[Git][security-tracker-team/security-tracker][master] 2 commits: lts: bullseye is no longer supported

Emilio Pozuelo Monfort (@pochu) pochu at debian.org
Tue Sep 1 15:17:21 BST 2026



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0055c324 by Emilio Pozuelo Monfort at 2026-09-01T16:13:22+02:00
lts: bullseye is no longer supported

Drop /bookworm suffix, it's no longer needed as bookworm is the
only supported release.

- - - - -
8cee763d by Emilio Pozuelo Monfort at 2026-09-01T16:13:23+02:00
lts: drop ca-certificates

It has already been uploaded to bookworm.

- - - - -


1 changed file:

- data/dla-needed.txt


Changes:

=====================================
data/dla-needed.txt
=====================================
@@ -25,17 +25,17 @@ To make it easier to see the entire history of an update, please append notes
 rather than remove/replace existing ones.
 
 --
-389-ds-base/bookworm
+389-ds-base
   NOTE: 20260413: Added by Front-Desk (rouca)
   NOTE: 20260413: Try to clean postponed CVE (rouca/FD)
   NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
 --
-activemq/bookworm
+activemq
   NOTE: 20260413: Added by Front-Desk (rouca)
   NOTE: 20260715: Also add for bookworm
   NOTE: 20260715: Upcoming DSA, though they may just bump version (Beuc/front-desk)
 --
-adminer/bookworm
+adminer
   NOTE: 20260801: Added by Front-Desk (ta)
 --
 amd64-microcode
@@ -53,7 +53,7 @@ amd64-microcode
   NOTE: 20251224: I think the required kernel microcode driver patch are: https://lists.openwall.net/linux-kernel/2025/10/27/1012
   NOTE: 20260615: bookworm (now lts) also needs fixes. (charles)
 --
-aom/bookworm
+aom
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: AV1 *encoder* flaws (SVC layer-id/LAP), CVE-2026-56208..56211; only
   NOTE: 20260709: bookworm (3.6.0) affected, bullseye not-affected (code added in aom 2.0.0).
@@ -69,37 +69,22 @@ busybox
   NOTE: 20260722: Also add for bookworm; CVE-2026-38752..38755 (ash/awk)
   NOTE: 20260722: share code, sponsored, already queued bullseye+ELTS (utkarsh)
 --
-ca-certificates
-  NOTE: 20250613: Added by Front-Desk (rouca)
-  NOTE: 20250613: Lack some certificates #1095913 (rouca/FD)
-  NOTE: 20250613: Coordinate with bookworm PU if needed (rouca/FD)
-  NOTE: 20250613: Document carefully changes in backport, particularly removed certificates (rouca/FD)
-  NOTE: 20250731: will likely need an upload of ca-certificates-jave before and breaks/update (rouca)
-  NOTE: 20250731: WIP break piuparts (rouca)
-  NOTE: 20250801: Propose for review a ca-certificates-java (rouca)
-  NOTE: 20250811: upload ca-certificates-java (rouca)
-  NOTE: 20250811: wait for direction from security team about bookworm update first (rouca)
-  NOTE: 20260216: partial update under debusine https://debusine.debian.net/debian/developers/work-request/446642/
-  NOTE: 20260220: Release partial DLA 4485-1
-  NOTE: 20260710: bookworm update seems to be required: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1107237#48 (santiago)
-  NOTE: 20260810: made a release from trixie DLA-4726-1 (rouca). Will need last sid version to go to trixie (rouca)
---
-cacti/bookworm
+cacti
   NOTE: 20260630: Added by Front-Desk (dleidert)
   NOTE: 20260630: A new bunch of issues and in DSA list (dleidert/front-desk)
 --
-caddy/bookworm
+caddy
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
-cjson/bookworm
+cjson
   NOTE: 20260801: Added by Front-Desk (ta)
 --
 clamav (Emilio)
   NOTE: 20260711: Added by Front-Desk (utkarsh)
   NOTE: 20260711: Needs a newer rustc to be backported as well. (utkarsh)
 --
-cockpit/bookworm
