[Git][security-tracker-team/security-tracker][master] 5 commits: mark CVE-2026-14957 as EOL for Bullseye
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Fri Jul 31 18:24:14 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e270b87b by Thorsten Alteholz at 2026-07-31T19:23:55+02:00
mark CVE-2026-14957 as EOL for Bullseye
- - - - -
bb0a0c33 by Thorsten Alteholz at 2026-07-31T19:23:57+02:00
mark CVE-2026-6879 as EOL for Bullseye
- - - - -
4332ed3b by Thorsten Alteholz at 2026-07-31T19:23:59+02:00
mark CVE-2026-67214 and CVE-2026-67213 as postponed for Bullseye
- - - - -
5535473d by Thorsten Alteholz at 2026-07-31T19:24:00+02:00
add libgd2
- - - - -
0883e9c5 by Thorsten Alteholz at 2026-07-31T19:24:00+02:00
add librabbitmq
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -2191,12 +2191,14 @@ CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to uncontrolled recursion lea
CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...)
- node-postcss 8.5.15+~cs9.3.39-1
- node-mocha 9.1.4+ds1+~cs28.2.8-1
+ [bullseye] - node-mocha <postponed> (Minor issue, only test framework)
NOTE: node-postcss bundles nanoid
NOTE: node-mocha/9.1.4+ds1+~cs28.2.8-1 removes the node-nanoid copy
NOTE: Fixed by: https://github.com/ai/nanoid/commit/6de05d794f62eeac3f527c74c34c6af0c1d32e49 (5.1.16)
CVE-2026-67213 (nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...)
- node-postcss 8.5.8+~cs9.3.30-1
- node-mocha 9.1.4+ds1+~cs28.2.8-1
+ [bullseye] - node-mocha <postponed> (Minor issue, only test framework)
NOTE: node-postcss bundles nanoid
NOTE: node-mocha/9.1.4+ds1+~cs28.2.8-1 removes the node-nanoid copy
NOTE: Fixed by: https://github.com/ai/nanoid/commit/cb3626d0f3342fdf179cd425fd9c4fbb92c7d0e7 (5.1.6)
@@ -2850,6 +2852,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
+ [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed>
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/
NOTE: https://github.com/python/cpython/issues/152674
@@ -4341,6 +4344,7 @@ CVE-2026-16566
TODO: check upstream report and status on fix
CVE-2026-14957
- libreswan <unfixed> (bug #1143067)
+ [bullseye] - libreswan <end-of-life> (EOL in bullseye LTS)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2501764
NOTE: https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.txt
NOTE: Patch: https://libreswan.org/security/CVE-2026-14957/CVE-2026-14957.patch
=====================================
data/dla-needed.txt
=====================================
@@ -341,6 +341,9 @@ libde265
NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
NOTE: 20260709: upstream fixes v1.0.19-v1.1.1 newer than Debian 1.0.11.
--
+libgd2
+ NOTE: 20260731: Added by Front-Desk (ta)
+--
libheif
NOTE: 20260612: Added by Front-Desk (rouca)
--
@@ -351,6 +354,9 @@ libio-compress-perl
libpgjava
NOTE: 20260613: Added by Front-Desk (rouca)
--
+librabbitmq
+ NOTE: 20260731: Added by Front-Desk (ta)
+--
libreoffice/bullseye (santiago)
NOTE: 20260508: Added by Front-Desk (dleidert)
NOTE: 20260508: Follow DSA-6251-1 (dleidert/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ecb2f0412a5fb484c01ec0bb8de5cc47d1d49980...0883e9c5d8c8ee98c8eb5a97802d44503c7f2b97
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ecb2f0412a5fb484c01ec0bb8de5cc47d1d49980...0883e9c5d8c8ee98c8eb5a97802d44503c7f2b97
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/78d2e450/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list