[Git][security-tracker-team/security-tracker][ecite/suricata-cves-202608] 511 commits: DLA template: Remove support to mention bullseye as LTS supported release

Andreas Dolp (@ecite) gitlab at salsa.debian.org
Tue Sep 8 10:38:11 BST 2026



Andreas Dolp pushed to branch ecite/suricata-cves-202608 at Debian Security Tracker / security-tracker


Commits:
a33f23f8 by Salvatore Bonaccorso at 2026-08-17T20:49:05+02:00
DLA template: Remove support to mention bullseye as LTS supported release

With EOL (from security-tracker and Debian's perspective) of Debian
bullseye, adapt the template to remove the bullseye mentioning and
bullseye from the Version field.

Link: https://lists.debian.org/debian-lts-announce/2026/08/msg00033.html
Signed-off-by: Salvatore Bonaccorso <carnil at debian.org>

- - - - -
216e67e0 by Salvatore Bonaccorso at 2026-08-17T20:49:15+02:00
config.json: Drop bullseye as supported release

Drop architecture and release setting for bullseye marking it
effectively as not supported anymore in the Debian security-tracker
instance.

Link: https://lists.debian.org/debian-lts-announce/2026/08/msg00033.html
Signed-off-by: Salvatore Bonaccorso <carnil at debian.org>

- - - - -
c1b5cd38 by Salvatore Bonaccorso at 2026-08-17T20:49:21+02:00
distributions.json: Drop contact information for bullseye

Link: https://lists.debian.org/debian-lts-announce/2026/08/msg00033.html
Signed-off-by: Salvatore Bonaccorso <carnil at debian.org>

- - - - -
23a0c324 by Salvatore Bonaccorso at 2026-08-31T20:23:53+02:00
Adjust introducing commit for CVE-2026-76956

- - - - -
a87da6cc by Salvatore Bonaccorso at 2026-08-31T20:25:48+02:00
Update status for some expat issues

- - - - -
c5b69185 by Salvatore Bonaccorso at 2026-08-31T20:30:38+02:00
Track fixed version for expat issues

- - - - -
b5e25583 by Salvatore Bonaccorso at 2026-08-31T20:51:51+02:00
Update references for CVE-2026-18497

While https://github.com/nothings/stb/issues/1962 looks in releated area
and might be a duplicate, CVE-2026-18497 is associated for
https://www.kb.cert.org/vuls/id/987105 and
https://github.com/nothings/stb/issues/1905 .

- - - - -
e893b8be by Moritz Muehlenhoff at 2026-08-31T20:54:32+02:00
one openssh issue n/a for debian

- - - - -
51f3919f by Salvatore Bonaccorso at 2026-08-31T21:03:55+02:00
Update status for CVE-2026-18393

- - - - -
c67331b4 by Salvatore Bonaccorso at 2026-08-31T21:08:37+02:00
Add Debian bug reference for CVE-2026-77220/pdfio

- - - - -
0a87d52a by security tracker role at 2026-08-31T19:13:52+00:00
automatic update

- - - - -
30ee9421 by security tracker role at 2026-08-31T19:14:55+00:00
automatic NOT-FOR-US entries update

- - - - -
6dc233fe by Salvatore Bonaccorso at 2026-08-31T21:15:50+02:00
Mark CVE-2026-82474/sudo as unimportant

- - - - -
c3d9f8a0 by Salvatore Bonaccorso at 2026-08-31T21:19:24+02:00
Remove notes from one rejected CVE

- - - - -
0c277f64 by Salvatore Bonaccorso at 2026-08-31T21:26:48+02:00
Process some NFUs

- - - - -
ebc17442 by Salvatore Bonaccorso at 2026-08-31T21:30:57+02:00
Add two "new" node-nodemailer issues

- - - - -
36a28bb3 by Salvatore Bonaccorso at 2026-08-31T21:43:33+02:00
Add two new issues in FLVMeta

- - - - -
60f58b0a by Salvatore Bonaccorso at 2026-08-31T21:44:34+02:00
Process some NFUs

- - - - -
c38f8eaa by Guilhem Moulin at 2026-08-31T21:48:07+02:00
Reserve DLA-4764-2 for libdbd-csv-perl

- - - - -
fc5626e5 by Salvatore Bonaccorso at 2026-08-31T21:55:42+02:00
Add new node-nodemailer issues

- - - - -
61a06b49 by Salvatore Bonaccorso at 2026-08-31T22:05:17+02:00
Add CVE-2026-82797/rlottie

- - - - -
818adc01 by Salvatore Bonaccorso at 2026-08-31T22:07:50+02:00
Add two valkey issues

- - - - -
dae82b86 by Salvatore Bonaccorso at 2026-08-31T22:08:21+02:00
Process some NFUs

- - - - -
89d5829c by Salvatore Bonaccorso at 2026-08-31T22:09:17+02:00
Add new undertow issue

- - - - -
0ed346b7 by Salvatore Bonaccorso at 2026-08-31T22:26:28+02:00
Add CVE-2026-78422/rust-zbus-polkit

- - - - -
b0d4fa6a by Moritz Mühlenhoff at 2026-08-31T22:47:45+02:00
fluidsynth spu

- - - - -
ab9e5f24 by Moritz Mühlenhoff at 2026-08-31T22:59:31+02:00
perl spu

- - - - -
af69d833 by Andrej Shadura at 2026-08-31T23:06:16+02:00
Reserve DLA-4765-1 for expat

- - - - -
b66660b4 by Daniel Leidert at 2026-09-01T00:02:19+02:00
lts: claim libass

- - - - -
3f9e883c by Salvatore Bonaccorso at 2026-09-01T05:32:58+02:00
Track proposed update for golang-github-containers-buildah

- - - - -
00d8ca06 by Salvatore Bonaccorso at 2026-09-01T05:33:48+02:00
Corrdination for trixie-pu done now, drop perl from dsa-needed

- - - - -
b46ca187 by Salvatore Bonaccorso at 2026-09-01T05:36:00+02:00
Track fixed version for various pytho-git issues

- - - - -
bfced484 by Salvatore Bonaccorso at 2026-09-01T06:25:38+02:00
Track fixed version for CVE-2026-19873/libhtml-formfu-perl

- - - - -
56a02fa9 by Salvatore Bonaccorso at 2026-09-01T06:36:46+02:00
Track fixed version for dovecot issues fixed via unstable

- - - - -
c50e0c1b by Salvatore Bonaccorso at 2026-09-01T06:47:40+02:00
Track fixed version for three openssh issues addressed via unstable

- - - - -
68342a9e by Salvatore Bonaccorso at 2026-09-01T06:57:13+02:00
Add new mariadb issues relating to Oracle CVEs assigned for MySQL

- - - - -
8c328eb9 by Salvatore Bonaccorso at 2026-09-01T07:18:08+02:00
Track fixed version via unstable for chromium issues

- - - - -
64839727 by Salvatore Bonaccorso at 2026-09-01T07:19:35+02:00
Track openssh-gssapi issues as well in sync with openssh

- - - - -
b125d9f6 by Salvatore Bonaccorso at 2026-09-01T07:20:50+02:00
Track fixed version via unstable for pcre2 issues

- - - - -
306f6486 by Salvatore Bonaccorso at 2026-09-01T07:32:07+02:00
Mark pcre2 issues as no-dsa

- - - - -
1c3197fb by Salvatore Bonaccorso at 2026-09-01T07:33:37+02:00
Track fixed version for CVE-2026-78422/rust-zbus-polkit via unstable

- - - - -
87c7e4e8 by Salvatore Bonaccorso at 2026-09-01T07:41:10+02:00
More CVEs covered in proposed trixie-pu update for python-aiohttp

- - - - -
14e97efe by Salvatore Bonaccorso at 2026-09-01T07:57:42+02:00
Update status for two node-babel7 issues

- - - - -
993969cd by Salvatore Bonaccorso at 2026-09-01T08:11:26+02:00
Add new libheif issue

- - - - -
da0dbea1 by Salvatore Bonaccorso at 2026-09-01T08:13:01+02:00
Mark CVE-2026-16517/libarchive

- - - - -
174b9773 by security tracker role at 2026-09-01T07:12:48+00:00
automatic update

- - - - -
b84eb790 by security tracker role at 2026-09-01T07:13:40+00:00
automatic NOT-FOR-US entries update

- - - - -
b810583b by Salvatore Bonaccorso at 2026-09-01T09:27:35+02:00
Process some NFUs

- - - - -
eb867030 by Salvatore Bonaccorso at 2026-09-01T09:36:01+02:00
Add CVE-2026-82398/pypdf

- - - - -
4df31a21 by Salvatore Bonaccorso at 2026-09-01T09:36:39+02:00
Process some NFUs

- - - - -
847b872b by Emilio Pozuelo Monfort at 2026-09-01T09:37:33+02:00
lts: drop some bullseye specific packages

- - - - -
a5c851c4 by Moritz Muehlenhoff at 2026-09-01T09:39:04+02:00
track libskia issues from latest Chromium release

- - - - -
e78a1f0a by Salvatore Bonaccorso at 2026-09-01T09:40:15+02:00
Add CVE-2026-82397/python-tornado

- - - - -
e1958382 by Salvatore Bonaccorso at 2026-09-01T09:40:35+02:00
Add two new pnpm issues

- - - - -
ec63421d by Salvatore Bonaccorso at 2026-09-01T09:41:25+02:00
Add CVE-2024-58379

- - - - -
a556b889 by Moritz Muehlenhoff at 2026-09-01T09:49:12+02:00
auto-nfu: Extend vmware rule

- - - - -
9859d119 by Salvatore Bonaccorso at 2026-09-01T10:16:29+02:00
Track fixed version via unstable for one sabnzbdplus issue

- - - - -
0ea5c074 by Salvatore Bonaccorso at 2026-09-01T11:05:27+02:00
Process some NFUs

- - - - -
fc690a68 by Emilio Pozuelo Monfort at 2026-09-01T13:54:38+02:00
lts: drop more bullseye specific packages

- - - - -
32169dbc by Emilio Pozuelo Monfort at 2026-09-01T14:15:31+02:00
lts: drop more bullseye packages

- - - - -
349a36ea by Emilio Pozuelo Monfort at 2026-09-01T14:33:30+02:00
lts: move some packages to bookworm only

- - - - -
e14935e3 by Salvatore Bonaccorso at 2026-09-01T14:46:24+02:00
Mark two perl issues as no-dsa

- - - - -
eef7db4e by Moritz Muehlenhoff at 2026-09-01T14:55:08+02:00
trixie triage

- - - - -
4f711957 by Sylvain Beucler at 2026-09-01T15:05:48+02:00
lts: reference prior cyrus-imapd bookworm work

- - - - -
6d12af25 by Salvatore Bonaccorso at 2026-09-01T15:27:35+02:00
Merge branch 'bullseye-lts-eol' into 'master'

Mark bullseye as end-of-life from tracker perspective

See merge request security-tracker-team/security-tracker!298
- - - - -
20339b2b by Salvatore Bonaccorso at 2026-09-01T16:03:57+02:00
Add new firefox issues from mfsa2026-82

- - - - -
0055c324 by Emilio Pozuelo Monfort at 2026-09-01T16:13:22+02:00
lts: bullseye is no longer supported

Drop /bookworm suffix, it's no longer needed as bookworm is the
only supported release.

- - - - -
8cee763d by Emilio Pozuelo Monfort at 2026-09-01T16:13:23+02:00
lts: drop ca-certificates

It has already been uploaded to bookworm.

- - - - -
8d1aa48c by Xavier Guimard at 2026-09-01T17:49:34+02:00
Reserve DLA-4766-1 for cyrus-imapd

- - - - -
635491ca by Moritz Muehlenhoff at 2026-09-01T18:00:27+02:00
trixie triage

- - - - -
8bf9eb27 by Salvatore Bonaccorso at 2026-09-01T18:02:32+02:00
Add tracking for firefox-esr (via mfsa2026-84)

- - - - -
55d31b75 by Salvatore Bonaccorso at 2026-09-01T18:02:33+02:00
Add firefox-esr to dsa-needed list

- - - - -
ad0b4c25 by Emilio Pozuelo Monfort at 2026-09-01T18:15:01+02:00
lts: add firefox-esr

- - - - -
3880d09e by Salvatore Bonaccorso at 2026-09-01T19:34:46+02:00
Track proposed update for dnsmasq via trixie-pu

- - - - -
5128b4ed by Salvatore Bonaccorso at 2026-09-01T20:31:33+02:00
Track fixed version for CVE-2026-68005 via unstable

- - - - -
d4488466 by Salvatore Bonaccorso at 2026-09-01T20:35:09+02:00
Track fixed version for pdfio issue fixed via unstable

- - - - -
13fd2c97 by Salvatore Bonaccorso at 2026-09-01T20:37:31+02:00
Track fixed version for two python-asyncssh issues

- - - - -
54f40afe by Salvatore Bonaccorso at 2026-09-01T20:44:09+02:00
Track packages now not present anymore in any supported suite

- - - - -
9ebf84eb by Salvatore Bonaccorso at 2026-09-01T20:47:19+02:00
Add Debian bug reference for CVE-2026-54552

- - - - -
d2420e3a by Salvatore Bonaccorso at 2026-09-01T20:51:01+02:00
Track fixed version for one npm issue fixed via unstable

- - - - -
b0e38878 by security tracker role at 2026-09-01T19:13:00+00:00
automatic update

- - - - -
f10c6113 by security tracker role at 2026-09-01T19:13:57+00:00
automatic NOT-FOR-US entries update

- - - - -
6b3a6a62 by Salvatore Bonaccorso at 2026-09-01T21:15:15+02:00
Cleanup some rejected CVEs

- - - - -
3b6c567f by Salvatore Bonaccorso at 2026-09-01T21:25:34+02:00
Add CVE-2026-84305/sqlparse

- - - - -
c3f68867 by Salvatore Bonaccorso at 2026-09-01T21:26:26+02:00
Add two golang-google-grpc issues

- - - - -
91a839d4 by Salvatore Bonaccorso at 2026-09-01T21:50:05+02:00
Add new gvfs issues

- - - - -
9a1e3aa1 by Salvatore Bonaccorso at 2026-09-01T21:56:44+02:00
Process some NFUs

- - - - -
95722640 by Salvatore Bonaccorso at 2026-09-01T21:57:51+02:00
Add CVE-2026-84233/rpm

- - - - -
a6b7765d by Salvatore Bonaccorso at 2026-09-01T22:00:13+02:00
Add CVE-2026-84206/snipe-it

- - - - -
301dab4e by Salvatore Bonaccorso at 2026-09-01T22:01:09+02:00
Add CVE-2026-84165/opennebula

- - - - -
db71d455 by Salvatore Bonaccorso at 2026-09-01T22:01:36+02:00
Map some CVEs to opennebula

- - - - -
e3bbac0a by Emmanuel Arias at 2026-09-01T17:07:03-03:00
Claim python-git in dla-needed.txt

- - - - -
42bc9ebf by Emmanuel Arias at 2026-09-01T17:11:02-03:00
data/CVE/list: Add commit link for CVE-2025-0938

- - - - -
3335f2a2 by Moritz Mühlenhoff at 2026-09-01T22:12:49+02:00
keystone DSA

- - - - -
92928578 by Salvatore Bonaccorso at 2026-09-01T22:24:04+02:00
Add node-xmldom issues

- - - - -
1a6fa770 by Emmanuel Arias at 2026-09-01T17:33:56-03:00
data/CVE/list: Add commit link for CVE-2023-24329 for v3.7

- - - - -
0ebc0a81 by Salvatore Bonaccorso at 2026-09-01T22:40:32+02:00
Add more node-xmldom issues

- - - - -
e59b8669 by Salvatore Bonaccorso at 2026-09-01T22:52:01+02:00
Add new spip issue

- - - - -
44dfd5be by Moritz Mühlenhoff at 2026-09-01T23:15:39+02:00
pcre2 spu

- - - - -
6d46a8e8 by Moritz Mühlenhoff at 2026-09-01T23:20:37+02:00
unrar-nonfree spu

- - - - -
57c06ec7 by Salvatore Bonaccorso at 2026-09-02T05:32:36+02:00
Track proposed udpate for libhttp-tiny-perl via trixie-pu

- - - - -
117f9c97 by Salvatore Bonaccorso at 2026-09-02T05:36:59+02:00
Track proposed update for libio-compress-perl via trixie-pu

- - - - -
ba2f76b2 by Salvatore Bonaccorso at 2026-09-02T05:38:35+02:00
Track proposed update for libsocket-perl via trixie-pu

- - - - -
51aeca22 by Salvatore Bonaccorso at 2026-09-02T05:39:28+02:00
Group src:perl related Perl modules uploads for reasier later review

- - - - -
c24b3e80 by Salvatore Bonaccorso at 2026-09-02T05:46:11+02:00
Add CVE-2026-81928/libnet-dns-perl

- - - - -
05d937cf by Aron Xu at 2026-09-02T12:05:05+08:00
Take libheif

- - - - -
71a3487d by Salvatore Bonaccorso at 2026-09-02T07:15:15+02:00
Track fixed version for firefox-esr issues

Note that CVE-2026-16371 version got bumped to 140.15.0 based one. It
was originally addressed in 140.13.0, but might have incomplete (no
details in the mfsa2026-84 on why it is fixed again).

