[Git][security-tracker-team/security-tracker][master] 15 commits: lts: triage selinux-python in bookworm/bullseye
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sun Jul 26 23:35:07 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8135f99f by Utkarsh Gupta at 2026-07-27T01:22:12+05:30
lts: triage selinux-python in bookworm/bullseye
- - - - -
609ca2ca by Utkarsh Gupta at 2026-07-27T01:30:19+05:30
lts: h2o postponed in bookworm/bullseye
- - - - -
6cbb8c70 by Utkarsh Gupta at 2026-07-27T01:35:35+05:30
lts: mina and mina2 not-affected in bookworm/bullseye
- - - - -
b42dc569 by Utkarsh Gupta at 2026-07-27T01:45:33+05:30
lts: python3.11 postponed in bookworm
- - - - -
c08f08b6 by Utkarsh Gupta at 2026-07-27T01:49:46+05:30
lts: gdk-pixbuf postponed in bookworm/bullseye
- - - - -
32718238 by Utkarsh Gupta at 2026-07-27T01:58:48+05:30
lts: glib2.0 postponed in bookworm/bullseye
- - - - -
dc77982c by Utkarsh Gupta at 2026-07-27T02:05:07+05:30
lts: gpsd postponed in bookworm/bullseye
- - - - -
2f429443 by Utkarsh Gupta at 2026-07-27T02:15:41+05:30
lts: triage golang-oras-oras-go in bookworm
- - - - -
65120a72 by Utkarsh Gupta at 2026-07-27T02:20:39+05:30
lts: rust-openssl not-affected in bookworm/bullseye
- - - - -
bfecf832 by Utkarsh Gupta at 2026-07-27T02:29:10+05:30
lts: mbedtls end-of-life in bookworm
- - - - -
6ffb456c by Utkarsh Gupta at 2026-07-27T02:34:57+05:30
lts: answer stale hdf5 TODO on the array datatype decode
- - - - -
342d48c9 by Utkarsh Gupta at 2026-07-27T04:04:19+05:30
merge stale RUSTSEC placeholder into rust-quinn-proto entry
- - - - -
9db7befa by Utkarsh Gupta at 2026-07-27T04:04:26+05:30
dla-needed: add redis
- - - - -
bd430bc9 by Utkarsh Gupta at 2026-07-27T04:04:26+05:30
lts: libsoup2.4 not-affected in bookworm/bullseye
- - - - -
37cde6c9 by Utkarsh Gupta at 2026-07-27T04:04:26+05:30
dla-needed: widen libsoup2.4 to bookworm
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1992,6 +1992,8 @@ CVE-2026-62825 (Improper authentication in Azure Key Vault allows an unauthorize
CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains a code ...)
- gpsd 3.27.5-1
[trixie] - gpsd <no-dsa> (Minor issue)
+ [bookworm] - gpsd <postponed> (Minor issue; code injection confined to the gpsprof diagnostic client via a hostile gpsd JSON stream or replayed log, local and requires user interaction)
+ [bullseye] - gpsd <postponed> (Minor issue; code injection confined to the gpsprof diagnostic client via a hostile gpsd JSON stream or replayed log, local and requires user interaction)
NOTE: https://gitlab.com/gpsd/gpsd/-/work_items/406
NOTE: Fixed by: https://gitlab.com/gpsd/gpsd/-/commit/5a9c44a42136b9bb98d460a8a716e9fd344a8d93
CVE-2026-58275 (Missing authorization in Azure DNS allows an unauthorized attacker to ...)
@@ -2055,7 +2057,9 @@ CVE-2026-34496 (Cwe-269 vulnerability in Johnson Controls victor Web on Windows
CVE-2026-28698 (Pronetiqs IntraVUE versions 3.2.1a14 and prior have an exposure of sen ...)
NOT-FOR-US: Pronetiqs IntraVUE
CVE-2026-25800 (Quinn is a pure-Rust, async-compatible implementation of the IETF QUIC ...)
