[Git][security-tracker-team/security-tracker][master] 4 commits: add libssh
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Fri Jul 31 18:42:14 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
179287bc by Thorsten Alteholz at 2026-07-31T19:27:48+02:00
add libssh
- - - - -
0dd47110 by Thorsten Alteholz at 2026-07-31T19:31:25+02:00
add libyaml-syck-perl
- - - - -
93e28a48 by Thorsten Alteholz at 2026-07-31T19:37:24+02:00
add opensc
- - - - -
5bde46ed by Thorsten Alteholz at 2026-07-31T19:40:13+02:00
libxmltok needs to be fixed in bookworm as well
- - - - -
1 changed file:
- data/dla-needed.txt
Changes:
=====================================
data/dla-needed.txt
=====================================
@@ -404,6 +404,9 @@ libsoup2.4
NOTE: 20260727: not-affected (no HTTP/2 in libsoup 2.x). Only
NOTE: 20260727: CVE-2026-12548 has an upstream fix (3.7.1). (utkarsh)
--
+libssh
+ NOTE: 20260731: Added by Front-Desk (ta)
+--
libssh2 (eamanu)
NOTE: 20260625: Added by Front-Desk (lamby)
NOTE: 20260702: patches are under review (eamanu)
@@ -423,17 +426,19 @@ libwebsockets/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
--
-libxmltok/bullseye
+libxmltok
NOTE: 20250421: Added by Front-Desk (ta)
NOTE: 20250421: Also review all other expat CVEs. (bunk)
NOTE: 20250421: Fixing the expat copy in xmlrpc-c at the same time would make sense. (bunk)
- NOTE: 20250505: WIP there are lots of CVEs to review (ta)
--
libxslt/bullseye
NOTE: 20250930: Added by Front-Desk (rouca)
NOTE: 20251020: In progress, waiting for upstream action (guilhem)
NOTE: 20251104: Done, but waiting for upstream to merge before uploading and issuing the DLA (guilhem)
--
+libyaml-syck-perl
+ NOTE: 20260731: Added by Front-Desk (ta)
+--
linux (Ben Hutchings)
NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
--
@@ -585,6 +590,10 @@ openimageio
NOTE: 20260726: 2.5.18.0. Note trixie also lacks USE_OPENJPH, so it looks
NOTE: 20260726: not-affected by CVE-2026-43905. (utkarsh/front-desk)
--
+opensc
+ NOTE: 20260731: Added by Front-Desk (ta)
+ NOTE: 20260731: lots of no-dsa issues piled up (ta)
+--
openvpn/bullseye (dleidert)
NOTE: 20260703: Added by Front-Desk (dleidert)
NOTE: 20260703: A regression has been reported; and a new set of CVEs is out (dleidert/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0883e9c5d8c8ee98c8eb5a97802d44503c7f2b97...5bde46ed9ee1230a95c37400bd708388ee81beac
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0883e9c5d8c8ee98c8eb5a97802d44503c7f2b97...5bde46ed9ee1230a95c37400bd708388ee81beac
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/359ec4f8/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list