- - - - -
5f8e6412 by Salvatore Bonaccorso at 2026-09-02T07:34:38+02:00
Add new chromium issues

- - - - -
61117de5 by Salvatore Bonaccorso at 2026-09-02T07:45:30+02:00
Track fixed version for firefox via unstable

- - - - -
6639d45e by Salvatore Bonaccorso at 2026-09-02T07:54:14+02:00
Update status for libnet-dns-perl

- - - - -
a503792e by Salvatore Bonaccorso at 2026-09-02T08:09:01+02:00
Process some NFUs

- - - - -
04118894 by Salvatore Bonaccorso at 2026-09-02T08:21:42+02:00
Add CVE-2026-83557/jackson-databind

- - - - -
adb0a3d1 by Salvatore Bonaccorso at 2026-09-02T08:29:53+02:00
Add CVE-2026-16658/ansible

- - - - -
0d38e370 by Salvatore Bonaccorso at 2026-09-02T08:39:22+02:00
Process two NFUs

- - - - -
42f98f8a by Salvatore Bonaccorso at 2026-09-02T08:44:07+02:00
Add new issues in envoyproxy

- - - - -
adec0342 by Salvatore Bonaccorso at 2026-09-02T08:48:27+02:00
Process more NFUs

- - - - -
99a68fd1 by Salvatore Bonaccorso at 2026-09-02T08:49:32+02:00
Add CVE-2026-80220/prometheus-postgres-exporter

Set it to undetermined since th Red Hat bugzilla entry is very light on
details.

- - - - -
411d1a1d by Salvatore Bonaccorso at 2026-09-02T08:55:51+02:00
Process two more NFUs

- - - - -
6dc6ae83 by Salvatore Bonaccorso at 2026-09-02T08:58:27+02:00
Add two pypdf issues

- - - - -
d6181e11 by Salvatore Bonaccorso at 2026-09-02T09:01:07+02:00
Process two more NFUs

- - - - -
cb22c8b0 by Salvatore Bonaccorso at 2026-09-02T09:06:15+02:00
Add CVE-2026-13608/curl

- - - - -
d85f714e by security tracker role at 2026-09-02T07:13:20+00:00
automatic update

- - - - -
442e6ecd by security tracker role at 2026-09-02T07:14:23+00:00
automatic NOT-FOR-US entries update

- - - - -
b6b00e4c by Salvatore Bonaccorso at 2026-09-02T09:16:31+02:00
Add more curl issues

- - - - -
b66a6f5f by Moritz Muehlenhoff at 2026-09-02T09:22:14+02:00
cleanup bogus nokogiri CVEs, which are now rejected

- - - - -
49919883 by Salvatore Bonaccorso at 2026-09-02T09:39:12+02:00
Add new curl issues

- - - - -
ee36f055 by Salvatore Bonaccorso at 2026-09-02T09:48:03+02:00
Process NFUs

- - - - -
6b969ff8 by Emilio Pozuelo Monfort at 2026-09-02T09:50:10+02:00
lts: add thunderbird

- - - - -
eff9f3a0 by Salvatore Bonaccorso at 2026-09-02T10:04:36+02:00
Process some more NFUs

- - - - -
9c798056 by Moritz Muehlenhoff at 2026-09-02T10:09:28+02:00
NFUs

- - - - -
8639ebcd by Emilio Pozuelo Monfort at 2026-09-02T10:20:15+02:00
lts: add pcre2

- - - - -
8a8362ae by Salvatore Bonaccorso at 2026-09-02T10:38:01+02:00
Add thunderbird issues from mfsa2026-87

- - - - -
7ef567f2 by Salvatore Bonaccorso at 2026-09-02T10:39:54+02:00
Add thunderbird to dsa-needed list

- - - - -
7ea65413 by Salvatore Bonaccorso at 2026-09-02T10:56:46+02:00
Process some NFUs

- - - - -
f70b198f by Salvatore Bonaccorso at 2026-09-02T10:57:22+02:00
Add CVE-2026-84441/piwigo

- - - - -
27a9e983 by Moritz Muehlenhoff at 2026-09-02T11:01:52+02:00
auto-nfu: Add rule for OpenAI

- - - - -
ddae56f6 by Moritz Muehlenhoff at 2026-09-02T11:08:57+02:00
NFUs

- - - - -
0092618d by Salvatore Bonaccorso at 2026-09-02T11:15:10+02:00
Add CVE-2026-84375/node-js-yaml

- - - - -
0f90dd27 by Salvatore Bonaccorso at 2026-09-02T11:15:34+02:00
Add CVE-2026-84372

- - - - -
b98fd32b by Salvatore Bonaccorso at 2026-09-02T11:16:36+02:00
Add two node-svgo issues

- - - - -
9ebe5224 by Salvatore Bonaccorso at 2026-09-02T11:37:42+02:00
Add Debian bug references for various issues

- - - - -
33f8c4bb by Emilio Pozuelo Monfort at 2026-09-02T12:02:17+02:00
lts: take keystone

- - - - -
7824fd40 by Emilio Pozuelo Monfort at 2026-09-02T12:07:21+02:00
Reserve DLA-4767-1 for keystone

- - - - -
eb2f587c by Moritz Muehlenhoff at 2026-09-02T12:13:45+02:00
two thunderbird issues n/a

- - - - -
a6d70651 by Salvatore Bonaccorso at 2026-09-02T12:37:15+02:00
Track fixed version for node-xmldom issues

- - - - -
5835f98a by Moritz Muehlenhoff at 2026-09-02T13:33:31+02:00
new resteasy issue

- - - - -
723031f8 by Moritz Muehlenhoff at 2026-09-02T13:55:13+02:00
new gdb non issue

- - - - -
5d8e1e9d by Moritz Muehlenhoff at 2026-09-02T13:57:52+02:00
new dogtag-pki issue

- - - - -
332ee0cd by Moritz Muehlenhoff at 2026-09-02T14:09:03+02:00
new popt issue

- - - - -
a681bdb1 by Moritz Muehlenhoff at 2026-09-02T14:11:35+02:00
new webkit issue

- - - - -
3aa1ef67 by Moritz Muehlenhoff at 2026-09-02T14:19:37+02:00
new ffmpeg issue

- - - - -
6af17666 by Moritz Muehlenhoff at 2026-09-02T15:11:08+02:00
NFUs

- - - - -
4295f35c by Salvatore Bonaccorso at 2026-09-02T15:39:45+02:00
Remove one CVE from DSA 6127-1

Issue is again open in Debian bookworm and re-introduced.

- - - - -
fb2d5312 by Moritz Muehlenhoff at 2026-09-02T16:06:36+02:00
unlink CVE-2026-78958 from libskia, thanks to Filip Strömbäck

It's a bug in how Chromium uses skia, not in skia itself.

- - - - -
6a11da96 by Salvatore Bonaccorso at 2026-09-02T19:37:31+02:00
Track proposed update for incus via trixie-pu

- - - - -
2065889a by Daniel Leidert at 2026-09-02T19:45:52+02:00
Reserve DLA-4768-1 for libapache2-mod-auth-openidc

- - - - -
2bef23f3 by Daniel Leidert at 2026-09-02T19:52:22+02:00
Reserve DLA-4769-1 for libass

- - - - -
a0715c8c by security tracker role at 2026-09-02T19:14:52+00:00
automatic update

- - - - -
34ce78f4 by security tracker role at 2026-09-02T19:15:47+00:00
automatic NOT-FOR-US entries update

- - - - -
0e1a337d by Salvatore Bonaccorso at 2026-09-02T22:01:21+02:00
Cleanup rejected CVEs

- - - - -
d4cc664a by Salvatore Bonaccorso at 2026-09-02T22:14:05+02:00
Process some NFUs

- - - - -
33566a79 by Salvatore Bonaccorso at 2026-09-02T22:14:45+02:00
Add two new rpm issues

- - - - -
74269644 by Salvatore Bonaccorso at 2026-09-02T22:23:24+02:00
Add new python-httpx2 issues

- - - - -
dfd0b381 by Salvatore Bonaccorso at 2026-09-02T22:42:02+02:00
Add one more CVE fixed via proposed composer update via trixie-pu

- - - - -
5f532fbb by Salvatore Bonaccorso at 2026-09-02T22:48:05+02:00
Process some NFUs

- - - - -
8c99b6c0 by Salvatore Bonaccorso at 2026-09-02T22:49:37+02:00
Add CVE-2026-82522/jpeg-xl

- - - - -
96512b51 by Salvatore Bonaccorso at 2026-09-02T22:50:10+02:00
Add CVE-2026-82293/kibana

- - - - -
e2f4310e by Salvatore Bonaccorso at 2026-09-02T22:50:44+02:00
Add CVE-2026-84366/python-scrapy

- - - - -
5188fb60 by Salvatore Bonaccorso at 2026-09-02T22:51:40+02:00
Add CVE-2026-84361/composer

- - - - -
b0c6c2f9 by Salvatore Bonaccorso at 2026-09-02T22:52:23+02:00
Add CVE-2026-84308/phpseclib

- - - - -
ca44bafc by Salvatore Bonaccorso at 2026-09-02T22:54:39+02:00
Add CVE-2026-84309/pypdf

- - - - -
8120093c by Moritz Mühlenhoff at 2026-09-02T22:56:52+02:00
firefox-esr DSA

- - - - -
16af4e02 by Moritz Mühlenhoff at 2026-09-02T23:08:06+02:00
transmission spu

- - - - -
74a6e116 by Salvatore Bonaccorso at 2026-09-03T05:37:00+02:00
Track fixed version for thunderbird issues in unstable

Note that we switched from the 140 ESR series to the 153 ESR series with
this unstable upload. Thus mark as well CVE-2026-16365 fixed with
1:153.2.0esr-1.

- - - - -
328b1a89 by Salvatore Bonaccorso at 2026-09-03T05:48:27+02:00
Add new util-linux issues

- - - - -
159deaa8 by Abhijith PA at 2026-09-03T03:50:12+00:00
data/dla-needed.txt: Claim puma
- - - - -
c4109941 by Salvatore Bonaccorso at 2026-09-03T05:53:28+02:00
Track fixes for python3.15 via unstable

- - - - -
962dc601 by Salvatore Bonaccorso at 2026-09-03T06:25:28+02:00
Track fixed version for chromium issues fixed via unstable

- - - - -
2e2858f2 by Salvatore Bonaccorso at 2026-09-03T06:28:05+02:00
Track fixed version for three libskia issues

- - - - -
317c4769 by Salvatore Bonaccorso at 2026-09-03T06:33:11+02:00
Track fixed version for CVE-2026-18917/libvirt

- - - - -
1562aa72 by Salvatore Bonaccorso at 2026-09-03T06:49:24+02:00
Add new slurm-wlm issues

- - - - -
a14120c6 by Salvatore Bonaccorso at 2026-09-03T06:55:12+02:00
Update status for CVE-2026-19685/network-manager

- - - - -
92a21516 by Salvatore Bonaccorso at 2026-09-03T07:51:03+02:00
Add Debian bug reference for Slurm issues

- - - - -
d4e98526 by Salvatore Bonaccorso at 2026-09-03T07:58:24+02:00
Process some NFUs

- - - - -
064e3043 by Salvatore Bonaccorso at 2026-09-03T07:59:37+02:00
Add two new libnginx-mod-js issues

- - - - -
e2fe3f58 by Salvatore Bonaccorso at 2026-09-03T08:00:15+02:00
Add new kibana issues

- - - - -
4e729860 by Salvatore Bonaccorso at 2026-09-03T08:28:00+02:00
Process NFUs

- - - - -
e35168c4 by Salvatore Bonaccorso at 2026-09-03T08:28:49+02:00
Add CVE-2026-75758/elixir-lang

- - - - -
3e71f80c by Moritz Muehlenhoff at 2026-09-03T08:42:18+02:00
trixie triage

- - - - -
82c22274 by Moritz Muehlenhoff at 2026-09-03T09:11:24+02:00
new freeipa issue

- - - - -
73111c4c by Salvatore Bonaccorso at 2026-09-03T09:14:41+02:00
Add RUSTSEC reference for CVE-2026-78422

- - - - -
8696f13e by Moritz Muehlenhoff at 2026-09-03T09:18:07+02:00
auto-nfu: Extend Nvidia rule

- - - - -
d90ba681 by Salvatore Bonaccorso at 2026-09-03T09:34:44+02:00
Process one NFU

- - - - -
dfb9c5ee by Salvatore Bonaccorso at 2026-09-03T09:36:48+02:00
Add another spip issue

- - - - -
d834699a by Salvatore Bonaccorso at 2026-09-03T09:43:13+02:00
Fix copy paste error on adding spip issue

- - - - -
cf29e370 by Salvatore Bonaccorso at 2026-09-03T09:43:42+02:00
Add CVE-2026-75538/erlang

- - - - -
bb52d955 by Salvatore Bonaccorso at 2026-09-03T10:27:23+02:00
Add new erlang issues

- - - - -
f1e8cf25 by Salvatore Bonaccorso at 2026-09-03T10:48:55+02:00
Add more erlang issues

- - - - -
33b043bc by Salvatore Bonaccorso at 2026-09-03T11:31:48+02:00
Add another batch of erlang issues

- - - - -
de70dfa7 by Salvatore Bonaccorso at 2026-09-03T11:32:27+02:00
Process some NFUs

- - - - -
8bb74f9f by Moritz Muehlenhoff at 2026-09-03T11:44:17+02:00
NFUs

- - - - -
8087f8cb by Moritz Muehlenhoff at 2026-09-03T11:58:07+02:00
auto-nfu: Extend rules for F5 and Cisco

- - - - -
d63cfd15 by Moritz Muehlenhoff at 2026-09-03T12:15:52+02:00
auto-nfu: Track the entire Grafana CNA as NFU

While src:grafana was packaged briefly, it has been removed eight years
ago and given the quick upstream pace and the complexities of the web UI
it will unlikely come back.

