[Git][security-tracker-team/security-tracker][master] 9 commits: lts: duktape postponed in bullseye
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sun Jul 26 16:59:43 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b6a2a5c5 by Utkarsh Gupta at 2026-07-26T21:29:09+05:30
lts: duktape postponed in bullseye
- - - - -
d6a78304 by Utkarsh Gupta at 2026-07-26T21:29:11+05:30
lts: rust-anyhow postponed in bullseye
- - - - -
bc91c63b by Utkarsh Gupta at 2026-07-26T21:29:12+05:30
lts: rust-git2 postponed in bullseye
- - - - -
990ddf71 by Utkarsh Gupta at 2026-07-26T21:29:14+05:30
lts: rust-quick-xml postponed in bullseye
- - - - -
368dfa6f by Utkarsh Gupta at 2026-07-26T21:29:15+05:30
lts: rust-stackvector postponed in bullseye
- - - - -
2ca1021b by Utkarsh Gupta at 2026-07-26T21:29:17+05:30
lts: golang-golang-x-net not-affected in bookworm/bullseye
- - - - -
5a890afa by Utkarsh Gupta at 2026-07-26T21:29:18+05:30
lts: golang-golang-x-text postponed in bookworm/bullseye
- - - - -
47cb97ee by Utkarsh Gupta at 2026-07-26T21:29:20+05:30
lts: hdf5 postponed in bookworm/bullseye
- - - - -
408a8bb6 by Utkarsh Gupta at 2026-07-26T21:29:21+05:30
lts: python2.7 end-of-life in bullseye
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5428,6 +5428,8 @@ CVE-2026-59143 (Data::RoaringBitmap::Shared versions before 0.02 for Perl allow
NOT-FOR-US: Data::RoaringBitmap::Shared Perl module
CVE-2026-56852 (A norm.Iter can enter an infinite loop when handling input containing ...)
- golang-golang-x-text <unfixed> (bug #1142674)
+ [bookworm] - golang-golang-x-text <postponed> (Limited support, minor issue; DoS only, reachable via norm.Iter with NFC/NFKC on unvalidated UTF-8)
+ [bullseye] - golang-golang-x-text <postponed> (Limited support, minor issue; DoS only, reachable via norm.Iter with NFC/NFKC on unvalidated UTF-8)
NOTE: https://github.com/golang/go/issues/80142
NOTE: Fixed by: https://github.com/golang/text/commit/5ae8e578e495731553eddba11b2d0e86c91a00ce (v0.39.0)
CVE-2026-56844 (A vulnerability in the Veeam Updater component of the Veeam Software A ...)
@@ -5697,8 +5699,11 @@ CVE-2026-46876 (Vulnerability in Oracle Application Testing Suite. The support
NOT-FOR-US: Oracle
CVE-2026-46600 (Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...)
- golang-golang-x-net 1:0.56.0-1
+ [bookworm] - golang-golang-x-net <not-affected> (SVCB/HTTPS RR support not present; dns/dnsmessage/svcb.go and unpackSVCBResource introduced in x/net v0.47.0)
+ [bullseye] - golang-golang-x-net <not-affected> (SVCB/HTTPS RR support not present; dns/dnsmessage/svcb.go and unpackSVCBResource introduced in x/net v0.47.0)
NOTE: https://github.com/golang/go/issues/79795
NOTE: Fixed by: https://github.com/golang/net/commit/82e7868a02167540748b74780b0bf825985256f7 (v0.56.0)
+ NOTE: Introduced by: https://github.com/golang/net/commit/bb2055dafd28a92822d2297d3121c7498d58f1f6 (v0.47.0)
CVE-2026-46556 (FlaskBB is a Forum Software written in Python using the micro framewor ...)
NOT-FOR-US: FlaskBB
CVE-2026-46403 (Klever-Go is the Go implementation of the Klever blockchain protocol. ...)
@@ -7173,7 +7178,10 @@ CVE-2026-26199 (HDF5 is a high-performance library and a file format specificati
TODO: isolate fixing commit
CVE-2026-26197 (HDF5 is a high-performance library and a file format specification tha ...)
