[Git][security-tracker-team/security-tracker][master] 2 commits: lts: glib2.0 postponed in bookworm/bullseye

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Mon Jul 27 01:06:22 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2caece0f by Utkarsh Gupta at 2026-07-27T04:49:06+05:30
lts: glib2.0 postponed in bookworm/bullseye

- - - - -
6fd1824e by Utkarsh Gupta at 2026-07-27T05:32:33+05:30
lts: fluidsynth postponed in bookworm/bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2157,12 +2157,15 @@ CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious boot
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
 CVE-2026-58264 [heap-based buffer overrun in command handler]
 	- fluidsynth 2.5.6+dfsg-1
+	[bookworm] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
+	[bullseye] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
 	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-mqmq-w63q-cj94
 	NOTE: https://github.com/FluidSynth/fluidsynth/pull/1796
 	NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/8131539ad6c37a832bd67ee26791ef8e28259423 (v1.1.2)
 	NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/762a3bd39a431cd45abf3bbcce7286c87909d087 (v2.5.6)
 CVE-2026-61714 [heap-based buffer overflow in MIDI player]
 	- fluidsynth 2.5.6+dfsg-1
+	[bookworm] - fluidsynth <postponed> (Needs a non-default synth.midi-channels > 16; MIDI file channels are masked to 4 bits so a crafted file cannot reach it)
 	[bullseye] - fluidsynth <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6
 	NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/6c593180ce05f8bbbd07217456bc4376a4ab4505 (v2.2.4)
@@ -7303,6 +7306,8 @@ CVE-2026-15813 (A vulnerability was found in the network packet de-fragmentation
 CVE-2026-15588 (A denial-of-service and resource exhaustion vulnerability exists withi ...)
 	- glib2.0 <unfixed> (bug #1142835)
 	[trixie] - glib2.0 <no-dsa> (Minor issue)
+	[bookworm] - glib2.0 <postponed> (Minor issue; unbounded pre-auth SASL line read in GDBusServer lets an unauthenticated peer exhaust memory; DoS only, the system/session buses run dbus-daemon)
+	[bullseye] - glib2.0 <postponed> (Minor issue; unbounded pre-auth SASL line read in GDBusServer lets an unauthenticated peer exhaust memory; DoS only, the system/session buses run dbus-daemon)
 	NOTE: https://gitlab.gnome.org/GNOME/glib/-/issues/3985
 	NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5240
 	NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5241



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37cde6c9adde38c210e94f96a96f4f00cd77ad23...6fd1824ec5a067d88ef895deb90fa00f7205c360

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37cde6c9adde38c210e94f96a96f4f00cd77ad23...6fd1824ec5a067d88ef895deb90fa00f7205c360
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/0c1aee5f/attachment.htm>


More information about the debian-security-tracker-commits mailing list