[Git][security-tracker-team/security-tracker][master] lts: drop some bullseye specific packages
Emilio Pozuelo Monfort (@pochu)
pochu at debian.org
Tue Sep 1 08:37:43 BST 2026
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker
Commits:
847b872b by Emilio Pozuelo Monfort at 2026-09-01T09:37:33+02:00
lts: drop some bullseye specific packages
- - - - -
1 changed file:
- data/dla-needed.txt
Changes:
=====================================
data/dla-needed.txt
=====================================
@@ -58,9 +58,6 @@ aom/bookworm
NOTE: 20260709: AV1 *encoder* flaws (SVC layer-id/LAP), CVE-2026-56208..56211; only
NOTE: 20260709: bookworm (3.6.0) affected, bullseye not-affected (code added in aom 2.0.0).
--
-apache-log4j2/bullseye
- NOTE: 20260413: Added by Front-Desk (rouca)
---
bouncycastle
NOTE: 20260417: Added by Front-Desk (rouca)
NOTE: 20260417: Priority: Fix CVE-2026-5588 then try to fix other pilled CVE (rouca/FD)
@@ -235,16 +232,6 @@ git-lfs/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
--
-glances/bullseye
- NOTE: 20260518: Added by Front-Desk (Beuc)
- NOTE: 20260518: Many postponed vulnerabilities piled-up (Beuc/front-desk)
---
-golang-glog/bullseye
- NOTE: 20250209: Added by Front-Desk (apo)
- NOTE: 20251107: Re-add as binNMUs are not all properly Installed in the archive:
- NOTE: 20251107: https://buildd.debian.org/status/package.php?p=+golang-github-grpc-ecosystem-grpc-gateway&suite=bullseye-security
- NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
---
gst-plugins-bad1.0
NOTE: 20260612: Added by Front-Desk (rouca)
--
@@ -304,16 +291,6 @@ kitty
NOTE: 20260523: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137210#45
NOTE: 20260528: DSA-6307-1 (2 CVEs)
--
-knot-resolver/bullseye
- NOTE: 20251206: Added by Front-Desk (rouca)
- NOTE: 20251206: Close CVE-2022-40188 buster regression. Try to fix other non ignored CVEs.
- NOTE: 20251223: complicated to backport no-dsa CVEs as CVE-2023-46317 reverts much of the patch
- NOTE: 20251223: for CVE-2023-26249 and then needs to be re-adjusted a bit for v5.3.1. nonetheless,
- NOTE: 20251223: update prepared @ https://salsa.debian.org/lts-team/packages/knot-resolver/-/tree/debian/bullseye?ref_type=heads.
- NOTE: 20251223: but have reached out to Jakub and Santiago, as maintainers, for a review. (utkarsh)
- NOTE: 20250104: still waiting to hear back. will upload to debusine for extra pipelines to run. (utkarsh)
- NOTE: 20250119: still waiting to hear back. (utkarsh)
---
ldap-account-manager
NOTE: 20260418: Added by Front-Desk (rouca)
NOTE: 20260725: Also add for bookworm (8.3); CVE-2026-27894 PDF-export LFI,
@@ -426,13 +403,6 @@ libssh2 (eamanu)
NOTE: 20260812: asked to upstream for more information about CVE-2026-58051 and CVE-2026-58050 (eamanu)
NOTE: 20260821: patches ready, waiting for trixie-pu (eamanu)
--
-libstb/bullseye
- NOTE: 20251206: Added by Front-Desk (rouca)
- NOTE: 20251206: avoid regresion from buster (rouca/front-desk)
- NOTE: 20251206: try to fix other CVEs and help with PU if needed (rouca/front-desk)
- NOTE: 20260226: Fixed CVE-2021-28021 CVE-2021-37789 CVE-2021-42715 CVE-2022-28041 CVE-2022-28042 with DLA-4493-1 (abhijith)
- NOTE: 20260429: Revisit when upstream merge the proposed fixes. Though other embed libstb projects patched (abhijith)
---
libwebsockets/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
@@ -476,43 +446,17 @@ memcached/bookworm
NOTE: 20260717: Follow DLA-4601-1/bullseye (2 CVEs)
NOTE: 20260717: Fix other postponed issues while we're at it (Beuc/front-desk)
--
-mimetex/bullseye
- NOTE: 20250422: Added by Front-Desk (rouca)
- NOTE: 20250629: There doesn't seem to be a fix so far according to #1103801 (dleidert)
- NOTE: 20250629: Best course of action seems to be some kind of mitigation similar to https://moodle.org/mod/forum/discuss.php?d=467592 (dleidert)
- NOTE: 20260531: bookworm EOL.
