[Git][security-tracker-team/security-tracker][master] 15 commits: lts: triage selinux-python in bookworm/bullseye

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Sun Jul 26 23:35:07 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8135f99f by Utkarsh Gupta at 2026-07-27T01:22:12+05:30
lts: triage selinux-python in bookworm/bullseye

- - - - -
609ca2ca by Utkarsh Gupta at 2026-07-27T01:30:19+05:30
lts: h2o postponed in bookworm/bullseye

- - - - -
6cbb8c70 by Utkarsh Gupta at 2026-07-27T01:35:35+05:30
lts: mina and mina2 not-affected in bookworm/bullseye

- - - - -
b42dc569 by Utkarsh Gupta at 2026-07-27T01:45:33+05:30
lts: python3.11 postponed in bookworm

- - - - -
c08f08b6 by Utkarsh Gupta at 2026-07-27T01:49:46+05:30
lts: gdk-pixbuf postponed in bookworm/bullseye

- - - - -
32718238 by Utkarsh Gupta at 2026-07-27T01:58:48+05:30
lts: glib2.0 postponed in bookworm/bullseye

- - - - -
dc77982c by Utkarsh Gupta at 2026-07-27T02:05:07+05:30
lts: gpsd postponed in bookworm/bullseye

- - - - -
2f429443 by Utkarsh Gupta at 2026-07-27T02:15:41+05:30
lts: triage golang-oras-oras-go in bookworm

- - - - -
65120a72 by Utkarsh Gupta at 2026-07-27T02:20:39+05:30
lts: rust-openssl not-affected in bookworm/bullseye

- - - - -
bfecf832 by Utkarsh Gupta at 2026-07-27T02:29:10+05:30
lts: mbedtls end-of-life in bookworm

- - - - -
6ffb456c by Utkarsh Gupta at 2026-07-27T02:34:57+05:30
lts: answer stale hdf5 TODO on the array datatype decode

- - - - -
342d48c9 by Utkarsh Gupta at 2026-07-27T04:04:19+05:30
merge stale RUSTSEC placeholder into rust-quinn-proto entry

- - - - -
9db7befa by Utkarsh Gupta at 2026-07-27T04:04:26+05:30
dla-needed: add redis

- - - - -
bd430bc9 by Utkarsh Gupta at 2026-07-27T04:04:26+05:30
lts: libsoup2.4 not-affected in bookworm/bullseye

- - - - -
37cde6c9 by Utkarsh Gupta at 2026-07-27T04:04:26+05:30
dla-needed: widen libsoup2.4 to bookworm