- - - - -
0d7f9bee by Salvatore Bonaccorso at 2026-09-03T12:46:18+02:00
Mark util-linux issues as no-dsa

- - - - -
a6f6c77f by Salvatore Bonaccorso at 2026-09-03T12:59:17+02:00
Add two more erlang issues

- - - - -
c6222eaf by Moritz Muehlenhoff at 2026-09-03T13:42:57+02:00
new rust-async-tar issue

- - - - -
108a1423 by Salvatore Bonaccorso at 2026-09-03T15:03:12+02:00
Track fixed version for CVE-2026-47667/cimg

- - - - -
4d7627ae by Moritz Muehlenhoff at 2026-09-03T15:56:37+02:00
trixie triage

- - - - -
3d65ecce by Moritz Muehlenhoff at 2026-09-03T16:17:58+02:00
NFUs

- - - - -
19175a5a by Moritz Muehlenhoff at 2026-09-03T16:22:56+02:00
auto-nfu: Add Delinea

Total CVEs from Delinea: 10
Total CVEs from Delinea with packages assigned: 0

Scope: Vulnerabilities in Delinea products or services listed on
delinea.com, or vulnerabilities in third-party products or services
discovered by or reported to Delinea, unless covered by the scope of
another CNA.

- - - - -
feaff430 by Moritz Muehlenhoff at 2026-09-03T16:32:59+02:00
NFUs

- - - - -
45bd5733 by Salvatore Bonaccorso at 2026-09-03T18:22:51+02:00
Coordinating with David about spip DSA

- - - - -
a0e11f31 by Andres Salomon at 2026-09-03T13:23:07-04:00
chromium dsa

- - - - -
13e4fc73 by Moritz Muehlenhoff at 2026-09-03T19:30:05+02:00
first batch of new libheif issues

- - - - -
f43cb67d by Salvatore Bonaccorso at 2026-09-03T20:22:13+02:00
Add reference for CVE-2026-80530

- - - - -
2388d395 by Salvatore Bonaccorso at 2026-09-03T20:26:01+02:00
Merge Linux CVEs from kernel-sec

- - - - -
d43df3f3 by Salvatore Bonaccorso at 2026-09-03T20:29:53+02:00
Merge Linux CVEs from kernel-sec

- - - - -
2f734a1c by Salvatore Bonaccorso at 2026-09-03T20:31:38+02:00
Mark libnet-dns-perl as no-dsa

- - - - -
42ea7d80 by Moritz Muehlenhoff at 2026-09-03T20:35:09+02:00
remaining libheif issues from 1.23.3

- - - - -
cf106c7c by Salvatore Bonaccorso at 2026-09-03T20:38:12+02:00
Add two new golang-go.crypto issues

- - - - -
997ced87 by Moritz Muehlenhoff at 2026-09-03T20:44:06+02:00
new libde265 issues

- - - - -
8470c732 by Salvatore Bonaccorso at 2026-09-03T21:04:17+02:00
Add Debian bug references for various issues

- - - - -
ba14af78 by security tracker role at 2026-09-03T19:12:42+00:00
automatic update

- - - - -
248af3ce by security tracker role at 2026-09-03T19:13:32+00:00
automatic NOT-FOR-US entries update

- - - - -
5b37855b by Salvatore Bonaccorso at 2026-09-03T21:18:12+02:00
Remove notes from some rejected CVEs

The llama.cpp one got withdrawn by the assigning CNA.

- - - - -
ba9a86d4 by Salvatore Bonaccorso at 2026-09-03T21:26:22+02:00
Add CVE-2026-85396/ruby-zip

- - - - -
773eca39 by Salvatore Bonaccorso at 2026-09-03T21:33:20+02:00
Add new python-jose CVE

- - - - -
108f40c0 by Salvatore Bonaccorso at 2026-09-03T21:36:00+02:00
Annotate entry for python-git indicating Emmanuel Arias might work on a update

- - - - -
055d9926 by Salvatore Bonaccorso at 2026-09-03T21:38:47+02:00
Add new glance issues

- - - - -
da085438 by Salvatore Bonaccorso at 2026-09-03T21:48:08+02:00
Adjust source package name for node-node-forge

- - - - -
8e6e6726 by Salvatore Bonaccorso at 2026-09-03T21:55:42+02:00
Process some NFUs

- - - - -
77a5b1c1 by Salvatore Bonaccorso at 2026-09-03T22:02:54+02:00
Add CVE-2026-85393/node-node-forge

- - - - -
e2e2646e by Salvatore Bonaccorso at 2026-09-03T22:03:49+02:00
Add new misp issues

- - - - -
20c2e71a by Salvatore Bonaccorso at 2026-09-03T22:08:42+02:00
Add CVE-2026-85180/ollama

- - - - -
c55b43d7 by Salvatore Bonaccorso at 2026-09-03T22:28:24+02:00
Add CVE-2026-85150/gst-plugins-base1.0

- - - - -
5a0824a5 by Salvatore Bonaccorso at 2026-09-03T22:29:45+02:00
Process some NFUs

- - - - -
f2d3856e by Salvatore Bonaccorso at 2026-09-03T22:47:01+02:00
Add CVE-2026-85091/zlib

- - - - -
9ea96a24 by Salvatore Bonaccorso at 2026-09-03T22:47:52+02:00
Add two new freerdp3 issues

- - - - -
d2fae8f2 by Salvatore Bonaccorso at 2026-09-03T22:51:23+02:00
Process some NFUs

- - - - -
c41e6e11 by Salvatore Bonaccorso at 2026-09-03T22:52:13+02:00
Add new kibana issues

- - - - -
2aac3732 by Salvatore Bonaccorso at 2026-09-03T22:58:10+02:00
Add new gfs-utils issues

- - - - -
e61ae124 by Salvatore Bonaccorso at 2026-09-03T23:06:53+02:00
Track fixed version for glance issues fixed via unstable

- - - - -
e5f0415f by Salvatore Bonaccorso at 2026-09-03T23:20:20+02:00
Add Debian bug references for various issues

- - - - -
14352c20 by Matheus Polkorny at 2026-09-03T18:51:20-03:00
Track status for libheif CVEs

- - - - -
963d1de2 by Emmanuel Arias at 2026-09-03T18:51:51-03:00
add commit patch for CVE-2026-42215

- - - - -
260fd76d by Emmanuel Arias at 2026-09-03T18:57:07-03:00
CVE-2026-42284: add commit link

- - - - -
75ce1019 by Emmanuel Arias at 2026-09-03T19:09:18-03:00
CVE-2026-67322: add commit link

- - - - -
60dfe886 by Emmanuel Arias at 2026-09-03T19:12:06-03:00
CVE-2026-67323: add commit link

- - - - -
79967f7f by Salvatore Bonaccorso at 2026-09-04T05:50:11+02:00
Add new openvpn issues

- - - - -
ad80c4b8 by Salvatore Bonaccorso at 2026-09-04T05:51:34+02:00
CVE-2026-84383/libheif assigned

- - - - -
d4edbe4d by Salvatore Bonaccorso at 2026-09-04T05:53:17+02:00
Merge branch 'master' into 'master'

Track status for libheif CVEs

See merge request security-tracker-team/security-tracker!326
- - - - -
d87dc51c by Salvatore Bonaccorso at 2026-09-04T05:56:17+02:00
Update information on CVE-2026-84383 and CVE-2026-62377

- - - - -
1db59d14 by Salvatore Bonaccorso at 2026-09-04T06:17:18+02:00
Add Debian bug references for some CVEs

- - - - -
0c9fd397 by Salvatore Bonaccorso at 2026-09-04T06:22:07+02:00
Update status for two valkey issues

- - - - -
75aafd7b by Salvatore Bonaccorso at 2026-09-04T06:33:56+02:00
Update status for CVE-2026-82608

- - - - -
5e5a9cc1 by Salvatore Bonaccorso at 2026-09-04T06:39:52+02:00
Add Debian bug references for various CVEs

- - - - -
78feb392 by Salvatore Bonaccorso at 2026-09-04T06:42:25+02:00
Add reference to commit for CVE-2026-81525

- - - - -
18bf51d2 by Salvatore Bonaccorso at 2026-09-04T06:46:31+02:00
Update status for CVE-2026-17523

- - - - -
57fec793 by Moritz Muehlenhoff at 2026-09-04T08:56:33+02:00
new wasmtime issues

- - - - -
460bff69 by security tracker role at 2026-09-04T07:12:40+00:00
automatic update

- - - - -
3ea7f2a5 by security tracker role at 2026-09-04T07:13:30+00:00
automatic NOT-FOR-US entries update

- - - - -
d0f60af1 by Salvatore Bonaccorso at 2026-09-04T09:15:30+02:00
Update status for CVE-2026-81525

- - - - -
6c3edf12 by Salvatore Bonaccorso at 2026-09-04T09:16:11+02:00
Remove notes from CVE-2026-19582

Rejected Reason: Red Hat Product Security has come to the conclusion
that this CVE is false due to upstream security policy.

- - - - -
ecb8c435 by Salvatore Bonaccorso at 2026-09-04T09:19:39+02:00
Add new freeipmi issues

- - - - -
a4efb404 by Salvatore Bonaccorso at 2026-09-04T09:26:06+02:00
Process some NFUs

- - - - -
69fbace6 by Salvatore Bonaccorso at 2026-09-04T09:27:09+02:00
Add Debian bug references for freeipmi issues

- - - - -
21685c03 by Salvatore Bonaccorso at 2026-09-04T09:41:29+02:00
Adjust notes for two imagemagick issues

- - - - -
a4a7aeea by Salvatore Bonaccorso at 2026-09-04T09:47:35+02:00
Add CVE-2026-18329/libnginx-mod-js

- - - - -
c9e2d151 by Salvatore Bonaccorso at 2026-09-04T09:55:35+02:00
Add CVE-2026-85063/node-csv-parse

- - - - -
637c43d2 by Salvatore Bonaccorso at 2026-09-04T09:57:25+02:00
Add chromium to dsa-needed list

- - - - -
212ddf71 by Salvatore Bonaccorso at 2026-09-04T09:59:06+02:00
Add new batch of chromium issues

- - - - -
e39121c5 by Emilio Pozuelo Monfort at 2026-09-04T10:02:07+02:00
Reserve DLA-4770-1 for firefox-esr

- - - - -
c6ee3094 by Emilio Pozuelo Monfort at 2026-09-04T10:03:36+02:00
dsa: drop bookworm version from chromium DSA

bookworm is now LTS and will be added to a DLA.

- - - - -
3f320114 by Emilio Pozuelo Monfort at 2026-09-04T10:11:42+02:00
Reserve DLA-4771-1 for chromium

- - - - -
d7f2d822 by Salvatore Bonaccorso at 2026-09-04T10:15:12+02:00
Process two NFUs

- - - - -
cf21ac7d by Salvatore Bonaccorso at 2026-09-04T10:16:49+02:00
Add new mongodb driver related CVEs

- - - - -
2297deca by Salvatore Bonaccorso at 2026-09-04T10:48:34+02:00
Add CVE-2026-84185/python-jwcrypto

- - - - -
f87f16c8 by Salvatore Bonaccorso at 2026-09-04T10:50:01+02:00
Process some NFUs

- - - - -
608f9a17 by Salvatore Bonaccorso at 2026-09-04T10:50:39+02:00
Add CVE-2026-84968/php-mongodb

- - - - -
e6814e43 by Salvatore Bonaccorso at 2026-09-04T10:52:13+02:00
Add two node-ajv issues (providing fast-uri)

- - - - -
9b67f758 by Salvatore Bonaccorso at 2026-09-04T11:04:06+02:00
Add Debian bug reference for node-ajv issues

- - - - -
4cdd9719 by Salvatore Bonaccorso at 2026-09-04T11:35:38+02:00
Reorder information for CVE-2025-0938 and remove pull request covered by commit

- - - - -
77f1f9b3 by Emilio Pozuelo Monfort at 2026-09-04T12:06:00+02:00
Reserve DLA-4772-1 for pcre2

- - - - -
1937a40f by Emilio Pozuelo Monfort at 2026-09-04T12:07:18+02:00
Mark temp issues as fixed in pcre2/bookworm

- - - - -
bc03f42a by Emilio Pozuelo Monfort at 2026-09-04T12:34:58+02:00
lts: triage two node issues as postponed

- - - - -
e0baf8a1 by Emilio Pozuelo Monfort at 2026-09-04T12:50:37+02:00
lts: add packages

- - - - -
31c75ed1 by Moritz Muehlenhoff at 2026-09-04T13:12:41+02:00
new jackson-databind issues

- - - - -
ff8141b3 by Moritz Muehlenhoff at 2026-09-04T13:13:53+02:00
auto-nfu: Extend vmware rule

- - - - -
4e3817ce by Emilio Pozuelo Monfort at 2026-09-04T13:45:27+02:00
lts: mark some issues as postponed

- - - - -
33743ce5 by Salvatore Bonaccorso at 2026-09-04T14:12:57+02:00
Track fixes for node-ajv via unstable

- - - - -
4c088739 by Salvatore Bonaccorso at 2026-09-04T14:17:34+02:00
Track fixed version via unstable for CVE-2026-84375/node-js-yaml

- - - - -
69cc1c44 by Salvatore Bonaccorso at 2026-09-04T14:24:17+02:00
Track fixed version for CVE-2026-85063/node-csv-parse

- - - - -
2b171171 by Salvatore Bonaccorso at 2026-09-04T14:41:27+02:00
Process some NFUs

- - - - -
f7fc3451 by Salvatore Bonaccorso at 2026-09-04T14:42:04+02:00
Add one new erlang issue

- - - - -
b39e8869 by Salvatore Bonaccorso at 2026-09-04T14:54:43+02:00
Process some NFUs

- - - - -
58f612ea by Salvatore Bonaccorso at 2026-09-04T14:55:30+02:00
Add new issues in ocsinventory-server

- - - - -
7130adf6 by Moritz Muehlenhoff at 2026-09-04T15:25:33+02:00
NFUs

- - - - -
dc2e1ea1 by Moritz Muehlenhoff at 2026-09-04T15:41:18+02:00
new spring issues

- - - - -
3979ae46 by Moritz Mühlenhoff at 2026-09-04T15:52:18+02:00
curl spu

- - - - -
f13ea7de by Moritz Muehlenhoff at 2026-09-04T15:58:03+02:00
new gfs2-utils issue