---
mistral
NOTE: 20260612: Added by Front-Desk (rouca)
--
-mongo-c-driver/bullseye
- NOTE: 20260522: Added by Front-Desk (Beuc)
- NOTE: 20260522: Follow bookworm 12.14 (4+1 CVEs) (Beuc/front-desk)
---
nagios4/bullseye
NOTE: 20260529: Added by Front-Desk (dleidert)
NOTE: 20260529: Follow recent upload of 4.4.6-4+deb12u1/4.4.6-4.1+deb13u1 (dleidert/front-desk)
--
-nagvis/bullseye
- NOTE: 20250117: Added by Front-Desk (rouca)
- NOTE: 20250119: Also check/fix https://bugs.debian.org/1061044
- NOTE: 20250119: when testing your fix for bookworm. (bunk)
- NOTE: 20250221: https://salsa.debian.org/lts-team/lts-updates-tasks/-/issues/193 (ah)
- NOTE: 20250501: DLA released; but we really should discuss #193 and I'll maybe take it (dleidert)
- NOTE: 20250625: To be clear, this package requires a PU for bookworm, to avoid upgrade regressions. (roberto)
- NOTE: 20250629: Next DLA for 2 new issues has been released (dleidert)
- NOTE: 20250629: PU is ready and will be tested before sending the PU request (dleidert)
---
nats-server/bookworm
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
-netatalk/bullseye
- NOTE: 20260518: Added by Front-Desk (Beuc)
- NOTE: 20260518: DSA-6280-1 released fixing 20 patches for trixie.
- NOTE: 20260518: ~low popcon, no sponsors, only fix if backporting the single
- NOTE: 20260518: consolidated patch is straightforward enough (Beuc/front-desk)
---
netty (rouca)
NOTE: 20250814: Added by Front-Desk (lamby)
NOTE: 20251115: Partial release for sid. Fix all CVEs except CVE-2025-58056 (rouca)
@@ -553,13 +497,6 @@ ntfs-3g
nvidia-cuda-toolkit/bullseye
NOTE: 20241004: Added by Front-Desk (Beuc)
--
-ocaml/bullseye
- NOTE: 20260419: Added by Front-Desk (rouca)
---
-opam/bullseye
- NOTE: 20260716: Added by Front-Desk (Beuc)
- NOTE: 20260716: Follow DSA-6386-1 and DLA-4684-1 (1 CVE) (Beuc/front-desk)
---
open-iscsi
NOTE: 20260802: Added by Front-Desk (ta)
--
@@ -599,13 +536,6 @@ openvpn/bullseye
NOTE: 20260706: The regression has been fixed. (dleidert)
NOTE: 20260731: The new CVEs require a more thorough examination. (dleidert)
--
-openvswitch/bullseye
- NOTE: 20260405: Added by Front-Desk (ta)
- NOTE: 20260422: Cf. OSPU (if approved) https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1133882 (Beuc)
---
-orthanc/bullseye
- NOTE: 20260419: Added by Front-Desk (rouca)
---
pacemaker
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Package is in dsa-needed (charles)
@@ -632,9 +562,6 @@ pglogical
php-dompdf
NOTE: 20260804: Added by Front-Desk (rouca)
--
-php-horde-imp/bullseye
- NOTE: 20260714: Added by Front-Desk (Beuc)
---
php-laravel-framework
NOTE: 20250307: Added by Front-Desk (rouca)
NOTE: 20251027: History of upstream branch fixing v12: git log 9de75259..2d133034^2.
@@ -648,11 +575,6 @@ php-twig/bullseye
NOTE: 20260521: Added by Front-Desk (Beuc)
NOTE: 20260521: Cf. symfony batch of CVEs, upcoming DSA (Beuc/front-desk)
--
-phpseclib/bullseye (Utkarsh)
- NOTE: 20260518: Added by Front-Desk (Beuc)
- NOTE: 20260518: Follow bookworm 12.14 (2 CVEs) (Beuc/front-desk)
- NOTE: 20260720: will get back to this after releasing squid. (utkarsh)
---
pipewire
NOTE: 20260805: Added by Front-Desk (rouca)
--
@@ -677,10 +599,6 @@ pyasn1 (eamanu)
NOTE: 20260802: Added by Front-Desk (ta)
NOTE: 20260825: patches for bookworm and bullseye are ready, waiting for trixie-pu being accepted (eamanu)
--
-pypdf2/bullseye (dleidert)
- NOTE: 20260328: Added by Front-Desk (Beuc)
- NOTE: 20260328: 6 new CVEs, and lots of postponed issues piled-up (Beuc/front-desk)
---
python-aiohttp (dleidert)
NOTE: 20260611: Added by Front-Desk (rouca)
NOTE: 20260602: Daniel Leidert is proposing to work on the update and provide debdiffs for bookworm and trixie (carnil)
@@ -723,9 +641,6 @@ python-msgpack
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-57585 (fixed 1.2.1; <=1.2.0 affected); Debian 1.0.x.