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1992,6 +1992,8 @@ CVE-2026-62825 (Improper authentication in Azure Key Vault allows an unauthorize
 CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains a code  ...)
 	- gpsd 3.27.5-1
 	[trixie] - gpsd <no-dsa> (Minor issue)
+	[bookworm] - gpsd <postponed> (Minor issue; code injection confined to the gpsprof diagnostic client via a hostile gpsd JSON stream or replayed log, local and requires user interaction)
+	[bullseye] - gpsd <postponed> (Minor issue; code injection confined to the gpsprof diagnostic client via a hostile gpsd JSON stream or replayed log, local and requires user interaction)
 	NOTE: https://gitlab.com/gpsd/gpsd/-/work_items/406
 	NOTE: Fixed by: https://gitlab.com/gpsd/gpsd/-/commit/5a9c44a42136b9bb98d460a8a716e9fd344a8d93
 CVE-2026-58275 (Missing authorization in Azure DNS allows an unauthorized attacker to  ...)
@@ -2055,7 +2057,9 @@ CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on Windows
 CVE-2026-28698 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sen ...)
 	NOT-FOR-US: Pronetiqs IntraVUE
 CVE-2026-25800 (Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC ...)
-	- rust-quinn-proto 0.11.16-1
+	- rust-quinn-proto 0.11.16-1 (bug #1141481)
+	[trixie] - rust-quinn-proto <no-dsa> (Minor issue)
+	[bookworm] - rust-quinn-proto <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/quinn-rs/quinn/security/advisories/GHSA-4w2j-m93h-cj5j
 	NOTE: https://github.com/quinn-rs/quinn/pull/2694
 	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0185.html
@@ -2572,6 +2576,8 @@ CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming PortPro
 CVE-2026-59677 (A Missing Authorization vulnerability in selinux policycoreutils seuns ...)
 	- policycoreutils 2.7-1
 	- selinux-python 3.7-1
+	[bookworm] - selinux-python <postponed> (Minor issue; seunshare is not setuid-root in Debian, it gets file capabilities without CAP_KILL, so killall() cannot signal root-owned processes)
+	[bullseye] - selinux-python <postponed> (Minor issue; seunshare is not setuid-root in Debian, it gets file capabilities without CAP_KILL, so killall() cannot signal root-owned processes)
 	NOTE: src:policycoreutils 2.7 dropped sandbox/seunshare.c core and stopped building
 	NOTE: policycoreutils-sandbox. Built from selinux-python until 3.7-1 and moved to a
 	NOTE: separate upstream package.
@@ -2744,6 +2750,8 @@ CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessib
 CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO f ...)
 	- gdk-pixbuf <unfixed>
 	[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
+	[bookworm] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the rendered image; unfixed upstream)
+	[bullseye] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the rendered image; unfixed upstream)
 	NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302
 CVE-2026-16756 (Missing connection and header-read timeouts and the absence of a concu ...)
 	NOT-FOR-US: Amazon
@@ -2902,6 +2910,8 @@ CVE-2026-60366 (Vulnerability in the Oracle Platform Security for Java product o
 CVE-2026-59676 (A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in s ...)
 	- policycoreutils 2.7-1
 	- selinux-python 3.7-1
+	[bookworm] - selinux-python <not-affected> (rm_rf() and its symlink-following openat() recursion introduced upstream in 3.10; earlier seunshare removes the tmpdir with /bin/rm -r run as the calling user)
+	[bullseye] - selinux-python <not-affected> (rm_rf() and its symlink-following openat() recursion introduced upstream in 3.10; earlier seunshare removes the tmpdir with /bin/rm -r run as the calling user)
 	NOTE: src:policycoreutils 2.7 dropped sandbox/seunshare.c core and stopped building
 	NOTE: policycoreutils-sandbox. Built from selinux-python until 3.7-1 and moved to a
 	NOTE: separate upstream package.
@@ -5916,51 +5926,67 @@ CVE-2026-47057 (Vulnerability in Oracle Java SE (component: Scripting).  Support
 CVE-2026-25832
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-35336
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-49300
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50579
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50580
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50581
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50583
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50584
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50585
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50586
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50587
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50588
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50640
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-50713
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-54435
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-54441
 	- mbedtls 3.6.7-2
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 al ...)
 	{DSA-6396-1}
 	- chromium 150.0.7871.181-1
@@ -6909,11 +6935,19 @@ CVE-2023-37507 (HCL DevOps Plan is susceptible to an information disclosure that
 	NOT-FOR-US: HCL
 CVE-2026-58624 (Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA ...)
 	- mina2 <unfixed> (bug #1142679)
+	[bookworm] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-git module)
