[Git][security-tracker-team/security-tracker][master] 2 commits: lts: bullseye is no longer supported
Emilio Pozuelo Monfort (@pochu)
pochu at debian.org
Tue Sep 1 15:17:21 BST 2026
Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0055c324 by Emilio Pozuelo Monfort at 2026-09-01T16:13:22+02:00
lts: bullseye is no longer supported
Drop /bookworm suffix, it's no longer needed as bookworm is the
only supported release.
- - - - -
8cee763d by Emilio Pozuelo Monfort at 2026-09-01T16:13:23+02:00
lts: drop ca-certificates
It has already been uploaded to bookworm.
- - - - -
1 changed file:
- data/dla-needed.txt
Changes:
=====================================
data/dla-needed.txt
=====================================
@@ -25,17 +25,17 @@ To make it easier to see the entire history of an update, please append notes
rather than remove/replace existing ones.
--
-389-ds-base/bookworm
+389-ds-base
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260413: Try to clean postponed CVE (rouca/FD)
NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
--
-activemq/bookworm
+activemq
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260715: Also add for bookworm
NOTE: 20260715: Upcoming DSA, though they may just bump version (Beuc/front-desk)
--
-adminer/bookworm
+adminer
NOTE: 20260801: Added by Front-Desk (ta)
--
amd64-microcode
@@ -53,7 +53,7 @@ amd64-microcode
NOTE: 20251224: I think the required kernel microcode driver patch are: https://lists.openwall.net/linux-kernel/2025/10/27/1012
NOTE: 20260615: bookworm (now lts) also needs fixes. (charles)
--
-aom/bookworm
+aom
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: AV1 *encoder* flaws (SVC layer-id/LAP), CVE-2026-56208..56211; only
NOTE: 20260709: bookworm (3.6.0) affected, bullseye not-affected (code added in aom 2.0.0).
@@ -69,37 +69,22 @@ busybox
NOTE: 20260722: Also add for bookworm; CVE-2026-38752..38755 (ash/awk)
NOTE: 20260722: share code, sponsored, already queued bullseye+ELTS (utkarsh)
--
-ca-certificates
- NOTE: 20250613: Added by Front-Desk (rouca)
- NOTE: 20250613: Lack some certificates #1095913 (rouca/FD)
- NOTE: 20250613: Coordinate with bookworm PU if needed (rouca/FD)
- NOTE: 20250613: Document carefully changes in backport, particularly removed certificates (rouca/FD)
- NOTE: 20250731: will likely need an upload of ca-certificates-jave before and breaks/update (rouca)
- NOTE: 20250731: WIP break piuparts (rouca)
- NOTE: 20250801: Propose for review a ca-certificates-java (rouca)
- NOTE: 20250811: upload ca-certificates-java (rouca)
- NOTE: 20250811: wait for direction from security team about bookworm update first (rouca)
- NOTE: 20260216: partial update under debusine https://debusine.debian.net/debian/developers/work-request/446642/
- NOTE: 20260220: Release partial DLA 4485-1
- NOTE: 20260710: bookworm update seems to be required: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1107237#48 (santiago)
- NOTE: 20260810: made a release from trixie DLA-4726-1 (rouca). Will need last sid version to go to trixie (rouca)
---
-cacti/bookworm
+cacti
NOTE: 20260630: Added by Front-Desk (dleidert)
NOTE: 20260630: A new bunch of issues and in DSA list (dleidert/front-desk)
--
-caddy/bookworm
+caddy
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
-cjson/bookworm
+cjson
NOTE: 20260801: Added by Front-Desk (ta)
--
clamav (Emilio)
