[Git][security-tracker-team/security-tracker][master] 2 commits: lts: drop more bullseye specific packages
Emilio Pozuelo Monfort (@pochu)
pochu at debian.org
Tue Sep 1 13:16:23 BST 2026
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fc690a68 by Emilio Pozuelo Monfort at 2026-09-01T13:54:38+02:00
lts: drop more bullseye specific packages
- - - - -
32169dbc by Emilio Pozuelo Monfort at 2026-09-01T14:15:31+02:00
lts: drop more bullseye packages
- - - - -
1 changed file:
- data/dla-needed.txt
Changes:
=====================================
data/dla-needed.txt
=====================================
@@ -111,9 +111,6 @@ containerd
NOTE: 20260621: Added by Front-Desk (charles)
NOTE: 20260621: Also in dsa-needed, sync with secteam or follow DSA (charles)
--
-coturn/bullseye
- NOTE: 20260414: Added by Front-Desk (rouca)
---
cups (Thorsten Alteholz)
NOTE: 20260404: Added by Front-Desk (ta)
NOTE: 20260615: bookworm also need the same fixes as bullseye. (charles)
@@ -142,10 +139,6 @@ dracut
dulwich
NOTE: 20260613: Added by Front-Desk (rouca)
--
-edk2/bullseye
- NOTE: 20251230: Added by Front-Desk (Beuc)
- NOTE: 20251230: Lots of postponed issues piled-up (Beuc/front-desk)
---
emacs
NOTE: 20260822: Added by Front-Desk (lamby)
--
@@ -185,9 +178,6 @@ firebird3.0
NOTE: 20260418: Added by Front-Desk (rouca)
NOTE: 20260702: Upcoming DSA (dleidert/front-desk)
--
-firmware-nonfree/bullseye
- NOTE: 20251130: Added by Front-Desk. Moreover, take care of postponed issue (rouca)
---
flatpak
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260811: A bunch of new vulnerabilities were released that can be
@@ -210,11 +200,6 @@ frr
gawk
NOTE: 20260801: Added by Front-Desk (ta)
--
-gdal/bullseye
- NOTE: 20260419: Added by Front-Desk (rouca)
- NOTE: 20260419: Investigate why embded zblib and maybe deemded beginning from sid (rouca/FD)
- NOTE: 20260419: check other zlib CVE (rouca/FD)
---
gegl
NOTE: 20260821: Added by Front-Desk (lamby)
NOTE: 20260821: Not immediately clear how the changes to libs/ctx/ctx.h (not present in bullseye LTS) interact with libs/rgbe/rgbe.c, so this may not be vulnerable in bullseye or earlier. (lamby)
@@ -303,11 +288,6 @@ libass (dleidert)
NOTE: 20260712: Added by Front-Desk (utkarsh)
NOTE: 20260712: TEMP-0000000-AA08BC (GHSA-pjjp-65r7-ppgm): OOB read+write in wrap_lines_measure from untrusted subtitles; secteam fixed stable via point release. Affected in bullseye (0.15.0) and bookworm (0.17.1). (utkarsh/front-desk)
--
-libcaca/bullseye
- NOTE: 20260519: Added by Front-Desk (Beuc)
- NOTE: 20260519: Fix unstable first. (Beuc/front-desk)
- NOTE: 20260601: Unstable fixed and OSPU ready https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138538
---
libcrypt-pbkdf2-perl
NOTE: 20260612: Added by Front-Desk (rouca)
NOTE: 20260613: you MUST follow #1139897 and coordinate (rouca/FD)
@@ -340,10 +320,6 @@ libio-compress-perl
libmojo-jwt-perl
NOTE: 20260805: Added by Front-Desk (rouca)
--
-libreoffice/bullseye (santiago)
- NOTE: 20260508: Added by Front-Desk (dleidert)
- NOTE: 20260508: Follow DSA-6251-1 (dleidert/front-desk)
---
librest
NOTE: 20260802: Added by Front-Desk (ta)
--
@@ -407,11 +383,6 @@ libwebsockets/bookworm
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
--
-libxslt/bullseye
- NOTE: 20250930: Added by Front-Desk (rouca)
- NOTE: 20251020: In progress, waiting for upstream action (guilhem)
- NOTE: 20251104: Done, but waiting for upstream to merge before uploading and issuing the DLA (guilhem)
---
linux (Ben Hutchings)
NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
--
@@ -433,10 +404,6 @@ lrzip/bookworm
lxml
NOTE: 20260614: Added by Front-Desk (rouca)
--
-mbedtls/bullseye
- NOTE: 20260427: Added by Front-Desk (lamby)
- NOTE: 20260531: bookworm EOL.