- - - - -
a768906e by Moritz Muehlenhoff at 2026-09-04T17:07:20+02:00
NFUs

- - - - -
278e8d19 by Moritz Muehlenhoff at 2026-09-04T17:10:45+02:00
more libskia references for chromium issues

- - - - -
8275d949 by Moritz Muehlenhoff at 2026-09-04T17:12:10+02:00
auto-nfu: Extend Eclipse rule

- - - - -
520d434c by Moritz Muehlenhoff at 2026-09-04T17:17:21+02:00
two rust-coreutils fixed a while back

- - - - -
91bf3675 by Moritz Muehlenhoff at 2026-09-04T17:23:29+02:00
new bluez issue

- - - - -
dc2f858e by Salvatore Bonaccorso at 2026-09-04T19:18:36+02:00
Update status for CVE-2026-81521

- - - - -
ac667081 by Salvatore Bonaccorso at 2026-09-04T19:28:43+02:00
Add Debian bug reference for CVE-2026-81521

- - - - -
a286e498 by Salvatore Bonaccorso at 2026-09-04T19:38:34+02:00
Add Debian bug references for various issues

- - - - -
a040f78f by Salvatore Bonaccorso at 2026-09-04T19:39:21+02:00
Group gfs2-utils issues together

- - - - -
61b6889e by Salvatore Bonaccorso at 2026-09-04T19:45:28+02:00
Adjust association of CVE-2026-48501 to src:gh only

- - - - -
288a1044 by Moritz Muehlenhoff at 2026-09-04T19:49:16+02:00
trixie triage

- - - - -
7e5c1907 by Moritz Muehlenhoff at 2026-09-04T19:52:03+02:00
new freeciv issues

- - - - -
d541322c by Moritz Mühlenhoff at 2026-09-04T20:00:42+02:00
thunderbird DSA

- - - - -
79e3bebe by Salvatore Bonaccorso at 2026-09-04T20:51:21+02:00
Update status for CVE-2026-25048

- - - - -
0a72aa19 by Salvatore Bonaccorso at 2026-09-04T20:52:11+02:00
Add Debian bug reference for CVE-2026-29036/cjson

- - - - -
1e927cbf by Moritz Muehlenhoff at 2026-09-04T21:06:16+02:00
bugnums

- - - - -
f27fde0a by Salvatore Bonaccorso at 2026-09-04T21:07:48+02:00
Add various reported bug references for CVEs

- - - - -
0403ef2b by Salvatore Bonaccorso at 2026-09-04T21:08:25+02:00
Merge Linux CVEs from kernel-sec

- - - - -
18fe144b by Salvatore Bonaccorso at 2026-09-04T21:10:03+02:00
Merge Linux CVEs from kernel-sec

- - - - -
6e9c8d36 by Salvatore Bonaccorso at 2026-09-04T21:12:27+02:00
Merge Linux CVEs from kernel-sec

- - - - -
d324430d by Salvatore Bonaccorso at 2026-09-04T21:18:14+02:00
Merge Linux CVEs from kernel-sec

- - - - -
0c036e20 by Salvatore Bonaccorso at 2026-09-04T21:22:17+02:00
Merge Linux CVEs from kernel-sec

- - - - -
ddf7a626 by Salvatore Bonaccorso at 2026-09-04T21:24:07+02:00
Merge Linux CVEs from kernel-sec

- - - - -
f99916b6 by Salvatore Bonaccorso at 2026-09-04T21:31:13+02:00
Add CVE-2026-82309 as NFU (Robots::Validate Perl module)

- - - - -
d0a9bc37 by Salvatore Bonaccorso at 2026-09-04T21:40:30+02:00
Add CVE-2026-82253/rust-gix{,-validate}

- - - - -
2923c5a1 by Salvatore Bonaccorso at 2026-09-04T21:47:34+02:00
Add more gix related CVEs

- - - - -
94a9de9d by Salvatore Bonaccorso at 2026-09-04T22:08:31+02:00
Add new kibana issues

- - - - -
29be98c3 by Salvatore Bonaccorso at 2026-09-04T22:09:20+02:00
Process some NFUs

- - - - -
ccb5203e by Salvatore Bonaccorso at 2026-09-04T22:10:31+02:00
Track fixed version for two freeciv issues

- - - - -
edb16940 by Salvatore Bonaccorso at 2026-09-04T22:19:32+02:00
Add CVE-2026-63435/ruby-mail

- - - - -
60164a8b by Salvatore Bonaccorso at 2026-09-04T22:20:03+02:00
Add new llama.cpp issues

- - - - -
11a810d9 by Salvatore Bonaccorso at 2026-09-04T22:23:12+02:00
Add two kamailio issues

- - - - -
c368831f by Salvatore Bonaccorso at 2026-09-04T22:29:46+02:00
Add CVE-2026-62993/smarty

- - - - -
bf05608c by Salvatore Bonaccorso at 2026-09-04T22:33:21+02:00
Add CVE-2026-58301/shiro

- - - - -
e21bd746 by Salvatore Bonaccorso at 2026-09-04T22:36:42+02:00
Add CVE-2026-76060/zoneminder

- - - - -
287e7d9f by Salvatore Bonaccorso at 2026-09-04T22:48:34+02:00
Process several NFUs

- - - - -
667f080b by Salvatore Bonaccorso at 2026-09-04T23:00:12+02:00
Track nginx update which now is routed via trixie-pu

- - - - -
0a25e355 by Salvatore Bonaccorso at 2026-09-04T23:23:57+02:00
Take one package from dsa-needed list

- - - - -
5f99e3f5 by Moritz Muehlenhoff at 2026-09-04T23:56:20+02:00
more issues from freerdp 3.31

- - - - -
83194d1c by Moritz Muehlenhoff at 2026-09-04T23:57:47+02:00
track entire Elastic CNA as NFU

elasticsearch has been removed a long time ago and won't come back and the
ITP for Kibana is closed and equally unpackageable for Debian.

- - - - -
f93536d8 by Moritz Mühlenhoff at 2026-09-05T00:03:28+02:00
socat spu

- - - - -
809eb3e9 by Moritz Mühlenhoff at 2026-09-05T00:07:15+02:00
squid spu

- - - - -
805fe00e by Moritz Muehlenhoff at 2026-09-05T00:38:14+02:00
trixie triage

- - - - -
390ffc3b by Moritz Muehlenhoff at 2026-09-05T00:41:26+02:00
xpdf n/a

- - - - -
2417d485 by Moritz Muehlenhoff at 2026-09-05T00:48:49+02:00
sssd fixed in sid

- - - - -
dcb47247 by Moritz Muehlenhoff at 2026-09-05T00:50:50+02:00
sssd fixed in sid

- - - - -
e9429e2c by Salvatore Bonaccorso at 2026-09-05T06:54:26+02:00
Convert kibana itp'ed entries to NFU

- - - - -
b9e5ca0f by Salvatore Bonaccorso at 2026-09-05T06:57:33+02:00
Track fixed version for chromium via unstable

- - - - -
f6b2c87c by Salvatore Bonaccorso at 2026-09-05T07:07:05+02:00
Add commit references for sssd issues

- - - - -
1b5bc6c2 by Salvatore Bonaccorso at 2026-09-05T07:15:11+02:00
Add oss-security reference for freerdp3 issues

- - - - -
d4d93e4b by Salvatore Bonaccorso at 2026-09-05T07:29:37+02:00
Update information on freerdp3 entries

- - - - -
836f8c89 by Salvatore Bonaccorso at 2026-09-05T07:33:38+02:00
Add references for xorg-server from stable branch

- - - - -
35f99455 by Emilio Pozuelo Monfort at 2026-09-05T08:50:51+02:00
lts: mark some issues as limited support

- - - - -
87d7003f by security tracker role at 2026-09-05T07:12:31+00:00
automatic update

- - - - -
208a2809 by security tracker role at 2026-09-05T07:13:27+00:00
automatic NOT-FOR-US entries update

- - - - -
6cfeb30e by Salvatore Bonaccorso at 2026-09-05T09:19:50+02:00
Remove one note from an apache product which got rejected

- - - - -
b5b5adf6 by Salvatore Bonaccorso at 2026-09-05T09:26:30+02:00
One CVE got assigned for pcre2 issue

- - - - -
26a56add by Salvatore Bonaccorso at 2026-09-05T09:38:24+02:00
Add new batch of CVEs for libxml2

- - - - -
6fe799f9 by Salvatore Bonaccorso at 2026-09-05T10:06:21+02:00
Process some NFUs

- - - - -
f1e14a7d by Salvatore Bonaccorso at 2026-09-05T10:09:54+02:00
Add ndpi issue

- - - - -
76e3b8d8 by Salvatore Bonaccorso at 2026-09-05T10:10:48+02:00
Add netcdf issue

- - - - -
fe31c7b9 by Salvatore Bonaccorso at 2026-09-05T10:11:30+02:00
Add two ntopng issues

- - - - -
b9259d25 by Salvatore Bonaccorso at 2026-09-05T10:12:56+02:00
Add CVE-2026-85769/libtpms

- - - - -
74e3f415 by Salvatore Bonaccorso at 2026-09-05T10:14:26+02:00
Add two new snipe-it issues

- - - - -
70abb8d0 by Salvatore Bonaccorso at 2026-09-05T10:15:17+02:00
Add new traefik issues, itp'ed

- - - - -
0b6b1c9e by Salvatore Bonaccorso at 2026-09-05T10:15:58+02:00
Add new misp issues

- - - - -
34de8174 by Salvatore Bonaccorso at 2026-09-05T10:20:25+02:00
Add new exiv2 issues

Note there were as well a ouple of not yet CVEified low severity
iessues. I skipped them now on purpose to not clutter the list iwth temp
entries for pratically non-issues/low-severity issue. When/if they get
assingned then the intention would be to backfill those as well.

- - - - -
0069ad5c by Salvatore Bonaccorso at 2026-09-05T10:34:22+02:00
Add new libsoup issues

- - - - -
695058e2 by Salvatore Bonaccorso at 2026-09-05T10:34:52+02:00
Add new valkey issue

- - - - -
83d432d2 by Salvatore Bonaccorso at 2026-09-05T10:37:01+02:00
Track fixes for libskia issues

- - - - -
3f67fab2 by Salvatore Bonaccorso at 2026-09-05T11:15:09+02:00
Add new batch of node-undici issues

- - - - -
d878b758 by Salvatore Bonaccorso at 2026-09-05T11:29:48+02:00
Add Debian bug reference for libxml2 issues

- - - - -
c7a1ea75 by Salvatore Bonaccorso at 2026-09-05T11:35:37+02:00
Track fixes for glibc via unstable

- - - - -
8ee77df6 by Salvatore Bonaccorso at 2026-09-05T11:58:15+02:00
Process some NFUs

- - - - -
a48a5388 by Salvatore Bonaccorso at 2026-09-05T11:59:23+02:00
Two new corosync issues

- - - - -
87425ba4 by Salvatore Bonaccorso at 2026-09-05T12:00:09+02:00
Add new open5gs issue

- - - - -
7d0e9503 by Moritz Muehlenhoff at 2026-09-05T12:58:14+02:00
pyrhon3.14 fixed in sid

- - - - -
cacba784 by Salvatore Bonaccorso at 2026-09-05T13:24:20+02:00
Add Debian bug references for node-undici issues

- - - - -
04ba4985 by Salvatore Bonaccorso at 2026-09-05T13:28:41+02:00
Track fixed version for node-undici issues

- - - - -
30f96e02 by Salvatore Bonaccorso at 2026-09-05T13:50:49+02:00
Add reference for CVE-2026-17615

- - - - -
9127160c by Salvatore Bonaccorso at 2026-09-05T14:22:28+02:00
Add Debian bug references for resteasy issues

- - - - -
1b238584 by Emmanuel Arias at 2026-09-05T09:46:37-03:00
Reserve DLA-4773-1 for libssh2

- - - - -
9e36e71c by Salvatore Bonaccorso at 2026-09-05T15:09:58+02:00
Adjust references for CVE-2026-84450/libheif

- - - - -
bdb3c6cb by Salvatore Bonaccorso at 2026-09-05T15:14:16+02:00
Annotate some upstream commits

- - - - -
f1a513de by Salvatore Bonaccorso at 2026-09-05T15:21:29+02:00
Consolite fixing commit reference for CVE-2026-19032

The fix go applied first in ackson-databind-2.18.10 and merged up in
each supported branch, so the commit is contained in each of the
referenced tags along up the way.

- - - - -
f6d0c086 by Salvatore Bonaccorso at 2026-09-05T15:26:33+02:00
Update status for CVE-2026-35341

- - - - -
25e6724d by Salvatore Bonaccorso at 2026-09-05T15:42:52+02:00
Add Debian bug reference for bluez issue

- - - - -
4ad98833 by Salvatore Bonaccorso at 2026-09-05T19:13:11+02:00
Track proposed update for libxml-bare-perl via trixie-pu

- - - - -
e410d84c by Andreas Henriksson at 2026-09-05T19:14:46+02:00
Claim aom in dla-needed.txt

- - - - -
04a31118 by Salvatore Bonaccorso at 2026-09-05T20:43:59+02:00
Track proposed update for libtie-hash-regex-perl via trixie-pu

- - - - -
197f6222 by Salvatore Bonaccorso at 2026-09-05T20:48:22+02:00
Track fixes for libxml2 via unstable upload

- - - - -
a3cd012e by security tracker role at 2026-09-05T19:14:24+00:00
automatic update

- - - - -
ec377fe9 by security tracker role at 2026-09-05T19:15:18+00:00
automatic NOT-FOR-US entries update

- - - - -
8fc4a97f by Salvatore Bonaccorso at 2026-09-05T21:28:13+02:00
Process some NFUs

- - - - -
4931bc4e by Salvatore Bonaccorso at 2026-09-05T21:28:44+02:00
Process two netbox issues

- - - - -
ac309e36 by Salvatore Bonaccorso at 2026-09-05T21:34:05+02:00
Add new libpcap issues

- - - - -
3b250c76 by Andres Salomon at 2026-09-05T16:22:06-04:00
chromium dsa

- - - - -
8d91cc9c by Moritz Muehlenhoff at 2026-09-05T23:37:16+02:00
new tryton-server issue

- - - - -
d1b7f9c3 by Salvatore Bonaccorso at 2026-09-06T06:55:36+02:00
Add new pjproject/asterisk issues

- - - - -
50071aeb by Salvatore Bonaccorso at 2026-09-06T07:06:45+02:00
Add Debian bug reference for libpcap issues

- - - - -
cad2823e by Salvatore Bonaccorso at 2026-09-06T08:50:31+02:00
Track freeipmi issues fixed in unstable

- - - - -
60496a99 by Salvatore Bonaccorso at 2026-09-06T08:54:11+02:00
Track fixed version for erlang issues

- - - - -
560fbdff by Salvatore Bonaccorso at 2026-09-06T08:59:34+02:00
Add CVE-2026-85498/policykit-1

- - - - -
1b2d5b10 by Guilhem Moulin at 2026-09-06T09:03:29+02:00
LTS: claim dovecot and lxml in dla-needed.txt

- - - - -
62872576 by security tracker role at 2026-09-06T07:13:06+00:00
automatic update

- - - - -
bde5f90c by security tracker role at 2026-09-06T07:13:57+00:00
automatic NOT-FOR-US entries update

- - - - -
a8ac0cca by Salvatore Bonaccorso at 2026-09-06T09:18:57+02:00
Process some NFUs

- - - - -
7cb837d6 by Moritz Muehlenhoff at 2026-09-06T11:56:23+02:00
openslide fixed in sid

- - - - -
9d3c4cf7 by Moritz Muehlenhoff at 2026-09-06T12:01:57+02:00
NFUs

- - - - -
a84096d0 by Moritz Muehlenhoff at 2026-09-06T12:07:09+02:00
Add CNA rule for check-mk

src:check-mk was removed seven years ago and won' come back. The rule
needs to be for products, since they also develop nagvis, which is
packaged in Debian.

