[Git][security-tracker-team/security-tracker][master] 4 commits: add libssh

Thorsten Alteholz (@alteholz) alteholz at debian.org
Fri Jul 31 18:42:14 BST 2026



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
179287bc by Thorsten Alteholz at 2026-07-31T19:27:48+02:00
add libssh

- - - - -
0dd47110 by Thorsten Alteholz at 2026-07-31T19:31:25+02:00
add libyaml-syck-perl

- - - - -
93e28a48 by Thorsten Alteholz at 2026-07-31T19:37:24+02:00
add opensc

- - - - -
5bde46ed by Thorsten Alteholz at 2026-07-31T19:40:13+02:00
libxmltok needs to be fixed in bookworm as well

- - - - -


1 changed file:

- data/dla-needed.txt


Changes:

=====================================
data/dla-needed.txt
=====================================
@@ -404,6 +404,9 @@ libsoup2.4
   NOTE: 20260727: not-affected (no HTTP/2 in libsoup 2.x). Only
   NOTE: 20260727: CVE-2026-12548 has an upstream fix (3.7.1). (utkarsh)
 --
+libssh
+  NOTE: 20260731: Added by Front-Desk (ta)
+--
 libssh2 (eamanu)
   NOTE: 20260625: Added by Front-Desk (lamby)
   NOTE: 20260702: patches are under review (eamanu)
@@ -423,17 +426,19 @@ libwebsockets/bookworm
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
 --
-libxmltok/bullseye
+libxmltok
   NOTE: 20250421: Added by Front-Desk (ta)
   NOTE: 20250421: Also review all other expat CVEs. (bunk)
   NOTE: 20250421: Fixing the expat copy in xmlrpc-c at the same time would make sense. (bunk)
-  NOTE: 20250505: WIP there are lots of CVEs to review (ta)
 --
 libxslt/bullseye
   NOTE: 20250930: Added by Front-Desk (rouca)
   NOTE: 20251020: In progress, waiting for upstream action (guilhem)
   NOTE: 20251104: Done, but waiting for upstream to merge before uploading and issuing the DLA (guilhem)
 --
+libyaml-syck-perl
+  NOTE: 20260731: Added by Front-Desk (ta)
+--
 linux (Ben Hutchings)
   NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
 --
@@ -585,6 +590,10 @@ openimageio
   NOTE: 20260726: 2.5.18.0. Note trixie also lacks USE_OPENJPH, so it looks
   NOTE: 20260726: not-affected by CVE-2026-43905. (utkarsh/front-desk)
 --
+opensc
+  NOTE: 20260731: Added by Front-Desk (ta)
+  NOTE: 20260731: lots of no-dsa issues piled up (ta)
+--
 openvpn/bullseye (dleidert)
   NOTE: 20260703: Added by Front-Desk (dleidert)
   NOTE: 20260703: A regression has been reported; and a new set of CVEs is out (dleidert/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0883e9c5d8c8ee98c8eb5a97802d44503c7f2b97...5bde46ed9ee1230a95c37400bd708388ee81beac

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0883e9c5d8c8ee98c8eb5a97802d44503c7f2b97...5bde46ed9ee1230a95c37400bd708388ee81beac
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/359ec4f8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list