---
mediawiki
NOTE: 20260713: Added by Front-Desk (Beuc)
NOTE: 20260713: Follow DSA-6380-1 (10 CVEs) (Beuc/front-desk)
@@ -449,10 +416,6 @@ memcached/bookworm
mistral
NOTE: 20260612: Added by Front-Desk (rouca)
--
-nagios4/bullseye
- NOTE: 20260529: Added by Front-Desk (dleidert)
- NOTE: 20260529: Follow recent upload of 4.4.6-4+deb12u1/4.4.6-4.1+deb13u1 (dleidert/front-desk)
---
nats-server/bookworm
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
@@ -494,9 +457,6 @@ ntfs-3g
NOTE: 20260716: Added by Front-Desk (Beuc)
NOTE: 20260716: Follow DSA-6389-1 (9 CVEs) (Beuc/front-desk)
--
-nvidia-cuda-toolkit/bullseye
- NOTE: 20241004: Added by Front-Desk (Beuc)
---
open-iscsi
NOTE: 20260802: Added by Front-Desk (ta)
--
@@ -530,12 +490,6 @@ openssl
NOTE: 20260830: Another round of CVEs; follow DSA-6465-1 (dleidert/front-desk)
NOTE: 20260830: For Bookworm, 3.0.22 should contain all fixes (dleidert/front-desk)
--
-openvpn/bullseye
- NOTE: 20260703: Added by Front-Desk (dleidert)
- NOTE: 20260703: A regression has been reported; and a new set of CVEs is out (dleidert/front-desk)
- NOTE: 20260706: The regression has been fixed. (dleidert)
- NOTE: 20260731: The new CVEs require a more thorough examination. (dleidert)
---
pacemaker
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Package is in dsa-needed (charles)
@@ -571,10 +525,6 @@ php-laravel-framework
NOTE: 20251027: tests is required to prevent regressions, but I could not get the upstream
NOTE: 20251027: test suite to work. It is not exercised as part of Debian packages build. (paride)
--
-php-twig/bullseye
- NOTE: 20260521: Added by Front-Desk (Beuc)
- NOTE: 20260521: Cf. symfony batch of CVEs, upcoming DSA (Beuc/front-desk)
---
pipewire
NOTE: 20260805: Added by Front-Desk (rouca)
--
@@ -584,10 +534,6 @@ proftpd-dfsg
NOTE: 20260511: https://salsa.debian.org/debian-proftpd-team/proftpd/-/commits/bullseye
NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
--
-prosody/bullseye
- NOTE: 20260511: Added by Front-Desk (dleidert)
- NOTE: 20260511: Follow DSA 6252-1 fixing 4 CVEs (dleidert/front-desk)
---
puma
NOTE: 20260804: Added by Front-Desk (rouca)
--
@@ -656,22 +602,9 @@ qemu
NOTE: 20260520: Also SPU/OSPU included a rebuild with updated glibc/glib2.0 (Beuc/front-desk)
NOTE: 20260713: New SPU/OSPU included a rebuild with updated gnutls28 (Beuc/front-desk)
--
-qtsvg-opensource-src/bullseye
- NOTE: 20260522: Added by Front-Desk (Beuc)
- NOTE: 20260522: Many postponed CVEs piled up (Beuc/front-desk)
---
-rabbitmq-server/bullseye
- NOTE: 20260504: Added by coordinator (santiago)
- NOTE: 20260504: Added to address out-standing minor issues
---
rails
NOTE: 20260805: Added by Front-Desk (rouca)
--
-request-tracker4/bullseye (Andrew Ruthven)
- NOTE: 20260529: Added by Front-Desk (dleidert)
- NOTE: 20260529: Follow DSA in preparation by maintainer (dleidert/front-desk)
- NOTE: 20260607: Andrew Ruthven (maintainer) is working on a DLA.
---
rsync (Thorsten Alteholz)
NOTE: 20260615: Added by Front-Desk (charles)
NOTE: 20260615: Requested by Sylvain to track regressions, same as in dsa-needed. (charles)
@@ -687,13 +620,6 @@ ruby-oj
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: Oj JSON parser memory-safety batch CVE-2026-54500..54903 (GHSA); affects 2.17-3.14.
