[Git][security-tracker-team/security-tracker][master] 2 commits: lts: glib2.0 postponed in bookworm/bullseye
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Mon Jul 27 01:06:22 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2caece0f by Utkarsh Gupta at 2026-07-27T04:49:06+05:30
lts: glib2.0 postponed in bookworm/bullseye
- - - - -
6fd1824e by Utkarsh Gupta at 2026-07-27T05:32:33+05:30
lts: fluidsynth postponed in bookworm/bullseye
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2157,12 +2157,15 @@ CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious boot
NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
CVE-2026-58264 [heap-based buffer overrun in command handler]
- fluidsynth 2.5.6+dfsg-1
+ [bookworm] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
+ [bullseye] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-mqmq-w63q-cj94
NOTE: https://github.com/FluidSynth/fluidsynth/pull/1796
NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/8131539ad6c37a832bd67ee26791ef8e28259423 (v1.1.2)
NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/762a3bd39a431cd45abf3bbcce7286c87909d087 (v2.5.6)
CVE-2026-61714 [heap-based buffer overflow in MIDI player]
- fluidsynth 2.5.6+dfsg-1
+ [bookworm] - fluidsynth <postponed> (Needs a non-default synth.midi-channels > 16; MIDI file channels are masked to 4 bits so a crafted file cannot reach it)
[bullseye] - fluidsynth <not-affected> (Vulnerable code not present)
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6
NOTE: Introduced with: https://github.com/FluidSynth/fluidsynth/commit/6c593180ce05f8bbbd07217456bc4376a4ab4505 (v2.2.4)
@@ -7303,6 +7306,8 @@ CVE-2026-15813 (A vulnerability was found in the network packet de-fragmentation
CVE-2026-15588 (A denial-of-service and resource exhaustion vulnerability exists withi ...)
- glib2.0 <unfixed> (bug #1142835)
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue; unbounded pre-auth SASL line read in GDBusServer lets an unauthenticated peer exhaust memory; DoS only, the system/session buses run dbus-daemon)
+ [bullseye] - glib2.0 <postponed> (Minor issue; unbounded pre-auth SASL line read in GDBusServer lets an unauthenticated peer exhaust memory; DoS only, the system/session buses run dbus-daemon)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/issues/3985
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5240
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5241
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37cde6c9adde38c210e94f96a96f4f00cd77ad23...6fd1824ec5a067d88ef895deb90fa00f7205c360
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/37cde6c9adde38c210e94f96a96f4f00cd77ad23...6fd1824ec5a067d88ef895deb90fa00f7205c360
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/0c1aee5f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list