+cockpit
   NOTE: 20260819: Added by Front-Desk (lamby)
 --
 composer
@@ -116,14 +101,14 @@ cups (Thorsten Alteholz)
   NOTE: 20260615: bookworm also need the same fixes as bullseye. (charles)
   NOTE: 20260705: still trying to find a solution to fix a CVE without changing the functionality of lpadmin
 --
-cyrus-imapd/bookworm
+cyrus-imapd
   NOTE: 20260717: Added by Front-Desk (Beuc)
   NOTE: 20260717: Upcoming DSA (Beuc/front-desk)
   NOTE: 20260901: Some CVE fixes were prepared on the bookworm branch by ejjl
   NOTE: 20260901: (a Debian Contributor) and merged by yadd (maintainer):
   NOTE: 20260901: https://salsa.debian.org/debian/cyrus-imapd/-/merge_requests/27
 --
-designate/bookworm
+designate
   NOTE: 20260818: Added by Front-Desk (lamby)
   NOTE: 20260823: Maintainer uploaded fixes for bookworm. (Charles)
 --
@@ -135,7 +120,7 @@ dovecot
   NOTE: 20260829: Added by Front-Desk (dleidert)
   NOTE: 20260829: Upcoming DSA (dleidert/front-desk)
 --
-dracut/bookworm
+dracut
   NOTE: 20260611: Added by Front-Desk (rouca)
   NOTE: 20260611: Please investigate impact of legacy network on older release of dracut aka CVE-2026-6893 (rouca/FD)
 --
@@ -153,7 +138,7 @@ erlang
   NOTE: 20260519: Fix ELTS at the same time. (Beuc/front-desk)
   NOTE: 20260702: Another round of issues and upcoming DSA (dleidert/front-desk)
 --
-evolution-data-server/bookworm
+evolution-data-server
   NOTE: 20260717: Added by Front-Desk (Beuc)
   NOTE: 20260717: Follow DLA-4503-1/bullseye (1 CVE) (Beuc/front-desk)
 --
@@ -187,7 +172,7 @@ flatpak
   NOTE: 20260811: chained to RCE. In DSA needed, maintainer taking care of
   NOTE: 20260811: trixie update, follow DSA. (charles)
 --
-freecad/bookworm
+freecad
   NOTE: 20260821: Added by Front-Desk (lamby)
 --
 freerdp2
@@ -203,20 +188,20 @@ frr
 gawk
   NOTE: 20260801: Added by Front-Desk (ta)
 --
-gegl/bookworm
+gegl
   NOTE: 20260821: Added by Front-Desk (lamby)
   NOTE: 20260821: Not immediately clear how the changes to libs/ctx/ctx.h (not present in bullseye LTS) interact with libs/rgbe/rgbe.c, so this may not be vulnerable in bullseye or earlier. (lamby)
 --
-gh/bookworm
+gh
   NOTE: 20241230: Added by Security Team (carnil)
   NOTE: 20260611: bookworm LTS handover.
 --
-gimp/bookworm
+gimp
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: PSP/PNM/PSD parser overflows CVE-2026-58379..58388 (crafted image); TIM-loader
   NOTE: 20260709: CVE-2026-59089 not-affected (GIMP 3.x-only).
 --
-git-lfs/bookworm
+git-lfs
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
 --
@@ -235,19 +220,19 @@ icinga2
   NOTE: 20260702: Follow DSA and/or support security team with DSA (dleidert/front-desk)
   NOTE: 20260702: also care about outstanding CVEs (dleidert/front-desk)
 --
-inkscape/bookworm
+inkscape
   NOTE: 20260522: Added by Security Team (jmm)
   NOTE: 20260611: bookworm LTS handover.
 --
-ironic/bookworm
+ironic
   NOTE: 20260610: Added by Front-Desk (rouca)
   NOTE: 20260816: Partial release by maintainer (charles)
 --
-isc-kea/bookworm
+isc-kea
   NOTE: 20260224: Added by Security Team (jmm)
   NOTE: 20260611: bookworm LTS handover.
 --
-jackson-databind/bookworm
+jackson-databind
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: CVE-2026-54512/54513/54514/54515 hit 2.12(bullseye)+2.14(bookworm);
   NOTE: 20260709: 54516/54517/54518 (>=2.21) and 50193 (bookworm 2.14) not-affected.
@@ -258,17 +243,17 @@ jbig2dec
 jetty9
   NOTE: 20260418: Added by Front-Desk. Fix CVE-2026-5795 maybe other (rouca)
 --
-jline3/bookworm
+jline3
   NOTE: 20260801: Added by Front-Desk (ta)
 --
-jpeg-xl/bookworm
+jpeg-xl