--
-ruby2.7/bullseye (Abhijith PA)
- NOTE: 20260419: Added by Front-Desk (rouca)
- NOTE: 20260608: https://people.debian.org/~abhijith/upload/ruby2.7_patches/ (abhijith)
- NOTE: 20260731: Prepared an upload with already triaged issues. Group Net::IMAP issues
- NOTE: 20260731: and do upload later (abhijith)
- NOTE: 20260804: Uploaded 2.7.4-1+deb11u6 and released DLA-4716-1 (abhijith)
---
ruby3.1/bookworm
NOTE: 20260713: Added by Front-Desk (Beuc)
NOTE: 20260523: Bumping to new upstream rejected by SRM, do backport patches:
@@ -762,9 +688,6 @@ sssd
NOTE: 20260804: Crash or DoS of sssd may lead to user lockdown (rouca/FD)
NOTE: 20260804: SSSD should be tested carefully, with integration test (rouca/FD)
--
-strongswan/bullseye
- NOTE: 20260423: Added by Front-Desk (pochu)
---
suricata-update
NOTE: 20260830: Added by Front-Desk (dleidert)
NOTE: 20260830: Follow DSA-6475-1 (dleidert/front-desk)
@@ -781,12 +704,6 @@ swift
NOTE: 20260819: Maintainer uploaded 2.30.1-0+deb12u2 fixing CVE-2026-50221
NOTE: 20260819: and CVE-2026-71190. (charles)
--
-symfony/bullseye
- NOTE: 20260521: Added by Front-Desk (Beuc)
- NOTE: 20260521: >20 CVEs disclosed, 10 not-affected,
- NOTE: 20260521: at least 1 SQLI and 1 stored XSS.
- NOTE: 20260521: Upcoming DSA (Beuc/front-desk)
---
tiff
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-12912 (fixed 4.7.2rc2) + CVE-2026-36849 (read-buffer alloc);
@@ -796,14 +713,6 @@ tomcat10/bookworm
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Upcoming DSA (Beuc/front-desk)
--
-tomcat9/bullseye
- NOTE: 20260714: Added by Front-Desk (Beuc)
- NOTE: 20260714: bookworm/9.0.70-2 is a stripped-down version and marks most CVEs as fixed.
- NOTE: 20260714: Unfortunately we now ship 9.0.118 in bullseye, which breaks upgrades,
- NOTE: 20260714: and also makes the tracker believe everything is fixed
- NOTE: 20260714: (as bullseye is now > 9.0.70-2). Check carefully.
- NOTE: 20260714: Upcoming DSA for tomcat10 (Beuc/front-desk)
---
u-boot
NOTE: 20260804: Added by Front-Desk (rouca)
--
@@ -812,10 +721,6 @@ unbound
NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
--
-uriparser/bullseye
- NOTE: 20260519: Added by Front-Desk (Beuc)
- NOTE: 20260519: Many postponed CVEs piled-up (Beuc/front-desk)
---
urwid
NOTE: 20260802: Added by Front-Desk (ta)
NOTE: 20260802: not the same code but the same reasoning (ta)
@@ -848,23 +753,9 @@ xen/bookworm
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie (Beuc/front-desk)
--
-xmlrpc-c/bullseye
- NOTE: 20250411: Added by Front-Desk (Beuc)
- NOTE: 20250411: See issues with old embedded expat library:
- NOTE: 20250411: https://www.openwall.com/lists/oss-security/2025/04/09/4
- NOTE: 20250411: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1102554
- NOTE: 20250413: General options investigated, posted to the bug and debian-lts (bunk)
- NOTE: 20250705: See also libxmltok above, a similarly old expat version.
- NOTE: 20250705: Ping'd secteam asking for current bookworm plans. (Beuc)
- NOTE: 20250705: https://lists.debian.org/debian-lts/2025/07/msg00006.html
---
xorg-server
NOTE: 20260818: Added by Front-Desk (lamby)
--
-zabbix/bullseye
- NOTE: 20260328: Added by Front-Desk (Beuc)
- NOTE: 20260328: CVE-2026-23919->24 appear to be in supported scope (Beuc/front-desk)
---
zfs-linux
NOTE: 20260830: Added by Front-Desk (dleidert)
NOTE: 20260830: Follow DSA-6462-1 (dleidert/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0ea5c074b34b3e2fe2411e83db880796d9fb09b6...32169dbc904e0792662e0e0ea16ad98b29c5b0ac
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0ea5c074b34b3e2fe2411e83db880796d9fb09b6...32169dbc904e0792662e0e0ea16ad98b29c5b0ac
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/4161fee4/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list