[Git][security-tracker-team/security-tracker][master] Reserve DLA-4773-1 for libssh2

Emmanuel Arias (@eamanu) eamanu at debian.org
Sat Sep 5 13:47:08 BST 2026



Emmanuel Arias pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1b238584 by Emmanuel Arias at 2026-09-05T09:46:37-03:00
Reserve DLA-4773-1 for libssh2

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -112775,7 +112775,6 @@ CVE-2026-7599 (A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This aff
 CVE-2026-7598 (A security vulnerability has been detected in libssh2 up to 1.11.1. Th ...)
 	{DSA-6365-1}
 	- libssh2 1.11.1-3 (bug #1135647)
-	[bookworm] - libssh2 <no-dsa> (Minor issue)
 	[bullseye] - libssh2 <postponed> (Minor issue, unlikely user/pass length)
 	NOTE: https://github.com/libssh2/libssh2/pull/1858
 	NOTE: https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[05 Sep 2026] DLA-4773-1 libssh2 - security update
+	{CVE-2025-15661 CVE-2026-7598 CVE-2026-58050 CVE-2026-58051 CVE-2026-66032 CVE-2026-66034}
+	[bookworm] - libssh2 1.10.0-3+deb12u1
 [04 Sep 2026] DLA-4772-1 pcre2 - security update
 	{CVE-2026-86145}
 	[bookworm] - pcre2 10.42-1+deb12u1


=====================================
data/dla-needed.txt
=====================================
@@ -348,16 +348,6 @@ libsoup2.4
 libssh
   NOTE: 20260731: Added by Front-Desk (ta)
 --
-libssh2 (eamanu)
-  NOTE: 20260625: Added by Front-Desk (lamby)
-  NOTE: 20260702: patches are under review (eamanu)
-  NOTE: 20260713: Still in review (eamanu)
-  NOTE: 20260808: mark CVE-2026-55200 and CVE-2026-55199 as not affected in bullseye
-  NOTE: 20260808: working in bookworm and in the new CVEs
-  NOTE: 20260809: bookworm and bullseye are ready, now will work on trixie-pu (eamanu)
-  NOTE: 20260812: asked to upstream for more information about CVE-2026-58051 and CVE-2026-58050 (eamanu)
-  NOTE: 20260821: patches ready, waiting for trixie-pu (eamanu)
---
 libwebsockets
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b238584550e9db948aba9bc18088265500e42d7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b238584550e9db948aba9bc18088265500e42d7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/0f390aaf/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list