[Git][security-tracker-team/security-tracker][master] bullseye triagging

Bastien Roucariès (@rouca) rouca at debian.org
Thu Jun 11 21:26:27 BST 2026



Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a6086eca by Bastien Roucariès at 2026-06-11T22:26:15+02:00
bullseye triagging

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2795,6 +2795,7 @@ CVE-2026-9669 (bz2.BZ2Decompressor objects could be reused after a decompression
 	- python3.11 <removed>
 	[bookworm] - python3.11 <no-dsa> (Minor issue)
 	- python3.9 <removed>
+	[bullseye] - python3.9 <postponed> (Minor issue)
 	NOTE: https://github.com/python/cpython/issues/150599
 	NOTE: https://github.com/python/cpython/pull/150600
 	NOTE: https://github.com/python/cpython/commit/d3ca26983dfbccdf609f24ff5877dc3118e4702d (3.15 branch)
@@ -5675,6 +5676,7 @@ CVE-2026-8916 (Out-of-bounds write vulnerability in Samsung Open Source rlottie
 	- rlottie <unfixed> (bug #1138916)
 	[trixie] - rlottie <no-dsa> (Minor issue)
 	[bookworm] - rlottie <no-dsa> (Minor issue)
+	[bullseye] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/589
 	NOTE: https://github.com/Samsung/rlottie/commit/ffe60942892c3d68b14560761ea920d360ef51bb
 CVE-2026-8762
@@ -6006,6 +6008,7 @@ CVE-2026-10305 (Out-of-bounds read vulnerability in Samsung Open Source rlottie
 	- rlottie <unfixed> (bug #1139179)
 	[trixie] - rlottie <no-dsa> (Minor issue)
 	[bookworm] - rlottie <no-dsa> (Minor issue)
+	[bullseye] - rlottie <postponed> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/587
 	NOTE: https://github.com/Samsung/rlottie/commit/b4f5101a4d1a8da60cc14cfd05608551b3448c77
 CVE-2025-71316 (SQLite 'sqldiff.exe' does not securely handle the way the Microsoft Wi ...)
@@ -9009,7 +9012,7 @@ CVE-2026-49214 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation i
 	- php-guzzlehttp-psr7 2.10.3-1 (bug #1138265)
 	[trixie] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
 	[bookworm] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
-	[bullseye] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+	[bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue)
 	NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-hq7v-mx3g-29hw
 CVE-2026-48998 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
 	- php-guzzlehttp-psr7 2.10.3-1 (bug #1138265)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6086ecaf2390fbfa440dc35659e2bac02e3f604

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a6086ecaf2390fbfa440dc35659e2bac02e3f604
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260611/b7ad8324/attachment.htm>


More information about the debian-security-tracker-commits mailing list