSA-v833-3823-cmhp
CVE-2026-11853 (Debusine is an integrated solution to build, distribute and maintain a ...)
- debusine 0.14.9
@@ -73181,11 +73193,13 @@ CVE-2025-11249
CVE-2026-5367 (A flaw was found in OVN (Open Virtual Network). A remote attacker, by ...)
- ovn 26.03.0-4 (bug #1134486)
[trixie] - ovn <no-dsa> (Minor issue)
+ [bookworm] - ovn <postponed> (Minor issue; bounded heap over-read/possible crash in pinctrl DHCPv6 handling, fix is a large parsing refactor)
NOTE: https://www.openwall.com/lists/oss-security/2026/04/20/3
NOTE: Fixed by: https://github.com/ovn-org/ovn/commit/78f6ce612403d6343f1e3782cbfff691d411dee4 (v26.03.1)
CVE-2026-5265 (When generating an ICMP Destination Unreachable or Packet Too Big resp ...)
- ovn 26.03.0-4 (bug #1134486)
[trixie] - ovn <no-dsa> (Minor issue)
+ [bookworm] - ovn <postponed> (Minor issue; bounded heap over-read in pinctrl ICMP error generation)
NOTE: https://www.openwall.com/lists/oss-security/2026/04/20/2
NOTE: Introduced with: https://github.com/ovn-org/ovn/commit/c2339d87268d748da9a44aaefbb6d1ecc490b99d (v20.03.0)
NOTE: Fixed by: https://github.com/ovn-org/ovn/commit/9d674c684a56aef12c53b1e4596b6eded23a0402 (v26.03.1)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3f6e1cc223f2a06e44fb603b72acf49190a33da4...41a05316559466df96f2ea9113bb38b2f410f2e3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3f6e1cc223f2a06e44fb603b72acf49190a33da4...41a05316559466df96f2ea9113bb38b2f410f2e3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/696d0cc5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list