[Git][security-tracker-team/security-tracker][master] 2 commits: lts: triage two node issues as postponed

Emilio Pozuelo Monfort (@pochu) pochu at debian.org
Fri Sep 4 11:50:52 BST 2026



Emilio Pozuelo Monfort pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bc03f42a by Emilio Pozuelo Monfort at 2026-09-04T12:34:58+02:00
lts: triage two node issues as postponed

- - - - -
e0baf8a1 by Emilio Pozuelo Monfort at 2026-09-04T12:50:37+02:00
lts: add packages

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2406,6 +2406,7 @@ CVE-2026-84059 (A flaw has been found in ICP DAS UA-2200 and UA-5200 up to 20260
 	NOT-FOR-US: ICP DAS UA-2200 and UA-5200
 CVE-2026-83619 (xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core)  ...)
 	- node-xmldom 0.9.5-1
+	[bookworm] - node-xmldom <postponed> (Minor issue)
 	NOTE: https://github.com/xmldom/xmldom/security/advisories/GHSA-x4fp-j954-r2f4
 	NOTE: https://github.com/xmldom/xmldom/pull/1072
 	NOTE: Fixed by: https://github.com/xmldom/xmldom/commit/3abb0934f5a8a84d83a1f9cde0f2bd04c08b2a09 (0.8.15)
@@ -3395,6 +3396,7 @@ CVE-2026-82855 (@hulumi/policies versions before 1.3.2 contain an evidence valid
 CVE-2026-82854 (Nodemailer before 8.0.4 is vulnerable to SMTP command injection throug ...)
 	- node-nodemailer 8.0.4+~7.0.11-1
 	[trixie] - node-nodemailer <no-dsa> (Minor issue)
+	[bookworm] - node-nodemailer <postponed> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-c7w3-x93f-qmm8
 CVE-2026-82853 (Nodemailer versions before 8.0.5 contain an SMTP command injection vul ...)
 	- node-nodemailer 8.0.11+~8.0.1-1


=====================================
data/dla-needed.txt
=====================================
@@ -77,6 +77,9 @@ caddy
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
+chromium (Emilio)
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 cjson
   NOTE: 20260801: Added by Front-Desk (ta)
 --
@@ -165,6 +168,9 @@ flatpak
   NOTE: 20260811: chained to RCE. In DSA needed, maintainer taking care of
   NOTE: 20260811: trixie update, follow DSA. (charles)
 --
+fort-validator
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 freecad
   NOTE: 20260821: Added by Front-Desk (lamby)
 --
@@ -273,6 +279,9 @@ libde265
   NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
   NOTE: 20260709: upstream fixes v1.0.19-v1.1.1 newer than Debian 1.0.11.
 --
+libevent
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 libgd-securityimage-perl
   NOTE: 20260806: Added by Front-Desk (rouca)
 --
@@ -386,6 +395,9 @@ memcached
 mistral
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
+nagios4
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 nats-server
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
@@ -423,6 +435,9 @@ node-re2
 nodejs
   NOTE: 20260622: Added by Front-Desk (lamby)
 --
+nsd
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 ntfs-3g
   NOTE: 20260716: Added by Front-Desk (Beuc)
   NOTE: 20260716: Follow DSA-6389-1 (9 CVEs) (Beuc/front-desk)
@@ -572,9 +587,15 @@ qemu
   NOTE: 20260520: Also SPU/OSPU included a rebuild with updated glibc/glib2.0 (Beuc/front-desk)
   NOTE: 20260713: New SPU/OSPU included a rebuild with updated gnutls28 (Beuc/front-desk)
 --
+rabbitmq-server
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 rails
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
+redis
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 rsync (Thorsten Alteholz)
   NOTE: 20260615: Added by Front-Desk (charles)
   NOTE: 20260615: Requested by Sylvain to track regressions, same as in dsa-needed. (charles)
@@ -650,6 +671,9 @@ snapd
   NOTE: 20260726: in 2.71-1. Entry was bullseye-only as bookworm was not yet
   NOTE: 20260726: LTS when it was filed in 2026-03. (utkarsh/front-desk)
 --
+sogo
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 srt
   NOTE: 20260809: Added by Front-Desk (rouca)
 --
@@ -715,6 +739,9 @@ vips
   NOTE: 20260812: Four news CVEs published, already in dsa-needed, sync with
   NOTE: 20260812: secteam or follow DSA.  (charles/front-desk)
 --
+weechat
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 wireshark
   NOTE: 20260430: Added by Front-Desk (lamby)
   NOTE: 20260706: Also add for bookworm (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1937a40fb482988dc31ba0219d1b58feddd1b45b...e0baf8a154a9ae1400ee2adfd59c463e901cd7d1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1937a40fb482988dc31ba0219d1b58feddd1b45b...e0baf8a154a9ae1400ee2adfd59c463e901cd7d1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/e3e694bb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list