- - rust-quinn-proto 0.11.16-1
+ - rust-quinn-proto 0.11.16-1 (bug #1141481)
+ [trixie] - rust-quinn-proto <no-dsa> (Minor issue)
+ [bookworm] - rust-quinn-proto <postponed> (Limited support, minor issue)
NOTE: https://github.com/quinn-rs/quinn/security/advisories/GHSA-4w2j-m93h-cj5j
NOTE: https://github.com/quinn-rs/quinn/pull/2694
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0185.html
@@ -2572,6 +2576,8 @@ CVE-2026-59678 (An Incorrect Authorization vulnerability in Linux-Gaming PortPro
CVE-2026-59677 (A Missing Authorization vulnerability in selinux policycoreutils seuns ...)
- policycoreutils 2.7-1
- selinux-python 3.7-1
+ [bookworm] - selinux-python <postponed> (Minor issue; seunshare is not setuid-root in Debian, it gets file capabilities without CAP_KILL, so killall() cannot signal root-owned processes)
+ [bullseye] - selinux-python <postponed> (Minor issue; seunshare is not setuid-root in Debian, it gets file capabilities without CAP_KILL, so killall() cannot signal root-owned processes)
NOTE: src:policycoreutils 2.7 dropped sandbox/seunshare.c core and stopped building
NOTE: policycoreutils-sandbox. Built from selinux-python until 3.7-1 and moved to a
NOTE: separate upstream package.
@@ -2744,6 +2750,8 @@ CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessib
CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO f ...)
- gdk-pixbuf <unfixed>
[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
+ [bookworm] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the rendered image; unfixed upstream)
+ [bullseye] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the rendered image; unfixed upstream)
NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302
CVE-2026-16756 (Missing connection and header-read timeouts and the absence of a concu ...)
NOT-FOR-US: Amazon
@@ -2902,6 +2910,8 @@ CVE-2026-60366 (Vulnerability in the Oracle Platform Security for Java product o
CVE-2026-59676 (A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in s ...)
- policycoreutils 2.7-1
- selinux-python 3.7-1
+ [bookworm] - selinux-python <not-affected> (rm_rf() and its symlink-following openat() recursion introduced upstream in 3.10; earlier seunshare removes the tmpdir with /bin/rm -r run as the calling user)
+ [bullseye] - selinux-python <not-affected> (rm_rf() and its symlink-following openat() recursion introduced upstream in 3.10; earlier seunshare removes the tmpdir with /bin/rm -r run as the calling user)
NOTE: src:policycoreutils 2.7 dropped sandbox/seunshare.c core and stopped building
NOTE: policycoreutils-sandbox. Built from selinux-python until 3.7-1 and moved to a
NOTE: separate upstream package.
@@ -5916,51 +5926,67 @@ CVE-2026-47057 (Vulnerability in Oracle Java SE (component: Scripting). Support
CVE-2026-25832
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-35336
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-49300
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50579
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50580
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50581
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50583
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50584
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50585
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50586
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50587
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50588
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50640
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-50713
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-54435
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-54441
- mbedtls 3.6.7-2
[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
+ [bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 al ...)
{DSA-6396-1}
- chromium 150.0.7871.181-1
@@ -6909,11 +6935,19 @@ CVE-2023-37507 (HCL DevOps Plan is susceptible to an information disclosure that
NOT-FOR-US: HCL
CVE-2026-58624 (Improper input validation in sshd-git in Apache MINA SSHD. Apache MINA ...)
- mina2 <unfixed> (bug #1142679)
+ [bookworm] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-git module)
+ [bullseye] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-git module)
- mina <removed>
+ [bookworm] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-git module)
+ [bullseye] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-git module)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/18
CVE-2026-56624 (Improper certificate validation in Apache MINA SSHD (server-side).Apac ...)
- mina2 <unfixed> (bug #1142679)
+ [bookworm] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-core module)
+ [bullseye] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-core module)
- mina <removed>
+ [bookworm] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-core module)
+ [bullseye] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-core module)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/17
CVE-2026-56623 (Path traversal on Windows in Apache MINA SSHD component sshd-git.Apach ...)