NOTE: 20260711: Added by Front-Desk (utkarsh)
NOTE: 20260711: Needs a newer rustc to be backported as well. (utkarsh)
--
-cockpit/bookworm
+cockpit
NOTE: 20260819: Added by Front-Desk (lamby)
--
composer
@@ -116,14 +101,14 @@ cups (Thorsten Alteholz)
NOTE: 20260615: bookworm also need the same fixes as bullseye. (charles)
NOTE: 20260705: still trying to find a solution to fix a CVE without changing the functionality of lpadmin
--
-cyrus-imapd/bookworm
+cyrus-imapd
NOTE: 20260717: Added by Front-Desk (Beuc)
NOTE: 20260717: Upcoming DSA (Beuc/front-desk)
NOTE: 20260901: Some CVE fixes were prepared on the bookworm branch by ejjl
NOTE: 20260901: (a Debian Contributor) and merged by yadd (maintainer):
NOTE: 20260901: https://salsa.debian.org/debian/cyrus-imapd/-/merge_requests/27
--
-designate/bookworm
+designate
NOTE: 20260818: Added by Front-Desk (lamby)
NOTE: 20260823: Maintainer uploaded fixes for bookworm. (Charles)
--
@@ -135,7 +120,7 @@ dovecot
NOTE: 20260829: Added by Front-Desk (dleidert)
NOTE: 20260829: Upcoming DSA (dleidert/front-desk)
--
-dracut/bookworm
+dracut
NOTE: 20260611: Added by Front-Desk (rouca)
NOTE: 20260611: Please investigate impact of legacy network on older release of dracut aka CVE-2026-6893 (rouca/FD)
--
@@ -153,7 +138,7 @@ erlang
NOTE: 20260519: Fix ELTS at the same time. (Beuc/front-desk)
NOTE: 20260702: Another round of issues and upcoming DSA (dleidert/front-desk)
--
-evolution-data-server/bookworm
+evolution-data-server
NOTE: 20260717: Added by Front-Desk (Beuc)
NOTE: 20260717: Follow DLA-4503-1/bullseye (1 CVE) (Beuc/front-desk)
--
@@ -187,7 +172,7 @@ flatpak
NOTE: 20260811: chained to RCE. In DSA needed, maintainer taking care of
NOTE: 20260811: trixie update, follow DSA. (charles)
--
-freecad/bookworm
+freecad
NOTE: 20260821: Added by Front-Desk (lamby)
--
freerdp2
@@ -203,20 +188,20 @@ frr
gawk
NOTE: 20260801: Added by Front-Desk (ta)
--
-gegl/bookworm
+gegl
NOTE: 20260821: Added by Front-Desk (lamby)
NOTE: 20260821: Not immediately clear how the changes to libs/ctx/ctx.h (not present in bullseye LTS) interact with libs/rgbe/rgbe.c, so this may not be vulnerable in bullseye or earlier. (lamby)
--
-gh/bookworm
+gh
NOTE: 20241230: Added by Security Team (carnil)
NOTE: 20260611: bookworm LTS handover.
--
-gimp/bookworm
+gimp
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: PSP/PNM/PSD parser overflows CVE-2026-58379..58388 (crafted image); TIM-loader
NOTE: 20260709: CVE-2026-59089 not-affected (GIMP 3.x-only).
--
-git-lfs/bookworm
+git-lfs
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
--
@@ -235,19 +220,19 @@ icinga2
NOTE: 20260702: Follow DSA and/or support security team with DSA (dleidert/front-desk)
NOTE: 20260702: also care about outstanding CVEs (dleidert/front-desk)
--
-inkscape/bookworm
+inkscape
NOTE: 20260522: Added by Security Team (jmm)
NOTE: 20260611: bookworm LTS handover.
--
-ironic/bookworm
+ironic
NOTE: 20260610: Added by Front-Desk (rouca)
NOTE: 20260816: Partial release by maintainer (charles)
--
-isc-kea/bookworm
+isc-kea
NOTE: 20260224: Added by Security Team (jmm)
NOTE: 20260611: bookworm LTS handover.
--
-jackson-databind/bookworm
+jackson-databind
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-54512/54513/54514/54515 hit 2.12(bullseye)+2.14(bookworm);
NOTE: 20260709: 54516/54517/54518 (>=2.21) and 50193 (bookworm 2.14) not-affected.