- - - - -
e2a99b6c by Moritz Muehlenhoff at 2026-09-06T12:53:16+02:00
trixie triage

- - - - -
69feb01c by Moritz Mühlenhoff at 2026-09-06T13:01:11+02:00
tryton-server DSA

- - - - -
612b907b by Moritz Muehlenhoff at 2026-09-06T13:07:34+02:00
mark three CVEs for Skia as specific to how Chromium uses Skia, not Skia itself

- - - - -
63abc622 by Moritz Muehlenhoff at 2026-09-06T13:13:48+02:00
update references for two pypdf issues

- - - - -
933f68cc by Andreas Henriksson at 2026-09-06T13:23:17+02:00
Reserve DLA-4774-1 for aom

- - - - -
1d60438b by Andreas Henriksson at 2026-09-06T14:10:23+02:00
Claim gawk in dla-needed.txt

- - - - -
29ebc244 by Salvatore Bonaccorso at 2026-09-06T14:21:18+02:00
Add CVE-2025-15614/ugrep

- - - - -
cb1c9666 by Salvatore Bonaccorso at 2026-09-06T14:24:02+02:00
Process some NFUs

- - - - -
7d79f881 by Salvatore Bonaccorso at 2026-09-06T14:30:01+02:00
Add CVE-2026-48932/nodejs

- - - - -
0c8cfa96 by Salvatore Bonaccorso at 2026-09-06T14:52:00+02:00
Add new roundcube issues

- - - - -
7a9b1421 by Salvatore Bonaccorso at 2026-09-06T15:01:15+02:00
roundcube: One issue already addressed by custom patch

- - - - -
0c770138 by Salvatore Bonaccorso at 2026-09-06T17:01:03+02:00
Track proposed update for clamav via trixie-pu

- - - - -
b56bbe81 by Salvatore Bonaccorso at 2026-09-06T17:08:35+02:00
Track fixed version for roundcube issues

- - - - -
ba827b88 by Salvatore Bonaccorso at 2026-09-06T17:18:01+02:00
Track fixed version for CVE-206-66357/erlang via unstable

- - - - -
5f930735 by Salvatore Bonaccorso at 2026-09-06T17:31:53+02:00
Add commit references for corosync issues

- - - - -
da16638b by Salvatore Bonaccorso at 2026-09-06T17:48:11+02:00
Add references for python-jwcrypto issue

- - - - -
37aa1a57 by Salvatore Bonaccorso at 2026-09-06T17:54:17+02:00
Mark CVE-2026-84185 as no-dsa for trixie

- - - - -
a634b8b0 by Salvatore Bonaccorso at 2026-09-06T18:19:07+02:00
Add Debian bug references for various issues

- - - - -
59c79ea0 by Moritz Muehlenhoff at 2026-09-06T20:17:14+02:00
trixie triage

- - - - -
a1ad695d by Moritz Mühlenhoff at 2026-09-06T20:28:46+02:00
libde265 DSA

- - - - -
2f63cf9f by Salvatore Bonaccorso at 2026-09-06T20:31:28+02:00
Add CVE-2026-86219/libauthen-sasl-perl

- - - - -
53438ffe by Salvatore Bonaccorso at 2026-09-06T20:47:31+02:00
Add Debian bug reference for various issues

- - - - -
44be29dc by Salvatore Bonaccorso at 2026-09-06T20:54:05+02:00
Add Debian bug references for some issues

- - - - -
c10038a3 by Moritz Muehlenhoff at 2026-09-06T21:03:10+02:00
NFUs

- - - - -
97cd0be8 by Salvatore Bonaccorso at 2026-09-06T21:08:03+02:00
Add Debian bug reference for CVE-2026-85091/zlib

- - - - -
72d9c050 by security tracker role at 2026-09-06T19:14:05+00:00
automatic update

- - - - -
c5eb06d5 by security tracker role at 2026-09-06T19:14:56+00:00
automatic NOT-FOR-US entries update

- - - - -
de8af151 by Moritz Muehlenhoff at 2026-09-06T21:20:45+02:00
rlottie/libstb n/a

- - - - -
7e29adda by Salvatore Bonaccorso at 2026-09-06T21:22:50+02:00
CVE-2026-85091: Move reference to commit to TODO as this is not enough

- - - - -
f5b573e6 by Emmanuel Arias at 2026-09-06T16:53:14-03:00
Claim tiff in dla-needed.txt

- - - - -
1f7d492a by Moritz Muehlenhoff at 2026-09-06T23:15:03+02:00
NFUs

- - - - -
73423f24 by Salvatore Bonaccorso at 2026-09-07T06:22:06+02:00
Mark CVE-2026-52490 as no-dsa

- - - - -
7c2cf5fc by Salvatore Bonaccorso at 2026-09-07T06:23:41+02:00
Add CVE-2026-86304 as NFU

- - - - -
4253008f by Salvatore Bonaccorso at 2026-09-07T06:41:33+02:00
Track fixed version for CVE-2026-86219 via unstable

- - - - -
10b55693 by Salvatore Bonaccorso at 2026-09-07T06:53:04+02:00
Track fixed version for slurm-wlm issues via unstable

- - - - -
2631ad2a by Salvatore Bonaccorso at 2026-09-07T07:07:02+02:00
Track fixed version for thrift issues now fixed in unstable

- - - - -
cf079c88 by Salvatore Bonaccorso at 2026-09-07T07:14:12+02:00
Process one NFU

- - - - -
f987d205 by Salvatore Bonaccorso at 2026-09-07T07:27:32+02:00
Update todo for one flatpak issue

- - - - -
05cdeefd by Salvatore Bonaccorso at 2026-09-07T08:38:10+02:00
Track proposed update for libyaml-perl via trixie-pu

- - - - -
03153e4d by Salvatore Bonaccorso at 2026-09-07T08:56:09+02:00
Add CVE-2026-85013/modules

- - - - -
4300af77 by security tracker role at 2026-09-07T07:13:29+00:00
automatic update

- - - - -
dd8e0645 by security tracker role at 2026-09-07T07:14:26+00:00
automatic NOT-FOR-US entries update

- - - - -
c03b871b by Salvatore Bonaccorso at 2026-09-07T09:19:08+02:00
Process some NFUs

- - - - -
0904f066 by Salvatore Bonaccorso at 2026-09-07T09:22:17+02:00
Add CVE-2026-86227/valkey

- - - - -
0457abb0 by Moritz Muehlenhoff at 2026-09-07T10:00:34+02:00
trixie triage

- - - - -
ca134544 by Aron Xu at 2026-09-07T16:35:36+08:00
Take libevent and slurm-wlm

- - - - -
7cac63b2 by Emilio Pozuelo Monfort at 2026-09-07T11:59:58+02:00
Reserve DLA-4775-1 for thunderbird

- - - - -
1ebd1c97 by Emilio Pozuelo Monfort at 2026-09-07T12:02:02+02:00
Reserve DLA-4776-1 for chromium

- - - - -
d1362070 by Emilio Pozuelo Monfort at 2026-09-07T13:21:15+02:00
lts: take expat

- - - - -
df747f43 by Moritz Muehlenhoff at 2026-09-07T17:44:33+02:00
trixie triage

- - - - -
9be786e7 by Salvatore Bonaccorso at 2026-09-07T17:48:51+02:00
Reference upstream question for CVE-2026-85091

- - - - -
802aa45f by Salvatore Bonaccorso at 2026-09-07T18:00:08+02:00
Track proposed update for libnet-dns-perl via trixie-pu

- - - - -
77783c2f by Salvatore Bonaccorso at 2026-09-07T18:06:55+02:00
Track proposed update for libtemplate-perl via trixie-pu

- - - - -
529b229b by Yves-Alexis Perez at 2026-09-07T18:20:52+02:00
allocate DSA for strongSwan

- - - - -
4cb0a374 by Salvatore Bonaccorso at 2026-09-07T19:04:58+02:00
Add missing strongswan CVE entries

- - - - -
f86e43b6 by Salvatore Bonaccorso at 2026-09-07T19:19:37+02:00
Associate CVE-2026-14330 to pipewire

- - - - -
d5e7937b by Moritz Muehlenhoff at 2026-09-07T19:45:27+02:00
modules fixed in sid

- - - - -
43035595 by Moritz Muehlenhoff at 2026-09-07T19:46:21+02:00
bluez fixed in sid

- - - - -
6d7959cb by Moritz Mühlenhoff at 2026-09-07T19:56:24+02:00
jbig2dec DSA

- - - - -
1f328dd3 by Moritz Muehlenhoff at 2026-09-07T19:57:11+02:00
pyzipper fixed in sid

- - - - -
c02cf6af by Moritz Muehlenhoff at 2026-09-07T20:03:06+02:00
new ant issue

- - - - -
052382c2 by Salvatore Bonaccorso at 2026-09-07T20:17:39+02:00
Merge Linux CVEs from kernel-sec

- - - - -
02cd8958 by Salvatore Bonaccorso at 2026-09-07T21:00:11+02:00
Add references for strongswan issues

- - - - -
cd441b6d by security tracker role at 2026-09-07T19:12:51+00:00
automatic update

- - - - -
951b3f16 by security tracker role at 2026-09-07T19:13:45+00:00
automatic NOT-FOR-US entries update

- - - - -
07bb6717 by Salvatore Bonaccorso at 2026-09-07T21:20:12+02:00
Remove reference to generic security page as information covered by the references

- - - - -
e0cb290c by Salvatore Bonaccorso at 2026-09-07T21:30:54+02:00
Add new issues in intellij-idea

- - - - -
252481f0 by Salvatore Bonaccorso at 2026-09-07T21:34:27+02:00
Addn new glib2.0 issue

- - - - -
e868893e by Salvatore Bonaccorso at 2026-09-07T21:35:59+02:00
Add new misp issues, itp'ed

- - - - -
3bae05c6 by Salvatore Bonaccorso at 2026-09-07T21:43:37+02:00
Process some NFUs

- - - - -
63415724 by Salvatore Bonaccorso at 2026-09-07T21:47:07+02:00
Add CVE-2026-86287

- - - - -
05e674d2 by Salvatore Bonaccorso at 2026-09-07T21:49:34+02:00
Add CVE-2026-16028/libprotocol-http2-perl

- - - - -
7c8f124b by Emmanuel Arias at 2026-09-07T17:01:10-03:00
CVE-2024-58379: Add commit link

- - - - -
9eb51854 by Salvatore Bonaccorso at 2026-09-07T22:04:07+02:00
Track proposed update for libhtml-formhandler-perl via trixie-pu

- - - - -
43da507f by Salvatore Bonaccorso at 2026-09-07T22:11:53+02:00
Add CVE-2026-86435/php-league-commonmark

- - - - -
34905d11 by Emmanuel Arias at 2026-09-07T17:16:02-03:00
CVE-2024-58379/node-nodemailer: mark it as postponed for bookworm LTS

- - - - -
7399b324 by Salvatore Bonaccorso at 2026-09-07T22:21:55+02:00
Update status for php-league-commonmark issues

- - - - -
86b4d760 by Moritz Muehlenhoff at 2026-09-07T22:23:18+02:00
trixie triage

- - - - -
92bc986d by Salvatore Bonaccorso at 2026-09-07T22:38:57+02:00
Update status for new php-league-commonmark issues

- - - - -
da96894b by Emmanuel Arias at 2026-09-07T17:40:42-03:00
lts: add strongswan

- - - - -
1125916a by Moritz Muehlenhoff at 2026-09-07T22:57:26+02:00
dsa-needed: take gst-plugins-base1.0

- - - - -
f8f9cfff by Salvatore Bonaccorso at 2026-09-07T22:59:22+02:00
Add new imagemagick issues

- - - - -
cfd00fcd by Salvatore Bonaccorso at 2026-09-08T05:59:10+02:00
Update status for strongswan issues

- - - - -
72b630de by Salvatore Bonaccorso at 2026-09-08T06:20:46+02:00
Process some NFUs

- - - - -
46b3419b by Salvatore Bonaccorso at 2026-09-08T06:24:20+02:00
Add CVE-2026-86317/llama.cpp

- - - - -
3e3f491b by Salvatore Bonaccorso at 2026-09-08T06:25:23+02:00
Add CVE-2026-86289/ollama

- - - - -
bfebdb00 by Salvatore Bonaccorso at 2026-09-08T06:26:03+02:00
Add CVE-2026-81830/openvpn

- - - - -
582ca83c by Salvatore Bonaccorso at 2026-09-08T06:40:38+02:00
Add two new freeipa issues

- - - - -
e1759c31 by Salvatore Bonaccorso at 2026-09-08T06:55:35+02:00
Add new batch of 389-ds-base issues

- - - - -
2919bd0e by Salvatore Bonaccorso at 2026-09-08T06:57:32+02:00
add CVE-2026-19204/jetty

- - - - -
c37fe5d3 by Salvatore Bonaccorso at 2026-09-08T06:58:24+02:00
Take review for roundcube from maintainer

- - - - -
47afd869 by Salvatore Bonaccorso at 2026-09-08T08:28:28+02:00
Track proposed update for sssd via trixie-pu

- - - - -
8f1651e2 by security tracker role at 2026-09-08T07:12:49+00:00
automatic update

- - - - -
d98413f5 by security tracker role at 2026-09-08T07:13:48+00:00
automatic NOT-FOR-US entries update

- - - - -
c53354a1 by Emilio Pozuelo Monfort at 2026-09-08T09:14:27+02:00
lts: mark two expat issues as postponed

- - - - -
e50aa645 by Emilio Pozuelo Monfort at 2026-09-08T09:17:00+02:00
lts: give expat to andrewsh

- - - - -
0d19dc28 by Salvatore Bonaccorso at 2026-09-08T09:42:40+02:00
Process some NFUs

- - - - -
4bb897d8 by Salvatore Bonaccorso at 2026-09-08T09:53:22+02:00
Process some NFUs

- - - - -
81d13d6c by Moritz Muehlenhoff at 2026-09-08T09:56:25+02:00
new gdk-pixbuf issue

- - - - -
5f134322 by Moritz Muehlenhoff at 2026-09-08T11:12:03+02:00
trixie triage

- - - - -
e8083a3e by Andreas Dolp at 2026-09-08T11:35:42+02:00
suricata: Add infos about CVEs of 8.0.5 / 7.0.16 and 8.0.6 / 7.0.17

- - - - -


11 changed files:

- data/CVE/list
- data/DLA/list
- data/DSA/list
- data/config.json
- data/dla-needed.txt
- data/dsa-needed.txt
- data/next-point-update.txt
- data/packages/nfu.yaml
- data/packages/removed-packages
- doc/DLA.template
- static/distributions.json


Changes:

=====================================
data/CVE/list
=====================================
The diff for this file was not included because it is too large.