+	[bullseye] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-git module)
 	- mina <removed>
+	[bookworm] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-git module)
+	[bullseye] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-git module)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/18
 CVE-2026-56624 (Improper certificate validation in Apache MINA SSHD (server-side).Apac ...)
 	- mina2 <unfixed> (bug #1142679)
+	[bookworm] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-core module)
+	[bullseye] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-core module)
 	- mina <removed>
+	[bookworm] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-core module)
+	[bullseye] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-core module)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/17
 CVE-2026-56623 (Path traversal on Windows in Apache MINA SSHD component sshd-git.Apach ...)
 	- mina2 <not-affected> (Only affects MINA SSHD on Windows)
@@ -6921,7 +6955,11 @@ CVE-2026-56623 (Path traversal on Windows in Apache MINA SSHD component sshd-git
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/16
 CVE-2026-56452 (Path traversal in the sshd-scp component of Apache MINA SSHD.Apache MI ...)
 	- mina2 <unfixed> (bug #1142679)
+	[bookworm] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-scp module)
+	[bullseye] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-scp module)
 	- mina <removed>
+	[bookworm] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-scp module)
+	[bullseye] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-scp module)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/15
 CVE-2026-61548 [rsyslog mmpstrucdata stack overflow]
 	- rsyslog 8.2606.0-4
@@ -7235,7 +7273,7 @@ CVE-2026-26197 (HDF5 is a high-performance library and a file format specificati
 	[bullseye] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
 	NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f
 	NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/8cd9f7a7ba6757fbb72e36bbe23e127f8507c8a6 (2.1.0)
-	TODO: check, isolate upstream change, might only be relevant for 2.0.0 onwards
+	NOTE: Unchecked H5T_ARRAY decode in src/H5Odtype.c predates 1.8.0, not 2.0.0-specific; fix is only on develop/2.1.0, not backported to the 1.14 branch
 CVE-2026-25039 (Parsec is a cloud-based application for simple and cryptographically s ...)
 	NOT-FOR-US: Parsec
 CVE-2026-21824 (HCL Commerce contains an privilege escalation vulnerability that could ...)
@@ -10189,15 +10227,18 @@ CVE-2026-50197 (Skipper is an HTTP router and reverse proxy for service composit
 	NOT-FOR-US: Zalando Skipper
 CVE-2026-50163 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, en ...)
 	- golang-oras-oras-go <unfixed> (bug #1142456)
+	[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, content/utils.go os.Link()s the unresolved Linkname)
 	NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp
 	NOTE: https://github.com/oras-project/oras-go/pull/1232
 	NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/c463c654ab3ef34422c1764cd619806cebf20451 (v2.6.2)
 CVE-2026-50162 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...)
 	- golang-oras-oras-go <unfixed> (bug #1142456)
+	[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, content/file.go resolveWritePath() lacks symlink resolution)
 	NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv
 	NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5 (v2.6.1)
 CVE-2026-50151 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...)
 	- golang-oras-oras-go <unfixed> (bug #1142456)
+	[bookworm] - golang-oras-oras-go <not-affected> (Blob upload path not present in v1.1.1; no blobStore and the Location header is never read)
 	NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7
 	NOTE: https://github.com/oras-project/oras-go/pull/1152
 	NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991 (v2.6.1)
@@ -10225,6 +10266,7 @@ CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information disc
 	NOTE: https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
 CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...)
 	- golang-oras-oras-go <unfixed> (bug #1142456)
+	[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, auth/client.go follows an unvalidated WWW-Authenticate realm)
 	NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w
 	NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/7a9f4b0b9558821b0422152ebe21ae56930fe764 (v2.6.1)
 CVE-2026-48819 (Hey API is an ecosystem for turning API specifications into production ...)
@@ -10247,6 +10289,8 @@ CVE-2026-45785 (OpenMcdf is a fully .NET / C# library to manipulate Compound Fil
 	NOT-FOR-US: OpenMcdf
 CVE-2026-45784 (rust-openssl provides OpenSSL bindings for the Rust programming langua ...)
 	- rust-openssl <unfixed> (bug #1142474)
+	[bookworm] - rust-openssl <not-affected> (Vulnerable CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are absent too)
+	[bullseye] - rust-openssl <not-affected> (Vulnerable CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are absent too)
 	NOTE: https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq
 	NOTE: https://github.com/rust-openssl/rust-openssl/pull/2638
 	NOTE: Fixed by: https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7 (openssl-v0.10.80)