- mina2 <not-affected> (Only affects MINA SSHD on Windows)
@@ -6921,7 +6955,11 @@ CVE-2026-56623 (Path traversal on Windows in Apache MINA SSHD component sshd-git
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/16
CVE-2026-56452 (Path traversal in the sshd-scp component of Apache MINA SSHD.Apache MI ...)
- mina2 <unfixed> (bug #1142679)
+ [bookworm] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-scp module)
+ [bullseye] - mina2 <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-scp module)
- mina <removed>
+ [bookworm] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-scp module)
+ [bullseye] - mina <not-affected> (MINA core does not ship the vulnerable MINA SSHD sshd-scp module)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/15
CVE-2026-61548 [rsyslog mmpstrucdata stack overflow]
- rsyslog 8.2606.0-4
@@ -7235,7 +7273,7 @@ CVE-2026-26197 (HDF5 is a high-performance library and a file format specificati
[bullseye] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/8cd9f7a7ba6757fbb72e36bbe23e127f8507c8a6 (2.1.0)
- TODO: check, isolate upstream change, might only be relevant for 2.0.0 onwards
+ NOTE: Unchecked H5T_ARRAY decode in src/H5Odtype.c predates 1.8.0, not 2.0.0-specific; fix is only on develop/2.1.0, not backported to the 1.14 branch
CVE-2026-25039 (Parsec is a cloud-based application for simple and cryptographically s ...)
NOT-FOR-US: Parsec
CVE-2026-21824 (HCL Commerce contains an privilege escalation vulnerability that could ...)
@@ -10189,15 +10227,18 @@ CVE-2026-50197 (Skipper is an HTTP router and reverse proxy for service composit
NOT-FOR-US: Zalando Skipper
CVE-2026-50163 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, en ...)
- golang-oras-oras-go <unfixed> (bug #1142456)
+ [bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, content/utils.go os.Link()s the unresolved Linkname)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp
NOTE: https://github.com/oras-project/oras-go/pull/1232
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/c463c654ab3ef34422c1764cd619806cebf20451 (v2.6.2)
CVE-2026-50162 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...)
- golang-oras-oras-go <unfixed> (bug #1142456)
+ [bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, content/file.go resolveWritePath() lacks symlink resolution)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5 (v2.6.1)
CVE-2026-50151 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...)
- golang-oras-oras-go <unfixed> (bug #1142456)
+ [bookworm] - golang-oras-oras-go <not-affected> (Blob upload path not present in v1.1.1; no blobStore and the Location header is never read)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7
NOTE: https://github.com/oras-project/oras-go/pull/1152
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/4683c46ef078091544f5f55fd25102f002806991 (v2.6.1)
@@ -10225,6 +10266,7 @@ CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information disc
NOTE: https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...)
- golang-oras-oras-go <unfixed> (bug #1142456)
+ [bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, auth/client.go follows an unvalidated WWW-Authenticate realm)
NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w
NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/7a9f4b0b9558821b0422152ebe21ae56930fe764 (v2.6.1)
CVE-2026-48819 (Hey API is an ecosystem for turning API specifications into production ...)
@@ -10247,6 +10289,8 @@ CVE-2026-45785 (OpenMcdf is a fully .NET / C# library to manipulate Compound Fil
NOT-FOR-US: OpenMcdf
CVE-2026-45784 (rust-openssl provides OpenSSL bindings for the Rust programming langua ...)
- rust-openssl <unfixed> (bug #1142474)
+ [bookworm] - rust-openssl <not-affected> (Vulnerable CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are absent too)
+ [bullseye] - rust-openssl <not-affected> (Vulnerable CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are absent too)
NOTE: https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq
NOTE: https://github.com/rust-openssl/rust-openssl/pull/2638
NOTE: Fixed by: https://github.com/rust-openssl/rust-openssl/commit/19eceb26f2404aae187e5444e65c404ebc1348a7 (openssl-v0.10.80)
@@ -10276,6 +10320,8 @@ CVE-2026-36669 (An unauthenticated arbitrary file upload vulnerability in ck_upl
CVE-2026-16118 (A flaw was found in xdgmime. A heap-based buffer overflow can be trigg ...)