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,42 @@
+[07 Sep 2026] DLA-4776-1 chromium - security update
+	{CVE-2026-85042 CVE-2026-85043 CVE-2026-85044 CVE-2026-85045 CVE-2026-85046 CVE-2026-85047 CVE-2026-85048 CVE-2026-85049 CVE-2026-85050 CVE-2026-85051 CVE-2026-85052 CVE-2026-85053}
+	[bookworm] - chromium 152.0.7977.82-1~deb12u1
+[07 Sep 2026] DLA-4775-1 thunderbird - security update
+	{CVE-2026-16365 CVE-2026-16371 CVE-2026-75874 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84124 CVE-2026-84131 CVE-2026-84143 CVE-2026-84145 CVE-2026-84639 CVE-2026-84640 CVE-2026-84641}
+	[bookworm] - thunderbird 1:140.15.0esr-1~deb12u1
+[06 Sep 2026] DLA-4774-1 aom - security update
+	{CVE-2026-56208 CVE-2026-56209 CVE-2026-56210 CVE-2026-56211}
+	[bookworm] - aom 3.6.0-1+deb12u3
+[05 Sep 2026] DLA-4773-1 libssh2 - security update
+	{CVE-2025-15661 CVE-2026-7598 CVE-2026-58050 CVE-2026-58051 CVE-2026-66032 CVE-2026-66034}
+	[bookworm] - libssh2 1.10.0-3+deb12u1
+[04 Sep 2026] DLA-4772-1 pcre2 - security update
+	{CVE-2026-86145}
+	[bookworm] - pcre2 10.42-1+deb12u1
+[04 Sep 2026] DLA-4771-1 chromium - security update
+	{CVE-2026-78891 CVE-2026-78892 CVE-2026-78893 CVE-2026-78894 CVE-2026-78895 CVE-2026-78896 CVE-2026-78897 CVE-2026-78898 CVE-2026-78899 CVE-2026-78900 CVE-2026-78901 CVE-2026-78903 CVE-2026-78904 CVE-2026-78905 CVE-2026-78906 CVE-2026-78907 CVE-2026-78908 CVE-2026-78909 CVE-2026-78910 CVE-2026-78911 CVE-2026-78912 CVE-2026-78913 CVE-2026-78914 CVE-2026-78915 CVE-2026-78934 CVE-2026-78935 CVE-2026-78936 CVE-2026-78937 CVE-2026-78938 CVE-2026-78939 CVE-2026-78940 CVE-2026-78941 CVE-2026-78942 CVE-2026-78943 CVE-2026-78944 CVE-2026-78945 CVE-2026-78946 CVE-2026-78947 CVE-2026-78948 CVE-2026-78949 CVE-2026-78950 CVE-2026-78951 CVE-2026-78952 CVE-2026-78953 CVE-2026-78954 CVE-2026-78955 CVE-2026-78956 CVE-2026-78957 CVE-2026-78958 CVE-2026-78959 CVE-2026-78960 CVE-2026-78961 CVE-2026-78962 CVE-2026-78963 CVE-2026-78964 CVE-2026-78965 CVE-2026-78966 CVE-2026-78967 CVE-2026-78968 CVE-2026-78969 CVE-2026-78974 CVE-2026-78975 CVE-2026-78976 CVE-2026-78977 CVE-2026-78978 CVE-2026-78979 CVE-2026-78980 CVE-2026-78981 CVE-2026-78983 CVE-2026-78984 CVE-2026-78985 CVE-2026-78986 CVE-2026-78987 CVE-2026-78989 CVE-2026-78990 CVE-2026-78991 CVE-2026-78999 CVE-2026-79000 CVE-2026-79001 CVE-2026-79002 CVE-2026-79003 CVE-2026-79004 CVE-2026-79005 CVE-2026-79006 CVE-2026-79007 CVE-2026-79008 CVE-2026-79009 CVE-2026-79010 CVE-2026-79011 CVE-2026-79012 CVE-2026-79013 CVE-2026-79014 CVE-2026-79015 CVE-2026-79016 CVE-2026-79017 CVE-2026-79018 CVE-2026-79019 CVE-2026-79020 CVE-2026-79021 CVE-2026-79022 CVE-2026-79023 CVE-2026-79024 CVE-2026-79025 CVE-2026-79026 CVE-2026-79027 CVE-2026-79028 CVE-2026-79030 CVE-2026-79031 CVE-2026-79032 CVE-2026-79033 CVE-2026-79034 CVE-2026-79038 CVE-2026-79039 CVE-2026-79040 CVE-2026-79041 CVE-2026-79042 CVE-2026-79043 CVE-2026-79044 CVE-2026-79045 CVE-2026-79046 CVE-2026-79047 CVE-2026-79048 CVE-2026-79049 CVE-2026-79050 CVE-2026-79051 CVE-2026-79052 CVE-2026-79053 CVE-2026-79054 CVE-2026-79055 CVE-2026-79056 CVE-2026-79057 CVE-2026-79058 CVE-2026-79059 CVE-2026-79060 CVE-2026-79064 CVE-2026-79065 CVE-2026-79066 CVE-2026-79067 CVE-2026-79068 CVE-2026-79069 CVE-2026-79070 CVE-2026-79071 CVE-2026-79072 CVE-2026-79073 CVE-2026-79074 CVE-2026-79075 CVE-2026-79076 CVE-2026-79077 CVE-2026-79078 CVE-2026-79082 CVE-2026-79083 CVE-2026-79084 CVE-2026-79085 CVE-2026-79086 CVE-2026-79087 CVE-2026-79088 CVE-2026-79089 CVE-2026-79090 CVE-2026-79091 CVE-2026-79093 CVE-2026-79094 CVE-2026-79095 CVE-2026-79097 CVE-2026-79098 CVE-2026-79099 CVE-2026-79103 CVE-2026-79104 CVE-2026-79105 CVE-2026-79106 CVE-2026-79107 CVE-2026-79108 CVE-2026-79109 CVE-2026-79110 CVE-2026-79111 CVE-2026-79112 CVE-2026-79116 CVE-2026-79117 CVE-2026-79118 CVE-2026-79119 CVE-2026-79120 CVE-2026-79121 CVE-2026-79122 CVE-2026-79123 CVE-2026-79124 CVE-2026-79125 CVE-2026-79126 CVE-2026-79127 CVE-2026-79128 CVE-2026-79129 CVE-2026-79130 CVE-2026-79131 CVE-2026-79132 CVE-2026-79133 CVE-2026-79134 CVE-2026-79136 CVE-2026-79137 CVE-2026-79138 CVE-2026-79139 CVE-2026-79140 CVE-2026-79141 CVE-2026-79142 CVE-2026-79143 CVE-2026-79144 CVE-2026-79146 CVE-2026-79147 CVE-2026-79148 CVE-2026-79149 CVE-2026-79150 CVE-2026-79151 CVE-2026-79152 CVE-2026-79154 CVE-2026-79155 CVE-2026-79173 CVE-2026-79174 CVE-2026-79175 CVE-2026-79176 CVE-2026-79177 CVE-2026-79178 CVE-2026-79179 CVE-2026-79180 CVE-2026-79181 CVE-2026-79182 CVE-2026-79183 CVE-2026-79184 CVE-2026-79185 CVE-2026-79186 CVE-2026-79187 CVE-2026-79188 CVE-2026-79189 CVE-2026-79190 CVE-2026-79191 CVE-2026-79192 CVE-2026-79193 CVE-2026-79194 CVE-2026-79195 CVE-2026-79196 CVE-2026-79197 CVE-2026-79198 CVE-2026-79199 CVE-2026-79200 CVE-2026-79201 CVE-2026-79202 CVE-2026-79203 CVE-2026-79204 CVE-2026-79205 CVE-2026-79206 CVE-2026-79207 CVE-2026-79208 CVE-2026-79209 CVE-2026-79210 CVE-2026-79211 CVE-2026-79212 CVE-2026-79213 CVE-2026-79214 CVE-2026-79215 CVE-2026-79216 CVE-2026-79217 CVE-2026-79218 CVE-2026-79219 CVE-2026-79220 CVE-2026-79221 CVE-2026-79222 CVE-2026-79223 CVE-2026-79224 CVE-2026-79225 CVE-2026-79226 CVE-2026-79227 CVE-2026-79228 CVE-2026-79229 CVE-2026-79230 CVE-2026-79231 CVE-2026-79232 CVE-2026-79233 CVE-2026-79234 CVE-2026-79235 CVE-2026-79236 CVE-2026-79237 CVE-2026-79238 CVE-2026-79239 CVE-2026-79240 CVE-2026-79241 CVE-2026-79242 CVE-2026-79243 CVE-2026-79244 CVE-2026-79245 CVE-2026-79246 CVE-2026-79247 CVE-2026-79248 CVE-2026-79249 CVE-2026-79250 CVE-2026-79251 CVE-2026-79252 CVE-2026-79253 CVE-2026-79254 CVE-2026-79255 CVE-2026-79256 CVE-2026-79257 CVE-2026-79258 CVE-2026-79259 CVE-2026-79260 CVE-2026-79261 CVE-2026-79262 CVE-2026-79263 CVE-2026-79264 CVE-2026-79265 CVE-2026-79266 CVE-2026-79267 CVE-2026-79269 CVE-2026-79270 CVE-2026-79271 CVE-2026-79272 CVE-2026-79273 CVE-2026-79274 CVE-2026-79275 CVE-2026-79276 CVE-2026-79282 CVE-2026-79283 CVE-2026-79284 CVE-2026-79285 CVE-2026-79286 CVE-2026-79287 CVE-2026-79288 CVE-2026-79289 CVE-2026-79290 CVE-2026-79291 CVE-2026-79292 CVE-2026-79293 CVE-2026-84323 CVE-2026-84324 CVE-2026-84325 CVE-2026-84326 CVE-2026-84327 CVE-2026-84328 CVE-2026-84329 CVE-2026-84330 CVE-2026-84331 CVE-2026-84332 CVE-2026-84333 CVE-2026-84334 CVE-2026-84335 CVE-2026-84347 CVE-2026-84348 CVE-2026-84349 CVE-2026-84350 CVE-2026-84351 CVE-2026-84352 CVE-2026-84353 CVE-2026-84354 CVE-2026-84355 CVE-2026-84356 CVE-2026-84357 CVE-2026-84358 CVE-2026-84359}
+	[bookworm] - chromium 152.0.7977.75-1~deb12u1
+[04 Sep 2026] DLA-4770-1 firefox-esr - security update
+	{CVE-2026-16365 CVE-2026-16371 CVE-2026-75874 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84124 CVE-2026-84131 CVE-2026-84143 CVE-2026-84145}
+	[bookworm] - firefox-esr 140.15.0esr-1~deb12u1
+[02 Sep 2026] DLA-4769-1 libass - security update
+	{CVE-2026-61627}
+	[bookworm] - libass 1:0.17.1-1+deb12u1
+[02 Sep 2026] DLA-4768-1 libapache2-mod-auth-openidc - security update
+	{CVE-2026-54789}
+	[bookworm] - libapache2-mod-auth-openidc 2.4.12.3-2+deb12u5
+[02 Sep 2026] DLA-4767-1 keystone - security update
+	{CVE-2026-80182 CVE-2026-80183 CVE-2026-80184}
+	[bookworm] - keystone 2:22.0.2-0+deb12u4
+[01 Sep 2026] DLA-4766-1 cyrus-imapd - security update
+	{CVE-2026-47081 CVE-2026-47082 CVE-2026-47084 CVE-2026-47085 CVE-2026-47086 CVE-2026-47087 CVE-2026-47088 CVE-2026-47089}
+	[bookworm] - cyrus-imapd 3.6.1-4+deb12u5
+[31 Aug 2026] DLA-4765-1 expat - security update
+	{CVE-2026-50219 CVE-2026-56131 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412 CVE-2026-72522 CVE-2026-76957}
+	[bookworm] - expat 2.5.0-1+deb12u3
+[31 Aug 2026] DLA-4764-2 libdbd-csv-perl - regression update
+	[bullseye] - libdbd-csv-perl 0.5800-1+deb11u1
+	[bookworm] - libdbd-csv-perl 0.6000-1+deb12u1
 [31 Aug 2026] DLA-4764-1 libdbi-perl - security update
 	{CVE-2026-14380 CVE-2026-14739 CVE-2026-14740 CVE-2026-15043 CVE-2026-15392 CVE-2026-60081 CVE-2026-60082 CVE-2026-73193 CVE-2026-73194}
 	[bullseye] - libdbi-perl 1.643-3+deb11u2