@@ -10276,6 +10320,8 @@ CVE-2026-36669 (An unauthenticated arbitrary file upload vulnerability in ck_upl
 CVE-2026-16118 (A flaw was found in xdgmime. A heap-based buffer overflow can be trigg ...)
 	- glib2.0 <unfixed> (bug #1142717)
 	[trixie] - glib2.0 <no-dsa> (Minor issue)
+	[bookworm] - glib2.0 <postponed> (Minor issue; 2-byte OOB write parsing the mime magic file in an XDG data dir, needs an attacker-writable XDG data dir; unfixed upstream)
+	[bullseye] - glib2.0 <postponed> (Minor issue; 2-byte OOB write parsing the mime magic file in an XDG data dir, needs an attacker-writable XDG data dir; unfixed upstream)
 	NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3992
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2501732
 	NOTE: https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41
@@ -10854,6 +10900,8 @@ CVE-2026-54526 (Argo Workflows is an open source container-native workflow engin
 	NOT-FOR-US: Argo
 CVE-2026-54340 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...)
 	- h2o <removed>
+	[bookworm] - h2o <postponed> (Minor issue, DoS; 2.2.5 h2o_hpack_parse_headers() bounds neither the decoded field count nor retained header state, but amplification requires many deliberately stalled HTTP/2 streams)
+	[bullseye] - h2o <postponed> (Minor issue, DoS; 2.2.5 h2o_hpack_parse_headers() bounds neither the decoded field count nor retained header state, but amplification requires many deliberately stalled HTTP/2 streams)
 	NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-qcrr-wrhc-pgq9
 	NOTE: Fixed by (merge commit): https://github.com/h2o/h2o/commit/9265bdd9a996ed992681055e3996baf3e09d2063
 CVE-2026-53598 (Prompty is a markdown file format (.prompty) for LLM prompts. Prior to ...)
@@ -10979,10 +11027,14 @@ CVE-2026-44595 (Yamcs is a mission control framework. Prior to 5.12.7, the IAM A
 	NOT-FOR-US: Yamcs
 CVE-2026-44453 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...)
 	- h2o <removed>
+	[bookworm] - h2o <postponed> (Minor issue, DoS; the alloca() in lib/handler/file.c on_req() is present, but the crash premise is musl's 128KB default pthread stack, and h2o passes no pthread attr so glibc worker threads get the 8MB default)
+	[bullseye] - h2o <postponed> (Minor issue, DoS; the alloca() in lib/handler/file.c on_req() is present, but the crash premise is musl's 128KB default pthread stack, and h2o passes no pthread attr so glibc worker threads get the 8MB default)
 	NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-rf9v-m59p-mq84
 	NOTE: Fixed by: https://github.com/h2o/h2o/commit/6b5370d9d09fcf83aa7620ddf77de1954a192181
 CVE-2026-44452 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...)
 	- h2o <removed>
+	[bookworm] - h2o <postponed> (Minor issue, DoS; bundled picotls client_hello_decode_server_name() accepts a zero-length SNI hostname, and on_client_hello_ptls() then calls ptls_set_server_name() which strlen()s the non-terminated ClientHello buffer)
+	[bullseye] - h2o <postponed> (Minor issue, DoS; bundled picotls client_hello_decode_server_name() accepts a zero-length SNI hostname, and on_client_hello_ptls() then calls ptls_set_server_name() which strlen()s the non-terminated ClientHello buffer)
 	NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-w68q-rqwx-7wvq
 	NOTE: Fixed by (merge): https://github.com/h2o/h2o/commit/8dc37cb1e6171f7f772667618ea440696fed82c3
 CVE-2026-44436 (Quicly is an IETF QUIC protocol implementation intended primarily for  ...)
@@ -13841,6 +13893,8 @@ CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implement
 CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in libsoup's (ver ...)
 	- libsoup3 <unfixed> (bug #1142841)
 	- libsoup2.4 <removed>
+	[bookworm] - libsoup2.4 <not-affected> (HTTP/2 support is libsoup3-only, libsoup 2.x has no HTTP/2 implementation)
+	[bullseye] - libsoup2.4 <not-affected> (HTTP/2 support is libsoup3-only, libsoup 2.x has no HTTP/2 implementation)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499939
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540
 CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing impleme ...)
@@ -16410,6 +16464,7 @@ CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for
 	- python3.14 <unfixed>
 	- python3.13 <unfixed>
 	- python3.11 <removed>
+	[bookworm] - python3.11 <postponed> (CPU-only DoS; the quadratic rescan requires the incremental feed() API driven in chunks, a single feed() of the whole document stays linear; no upstream 3.11 fix released, backport PR gh-153042 still unmerged)
 	- python3.9 <removed>
 	- python2.7 <removed>
 	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
@@ -19230,12 +19285,6 @@ CVE-2026-12194 (PHPIPAM is affected by an authenticated local file inclusion vul
 	- phpipam <itp> (bug #731713)
 CVE-2025-13475 (In multi-tenanted deployments, the application consent management mech ...)
 	NOT-FOR-US: WSO2
-CVE-2026-XXXX [RUSTSEC-2026-0185]
-	- rust-quinn-proto <unfixed> (bug #1141481)
-	[trixie] - rust-quinn-proto <no-dsa> (Minor issue)
-	[bookworm] - rust-quinn-proto <postponed> (Limited support, minor issue)
-	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0185.html
-	NOTE: https://github.com/quinn-rs/quinn/pull/2694
 CVE-2026-XXXX [RUSTSEC-2026-0187]
 	- rust-lopdf <unfixed> (bug #1141480)
 	[trixie] - rust-lopdf <no-dsa> (Minor issue)