   NOTE: 20260619: Added by Front-Desk (charles)
   NOTE: 20260619: Follow DSA-6342-1 (charles)
 --
-kamailio/bookworm
+kamailio
   NOTE: 20260413: Added by Front-Desk (rouca)
 --
-keystone/bookworm
+keystone
   NOTE: 20260830: Added by Front-Desk (dleidert)
   NOTE: 20260830: Upcoming DSA (dleidert/front-desk)
 --
@@ -320,18 +305,18 @@ libio-compress-perl
   NOTE: 20260612: Added by Front-Desk (rouca)
   NOTE: 20260612: MUST hold-back following the upper suites and wait for green light from security team (rouca/FD)
 --
-libmojo-jwt-perl/bookworm
+libmojo-jwt-perl
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
 librest
   NOTE: 20260802: Added by Front-Desk (ta)
 --
-libreswan/bookworm
+libreswan
   NOTE: 20230301: Added by Security Team (jmm)
   NOTE: 20260611: bookworm LTS handover.
   NOTE: 20260611: Sync with maintainer (dkg), hard to test.
 --
-libsoup2.4/bookworm
+libsoup2.4
   NOTE: 20250408: Added by Front-Desk (Beuc)
   NOTE: 20250427: libsoup2.4 2.72.0-2+deb11u2 (bullseye) uploaded ...
   NOTE: 20250427: ... without CVE-2025-32907 and CVE-2025-32049.
@@ -382,11 +367,11 @@ libssh2 (eamanu)
   NOTE: 20260812: asked to upstream for more information about CVE-2026-58051 and CVE-2026-58050 (eamanu)
   NOTE: 20260821: patches ready, waiting for trixie-pu (eamanu)
 --
-libwebsockets/bookworm
+libwebsockets
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
 --
-linux/bookworm (Ben Hutchings)
+linux (Ben Hutchings)
   NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
 --
 logback
@@ -397,7 +382,7 @@ logback
   NOTE: 20260726: LTS too. Also fix the other postponed logback CVEs, and it
   NOTE: 20260726: should be fixed for trixie too (1.2.11-6 affected). (utkarsh/front-desk)
 --
-lrzip/bookworm
+lrzip
   NOTE: 20260725: Added by Front-Desk (utkarsh)
   NOTE: 20260725: CVE-2025-15570; fixed in bullseye via DLA-4567-1. bookworm
   NOTE: 20260725: 0.651-2 has the same UAF (thread_count guard absent); fix is
@@ -407,23 +392,23 @@ lrzip/bookworm
 lxml
   NOTE: 20260614: Added by Front-Desk (rouca)
 --
-mediawiki/bookworm
+mediawiki
   NOTE: 20260713: Added by Front-Desk (Beuc)
   NOTE: 20260713: Follow DSA-6380-1 (10 CVEs) (Beuc/front-desk)
 --
-memcached/bookworm
+memcached
   NOTE: 20260717: Added by Front-Desk (Beuc)
   NOTE: 20260717: Follow DLA-4601-1/bullseye (2 CVEs)
   NOTE: 20260717: Fix other postponed issues while we're at it (Beuc/front-desk)
 --
-mistral/bookworm
+mistral
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
-nats-server/bookworm
+nats-server
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
-netty/bookworm (rouca)
+netty (rouca)
   NOTE: 20250814: Added by Front-Desk (lamby)
   NOTE: 20251115: Partial release for sid. Fix all CVEs except CVE-2025-58056 (rouca)
   NOTE: 20251127: all CVEs fixed under sid (rouca)
@@ -438,18 +423,18 @@ nginx (charles)
   NOTE: 20260618: There was also a customer request to fix it. (charles)
   NOTE: 20260630: Bullseye fix release with 2 CVE fixes + http2 bomb fix. Bookworm coming soon. (charles)
 --
-node-dompurify/bookworm
+node-dompurify
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
-node-ip-address/bookworm
+node-ip-address
   NOTE: 20260804: Added by Front-Desk (rouca)
 --
-node-lodash/bookworm (utkarsh)
+node-lodash (utkarsh)
   NOTE: 20260703: Added by Front-Desk (dleidert)
   NOTE: 20260703: Follow DLA 4663-1; assigned to Utkarsh to grab this (dleidert/front-desk)
 --
-node-re2/bookworm
+node-re2
   NOTE: 20260806: Added by Front-Desk (rouca)
   NOTE: 20260806: CVE-2026-68499 is worth fixing due to re2 used for fixing redos and other regex problem on backport (rouca)