@@ -258,17 +243,17 @@ jbig2dec
jetty9
NOTE: 20260418: Added by Front-Desk. Fix CVE-2026-5795 maybe other (rouca)
--
-jline3/bookworm
+jline3
NOTE: 20260801: Added by Front-Desk (ta)
--
-jpeg-xl/bookworm
+jpeg-xl
NOTE: 20260619: Added by Front-Desk (charles)
NOTE: 20260619: Follow DSA-6342-1 (charles)
--
-kamailio/bookworm
+kamailio
NOTE: 20260413: Added by Front-Desk (rouca)
--
-keystone/bookworm
+keystone
NOTE: 20260830: Added by Front-Desk (dleidert)
NOTE: 20260830: Upcoming DSA (dleidert/front-desk)
--
@@ -320,18 +305,18 @@ libio-compress-perl
NOTE: 20260612: Added by Front-Desk (rouca)
NOTE: 20260612: MUST hold-back following the upper suites and wait for green light from security team (rouca/FD)
--
-libmojo-jwt-perl/bookworm
+libmojo-jwt-perl
NOTE: 20260805: Added by Front-Desk (rouca)
--
librest
NOTE: 20260802: Added by Front-Desk (ta)
--
-libreswan/bookworm
+libreswan
NOTE: 20230301: Added by Security Team (jmm)
NOTE: 20260611: bookworm LTS handover.
NOTE: 20260611: Sync with maintainer (dkg), hard to test.
--
-libsoup2.4/bookworm
+libsoup2.4
NOTE: 20250408: Added by Front-Desk (Beuc)
NOTE: 20250427: libsoup2.4 2.72.0-2+deb11u2 (bullseye) uploaded ...
NOTE: 20250427: ... without CVE-2025-32907 and CVE-2025-32049.
@@ -382,11 +367,11 @@ libssh2 (eamanu)
NOTE: 20260812: asked to upstream for more information about CVE-2026-58051 and CVE-2026-58050 (eamanu)
NOTE: 20260821: patches ready, waiting for trixie-pu (eamanu)
--
-libwebsockets/bookworm
+libwebsockets
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
--
-linux/bookworm (Ben Hutchings)
+linux (Ben Hutchings)
NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
--
logback
@@ -397,7 +382,7 @@ logback
NOTE: 20260726: LTS too. Also fix the other postponed logback CVEs, and it
NOTE: 20260726: should be fixed for trixie too (1.2.11-6 affected). (utkarsh/front-desk)
--
-lrzip/bookworm
+lrzip
NOTE: 20260725: Added by Front-Desk (utkarsh)
NOTE: 20260725: CVE-2025-15570; fixed in bullseye via DLA-4567-1. bookworm
NOTE: 20260725: 0.651-2 has the same UAF (thread_count guard absent); fix is
@@ -407,23 +392,23 @@ lrzip/bookworm
lxml
NOTE: 20260614: Added by Front-Desk (rouca)
--
-mediawiki/bookworm
+mediawiki
NOTE: 20260713: Added by Front-Desk (Beuc)
NOTE: 20260713: Follow DSA-6380-1 (10 CVEs) (Beuc/front-desk)
--
-memcached/bookworm
+memcached
NOTE: 20260717: Added by Front-Desk (Beuc)
NOTE: 20260717: Follow DLA-4601-1/bullseye (2 CVEs)
NOTE: 20260717: Fix other postponed issues while we're at it (Beuc/front-desk)
--
-mistral/bookworm
+mistral
NOTE: 20260612: Added by Front-Desk (rouca)
--
-nats-server/bookworm
+nats-server
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
-netty/bookworm (rouca)
+netty (rouca)
NOTE: 20250814: Added by Front-Desk (lamby)
NOTE: 20251115: Partial release for sid. Fix all CVEs except CVE-2025-58056 (rouca)
NOTE: 20251127: all CVEs fixed under sid (rouca)
@@ -438,18 +423,18 @@ nginx (charles)
NOTE: 20260618: There was also a customer request to fix it. (charles)
NOTE: 20260630: Bullseye fix release with 2 CVE fixes + http2 bomb fix. Bookworm coming soon. (charles)
--
-node-dompurify/bookworm
+node-dompurify
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
-node-ip-address/bookworm
+node-ip-address
NOTE: 20260804: Added by Front-Desk (rouca)
--
-node-lodash/bookworm (utkarsh)
+node-lodash (utkarsh)
NOTE: 20260703: Added by Front-Desk (dleidert)
NOTE: 20260703: Follow DLA 4663-1; assigned to Utkarsh to grab this (dleidert/front-desk)
--
-node-re2/bookworm
+node-re2
NOTE: 20260806: Added by Front-Desk (rouca)
NOTE: 20260806: CVE-2026-68499 is worth fixing due to re2 used for fixing redos and other regex problem on backport (rouca)
--
@@ -467,7 +452,7 @@ openexr