- glib2.0 <unfixed> (bug #1142717)
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; 2-byte OOB write parsing the mime magic file in an XDG data dir, needs an attacker-writable XDG data dir; unfixed upstream)
+ [bullseye] - glib2.0 <postponed> (Minor issue; 2-byte OOB write parsing the mime magic file in an XDG data dir, needs an attacker-writable XDG data dir; unfixed upstream)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3992
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2501732
NOTE: https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41
@@ -10854,6 +10900,8 @@ CVE-2026-54526 (Argo Workflows is an open source container-native workflow engin
NOT-FOR-US: Argo
CVE-2026-54340 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...)
- h2o <removed>
+ [bookworm] - h2o <postponed> (Minor issue, DoS; 2.2.5 h2o_hpack_parse_headers() bounds neither the decoded field count nor retained header state, but amplification requires many deliberately stalled HTTP/2 streams)
+ [bullseye] - h2o <postponed> (Minor issue, DoS; 2.2.5 h2o_hpack_parse_headers() bounds neither the decoded field count nor retained header state, but amplification requires many deliberately stalled HTTP/2 streams)
NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-qcrr-wrhc-pgq9
NOTE: Fixed by (merge commit): https://github.com/h2o/h2o/commit/9265bdd9a996ed992681055e3996baf3e09d2063
CVE-2026-53598 (Prompty is a markdown file format (.prompty) for LLM prompts. Prior to ...)
@@ -10979,10 +11027,14 @@ CVE-2026-44595 (Yamcs is a mission control framework. Prior to 5.12.7, the IAM A
NOT-FOR-US: Yamcs
CVE-2026-44453 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...)
- h2o <removed>
+ [bookworm] - h2o <postponed> (Minor issue, DoS; the alloca() in lib/handler/file.c on_req() is present, but the crash premise is musl's 128KB default pthread stack, and h2o passes no pthread attr so glibc worker threads get the 8MB default)
+ [bullseye] - h2o <postponed> (Minor issue, DoS; the alloca() in lib/handler/file.c on_req() is present, but the crash premise is musl's 128KB default pthread stack, and h2o passes no pthread attr so glibc worker threads get the 8MB default)
NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-rf9v-m59p-mq84
NOTE: Fixed by: https://github.com/h2o/h2o/commit/6b5370d9d09fcf83aa7620ddf77de1954a192181
CVE-2026-44452 (h2o is an HTTP server with support for HTTP/1.x, HTTP/2 and HTTP/3. Pr ...)
- h2o <removed>
+ [bookworm] - h2o <postponed> (Minor issue, DoS; bundled picotls client_hello_decode_server_name() accepts a zero-length SNI hostname, and on_client_hello_ptls() then calls ptls_set_server_name() which strlen()s the non-terminated ClientHello buffer)
+ [bullseye] - h2o <postponed> (Minor issue, DoS; bundled picotls client_hello_decode_server_name() accepts a zero-length SNI hostname, and on_client_hello_ptls() then calls ptls_set_server_name() which strlen()s the non-terminated ClientHello buffer)
NOTE: https://github.com/h2o/h2o/security/advisories/GHSA-w68q-rqwx-7wvq
NOTE: Fixed by (merge): https://github.com/h2o/h2o/commit/8dc37cb1e6171f7f772667618ea440696fed82c3
CVE-2026-44436 (Quicly is an IETF QUIC protocol implementation intended primarily for ...)
@@ -13841,6 +13893,8 @@ CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implement
CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in libsoup's (ver ...)
- libsoup3 <unfixed> (bug #1142841)
- libsoup2.4 <removed>
+ [bookworm] - libsoup2.4 <not-affected> (HTTP/2 support is libsoup3-only, libsoup 2.x has no HTTP/2 implementation)
+ [bullseye] - libsoup2.4 <not-affected> (HTTP/2 support is libsoup3-only, libsoup 2.x has no HTTP/2 implementation)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499939
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540
CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing impleme ...)
