[Git][security-tracker-team/security-tracker][master] bullseye triagging
Bastien Roucariès (@rouca)
rouca at debian.org
Thu Jun 11 21:26:27 BST 2026
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a6086eca by Bastien Roucariès at 2026-06-11T22:26:15+02:00
bullseye triagging
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2795,6 +2795,7 @@ CVE-2026-9669 (bz2.BZ2Decompressor objects could be reused after a decompression
- python3.11 <removed>
[bookworm] - python3.11 <no-dsa> (Minor issue)
- python3.9 <removed>
+ [bullseye] - python3.9 <postponed> (Minor issue)
NOTE: https://github.com/python/cpython/issues/150599
NOTE: https://github.com/python/cpython/pull/150600
NOTE: https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d (3.15 branch)
@@ -5675,6 +5676,7 @@ CVE-2026-8916 (Out-of-bounds write vulnerability in Samsung Open Source rlottie
- rlottie <unfixed> (bug #1138916)
[trixie] - rlottie <no-dsa> (Minor issue)
[bookworm] - rlottie <no-dsa> (Minor issue)
+ [bullseye] - rlottie <postponed> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/589
NOTE: https://github.com/Samsung/rlottie/commit/ffe60942892c3d68b14560761ea920d360ef51bb
CVE-2026-8762
@@ -6006,6 +6008,7 @@ CVE-2026-10305 (Out-of-bounds read vulnerability in Samsung Open Source rlottie
- rlottie <unfixed> (bug #1139179)
[trixie] - rlottie <no-dsa> (Minor issue)
[bookworm] - rlottie <no-dsa> (Minor issue)
+ [bullseye] - rlottie <postponed> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/587
NOTE: https://github.com/Samsung/rlottie/commit/b4f5101a4d1a8da60cc14cfd05608551b3448c77
CVE-2025-71316 (SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Wi ...)
@@ -9009,7 +9012,7 @@ CVE-2026-49214 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation i
- php-guzzlehttp-psr7 2.10.3-1 (bug #1138265)
[trixie] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
[bookworm] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
- [bullseye] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+ [bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue)
NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-hq7v-mx3g-29hw
CVE-2026-48998 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
- php-guzzlehttp-psr7 2.10.3-1 (bug #1138265)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6086ecaf2390fbfa440dc35659e2bac02e3f604
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6086ecaf2390fbfa440dc35659e2bac02e3f604
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260611/b7ad8324/attachment.htm>
More information about the debian-security-tracker-commits
mailing list