=====================================
data/dla-needed.txt
=====================================
@@ -378,7 +378,7 @@ libreswan/bookworm
   NOTE: 20260611: bookworm LTS handover.
   NOTE: 20260611: Sync with maintainer (dkg), hard to test.
 --
-libsoup2.4/bullseye
+libsoup2.4
   NOTE: 20250408: Added by Front-Desk (Beuc)
   NOTE: 20250427: libsoup2.4 2.72.0-2+deb11u2 (bullseye) uploaded ...
   NOTE: 20250427: ... without CVE-2025-32907 and CVE-2025-32049.
@@ -408,6 +408,13 @@ libsoup2.4/bullseye
   NOTE: 20251209: Remaining open CVEs need upstream work and then revisited,
   NOTE: 20251209: possibly also look into wip by spwitton, thus unclaiming
   NOTE: 20251209: rather than removing this entry. (ah)
+  NOTE: 20260727: Widened to bookworm: the same unfixed CVEs affect
+  NOTE: 20260727: 2.74.3-1+deb12u1. Fix CVE-2026-12547, CVE-2026-12548,
+  NOTE: 20260727: CVE-2026-15709, CVE-2026-15711, CVE-2026-15713,
+  NOTE: 20260727: CVE-2026-15714, CVE-2026-66337, CVE-2026-66338 and
+  NOTE: 20260727: CVE-2026-66339 in bookworm too. CVE-2026-15712 is
+  NOTE: 20260727: not-affected (no HTTP/2 in libsoup 2.x). Only
+  NOTE: 20260727: CVE-2026-12548 has an upstream fix (3.7.1). (utkarsh)
 --
 libssh2 (eamanu)
   NOTE: 20260625: Added by Front-Desk (lamby)
@@ -738,6 +745,14 @@ rabbitmq-server/bullseye
   NOTE: 20260504: Added by coordinator (santiago)
   NOTE: 20260504: Added to address out-standing minor issues
 --
+redis
+  NOTE: 20260727: Added by Front-Desk (utkarsh)
+  NOTE: 20260727: CVE-2026-66373: double free in the stream consumer PEL
+  NOTE: 20260727: loader (rdbLoadObject), reachable via RESTORE. Fixed
+  NOTE: 20260727: upstream in 6.2.23/7.2.15/8.6.5; bookworm ships
+  NOTE: 20260727: 7.0.15-1~deb12u8 and bullseye 6.0.16-1+deb11u8, both
+  NOTE: 20260727: still unguarded.
+--
 request-tracker4/bullseye (Andrew Ruthven)
   NOTE: 20260529: Added by Front-Desk (dleidert)
   NOTE: 20260529: Follow DSA in preparation by maintainer (dleidert/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/eed1b04e99770af2fc258ff5bec8f06273e6d48c...37cde6c9adde38c210e94f96a96f4f00cd77ad23

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/eed1b04e99770af2fc258ff5bec8f06273e6d48c...37cde6c9adde38c210e94f96a96f4f00cd77ad23
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/b226bf53/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list