[Git][security-tracker-team/security-tracker][master] CVE-2026-7774/bullseye

Bastien Roucariès (@rouca) rouca at debian.org
Mon Jun 8 21:20:43 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a853ef77 by Bastien Roucariès at 2026-06-08T22:20:09+02:00
CVE-2026-7774/bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2829,6 +2829,7 @@ CVE-2026-7774 (tarfile.data_filter could be bypassed using crafted link entries,
 	- python3.11 <removed>
 	[bookworm] - python3.11 <no-dsa> (Minor issue)
 	- python3.9 <removed>
+	[bullseye] - python3.9 <postponed> (Minor issue)
 	- python2.7 <removed>
 	[bullseye] - python2.7 <end-of-life> (not supported in bullseye)
 	- pypy3 <unfixed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a853ef771b2c77c2cb8687e66d133e067baf80f3

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a853ef771b2c77c2cb8687e66d133e067baf80f3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260608/eee4342c/attachment.htm>


More information about the debian-security-tracker-commits mailing list