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,29 @@
+[07 Sep 2026] DSA-6488-1 jbig2dec - security update
+	{CVE-2026-38076}
+	[trixie] - jbig2dec 0.20-1+deb13u1
+[07 Sep 2026] DSA-6487-1 strongswan - security update
+	{CVE-2026-78123 CVE-2026-78124 CVE-2026-78126 CVE-2026-78127 CVE-2026-78129 CVE-2026-78130 CVE-2026-78131 CVE-2026-78132 CVE-2026-78133 CVE-2026-78134 CVE-2026-78135}
+	[trixie] - strongswan 6.0.1-6+deb13u7
+[06 Sep 2026] DSA-6486-1 libde265 - security update
+	{CVE-2026-33164 CVE-2026-33165}
+	[trixie] - libde265 1.0.15-1+deb13u2
+[06 Sep 2026] DSA-6485-1 tryton-server - security update
+	[trixie] - tryton-server 7.0.30-1+deb13u2
+[05 Sep 2026] DSA-6484-1 chromium - security update
+	{CVE-2026-85042 CVE-2026-85043 CVE-2026-85044 CVE-2026-85045 CVE-2026-85046 CVE-2026-85047 CVE-2026-85048 CVE-2026-85049 CVE-2026-85050 CVE-2026-85051 CVE-2026-85052 CVE-2026-85053}
+	[trixie] - chromium 152.0.7977.82-1~deb13u1
+[04 Sep 2026] DSA-6483-1 thunderbird - security update
+	{CVE-2026-16365 CVE-2026-16371 CVE-2026-75874 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84124 CVE-2026-84131 CVE-2026-84143 CVE-2026-84145 CVE-2026-84639 CVE-2026-84640 CVE-2026-84641}
+	[trixie] - thunderbird 1:140.15.0esr-1~deb13u1
+[03 Sep 2026] DSA-6482-1 chromium - security update
+	{CVE-2026-78891 CVE-2026-78892 CVE-2026-78893 CVE-2026-78894 CVE-2026-78895 CVE-2026-78896 CVE-2026-78897 CVE-2026-78898 CVE-2026-78899 CVE-2026-78900 CVE-2026-78901 CVE-2026-78903 CVE-2026-78904 CVE-2026-78905 CVE-2026-78906 CVE-2026-78907 CVE-2026-78908 CVE-2026-78909 CVE-2026-78910 CVE-2026-78911 CVE-2026-78912 CVE-2026-78913 CVE-2026-78914 CVE-2026-78915 CVE-2026-78934 CVE-2026-78935 CVE-2026-78936 CVE-2026-78937 CVE-2026-78938 CVE-2026-78939 CVE-2026-78940 CVE-2026-78941 CVE-2026-78942 CVE-2026-78943 CVE-2026-78944 CVE-2026-78945 CVE-2026-78946 CVE-2026-78947 CVE-2026-78948 CVE-2026-78949 CVE-2026-78950 CVE-2026-78951 CVE-2026-78952 CVE-2026-78953 CVE-2026-78954 CVE-2026-78955 CVE-2026-78956 CVE-2026-78957 CVE-2026-78958 CVE-2026-78959 CVE-2026-78960 CVE-2026-78961 CVE-2026-78962 CVE-2026-78963 CVE-2026-78964 CVE-2026-78965 CVE-2026-78966 CVE-2026-78967 CVE-2026-78968 CVE-2026-78969 CVE-2026-78974 CVE-2026-78975 CVE-2026-78976 CVE-2026-78977 CVE-2026-78978 CVE-2026-78979 CVE-2026-78980 CVE-2026-78981 CVE-2026-78983 CVE-2026-78984 CVE-2026-78985 CVE-2026-78986 CVE-2026-78987 CVE-2026-78989 CVE-2026-78990 CVE-2026-78991 CVE-2026-78999 CVE-2026-79000 CVE-2026-79001 CVE-2026-79002 CVE-2026-79003 CVE-2026-79004 CVE-2026-79005 CVE-2026-79006 CVE-2026-79007 CVE-2026-79008 CVE-2026-79009 CVE-2026-79010 CVE-2026-79011 CVE-2026-79012 CVE-2026-79013 CVE-2026-79014 CVE-2026-79015 CVE-2026-79016 CVE-2026-79017 CVE-2026-79018 CVE-2026-79019 CVE-2026-79020 CVE-2026-79021 CVE-2026-79022 CVE-2026-79023 CVE-2026-79024 CVE-2026-79025 CVE-2026-79026 CVE-2026-79027 CVE-2026-79028 CVE-2026-79030 CVE-2026-79031 CVE-2026-79032 CVE-2026-79033 CVE-2026-79034 CVE-2026-79038 CVE-2026-79039 CVE-2026-79040 CVE-2026-79041 CVE-2026-79042 CVE-2026-79043 CVE-2026-79044 CVE-2026-79045 CVE-2026-79046 CVE-2026-79047 CVE-2026-79048 CVE-2026-79049 CVE-2026-79050 CVE-2026-79051 CVE-2026-79052 CVE-2026-79053 CVE-2026-79054 CVE-2026-79055 CVE-2026-79056 CVE-2026-79057 CVE-2026-79058 CVE-2026-79059 CVE-2026-79060 CVE-2026-79064 CVE-2026-79065 CVE-2026-79066 CVE-2026-79067 CVE-2026-79068 CVE-2026-79069 CVE-2026-79070 CVE-2026-79071 CVE-2026-79072 CVE-2026-79073 CVE-2026-79074 CVE-2026-79075 CVE-2026-79076 CVE-2026-79077 CVE-2026-79078 CVE-2026-79082 CVE-2026-79083 CVE-2026-79084 CVE-2026-79085 CVE-2026-79086 CVE-2026-79087 CVE-2026-79088 CVE-2026-79089 CVE-2026-79090 CVE-2026-79091 CVE-2026-79093 CVE-2026-79094 CVE-2026-79095 CVE-2026-79097 CVE-2026-79098 CVE-2026-79099 CVE-2026-79103 CVE-2026-79104 CVE-2026-79105 CVE-2026-79106 CVE-2026-79107 CVE-2026-79108 CVE-2026-79109 CVE-2026-79110 CVE-2026-79111 CVE-2026-79112 CVE-2026-79116 CVE-2026-79117 CVE-2026-79118 CVE-2026-79119 CVE-2026-79120 CVE-2026-79121 CVE-2026-79122 CVE-2026-79123 CVE-2026-79124 CVE-2026-79125 CVE-2026-79126 CVE-2026-79127 CVE-2026-79128 CVE-2026-79129 CVE-2026-79130 CVE-2026-79131 CVE-2026-79132 CVE-2026-79133 CVE-2026-79134 CVE-2026-79136 CVE-2026-79137 CVE-2026-79138 CVE-2026-79139 CVE-2026-79140 CVE-2026-79141 CVE-2026-79142 CVE-2026-79143 CVE-2026-79144 CVE-2026-79146 CVE-2026-79147 CVE-2026-79148 CVE-2026-79149 CVE-2026-79150 CVE-2026-79151 CVE-2026-79152 CVE-2026-79154 CVE-2026-79155 CVE-2026-79173 CVE-2026-79174 CVE-2026-79175 CVE-2026-79176 CVE-2026-79177 CVE-2026-79178 CVE-2026-79179 CVE-2026-79180 CVE-2026-79181 CVE-2026-79182 CVE-2026-79183 CVE-2026-79184 CVE-2026-79185 CVE-2026-79186 CVE-2026-79187 CVE-2026-79188 CVE-2026-79189 CVE-2026-79190 CVE-2026-79191 CVE-2026-79192 CVE-2026-79193 CVE-2026-79194 CVE-2026-79195 CVE-2026-79196 CVE-2026-79197 CVE-2026-79198 CVE-2026-79199 CVE-2026-79200 CVE-2026-79201 CVE-2026-79202 CVE-2026-79203 CVE-2026-79204 CVE-2026-79205 CVE-2026-79206 CVE-2026-79207 CVE-2026-79208 CVE-2026-79209 CVE-2026-79210 CVE-2026-79211 CVE-2026-79212 CVE-2026-79213 CVE-2026-79214 CVE-2026-79215 CVE-2026-79216 CVE-2026-79217 CVE-2026-79218 CVE-2026-79219 CVE-2026-79220 CVE-2026-79221 CVE-2026-79222 CVE-2026-79223 CVE-2026-79224 CVE-2026-79225 CVE-2026-79226 CVE-2026-79227 CVE-2026-79228 CVE-2026-79229 CVE-2026-79230 CVE-2026-79231 CVE-2026-79232 CVE-2026-79233 CVE-2026-79234 CVE-2026-79235 CVE-2026-79236 CVE-2026-79237 CVE-2026-79238 CVE-2026-79239 CVE-2026-79240 CVE-2026-79241 CVE-2026-79242 CVE-2026-79243 CVE-2026-79244 CVE-2026-79245 CVE-2026-79246 CVE-2026-79247 CVE-2026-79248 CVE-2026-79249 CVE-2026-79250 CVE-2026-79251 CVE-2026-79252 CVE-2026-79253 CVE-2026-79254 CVE-2026-79255 CVE-2026-79256 CVE-2026-79257 CVE-2026-79258 CVE-2026-79259 CVE-2026-79260 CVE-2026-79261 CVE-2026-79262 CVE-2026-79263 CVE-2026-79264 CVE-2026-79265 CVE-2026-79266 CVE-2026-79267 CVE-2026-79269 CVE-2026-79270 CVE-2026-79271 CVE-2026-79272 CVE-2026-79273 CVE-2026-79274 CVE-2026-79275 CVE-2026-79276 CVE-2026-79282 CVE-2026-79283 CVE-2026-79284 CVE-2026-79285 CVE-2026-79286 CVE-2026-79287 CVE-2026-79288 CVE-2026-79289 CVE-2026-79290 CVE-2026-79291 CVE-2026-79292 CVE-2026-79293 CVE-2026-84323 CVE-2026-84324 CVE-2026-84325 CVE-2026-84326 CVE-2026-84327 CVE-2026-84328 CVE-2026-84329 CVE-2026-84330 CVE-2026-84331 CVE-2026-84332 CVE-2026-84333 CVE-2026-84334 CVE-2026-84335 CVE-2026-84347 CVE-2026-84348 CVE-2026-84349 CVE-2026-84350 CVE-2026-84351 CVE-2026-84352 CVE-2026-84353 CVE-2026-84354 CVE-2026-84355 CVE-2026-84356 CVE-2026-84357 CVE-2026-84358 CVE-2026-84359}
+	[trixie] - chromium 152.0.7977.75-1~deb13u1
+[02 Sep 2026] DSA-6481-1 firefox-esr - security update
+	{CVE-2026-16365 CVE-2026-16371 CVE-2026-75874 CVE-2026-84119 CVE-2026-84120 CVE-2026-84121 CVE-2026-84122 CVE-2026-84124 CVE-2026-84131 CVE-2026-84143 CVE-2026-84145}
+	[trixie] - firefox-esr 140.15.0esr-1~deb13u1
+[01 Sep 2026] DSA-6480-1 keystone - security update
+	{CVE-2026-80182 CVE-2026-80183 CVE-2026-80184}
+	[trixie] - keystone 2:27.0.0-3+deb13u5
 [30 Aug 2026] DSA-6479-1 roundcube - security update
 	{CVE-2026-74997 CVE-2026-74998 CVE-2026-74999 CVE-2026-75000 CVE-2026-75002 CVE-2026-75003 CVE-2026-75004 CVE-2026-75006 CVE-2026-75007 CVE-2026-75010}
 	[trixie] - roundcube 1.6.18+dfsg-0+deb13u1
@@ -665,7 +691,7 @@
 	{CVE-2026-6472 CVE-2026-6473 CVE-2026-6474 CVE-2026-6475 CVE-2026-6477 CVE-2026-6478 CVE-2026-6479 CVE-2026-6637}
 	[bookworm] - postgresql-15 15.18-0+deb12u1
 [14 May 2026] DSA-6268-1 ffmpeg - security update
-	{CVE-2026-40962 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348 CVE-2026-38349}
+	{CVE-2026-40962 CVE-2026-38343 CVE-2026-38344 CVE-2026-38346 CVE-2026-38348 CVE-2026-38349 CVE-2026-52295}
 	[trixie] - ffmpeg 7:7.1.4-0+deb13u1
 [14 May 2026] DSA-6267-1 thunderbird - security update
 	{CVE-2026-8090 CVE-2026-8092 CVE-2026-8094}
@@ -1182,7 +1208,7 @@
 	[bookworm] - shaarli 0.12.1+dfsg-8+deb12u2
 	[trixie] - shaarli 0.14.0+dfsg-2+deb13u1
 [09 Feb 2026] DSA-6127-1 linux - security update
-	{CVE-2023-52658 CVE-2023-53421 CVE-2023-54285 CVE-2024-42079 CVE-2024-46786 CVE-2024-49968 CVE-2025-21946 CVE-2025-22022 CVE-2025-22083 CVE-2025-22090 CVE-2025-22107 CVE-2025-22111 CVE-2025-22121 CVE-2025-37926 CVE-2025-38022 CVE-2025-38104 CVE-2025-38125 CVE-2025-38129 CVE-2025-38232 CVE-2025-38361 CVE-2025-38408 CVE-2025-38591 CVE-2025-38718 CVE-2025-39721 CVE-2025-39871 CVE-2025-40039 CVE-2025-40110 CVE-2025-40149 CVE-2025-40164 CVE-2025-40215 CVE-2025-68211 CVE-2025-68223 CVE-2025-68254 CVE-2025-68255 CVE-2025-68256 CVE-2025-68257 CVE-2025-68258 CVE-2025-68259 CVE-2025-68261 CVE-2025-68263 CVE-2025-68264 CVE-2025-68266 CVE-2025-68291 CVE-2025-68325 CVE-2025-68332 CVE-2025-68335 CVE-2025-68336 CVE-2025-68337 CVE-2025-68340 CVE-2025-68344 CVE-2025-68345 CVE-2025-68346 CVE-2025-68347 CVE-2025-68349 CVE-2025-68354 CVE-2025-68362 CVE-2025-68363 CVE-2025-68364 CVE-2025-68365 CVE-2025-68366 CVE-2025-68367 CVE-2025-68369 CVE-2025-68371 CVE-2025-68372 CVE-2025-68380 CVE-2025-68724 CVE-2025-68725 CVE-2025-68727 CVE-2025-68728 CVE-2025-68732 CVE-2025-68733 CVE-2025-68740 CVE-2025-68742 CVE-2025-68746 CVE-2025-68753 CVE-2025-68757 CVE-2025-68758 CVE-2025-68759 CVE-2025-68764 CVE-2025-68765 CVE-2025-68766 CVE-2025-68767 CVE-2025-68769 CVE-2025-68771 CVE-2025-68772 CVE-2025-68773 CVE-2025-68774 CVE-2025-68776 CVE-2025-68777 CVE-2025-68778 CVE-2025-68780 CVE-2025-68781 CVE-2025-68782 CVE-2025-68783 CVE-2025-68785 CVE-2025-68786 CVE-2025-68787 CVE-2025-68788 CVE-2025-68795 CVE-2025-68796 CVE-2025-68797 CVE-2025-68798 CVE-2025-68799 CVE-2025-68800 CVE-2025-68801 CVE-2025-68803 CVE-2025-68804 CVE-2025-68806 CVE-2025-68808 CVE-2025-68813 CVE-2025-68814 CVE-2025-68815 CVE-2025-68816 CVE-2025-68817 CVE-2025-68818 CVE-2025-68819 CVE-2025-68820 CVE-2025-68821 CVE-2025-71064 CVE-2025-71066 CVE-2025-71069 CVE-2025-71071 CVE-2025-71075 CVE-2025-71077 CVE-2025-71078 CVE-2025-71079 CVE-2025-71081 CVE-2025-71082 CVE-2025-71083 CVE-2025-71084 CVE-2025-71085 CVE-2025-71086 CVE-2025-71087 CVE-2025-71088 CVE-2025-71091 CVE-2025-71093 CVE-2025-71094 CVE-2025-71095 CVE-2025-71096 CVE-2025-71097 CVE-2025-71098 CVE-2025-71102 CVE-2025-71104 CVE-2025-71105 CVE-2025-71108 CVE-2025-71111 CVE-2025-71112 CVE-2025-71113 CVE-2025-71114 CVE-2025-71116 CVE-2025-71118 CVE-2025-71119 CVE-2025-71120 CVE-2025-71121 CVE-2025-71123 CVE-2025-71125 CVE-2025-71126 CVE-2025-71127 CVE-2025-71130 CVE-2025-71131 CVE-2025-71132 CVE-2025-71133 CVE-2025-71136 CVE-2025-71137 CVE-2025-71147 CVE-2025-71150 CVE-2025-71154 CVE-2025-71162 CVE-2025-71163 CVE-2025-71180 CVE-2025-71182 CVE-2025-71183 CVE-2025-71185 CVE-2025-71186 CVE-2025-71189 CVE-2025-71190 CVE-2025-71191 CVE-2025-71192 CVE-2025-71194 CVE-2025-71196 CVE-2025-71197 CVE-2025-71199 CVE-2026-22976 CVE-2026-22977 CVE-2026-22978 CVE-2026-22979 CVE-2026-22980 CVE-2026-22982 CVE-2026-22984 CVE-2026-22990 CVE-2026-22991 CVE-2026-22992 CVE-2026-22994 CVE-2026-22997 CVE-2026-22998 CVE-2026-22999 CVE-2026-23001 CVE-2026-23003 CVE-2026-23005 CVE-2026-23006 CVE-2026-23010 CVE-2026-23011 CVE-2026-23019 CVE-2026-23020 CVE-2026-23021 CVE-2026-23025 CVE-2026-23026 CVE-2026-23030 CVE-2026-23031 CVE-2026-23033 CVE-2026-23037 CVE-2026-23038 CVE-2026-23047 CVE-2026-23049 CVE-2026-23054 CVE-2026-23056 CVE-2026-23058 CVE-2026-23060 CVE-2026-23061 CVE-2026-23063 CVE-2026-23064 CVE-2026-23068 CVE-2026-23069 CVE-2026-23071 CVE-2026-23073 CVE-2026-23074 CVE-2026-23075 CVE-2026-23076 CVE-2026-23078 CVE-2026-23080 CVE-2026-23083 CVE-2026-23084 CVE-2026-23085 CVE-2026-23086 CVE-2026-23087 CVE-2026-23089 CVE-2026-23090 CVE-2026-23091 CVE-2026-23093 CVE-2026-23095 CVE-2026-23096 CVE-2026-23097 CVE-2026-23098 CVE-2026-23099 CVE-2026-23101 CVE-2026-23102 CVE-2026-23103 CVE-2026-23105 CVE-2026-23107 CVE-2026-23108 CVE-2026-23110}
+	{CVE-2023-52658 CVE-2023-53421 CVE-2023-54285 CVE-2024-42079 CVE-2024-46786 CVE-2024-49968 CVE-2025-21946 CVE-2025-22022 CVE-2025-22083 CVE-2025-22090 CVE-2025-22107 CVE-2025-22111 CVE-2025-22121 CVE-2025-37926 CVE-2025-38022 CVE-2025-38104 CVE-2025-38125 CVE-2025-38129 CVE-2025-38232 CVE-2025-38361 CVE-2025-38408 CVE-2025-38591 CVE-2025-38718 CVE-2025-39721 CVE-2025-39871 CVE-2025-40039 CVE-2025-40110 CVE-2025-40149 CVE-2025-40164 CVE-2025-40215 CVE-2025-68211 CVE-2025-68223 CVE-2025-68254 CVE-2025-68255 CVE-2025-68256 CVE-2025-68257 CVE-2025-68258 CVE-2025-68259 CVE-2025-68261 CVE-2025-68263 CVE-2025-68264 CVE-2025-68266 CVE-2025-68291 CVE-2025-68325 CVE-2025-68332 CVE-2025-68335 CVE-2025-68336 CVE-2025-68337 CVE-2025-68340 CVE-2025-68344 CVE-2025-68345 CVE-2025-68346 CVE-2025-68347 CVE-2025-68349 CVE-2025-68354 CVE-2025-68362 CVE-2025-68363 CVE-2025-68364 CVE-2025-68365 CVE-2025-68366 CVE-2025-68367 CVE-2025-68369 CVE-2025-68371 CVE-2025-68372 CVE-2025-68380 CVE-2025-68724 CVE-2025-68725 CVE-2025-68727 CVE-2025-68728 CVE-2025-68732 CVE-2025-68733 CVE-2025-68740 CVE-2025-68742 CVE-2025-68746 CVE-2025-68753 CVE-2025-68757 CVE-2025-68758 CVE-2025-68759 CVE-2025-68764 CVE-2025-68765 CVE-2025-68766 CVE-2025-68767 CVE-2025-68769 CVE-2025-68771 CVE-2025-68772 CVE-2025-68773 CVE-2025-68774 CVE-2025-68776 CVE-2025-68777 CVE-2025-68778 CVE-2025-68780 CVE-2025-68782 CVE-2025-68783 CVE-2025-68785 CVE-2025-68786 CVE-2025-68787 CVE-2025-68788 CVE-2025-68795 CVE-2025-68796 CVE-2025-68797 CVE-2025-68798 CVE-2025-68799 CVE-2025-68800 CVE-2025-68801 CVE-2025-68803 CVE-2025-68804 CVE-2025-68806 CVE-2025-68808 CVE-2025-68813 CVE-2025-68814 CVE-2025-68815 CVE-2025-68816 CVE-2025-68817 CVE-2025-68818 CVE-2025-68819 CVE-2025-68820 CVE-2025-68821 CVE-2025-71064 CVE-2025-71066 CVE-2025-71069 CVE-2025-71071 CVE-2025-71075 CVE-2025-71077 CVE-2025-71078 CVE-2025-71079 CVE-2025-71081 CVE-2025-71082 CVE-2025-71083 CVE-2025-71084 CVE-2025-71085 CVE-2025-71086 CVE-2025-71087 CVE-2025-71088 CVE-2025-71091 CVE-2025-71093 CVE-2025-71094 CVE-2025-71095 CVE-2025-71096 CVE-2025-71097 CVE-2025-71098 CVE-2025-71102 CVE-2025-71104 CVE-2025-71105 CVE-2025-71108 CVE-2025-71111 CVE-2025-71112 CVE-2025-71113 CVE-2025-71114 CVE-2025-71116 CVE-2025-71118 CVE-2025-71119 CVE-2025-71120 CVE-2025-71121 CVE-2025-71123 CVE-2025-71125 CVE-2025-71126 CVE-2025-71127 CVE-2025-71130 CVE-2025-71131 CVE-2025-71132 CVE-2025-71133 CVE-2025-71136 CVE-2025-71137 CVE-2025-71147 CVE-2025-71150 CVE-2025-71154 CVE-2025-71162 CVE-2025-71163 CVE-2025-71180 CVE-2025-71182 CVE-2025-71183 CVE-2025-71185 CVE-2025-71186 CVE-2025-71189 CVE-2025-71190 CVE-2025-71191 CVE-2025-71192 CVE-2025-71194 CVE-2025-71196 CVE-2025-71197 CVE-2025-71199 CVE-2026-22976 CVE-2026-22977 CVE-2026-22978 CVE-2026-22979 CVE-2026-22980 CVE-2026-22982 CVE-2026-22984 CVE-2026-22990 CVE-2026-22991 CVE-2026-22992 CVE-2026-22994 CVE-2026-22997 CVE-2026-22998 CVE-2026-22999 CVE-2026-23001 CVE-2026-23003 CVE-2026-23005 CVE-2026-23006 CVE-2026-23010 CVE-2026-23011 CVE-2026-23019 CVE-2026-23020 CVE-2026-23021 CVE-2026-23025 CVE-2026-23026 CVE-2026-23030 CVE-2026-23031 CVE-2026-23033 CVE-2026-23037 CVE-2026-23038 CVE-2026-23047 CVE-2026-23049 CVE-2026-23054 CVE-2026-23056 CVE-2026-23058 CVE-2026-23060 CVE-2026-23061 CVE-2026-23063 CVE-2026-23064 CVE-2026-23068 CVE-2026-23069 CVE-2026-23071 CVE-2026-23073 CVE-2026-23074 CVE-2026-23075 CVE-2026-23076 CVE-2026-23078 CVE-2026-23080 CVE-2026-23083 CVE-2026-23084 CVE-2026-23085 CVE-2026-23086 CVE-2026-23087 CVE-2026-23089 CVE-2026-23090 CVE-2026-23091 CVE-2026-23093 CVE-2026-23095 CVE-2026-23096 CVE-2026-23097 CVE-2026-23098 CVE-2026-23099 CVE-2026-23101 CVE-2026-23102 CVE-2026-23103 CVE-2026-23105 CVE-2026-23107 CVE-2026-23108 CVE-2026-23110}
 	[bookworm] - linux 6.1.162-1
 [09 Feb 2026] DSA-6126-1 linux - security update
 	{CVE-2024-58096 CVE-2024-58097 CVE-2025-22111 CVE-2025-38234 CVE-2025-38248 CVE-2025-38591 CVE-2025-39872 CVE-2025-40149 CVE-2025-40164 CVE-2025-40170 CVE-2025-40276 CVE-2025-40325 CVE-2025-68206 CVE-2025-68333 CVE-2025-68345 CVE-2025-68351 CVE-2025-68357 CVE-2025-68358 CVE-2025-68365 CVE-2025-68725 CVE-2025-68749 CVE-2025-68767 CVE-2025-68769 CVE-2025-68770 CVE-2025-68771 CVE-2025-68772 CVE-2025-68773 CVE-2025-68774 CVE-2025-68775 CVE-2025-68776 CVE-2025-68777 CVE-2025-68778 CVE-2025-68780 CVE-2025-68781 CVE-2025-68782 CVE-2025-68783 CVE-2025-68784 CVE-2025-68785 CVE-2025-68786 CVE-2025-68787 CVE-2025-68788 CVE-2025-68792 CVE-2025-68794 CVE-2025-68795 CVE-2025-68796 CVE-2025-68797 CVE-2025-68798 CVE-2025-68799 CVE-2025-68800 CVE-2025-68801 CVE-2025-68802 CVE-2025-68803 CVE-2025-68804 CVE-2025-68806 CVE-2025-68808 CVE-2025-68809 CVE-2025-68810 CVE-2025-68811 CVE-2025-68813 CVE-2025-68814 CVE-2025-68815 CVE-2025-68816 CVE-2025-68817 CVE-2025-68818 CVE-2025-68819 CVE-2025-68820 CVE-2025-68821 CVE-2025-68822 CVE-2025-71064 CVE-2025-71065 CVE-2025-71066 CVE-2025-71067 CVE-2025-71068 CVE-2025-71069 CVE-2025-71071 CVE-2025-71072 CVE-2025-71073 CVE-2025-71075 CVE-2025-71076 CVE-2025-71077 CVE-2025-71078 CVE-2025-71079 CVE-2025-71080 CVE-2025-71081 CVE-2025-71082 CVE-2025-71083 CVE-2025-71084 CVE-2025-71085 CVE-2025-71086 CVE-2025-71087 CVE-2025-71088 CVE-2025-71089 CVE-2025-71091 CVE-2025-71093 CVE-2025-71094 CVE-2025-71095 CVE-2025-71096 CVE-2025-71097 CVE-2025-71098 CVE-2025-71099 CVE-2025-71100 CVE-2025-71101 CVE-2025-71102 CVE-2025-71104 CVE-2025-71105 CVE-2025-71107 CVE-2025-71108 CVE-2025-71109 CVE-2025-71111 CVE-2025-71112 CVE-2025-71113 CVE-2025-71114 CVE-2025-71116 CVE-2025-71118 CVE-2025-71119 CVE-2025-71120 CVE-2025-71121 CVE-2025-71122 CVE-2025-71123 CVE-2025-71125 CVE-2025-71126 CVE-2025-71127 CVE-2025-71129 CVE-2025-71130 CVE-2025-71131 CVE-2025-71132 CVE-2025-71133 CVE-2025-71134 CVE-2025-71135 CVE-2025-71136 CVE-2025-71137 CVE-2025-71138 CVE-2025-71140 CVE-2025-71143 CVE-2025-71144 CVE-2025-71146 CVE-2025-71147 CVE-2025-71148 CVE-2025-71150 CVE-2025-71151 CVE-2025-71153 CVE-2025-71154 CVE-2025-71156 CVE-2025-71157 CVE-2025-71160 CVE-2025-71162 CVE-2025-71163 CVE-2025-71180 CVE-2025-71182 CVE-2025-71183 CVE-2025-71184 CVE-2025-71185 CVE-2025-71186 CVE-2025-71189 CVE-2025-71190 CVE-2025-71191 CVE-2025-71192 CVE-2025-71193 CVE-2025-71194 CVE-2025-71195 CVE-2025-71196 CVE-2025-71197 CVE-2025-71198 CVE-2025-71199 CVE-2026-22976 CVE-2026-22977 CVE-2026-22978 CVE-2026-22979 CVE-2026-22980 CVE-2026-22982 CVE-2026-22984 CVE-2026-22989 CVE-2026-22990 CVE-2026-22991 CVE-2026-22992 CVE-2026-22994 CVE-2026-22996 CVE-2026-22997 CVE-2026-22998 CVE-2026-22999 CVE-2026-23000 CVE-2026-23001 CVE-2026-23002 CVE-2026-23003 CVE-2026-23005 CVE-2026-23006 CVE-2026-23010 CVE-2026-23011 CVE-2026-23013 CVE-2026-23019 CVE-2026-23020 CVE-2026-23021 CVE-2026-23023 CVE-2026-23025 CVE-2026-23026 CVE-2026-23030 CVE-2026-23031 CVE-2026-23032 CVE-2026-23033 CVE-2026-23035 CVE-2026-23037 CVE-2026-23038 CVE-2026-23047 CVE-2026-23049 CVE-2026-23050 CVE-2026-23053 CVE-2026-23054 CVE-2026-23055 CVE-2026-23056 CVE-2026-23057 CVE-2026-23058 CVE-2026-23059 CVE-2026-23060 CVE-2026-23061 CVE-2026-23062 CVE-2026-23063 CVE-2026-23064 CVE-2026-23065 CVE-2026-23068 CVE-2026-23069 CVE-2026-23071 CVE-2026-23072 CVE-2026-23073 CVE-2026-23074 CVE-2026-23075 CVE-2026-23076 CVE-2026-23078 CVE-2026-23080 CVE-2026-23083 CVE-2026-23084 CVE-2026-23085 CVE-2026-23086 CVE-2026-23087 CVE-2026-23088 CVE-2026-23089 CVE-2026-23090 CVE-2026-23091 CVE-2026-23093 CVE-2026-23094 CVE-2026-23095 CVE-2026-23096 CVE-2026-23097 CVE-2026-23098 CVE-2026-23099 CVE-2026-23101 CVE-2026-23103 CVE-2026-23105 CVE-2026-23107 CVE-2026-23108 CVE-2026-23110}