--
-python-oslo.messaging/bullseye
- NOTE: 20260612: Added by Front-Desk (rouca)
---
python-tornado
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: See also https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/322 (Beuc/front-desk)
@@ -800,13 +715,6 @@ runc
NOTE: 20260223: Updated #1120140 with some thoughts, asking for more opinions (kanashiro)
NOTE: 20260706: Please handle Bookworm as well (dleidert/front-desk)
--
-rust-openssl/bullseye
- NOTE: 20250209: Added by Front-Desk (apo)
- NOTE: 20251107: Re-add as binNMUs are not all properly Installed in the archive:
- NOTE: 20251107: https://buildd.debian.org/status/package.php?p=rust-condure&suite=bullseye-security
- NOTE: 20251107: https://buildd.debian.org/status/package.php?p=rust-debcargo&suite=bullseye-security
- NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
---
sabnzbdplus
NOTE: 20260830: Added by Front-Desk (dleidert)
NOTE: 20260830: Follow DSA 6454-1 (dleidert/front-desk)
@@ -830,10 +738,6 @@ shiro
NOTE: 20260726: Should be fixed for trixie too, which ships the same
NOTE: 20260726: affected 1.3.2. (utkarsh/front-desk)
--
-smb4k/bullseye
- NOTE: 20251217: Added by Front-Desk (pochu)
- NOTE: 20260531: bookworm EOL.
---
snapd
NOTE: 20260324: Added by Front-Desk (Beuc)
NOTE: 20260324: See DSA-6170-1 (root LPE) (Beuc/front-desk)
@@ -850,13 +754,6 @@ snapd
NOTE: 20260726: in 2.71-1. Entry was bullseye-only as bookworm was not yet
NOTE: 20260726: LTS when it was filed in 2026-03. (utkarsh/front-desk)
--
-spip/bullseye
- NOTE: 20260220: Added by Front-Desk (rouca)
- NOTE: 20260326: EOL candidate? Many issues pile-up, 3.2 EOL'd upstream,
- NOTE: 20260326: not in bookworm, trixie updated through upstream 4.4 LTS releases,
- NOTE: 20260326: very low popcon (Beuc/front-desk)
- NOTE: 20260422: https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/342
---
srt
NOTE: 20260809: Added by Front-Desk (rouca)
--
@@ -868,10 +765,6 @@ sssd
strongswan/bullseye
NOTE: 20260423: Added by Front-Desk (pochu)
--
-suricata/bullseye
- NOTE: 20250331: re added to fix next bunch of CVEs (ta)
- NOTE: 20250825: testing package (ta)
---
suricata-update
NOTE: 20260830: Added by Front-Desk (dleidert)
NOTE: 20260830: Follow DSA-6475-1 (dleidert/front-desk)
@@ -911,17 +804,6 @@ tomcat9/bullseye
NOTE: 20260714: (as bullseye is now > 9.0.70-2). Check carefully.
NOTE: 20260714: Upcoming DSA for tomcat10 (Beuc/front-desk)
--
-trafficserver/bullseye
- NOTE: 20241120: Added by Front-Desk (Beuc)
- NOTE: 20241120: Upcoming DSA (Beuc/front-desk)
- NOTE: 20241203: Upstream announcement does not mention 8.1 for any of the 3 CVEs.
- NOTE: 20241203: AFAIR upstream 8.1 support ended with the release of 10.0 (bunk)
- NOTE: 20250216: DLA released fixing CVE-2024-38479 and CVE-2024-50306 (dleidert)
- NOTE: 20250216: IMHO CVE-2024-50305 does not affect 8.x due to affected code being introduced later (dleidert)
- NOTE: 20250216: Bookworm-PU necessary, but issues not fixed in Sid yet; contacted maintainer (dleidert)
- NOTE: 20250403: There are multiple new CVEs. But none of them is addresses in Sid and maintainers didn't reply to me last time (dleidert)
- NOTE: 20250405: DSA 5896-1 is out (Beuc/front-desk)
---
u-boot
NOTE: 20260804: Added by Front-Desk (rouca)
--
@@ -955,17 +837,6 @@ vips
NOTE: 20260812: Four news CVEs published, already in dsa-needed, sync with
NOTE: 20260812: secteam or follow DSA. (charles/front-desk)
--
-vitrage/bullseye
- NOTE: 20260419: Added by Front-Desk. Get in touch with zigo/upstream before (rouca)
- NOTE: 20260419: CVE-2026-28370 is RCE
---
-watcher/bullseye
- NOTE: 20250908: Added by Front-Desk (apo)
- NOTE: 20250908: See also nova. (apo)
- NOTE: 20251023: See notes <aPqc5NoWRLG3jKLw at isildor2.loewenhoehle.ip>
- NOTE: 20251027: Maintainer contacted (tobi)
- NOTE: 20251106: Part of OpenStack (Beuc/front-desk)
---
wireshark
NOTE: 20260430: Added by Front-Desk (lamby)
NOTE: 20260706: Also add for bookworm (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/847b872bc0732a58d372a6c66a2da775c5b6c71d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/847b872bc0732a58d372a6c66a2da775c5b6c71d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/affbe8e7/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list