[Git][security-tracker-team/security-tracker][master] Reserve DSA number for php8.4 update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 31 22:10:45 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
84f44d10 by Salvatore Bonaccorso at 2026-07-31T23:09:55+02:00
Reserve DSA number for php8.4 update

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -960,6 +960,7 @@ CVE-2026-62268
 CVE-2026-9672
 	- libgd2 2.3.3-14 (bug #1143152)
 	- php8.4 8.4.24-1 (unimportant)
+	[trixie] - php8.4 8.4.24-1~deb13u1
 	- php8.2 <removed> (unimportant)
 	- php7.4 <removed> (unimportant)
 	NOTE: Fixed by: https://github.com/php/php-src/commit/b590f0380fda26ed180874a0255f0be078434315 (php-8.4.24)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[31 Jul 2026] DSA-6406-1 php8.4 - security update
+	{CVE-2026-7260 CVE-2026-17543 CVE-2026-17544}
+	[trixie] - php8.4 8.4.24-1~deb13u1
 [31 Jul 2026] DSA-6405-1 linux - security update
 	{CVE-2026-45944 CVE-2026-53005 CVE-2026-53260 CVE-2026-53365 CVE-2026-63970 CVE-2026-64192 CVE-2026-64206 CVE-2026-64227 CVE-2026-64286 CVE-2026-64287 CVE-2026-64307 CVE-2026-64341 CVE-2026-64352 CVE-2026-64361 CVE-2026-64363 CVE-2026-64364 CVE-2026-64369 CVE-2026-64371 CVE-2026-64375 CVE-2026-64390 CVE-2026-64401 CVE-2026-64405 CVE-2026-64413 CVE-2026-64416 CVE-2026-64421 CVE-2026-64428 CVE-2026-64434 CVE-2026-64438 CVE-2026-64441 CVE-2026-64461 CVE-2026-64462 CVE-2026-64472 CVE-2026-64481 CVE-2026-64488 CVE-2026-64493 CVE-2026-64507 CVE-2026-64508 CVE-2026-64509 CVE-2026-64510 CVE-2026-64530 CVE-2026-64531 CVE-2026-64532 CVE-2026-64533 CVE-2026-64534 CVE-2026-64535 CVE-2026-64537 CVE-2026-64538 CVE-2026-64539 CVE-2026-64540 CVE-2026-64541 CVE-2026-64542 CVE-2026-64543 CVE-2026-64544 CVE-2026-64545 CVE-2026-64546 CVE-2026-64547 CVE-2026-64548 CVE-2026-64549 CVE-2026-64550 CVE-2026-64551 CVE-2026-64552 CVE-2026-64553 CVE-2026-64554 CVE-2026-64555 CVE-2026-64557 CVE-2026-64558 CVE-2026-64559 CVE-2026-64560}
 	[trixie] - linux 6.12.100-1


=====================================
data/dsa-needed.txt
=====================================
@@ -117,9 +117,6 @@ pdfminer (carnil)
 perl (carnil)
   Comment from maintainer: I'd prefer to wait until upstream gets the point releases out
 --
-php8.4 (carnil)
-  Maintainer preparing updates
---
 podman
 --
 proftpd-dfsg



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/84f44d103b137fa7a60d67cf6f3c34afc537582a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/84f44d103b137fa7a60d67cf6f3c34afc537582a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/a10a3521/attachment.htm>


More information about the debian-security-tracker-commits mailing list