NOTE: 20260413: Added by Front-Desk (rouca)
NOTE: 20260713: Also add for bookworm (Beuc/front-desk)
--
-openimageio/bookworm
+openimageio
NOTE: 20260726: Added by Front-Desk (utkarsh)
NOTE: 20260726: Six memory-corruption flaws in image readers that are
NOTE: 20260726: built by default and reached by decoding an untrusted
@@ -497,10 +482,10 @@ pacemaker
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Package is in dsa-needed (charles)
--
-pcp/bookworm
+pcp
NOTE: 20260801: Added by Front-Desk (ta)
--
-pdfminer/bookworm
+pdfminer
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: CVE-2025-70559 is follow-up fix for CVE-2025-64512
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
@@ -509,17 +494,17 @@ perl
NOTE: 20260527: Added by Front-Desk (santiago)
NOTE: 20260527: wait for the DSA before releasing
--
-pgextwlist/bookworm
+pgextwlist
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Follow DSA-6385-1 (1 CVE) (Beuc/front-desk)
--
-pglogical/bookworm
+pglogical
NOTE: 20260805: Added by Front-Desk, due to CVE-2026-50738 (rouca)
--
-php-dompdf/bookworm
+php-dompdf
NOTE: 20260804: Added by Front-Desk (rouca)
--
-php-laravel-framework/bookworm
+php-laravel-framework
NOTE: 20250307: Added by Front-Desk (rouca)
NOTE: 20251027: History of upstream branch fixing v12: git log 9de75259..2d133034^2.
NOTE: 20251027: There was an attempt to backport to v9, but it got rejected upstream
@@ -537,10 +522,10 @@ proftpd-dfsg
NOTE: 20260511: https://salsa.debian.org/debian-proftpd-team/proftpd/-/commits/bullseye
NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
--
-puma/bookworm
+puma
NOTE: 20260804: Added by Front-Desk (rouca)
--
-py7zr/bookworm
+py7zr
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-23879 (GHSA range <=1.1.2); Debian 0.11.3 in range.
--
@@ -552,17 +537,17 @@ python-aiohttp (dleidert)
NOTE: 20260611: Added by Front-Desk (rouca)
NOTE: 20260602: Daniel Leidert is proposing to work on the update and provide debdiffs for bookworm and trixie (carnil)
--
-python-asyncssh/bookworm
+python-asyncssh
NOTE: 20260806: Added by Front-Desk (rouca)
--
python-cryptography
NOTE: 20260805: Added by Front-Desk (rouca)
--
-python-eventlet/bookworm
+python-eventlet
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
--
-python-geopandas/bookworm
+python-geopandas
NOTE: 20260725: Added by Front-Desk (utkarsh)
NOTE: 20260725: CVE-2025-69662; fixed in bullseye via DLA-4523-1. bookworm
NOTE: 20260725: 0.12.2-1 still builds the Find_SRID query with .format(); fix
@@ -570,7 +555,7 @@ python-geopandas/bookworm
NOTE: 20260725: Should be fixed for trixie too, which still ships an
NOTE: 20260725: affected 1.0.1-2. (utkarsh/front-desk)
--
-python-git/bookworm
+python-git
NOTE: 20260726: Added by Front-Desk (utkarsh)
NOTE: 20260726: CVE-2026-42215 bypasses the check_unsafe_options guard
NOTE: 20260726: that DLA-3939-1 itself backported, so our own earlier fix
@@ -596,7 +581,7 @@ python-tornado
NOTE: 20260722: Extend to bullseye; CVE-2026-49853/49854/49855 in 6.1.0 too,
NOTE: 20260722: shared with bookworm; fix in 6.5.6 (utkarsh/front-desk)
--
-python-zeroconf/bookworm
+python-zeroconf
NOTE: 20260804: Added by Front-Desk (rouca)
--
qemu
@@ -613,17 +598,17 @@ rsync (Thorsten Alteholz)
NOTE: 20260615: Requested by Sylvain to track regressions, same as in dsa-needed. (charles)
NOTE: 20260705: making progress with updated patches
--
-ruby-jwt/bookworm
+ruby-jwt
NOTE: 20260805: Added by Front-Desk (rouca)
--
-ruby-oauth2/bookworm
+ruby-oauth2
NOTE: 20260805: Added by Front-Desk (rouca)
--
-ruby-oj/bookworm
+ruby-oj
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: Oj JSON parser memory-safety batch CVE-2026-54500..54903 (GHSA); affects 2.17-3.14.