@@ -16410,6 +16464,7 @@ CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows for
- python3.14 <unfixed>
- python3.13 <unfixed>
- python3.11 <removed>
+ [bookworm] - python3.11 <postponed> (CPU-only DoS; the quadratic rescan requires the incremental feed() API driven in chunks, a single feed() of the whole document stays linear; no upstream 3.11 fix released, backport PR gh-153042 still unmerged)
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
@@ -19230,12 +19285,6 @@ CVE-2026-12194 (PHPIPAM is affected by an authenticated local file inclusion vul
- phpipam <itp> (bug #731713)
CVE-2025-13475 (In multi-tenanted deployments, the application consent management mech ...)
NOT-FOR-US: WSO2
-CVE-2026-XXXX [RUSTSEC-2026-0185]
- - rust-quinn-proto <unfixed> (bug #1141481)
- [trixie] - rust-quinn-proto <no-dsa> (Minor issue)
- [bookworm] - rust-quinn-proto <postponed> (Limited support, minor issue)
- NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0185.html
- NOTE: https://github.com/quinn-rs/quinn/pull/2694
CVE-2026-XXXX [RUSTSEC-2026-0187]
- rust-lopdf <unfixed> (bug #1141480)
[trixie] - rust-lopdf <no-dsa> (Minor issue)
=====================================
data/dla-needed.txt
=====================================
@@ -378,7 +378,7 @@ libreswan/bookworm
NOTE: 20260611: bookworm LTS handover.
NOTE: 20260611: Sync with maintainer (dkg), hard to test.
--
-libsoup2.4/bullseye
+libsoup2.4
NOTE: 20250408: Added by Front-Desk (Beuc)
NOTE: 20250427: libsoup2.4 2.72.0-2+deb11u2 (bullseye) uploaded ...
NOTE: 20250427: ... without CVE-2025-32907 and CVE-2025-32049.
@@ -408,6 +408,13 @@ libsoup2.4/bullseye
NOTE: 20251209: Remaining open CVEs need upstream work and then revisited,
NOTE: 20251209: possibly also look into wip by spwitton, thus unclaiming
NOTE: 20251209: rather than removing this entry. (ah)
+ NOTE: 20260727: Widened to bookworm: the same unfixed CVEs affect
+ NOTE: 20260727: 2.74.3-1+deb12u1. Fix CVE-2026-12547, CVE-2026-12548,
+ NOTE: 20260727: CVE-2026-15709, CVE-2026-15711, CVE-2026-15713,
+ NOTE: 20260727: CVE-2026-15714, CVE-2026-66337, CVE-2026-66338 and
+ NOTE: 20260727: CVE-2026-66339 in bookworm too. CVE-2026-15712 is
+ NOTE: 20260727: not-affected (no HTTP/2 in libsoup 2.x). Only
+ NOTE: 20260727: CVE-2026-12548 has an upstream fix (3.7.1). (utkarsh)
--
libssh2 (eamanu)
NOTE: 20260625: Added by Front-Desk (lamby)
@@ -738,6 +745,14 @@ rabbitmq-server/bullseye
NOTE: 20260504: Added by coordinator (santiago)
NOTE: 20260504: Added to address out-standing minor issues
--
+redis
+ NOTE: 20260727: Added by Front-Desk (utkarsh)
+ NOTE: 20260727: CVE-2026-66373: double free in the stream consumer PEL
+ NOTE: 20260727: loader (rdbLoadObject), reachable via RESTORE. Fixed
+ NOTE: 20260727: upstream in 6.2.23/7.2.15/8.6.5; bookworm ships
+ NOTE: 20260727: 7.0.15-1~deb12u8 and bullseye 6.0.16-1+deb11u8, both
+ NOTE: 20260727: still unguarded.
+--
request-tracker4/bullseye (Andrew Ruthven)
NOTE: 20260529: Added by Front-Desk (dleidert)
NOTE: 20260529: Follow DSA in preparation by maintainer (dleidert/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/eed1b04e99770af2fc258ff5bec8f06273e6d48c...37cde6c9adde38c210e94f96a96f4f00cd77ad23
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/eed1b04e99770af2fc258ff5bec8f06273e6d48c...37cde6c9adde38c210e94f96a96f4f00cd77ad23
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/b226bf53/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list