[Git][security-tracker-team/security-tracker][master] 5 commits: mark CVE-2026-14957 as EOL for Bullseye

Thorsten Alteholz (@alteholz) alteholz at debian.org
Fri Jul 31 18:24:14 BST 2026



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e270b87b by Thorsten Alteholz at 2026-07-31T19:23:55+02:00
mark CVE-2026-14957 as EOL for Bullseye

- - - - -
bb0a0c33 by Thorsten Alteholz at 2026-07-31T19:23:57+02:00
mark CVE-2026-6879 as EOL for Bullseye

- - - - -
4332ed3b by Thorsten Alteholz at 2026-07-31T19:23:59+02:00
mark CVE-2026-67214 and CVE-2026-67213 as postponed for Bullseye

- - - - -
5535473d by Thorsten Alteholz at 2026-07-31T19:24:00+02:00
add libgd2

- - - - -
0883e9c5 by Thorsten Alteholz at 2026-07-31T19:24:00+02:00
add librabbitmq

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2191,12 +2191,14 @@ CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to uncontrolled recursion lea
 CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...)
 	- node-postcss 8.5.15+~cs9.3.39-1
 	- node-mocha 9.1.4+ds1+~cs28.2.8-1
+	[bullseye] - node-mocha <postponed> (Minor issue, only test framework)
 	NOTE: node-postcss bundles nanoid
 	NOTE: node-mocha/9.1.4+ds1+~cs28.2.8-1 removes the node-nanoid copy
 	NOTE: Fixed by: https://github.com/ai/nanoid/commit/6de05d794f62eeac3f527c74c34c6af0c1d32e49 (5.1.16)
 CVE-2026-67213 (nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...)
 	- node-postcss 8.5.8+~cs9.3.30-1
 	- node-mocha 9.1.4+ds1+~cs28.2.8-1
+	[bullseye] - node-mocha <postponed> (Minor issue, only test framework)
 	NOTE: node-postcss bundles nanoid
 	NOTE: node-mocha/9.1.4+ds1+~cs28.2.8-1 removes the node-nanoid copy
 	NOTE: Fixed by: https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7 (5.1.6)
@@ -2850,6 +2852,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
 	- python3.11 <removed>
 	- python3.9 <removed>
 	- python2.7 <removed>
+	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
 	- pypy3 <unfixed>
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/
 	NOTE: https://github.com/python/cpython/issues/152674
@@ -4341,6 +4344,7 @@ CVE-2026-16566
 	TODO: check upstream report and status on fix
 CVE-2026-14957
 	- libreswan <unfixed> (bug #1143067)
+	[bullseye] - libreswan <end-of-life> (EOL in bullseye LTS)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2501764
 	NOTE: https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt
 	NOTE: Patch: https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.patch


=====================================
data/dla-needed.txt
=====================================
@@ -341,6 +341,9 @@ libde265
   NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
   NOTE: 20260709: upstream fixes v1.0.19-v1.1.1 newer than Debian 1.0.11.
 --
+libgd2
+  NOTE: 20260731: Added by Front-Desk (ta)
+--
 libheif
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
@@ -351,6 +354,9 @@ libio-compress-perl
 libpgjava
   NOTE: 20260613: Added by Front-Desk (rouca)
 --
+librabbitmq
+  NOTE: 20260731: Added by Front-Desk (ta)
+--
 libreoffice/bullseye (santiago)
   NOTE: 20260508: Added by Front-Desk (dleidert)
   NOTE: 20260508: Follow DSA-6251-1 (dleidert/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ecb2f0412a5fb484c01ec0bb8de5cc47d1d49980...0883e9c5d8c8ee98c8eb5a97802d44503c7f2b97

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ecb2f0412a5fb484c01ec0bb8de5cc47d1d49980...0883e9c5d8c8ee98c8eb5a97802d44503c7f2b97
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/78d2e450/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list