[Git][security-tracker-team/security-tracker][master] Track proposed updates for ruby-css-parser via {trixie,bookworm}-pu
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Jun 6 21:17:12 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5303c655 by Salvatore Bonaccorso at 2026-06-06T22:16:42+02:00
Track proposed updates for ruby-css-parser via {trixie,bookworm}-pu
- - - - -
3 changed files:
- data/CVE/list
- data/next-oldstable-point-update.txt
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -14707,6 +14707,8 @@ CVE-2026-44348 (PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before
NOTE: Fixed by: https://github.com/podofo/podofo/commit/696d765c3a71ef224d4abffe1f174fef11292d7e (1.0.4)
CVE-2026-44312 (css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Pa ...)
- ruby-css-parser 2.1.0-1
+ [trixie] - ruby-css-parser <no-dsa> (Minor issue)
+ [bookworm] - ruby-css-parser <no-dsa> (Minor issue)
NOTE: https://github.com/premailer/css_parser/security/advisories/GHSA-ff6c-w6qf-7xqc
NOTE: https://github.com/premailer/css_parser/issues/185
NOTE: Fixed by: https://github.com/premailer/css_parser/commit/35e689c904225add78e0c488cf04bad052666449 (v2.1.0)
=====================================
data/next-oldstable-point-update.txt
=====================================
@@ -112,3 +112,5 @@ CVE-2026-48711
[bookworm] - sshfs-fuse 3.7.3-1.2~deb12u1
CVE-2026-50593
[bookworm] - graphite2 1.3.14-1+deb12u1
+CVE-2026-44312
+ [bookworm] - ruby-css-parser 1.6.0-2+deb12u1
=====================================
data/next-point-update.txt
=====================================
@@ -212,3 +212,5 @@ CVE-2026-48711
[trixie] - sshfs-fuse 3.7.3-1.2~deb13u1
CVE-2026-50593
[trixie] - graphite2 1.3.14-2+deb13u1
+CVE-2026-44312
+ [trixie] - ruby-css-parser 1.19.0-1+deb13u1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5303c655924cf1c87e9a042f7746efe1d4efccb4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5303c655924cf1c87e9a042f7746efe1d4efccb4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260606/c1be7c0d/attachment.htm>
More information about the debian-security-tracker-commits
mailing list