[Git][security-tracker-team/security-tracker][master] 2 commits: lts: python-multipart postponed in bookworm/bullseye
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sun Jul 26 15:17:30 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3dee1cff by Utkarsh Gupta at 2026-07-26T19:41:45+05:30
lts: python-multipart postponed in bookworm/bullseye
- - - - -
1baf5722 by Utkarsh Gupta at 2026-07-26T19:46:52+05:30
lts: rtklib not-affected in bookworm
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -26178,11 +26178,13 @@ CVE-2026-56789 (RTKLIB through 2.4.3 contains a heap buffer overflow vulnerabili
CVE-2026-56788 (RTKLIB through 2.4.3 contains an out-of-bounds read vulnerability in g ...)
- rtklib <unfixed> (bug #1140766)
[trixie] - rtklib <no-dsa> (Minor issue)
+ [bookworm] - rtklib <not-affected> (Negative codepris[] index not reachable; 2.4.3 b34 getcodepri() guards with "if ((j=code2idx(sys,code))<0) return 0", and code2idx returns at most 4 < MAXFREQ)
[bullseye] - rtklib <postponed> (Minor issue; codepris[i][-1] over-read on an unrecognised observation code, requires processing an attacker-supplied RINEX observation file)
NOTE: https://github.com/tomojitakasu/RTKLIB/issues/797
CVE-2026-56787 (RTKLIB through 2.4.3 contains an off-by-one out-of-bounds read vulnera ...)
- rtklib <unfixed> (bug #1140766)
[trixie] - rtklib <no-dsa> (Minor issue)
+ [bookworm] - rtklib <not-affected> (Off-by-one "mode<=ncode" construct not present; 2.4.3 b34 rewrote decode_ssr3 to index fixed ssr_sig_*[32] tables with the 5-bit mode field, in bounds by construction)
[bullseye] - rtklib <postponed> (Minor issue; one-element global over-read of the codes_* tables in decode_ssr3, requires an attacker-controlled RTCM3/NTRIP correction stream)
NOTE: https://github.com/tomojitakasu/RTKLIB/issues/798
CVE-2026-56786 (RTKLIB through 2.4.3 contains an out-of-bounds write vulnerability in ...)
@@ -30653,6 +30655,8 @@ CVE-2026-53540 (Python-Multipart is a streaming multipart parser for Python. Pri
CVE-2026-53539 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
- python-multipart <unfixed> (bug #1140628)
[trixie] - python-multipart <no-dsa> (Minor issue)
+ [bookworm] - python-multipart <postponed> (Minor issue; quadratic separator scan in QuerystringParser on ';'-separated urlencoded bodies)
+ [bullseye] - python-multipart <postponed> (Minor issue; quadratic separator scan in QuerystringParser on ';'-separated urlencoded bodies)
NOTE: https://github.com/Kludex/python-multipart/security/advisories/GHSA-5rvq-cxj2-64vf
NOTE: Fixed by: https://github.com/Kludex/python-multipart/commit/d69df35cd2cad9c72794c2c340db646afae957d8 (0.0.30)
CVE-2026-53538 (Python-Multipart is a streaming multipart parser for Python. Prior to ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/302e9962a7be88177cc75fa35c16f9f7ffdc656d...1baf572271aee2ce654fba36b6f6493f7974ca96
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/302e9962a7be88177cc75fa35c16f9f7ffdc656d...1baf572271aee2ce654fba36b6f6493f7974ca96
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/74c0d65e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list