--
-ruby3.1/bookworm
+ruby3.1
NOTE: 20260713: Added by Front-Desk (Beuc)
NOTE: 20260523: Bumping to new upstream rejected by SRM, do backport patches:
NOTE: 20260523: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1103854
@@ -644,14 +629,14 @@ runc
NOTE: 20260223: Updated #1120140 with some thoughts, asking for more opinions (kanashiro)
NOTE: 20260706: Please handle Bookworm as well (dleidert/front-desk)
--
-sabnzbdplus/bookworm
+sabnzbdplus
NOTE: 20260830: Added by Front-Desk (dleidert)
NOTE: 20260830: Follow DSA 6454-1 (dleidert/front-desk)
--
samba (Markus Koschany)
NOTE: 20260809: Added by Front-Desk (rouca)
--
-shiro/bookworm
+shiro
NOTE: 20260726: Added by Front-Desk (utkarsh)
NOTE: 20260726: CVE-2026-56091: SimpleFilterChainResolver in shiro-guice
NOTE: 20260726: does not normalise a trailing slash, so a request for
@@ -691,11 +676,11 @@ sssd
NOTE: 20260804: Crash or DoS of sssd may lead to user lockdown (rouca/FD)
NOTE: 20260804: SSSD should be tested carefully, with integration test (rouca/FD)
--
-suricata-update/bookworm
+suricata-update
NOTE: 20260830: Added by Front-Desk (dleidert)
NOTE: 20260830: Follow DSA-6475-1 (dleidert/front-desk)
--
-swift/bookworm
+swift
NOTE: 20260726: Added by Front-Desk (utkarsh)
NOTE: 20260726: CVE-2026-50221: proxy gatekeeper does not strip the
NOTE: 20260726: X-Container-Host/X-Delete-At-Host update headers from
@@ -712,7 +697,7 @@ tiff
NOTE: 20260709: CVE-2026-12912 (fixed 4.7.2rc2) + CVE-2026-36849 (read-buffer alloc);
NOTE: 20260709: read-path, both suites.
--
-tomcat10/bookworm
+tomcat10
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Upcoming DSA (Beuc/front-desk)
--
@@ -724,7 +709,7 @@ unbound
NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
--
-urwid/bookworm
+urwid
NOTE: 20260802: Added by Front-Desk (ta)
NOTE: 20260802: not the same code but the same reasoning (ta)
--
@@ -739,7 +724,7 @@ vim (lee)
NOTE: 20260228: useful to spot regressions. (paride)
NOTE: 20260706: Fix Bookworm as well; was this already intended when offering the updates for stable/DSA? (dleidert/front-desk)
--
-vips/bookworm
+vips
NOTE: 20260522: Added by Front-Desk (Beuc)
NOTE: 20260522: Follow bookworm 12.14 (8 CVEs) (Beuc/front-desk)
NOTE: 20260812: Four news CVEs published, already in dsa-needed, sync with
@@ -749,10 +734,10 @@ wireshark
NOTE: 20260430: Added by Front-Desk (lamby)
NOTE: 20260706: Also add for bookworm (Beuc/front-desk)
--
-wordpress/bookworm
+wordpress
NOTE: 20260807: Added by Front-Desk. Follow DSA (rouca)
--
-xen/bookworm
+xen
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie (Beuc/front-desk)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/20339b2b96b8357296aae5d4326ad9dae95d337e...8cee763d31f5ff5deb692773f6105028f108ea84
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/20339b2b96b8357296aae5d4326ad9dae95d337e...8cee763d31f5ff5deb692773f6105028f108ea84
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/15939621/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list