[Git][security-tracker-team/security-tracker][master] 8 commits: dla-needed: extend snapd to bookworm

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Sun Jul 26 03:26:04 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
10894091 by Utkarsh Gupta at 2026-07-26T06:24:14+05:30
dla-needed: extend snapd to bookworm

- - - - -
4407f92f by Utkarsh Gupta at 2026-07-26T06:28:14+05:30
lts: vtk-dicom postponed in bookworm/bullseye

- - - - -
3419a0e9 by Utkarsh Gupta at 2026-07-26T07:55:25+05:30
lts: yard postponed in bookworm/bullseye

- - - - -
daa510ca by Utkarsh Gupta at 2026-07-26T07:55:29+05:30
lts: weasyprint postponed in bookworm/bullseye

- - - - -
3a041641 by Utkarsh Gupta at 2026-07-26T07:55:33+05:30
lts: sqlfluff postponed in bookworm

- - - - -
8bd12fad by Utkarsh Gupta at 2026-07-26T07:55:38+05:30
lts: ujson postponed in bookworm

- - - - -
8a7f8303 by Utkarsh Gupta at 2026-07-26T07:55:39+05:30
lts: ujson not-affected in bullseye

- - - - -
4da64e27 by Utkarsh Gupta at 2026-07-26T07:55:43+05:30
dla-needed: add swift

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -25757,6 +25757,8 @@ CVE-2026-2299 (The Mattermost Google Drive plugin before version 1.1.0 fails to
 CVE-2026-22879 (vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer overflow  ...)
 	- vtk-dicom <unfixed> (bug #1142344)
 	[trixie] - vtk-dicom <no-dsa> (Minor issue)
+	[bookworm] - vtk-dicom <postponed> (Minor issue; OOB write reachable only by parsing an attacker-supplied DICOM file, and no upstream fix exists yet, PR #253 unmerged)
+	[bullseye] - vtk-dicom <postponed> (Minor issue; OOB write reachable only by parsing an attacker-supplied DICOM file, and no upstream fix exists yet, PR #253 unmerged)
 	NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2366
 	NOTE: https://github.com/dgobbi/vtk-dicom/pull/253
 CVE-2026-13322 (A flaw was found in KubeVirt's downward metrics virtio-serial server.  ...)
@@ -31039,6 +31041,8 @@ CVE-2026-49344 (Mercator is an open source web application that enables mapping
 CVE-2026-49342 (YARD is a documentation generation tool for the Ruby programming langu ...)
 	- yard 0.9.44-1
 	[trixie] - yard <no-dsa> (Minor issue)
+	[bookworm] - yard <postponed> (Minor issue; static-cache traversal only reachable when yard server is run with --docroot)
+	[bullseye] - yard <postponed> (Minor issue; static-cache traversal only reachable when yard server is run with --docroot)
 	NOTE: https://github.com/lsegal/yard/security/advisories/GHSA-pxcc-8665-phx8
 	NOTE: https://github.com/lsegal/yard/commit/f78c19f0dd33a407085b4ed181bb60c0aa0078b4 (v0.9.44)
 CVE-2026-49340 (gonic is a music streaming server / free-software subsonic server API  ...)
@@ -35063,6 +35067,8 @@ CVE-2026-XXXX [SSLMate go-pkcs12: Authentication bypass in Decode functions]
 CVE-2026-49452
 	- weasyprint 69.0-1
 	[trixie] - weasyprint <no-dsa> (Minor issue)
+	[bookworm] - weasyprint <postponed> (Minor issue; only exploitable when presentational hints are enabled, disabled by default)
+	[bullseye] - weasyprint <postponed> (Minor issue; only exploitable when presentational hints are enabled, disabled by default)
 	NOTE: https://www.courtbouillon.org/blog/00067-weasyprint-69/
 	NOTE: https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jhhc-3hcp-qhm5
 CVE-2026-54413 (driftregion iso14229 through 0.9.0 contains an integer underflow and d ...)
@@ -37102,10 +37108,12 @@ CVE-2026-46411 (FlashMQ is a MQTT broker/server, designed for multi-CPU environm
 CVE-2026-46374 (SQLFluff is a modular SQL linter and auto-formatter with support for m ...)
 	- sqlfluff <unfixed> (bug #1139640)
 	[trixie] - sqlfluff <no-dsa> (Minor issue)
+	[bookworm] - sqlfluff <postponed> (Parser resource-exhaustion DoS, only reachable where untrusted SQL is linted; upstream fix adds new parse limits that do not apply to the pre-3.0 parser in 1.4.5)
 	NOTE: https://github.com/sqlfluff/sqlfluff/security/advisories/GHSA-73jc-5mrq-prw7
 CVE-2026-46373 (SQLFluff is a modular SQL linter and auto-formatter with support for m ...)
 	- sqlfluff <unfixed> (bug #1139640)
 	[trixie] - sqlfluff <no-dsa> (Minor issue)
+	[bookworm] - sqlfluff <postponed> (Parser resource-exhaustion DoS, only reachable where untrusted SQL is linted; upstream fix adds new parse limits that do not apply to the pre-3.0 parser in 1.4.5)
 	NOTE: https://github.com/sqlfluff/sqlfluff/security/advisories/GHSA-wmhf-fqc8-vxhh
 CVE-2026-45782 (Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. Fro ...)
 	NOT-FOR-US: Cloud Hypervisor
@@ -47577,6 +47585,7 @@ CVE-2026-44681 (Authlib is a Python library which builds OAuth and OpenID Connec
 CVE-2026-44660 (UltraJSON is a fast JSON encoder and decoder written in pure C with bi ...)
 	- ujson 5.13.0-1 (bug #1138258)
 	[trixie] - ujson <no-dsa> (Minor issue)
+	[bookworm] - ujson <postponed> (Minor issue)
 	[bullseye] - ujson <postponed> (Minor issue)
 	NOTE: https://github.com/ultrajson/ultrajson/security/advisories/GHSA-c38f-wx89-p2xg
 	NOTE: Fixed by: https://github.com/ultrajson/ultrajson/commit/82af1d0ac01d09aa40c887b460d44b9d9f4bccd9 (5.12.1)
@@ -90427,14 +90436,16 @@ CVE-2026-32880 (ChurchCRM is an open-source church management system. Versions p
 CVE-2026-32875 (UltraJSON is a fast JSON encoder and decoder written in pure C with bi ...)
 	- ujson 5.13.0-1 (bug #1131485)
 	[trixie] - ujson <no-dsa> (Minor issue)
-	[bullseye] - ujson <postponed> (Minor issue; DoS)
+	[bookworm] - ujson <postponed> (Minor issue; DoS)
+	[bullseye] - ujson <not-affected> (Indent arithmetic in Buffer_Reserve() introduced in 5.2.0)
 	NOTE: https://github.com/ultrajson/ultrajson/security/advisories/GHSA-c8rr-9gxc-jprv
 	NOTE: https://github.com/ultrajson/ultrajson/issues/700
 	NOTE: Fixed by: https://github.com/ultrajson/ultrajson/commit/486bd4553dc471a1de11613bc7347a6b318e37ea (5.12.0)
 CVE-2026-32874 (UltraJSON is a fast JSON encoder and decoder written in pure C with bi ...)
 	- ujson 5.13.0-1 (bug #1131486)
 	[trixie] - ujson <no-dsa> (Minor issue)
-	[bullseye] - ujson <postponed> (Minor issue; DoS)
+	[bookworm] - ujson <postponed> (Minor issue; DoS)
+	[bullseye] - ujson <not-affected> (Object_newIntegerFromString() introduced in 5.4.0)
 	NOTE: https://github.com/ultrajson/ultrajson/security/advisories/GHSA-wgvc-ghv9-3pmm
 	NOTE: Fixed by: https://github.com/ultrajson/ultrajson/commit/4baeb950df780092bd3c89fc702a868e99a3a1d2 (5.12.0)
 CVE-2026-32873 (ewe is a Gleam web server. Versions 0.8.0 through 3.0.4 contain a bug  ...)


