[Git][security-tracker-team/security-tracker][master] Reserve DLA-4559-1 for imagemagick
Bastien Roucariès (@rouca)
rouca at debian.org
Fri May 1 21:29:40 BST 2026
Bastien Roucariès pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b66529a4 by Bastien Roucariès at 2026-05-01T22:29:26+02:00
Reserve DLA-4559-1 for imagemagick
- - - - -
2 changed files:
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[01 May 2026] DLA-4559-1 imagemagick - security update
+ {CVE-2026-33899 CVE-2026-33900 CVE-2026-33901 CVE-2026-33905 CVE-2026-33908 CVE-2026-34238 CVE-2026-40310 CVE-2026-40311}
+ [bullseye] - imagemagick 8:6.9.11.60+dfsg-1.3+deb11u12
[01 May 2026] DLA-4558-1 libexif - security update
{CVE-2026-32775 CVE-2026-40385 CVE-2026-40386}
[bullseye] - libexif 0.6.22-3+deb11u1
=====================================
data/dla-needed.txt
=====================================
@@ -201,12 +201,6 @@ grub2
NOTE: 20260406: grub2/bookworm approved https://bugs.debian.org/1132510 (partial update)
NOTE: 20260407: shim/bookworm approved https://bugs.debian.org/1131862 (but waiting for Microsoft signature)
--
-imagemagick (rouca)
- NOTE: 20260228: Added by Front-Desk (charles)
- NOTE: 20260228: In dsa-needed, coordinate with secteam (charles)
- NOTE: 20260311: made a partial release (rouca)
- NOTE: 20260419: made a partial release (rouca)
---
jackson-core (Markus Koschany)
NOTE: 20250707: Added by Front-Desk (apo)
NOTE: 20251016: A single patch is not possible to apply to fix the CVE. I'm working on backporting more than one.
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b66529a4ca360e0be4431688e29597a0e8717fe1
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b66529a4ca360e0be4431688e29597a0e8717fe1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260501/95c8a618/attachment.htm>
More information about the debian-security-tracker-commits
mailing list