 --
@@ -467,7 +452,7 @@ openexr
   NOTE: 20260413: Added by Front-Desk (rouca)
   NOTE: 20260713: Also add for bookworm (Beuc/front-desk)
 --
-openimageio/bookworm
+openimageio
   NOTE: 20260726: Added by Front-Desk (utkarsh)
   NOTE: 20260726: Six memory-corruption flaws in image readers that are
   NOTE: 20260726: built by default and reached by decoding an untrusted
@@ -497,10 +482,10 @@ pacemaker
   NOTE: 20260618: Added by Front-Desk (charles)
   NOTE: 20260618: Package is in dsa-needed (charles)
 --
-pcp/bookworm
+pcp
   NOTE: 20260801: Added by Front-Desk (ta)
 --
-pdfminer/bookworm
+pdfminer
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: CVE-2025-70559 is follow-up fix for CVE-2025-64512
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
@@ -509,17 +494,17 @@ perl
   NOTE: 20260527: Added by Front-Desk (santiago)
   NOTE: 20260527: wait for the DSA before releasing
 --
-pgextwlist/bookworm
+pgextwlist
   NOTE: 20260714: Added by Front-Desk (Beuc)
   NOTE: 20260714: Follow DSA-6385-1 (1 CVE) (Beuc/front-desk)
 --
-pglogical/bookworm
+pglogical
   NOTE: 20260805: Added by Front-Desk, due to CVE-2026-50738 (rouca)
 --
-php-dompdf/bookworm
+php-dompdf
   NOTE: 20260804: Added by Front-Desk (rouca)
 --
-php-laravel-framework/bookworm
+php-laravel-framework
   NOTE: 20250307: Added by Front-Desk (rouca)
   NOTE: 20251027: History of upstream branch fixing v12: git log 9de75259..2d133034^2.
   NOTE: 20251027: There was an attempt to backport to v9, but it got rejected upstream
@@ -537,10 +522,10 @@ proftpd-dfsg
   NOTE: 20260511: https://salsa.debian.org/debian-proftpd-team/proftpd/-/commits/bullseye
   NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
 --
-puma/bookworm
+puma
   NOTE: 20260804: Added by Front-Desk (rouca)
 --
-py7zr/bookworm
+py7zr
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: CVE-2026-23879 (GHSA range <=1.1.2); Debian 0.11.3 in range.
 --
@@ -552,17 +537,17 @@ python-aiohttp (dleidert)
   NOTE: 20260611: Added by Front-Desk (rouca)
   NOTE: 20260602: Daniel Leidert is proposing to work on the update and provide debdiffs for bookworm and trixie (carnil)
 --
-python-asyncssh/bookworm
+python-asyncssh
   NOTE: 20260806: Added by Front-Desk (rouca)
 --
 python-cryptography
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
-python-eventlet/bookworm
+python-eventlet
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
 --
-python-geopandas/bookworm
+python-geopandas
   NOTE: 20260725: Added by Front-Desk (utkarsh)
   NOTE: 20260725: CVE-2025-69662; fixed in bullseye via DLA-4523-1. bookworm
   NOTE: 20260725: 0.12.2-1 still builds the Find_SRID query with .format(); fix
@@ -570,7 +555,7 @@ python-geopandas/bookworm
   NOTE: 20260725: Should be fixed for trixie too, which still ships an
   NOTE: 20260725: affected 1.0.1-2. (utkarsh/front-desk)
 --
-python-git/bookworm
+python-git
   NOTE: 20260726: Added by Front-Desk (utkarsh)
   NOTE: 20260726: CVE-2026-42215 bypasses the check_unsafe_options guard
   NOTE: 20260726: that DLA-3939-1 itself backported, so our own earlier fix
@@ -596,7 +581,7 @@ python-tornado
   NOTE: 20260722: Extend to bullseye; CVE-2026-49853/49854/49855 in 6.1.0 too,
   NOTE: 20260722: shared with bookworm; fix in 6.5.6 (utkarsh/front-desk)
 --
-python-zeroconf/bookworm
+python-zeroconf
   NOTE: 20260804: Added by Front-Desk (rouca)
 --
 qemu
@@ -613,17 +598,17 @@ rsync (Thorsten Alteholz)
   NOTE: 20260615: Requested by Sylvain to track regressions, same as in dsa-needed. (charles)
   NOTE: 20260705: making progress with updated patches
