[Git][security-tracker-team/security-tracker][master] Reserve DLA-4773-1 for libssh2
Emmanuel Arias (@eamanu)
eamanu at debian.org
Sat Sep 5 13:47:08 BST 2026
Emmanuel Arias pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1b238584 by Emmanuel Arias at 2026-09-05T09:46:37-03:00
Reserve DLA-4773-1 for libssh2
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -112775,7 +112775,6 @@ CVE-2026-7599 (A vulnerability was detected in Dayoooun hwpx-mcp 0.2.0. This aff
CVE-2026-7598 (A security vulnerability has been detected in libssh2 up to 1.11.1. Th ...)
{DSA-6365-1}
- libssh2 1.11.1-3 (bug #1135647)
- [bookworm] - libssh2 <no-dsa> (Minor issue)
[bullseye] - libssh2 <postponed> (Minor issue, unlikely user/pass length)
NOTE: https://github.com/libssh2/libssh2/pull/1858
NOTE: https://github.com/libssh2/libssh2/commit/256d04b60d80bf1190e96b0ad1e91b2174d744b1
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[05 Sep 2026] DLA-4773-1 libssh2 - security update
+ {CVE-2025-15661 CVE-2026-7598 CVE-2026-58050 CVE-2026-58051 CVE-2026-66032 CVE-2026-66034}
+ [bookworm] - libssh2 1.10.0-3+deb12u1
[04 Sep 2026] DLA-4772-1 pcre2 - security update
{CVE-2026-86145}
[bookworm] - pcre2 10.42-1+deb12u1
=====================================
data/dla-needed.txt
=====================================
@@ -348,16 +348,6 @@ libsoup2.4
libssh
NOTE: 20260731: Added by Front-Desk (ta)
--
-libssh2 (eamanu)
- NOTE: 20260625: Added by Front-Desk (lamby)
- NOTE: 20260702: patches are under review (eamanu)
- NOTE: 20260713: Still in review (eamanu)
- NOTE: 20260808: mark CVE-2026-55200 and CVE-2026-55199 as not affected in bullseye
- NOTE: 20260808: working in bookworm and in the new CVEs
- NOTE: 20260809: bookworm and bullseye are ready, now will work on trixie-pu (eamanu)
- NOTE: 20260812: asked to upstream for more information about CVE-2026-58051 and CVE-2026-58050 (eamanu)
- NOTE: 20260821: patches ready, waiting for trixie-pu (eamanu)
---
libwebsockets
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b238584550e9db948aba9bc18088265500e42d7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1b238584550e9db948aba9bc18088265500e42d7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/0f390aaf/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list