=====================================
data/dla-needed.txt
=====================================
@@ -765,13 +765,21 @@ smb4k/bullseye
   NOTE: 20251217: Added by Front-Desk (pochu)
   NOTE: 20260531: bookworm EOL.
 --
-snapd/bullseye
+snapd
   NOTE: 20260324: Added by Front-Desk (Beuc)
   NOTE: 20260324: See DSA-6170-1 (root LPE) (Beuc/front-desk)
   NOTE: 20260324: Debian <=bookworm doesn't prune /tmp by default (cf. /usr/lib/tmpfiles.d/tmp.conf),
   NOTE: 20260324: but a local administrator could change that, so I'd suggest fixing anyway (Beuc/front-desk)
   NOTE: 20260713: Need to add a recent /usr/lib/tmpfiles.d/snapd.conf to fix CVE-2026-3888
   NOTE: 20260713: systemd functionality should be backported because bullseye have so systemd policy
+  NOTE: 20260726: Also add for bookworm (2.57.6): CVE-2026-15226 (seccomp
+  NOTE: 20260726: template allows the bare setuid/setgid family) and
+  NOTE: 20260726: CVE-2024-5300 (apparmor base profile grants access to
+  NOTE: 20260726: /run/systemd/userdb) both apply there. CVE-2026-8933 does
+  NOTE: 20260726: not: only set-capabilities snap-confine is vulnerable and
+  NOTE: 20260726: bookworm still ships it setuid-root, non-suid landing only
+  NOTE: 20260726: in 2.71-1. Entry was bullseye-only as bookworm was not yet
+  NOTE: 20260726: LTS when it was filed in 2026-03. (utkarsh/front-desk)
 --
 spip/bullseye
   NOTE: 20260220: Added by Front-Desk (rouca)
@@ -792,6 +800,16 @@ suricata/bullseye
   NOTE: 20250331: re added to fix next bunch of CVEs (ta)
   NOTE: 20250825: testing package (ta)
 --
+swift
+  NOTE: 20260726: Added by Front-Desk (utkarsh)
+  NOTE: 20260726: CVE-2026-50221: proxy gatekeeper does not strip the
+  NOTE: 20260726: X-Container-Host/X-Delete-At-Host update headers from
+  NOTE: 20260726: clients (SSRF). Already in ela-needed for buster, so it
+  NOTE: 20260726: makes sense to fix bookworm+bullseye alongside it;
+  NOTE: 20260726: trixie (2.35.1) is affected too and should be fixed.
+  NOTE: 20260726: Fix is 3 regexes in gatekeeper.py, applies cleanly to
+  NOTE: 20260726: 2.30.1 and 2.26.0. (utkarsh/front-desk)
+--
 symfony/bullseye
   NOTE: 20260521: Added by Front-Desk (Beuc)
   NOTE: 20260521: >20 CVEs disclosed, 10 not-affected,



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee186076f0a2dc99080c2357ff7b0c2f0ce69a5f...4da64e27a7d7c4e16637cf9c03cc9143013bf6c4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee186076f0a2dc99080c2357ff7b0c2f0ce69a5f...4da64e27a7d7c4e16637cf9c03cc9143013bf6c4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/db1956c7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list