[Git][security-tracker-team/security-tracker][master] Reserve DLA-4704-1 for libraw

Guilhem Moulin (@guilhem) guilhem at debian.org
Wed Jul 29 03:51:42 BST 2026



Guilhem Moulin pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1fb91c8a by Guilhem Moulin at 2026-07-29T04:51:28+02:00
Reserve DLA-4704-1 for libraw

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -83883,8 +83883,6 @@ CVE-2026-5344 (A security vulnerability has been detected in Textpattern up to 4
 CVE-2026-5342 (A flaw has been found in LibRaw up to 0.22.0. This affects the functio ...)
 	- libraw 0.22.1-1 (bug #1132655)
 	[trixie] - libraw <no-dsa> (Minor issue)
-	[bookworm] - libraw <no-dsa> (Minor issue)
-	[bullseye] - libraw <postponed> (Minor issue)
 	NOTE: https://github.com/LibRaw/LibRaw/issues/795
 	NOTE: Fixed by: https://github.com/LibRaw/LibRaw/commit/b8397cd45657b84e88bd1202528d1764265f185c
 	NOTE: Fixed by: https://github.com/LibRaw/LibRaw/commit/2468614a9cbcab6b75ca279ab60cac62156f7aeb (0.22.1)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,7 @@
+[29 Jul 2026] DLA-4704-1 libraw - security update
+	{CVE-2026-5342 CVE-2026-20884 CVE-2026-20889 CVE-2026-21413 CVE-2026-24660}
+	[bullseye] - libraw 0.20.2-1+deb11u3
+	[bookworm] - libraw 0.20.2-2.1+deb12u2
 [28 Jul 2026] DLA-4703-1 openjdk-17 - security update
 	{CVE-2026-41254 CVE-2026-46917 CVE-2026-46968 CVE-2026-47010 CVE-2026-47021 CVE-2026-47027 CVE-2026-47059 CVE-2026-47063 CVE-2026-60147}
 	[bullseye] - openjdk-17 17.0.20+8-1~deb11u1


=====================================
data/dla-needed.txt
=====================================
@@ -364,10 +364,6 @@ libio-compress-perl
 libpgjava
   NOTE: 20260613: Added by Front-Desk (rouca)
 --
-libraw (guilhem)
-  NOTE: 20260417: Added by Front-Desk (rouca)
-  NOTE: 20260718: Also add for bookworm (Beuc/front-desk)
---
 libreoffice/bullseye (santiago)
   NOTE: 20260508: Added by Front-Desk (dleidert)
   NOTE: 20260508: Follow DSA-6251-1 (dleidert/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb91c8a0dc480c655c0fb084016b59b726b4487

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1fb91c8a0dc480c655c0fb084016b59b726b4487
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/856917fc/attachment.htm>


More information about the debian-security-tracker-commits mailing list