 --
-ruby-jwt/bookworm
+ruby-jwt
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
-ruby-oauth2/bookworm
+ruby-oauth2
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
-ruby-oj/bookworm
+ruby-oj
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: Oj JSON parser memory-safety batch CVE-2026-54500..54903 (GHSA); affects 2.17-3.14.
 --
-ruby3.1/bookworm
+ruby3.1
   NOTE: 20260713: Added by Front-Desk (Beuc)
   NOTE: 20260523: Bumping to new upstream rejected by SRM, do backport patches:
   NOTE: 20260523: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1103854
@@ -644,14 +629,14 @@ runc
   NOTE: 20260223: Updated #1120140 with some thoughts, asking for more opinions (kanashiro)
   NOTE: 20260706: Please handle Bookworm as well (dleidert/front-desk)
 --
-sabnzbdplus/bookworm
+sabnzbdplus
   NOTE: 20260830: Added by Front-Desk (dleidert)
   NOTE: 20260830: Follow DSA 6454-1 (dleidert/front-desk)
 --
 samba (Markus Koschany)
   NOTE: 20260809: Added by Front-Desk (rouca)
 --
-shiro/bookworm
+shiro
   NOTE: 20260726: Added by Front-Desk (utkarsh)
   NOTE: 20260726: CVE-2026-56091: SimpleFilterChainResolver in shiro-guice
   NOTE: 20260726: does not normalise a trailing slash, so a request for
@@ -691,11 +676,11 @@ sssd
   NOTE: 20260804: Crash or DoS of sssd may lead to user lockdown (rouca/FD)
   NOTE: 20260804: SSSD should be tested carefully, with integration test (rouca/FD)
 --
-suricata-update/bookworm
+suricata-update
   NOTE: 20260830: Added by Front-Desk (dleidert)
   NOTE: 20260830: Follow DSA-6475-1 (dleidert/front-desk)
 --
-swift/bookworm
+swift
   NOTE: 20260726: Added by Front-Desk (utkarsh)
   NOTE: 20260726: CVE-2026-50221: proxy gatekeeper does not strip the
   NOTE: 20260726: X-Container-Host/X-Delete-At-Host update headers from
@@ -712,7 +697,7 @@ tiff
   NOTE: 20260709: CVE-2026-12912 (fixed 4.7.2rc2) + CVE-2026-36849 (read-buffer alloc);
   NOTE: 20260709: read-path, both suites.
 --
-tomcat10/bookworm
+tomcat10
   NOTE: 20260714: Added by Front-Desk (Beuc)
   NOTE: 20260714: Upcoming DSA (Beuc/front-desk)
 --
@@ -724,7 +709,7 @@ unbound
   NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
   NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
 --
-urwid/bookworm
+urwid
   NOTE: 20260802: Added by Front-Desk (ta)
   NOTE: 20260802: not the same code but the same reasoning (ta)
 --
@@ -739,7 +724,7 @@ vim (lee)
   NOTE: 20260228: useful to spot regressions. (paride)
   NOTE: 20260706: Fix Bookworm as well; was this already intended when offering the updates for stable/DSA? (dleidert/front-desk)
 --
-vips/bookworm
+vips
   NOTE: 20260522: Added by Front-Desk (Beuc)
   NOTE: 20260522: Follow bookworm 12.14 (8 CVEs) (Beuc/front-desk)
   NOTE: 20260812: Four news CVEs published, already in dsa-needed, sync with
@@ -749,10 +734,10 @@ wireshark
   NOTE: 20260430: Added by Front-Desk (lamby)
   NOTE: 20260706: Also add for bookworm (Beuc/front-desk)
 --
-wordpress/bookworm
+wordpress
   NOTE: 20260807: Added by Front-Desk. Follow DSA (rouca)
 --
-xen/bookworm
+xen
   NOTE: 20260714: Added by Front-Desk (Beuc)
   NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie (Beuc/front-desk)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/20339b2b96b8357296aae5d4326ad9dae95d337e...8cee763d31f5ff5deb692773f6105028f108ea84

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/20339b2b96b8357296aae5d4326ad9dae95d337e...8cee763d31f5ff5deb692773f6105028f108ea84
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/15939621/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list