- hdf5 <unfixed>
+ [bookworm] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
+ [bullseye] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f
+ NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/8cd9f7a7ba6757fbb72e36bbe23e127f8507c8a6 (2.1.0)
TODO: check, isolate upstream change, might only be relevant for 2.0.0 onwards
CVE-2026-25039 (Parsec is a cloud-based application for simple and cryptographically s ...)
NOT-FOR-US: Parsec
@@ -16311,6 +16319,7 @@ CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
+ [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/F6453LWKSHKCTWFLCOURWPLETNUIW2Z5/
NOTE: https://github.com/python/cpython/issues/153030
NOTE: https://github.com/python/cpython/pull/153031
@@ -18686,6 +18695,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0190]
- rust-anyhow <unfixed> (bug #1141593)
[trixie] - rust-anyhow <no-dsa> (Minor issue)
[bookworm] - rust-anyhow <postponed> (Limited support, minor issue)
+ [bullseye] - rust-anyhow <postponed> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0190.html
NOTE: https://github.com/dtolnay/anyhow/issues/451
CVE-2026-XXXX [RUSTSEC-2026-0193]
@@ -18697,6 +18707,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0194]
- rust-quick-xml <unfixed> (bug #1141595)
[trixie] - rust-quick-xml <no-dsa> (Minor issue)
[bookworm] - rust-quick-xml <postponed> (Limited support, minor issue)
+ [bullseye] - rust-quick-xml <postponed> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0194.html
NOTE: https://github.com/tafia/quick-xml/issues/969
NOTE: https://github.com/tafia/quick-xml/pull/971
@@ -18719,6 +18730,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0195]
- rust-quick-xml <unfixed> (bug #1141588)
[trixie] - rust-quick-xml <no-dsa> (Minor issue)
[bookworm] - rust-quick-xml <postponed> (Limited support, minor issue)
+ [bullseye] - rust-quick-xml <postponed> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0195.html
NOTE: https://github.com/tafia/quick-xml/issues/970
NOTE: https://github.com/tafia/quick-xml/commit/7ca25266e94987210daa864889ab15c9332c8a2a (v0.41.0)
@@ -18740,6 +18752,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0166]
- rust-stackvector <unfixed> (bug #1141592)
[trixie] - rust-stackvector <no-dsa> (Minor issue)
[bookworm] - rust-stackvector <postponed> (Limited support, minor issue)
+ [bullseye] - rust-stackvector <postponed> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0166.html
NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/3
NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/5
@@ -32005,12 +32018,14 @@ CVE-2026-XXXX [RUSTSEC-2026-0183]
- rust-git2 <unfixed>
[trixie] - rust-git2 <no-dsa> (Minor issue)
[bookworm] - rust-git2 <postponed> (Limited support, minor issue)
+ [bullseye] - rust-git2 <postponed> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0183.html
NOTE: https://github.com/rust-lang/git2-rs/pull/1250
CVE-2026-XXXX [RUSTSEC-2026-0184]
- rust-git2 <unfixed>
[trixie] - rust-git2 <no-dsa> (Minor issue)
[bookworm] - rust-git2 <postponed> (Limited support, minor issue)
+ [bullseye] - rust-git2 <postponed> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0184.html
NOTE: https://github.com/rust-lang/git2-rs/pull/1254
CVE-2026-50190
@@ -35277,6 +35292,7 @@ CVE-2026-12216 (A weakness has been identified in svaarala duktape up to 2.99.99
- duktape <unfixed> (bug #1140485)
[trixie] - duktape <no-dsa> (Minor issue)
[bookworm] - duktape <postponed> (Minor issue, OOB read, revisit when/if fixed upstream)
+ [bullseye] - duktape <postponed> (Minor issue, OOB read, revisit when/if fixed upstream)
NOTE: https://github.com/hmKunlun/compileOOB/blob/main/api_bytecode.md
CVE-2026-12214 (A security flaw has been discovered in Qihoo 360 Total Security 6.0. T ...)
NOT-FOR-US: Qihoo
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e326999fedac2c2e72bbe825e01345ab29a4d4bb...408a8bb6c10d0f2e761dc5435e9954c3778122c1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e326999fedac2c2e72bbe825e01345ab29a4d4bb...408a8bb6c10d0f2e761dc5435e9954c3778122c1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/c2742283/attachment.htm>
More information about the debian-security-tracker-commits
mailing list