=====================================
data/config.json
=====================================
@@ -91,9 +91,7 @@
         "optional": [
           "bullseye-proposed-updates"
         ]
-      },
-      "architectures": [ "amd64", "arm64", "armhf", "i386" ],
-      "release": "oldoldstable"
+      }
     },
     "bookworm": {
       "members": {


=====================================
data/dla-needed.txt
=====================================
@@ -53,14 +53,6 @@ amd64-microcode
   NOTE: 20251224: I think the required kernel microcode driver patch are: https://lists.openwall.net/linux-kernel/2025/10/27/1012
   NOTE: 20260615: bookworm (now lts) also needs fixes. (charles)
 --
-aom/bookworm
-  NOTE: 20260709: Added by Front-Desk (utkarsh)
-  NOTE: 20260709: AV1 *encoder* flaws (SVC layer-id/LAP), CVE-2026-56208..56211; only
-  NOTE: 20260709: bookworm (3.6.0) affected, bullseye not-affected (code added in aom 2.0.0).
---
-apache-log4j2/bullseye
-  NOTE: 20260413: Added by Front-Desk (rouca)
---
 bouncycastle
   NOTE: 20260417: Added by Front-Desk (rouca)
   NOTE: 20260417: Priority: Fix CVE-2026-5588 then try to fix other pilled CVE (rouca/FD)
@@ -72,26 +64,11 @@ busybox
   NOTE: 20260722: Also add for bookworm; CVE-2026-38752..38755 (ash/awk)
   NOTE: 20260722: share code, sponsored, already queued bullseye+ELTS (utkarsh)
 --
-ca-certificates
-  NOTE: 20250613: Added by Front-Desk (rouca)
-  NOTE: 20250613: Lack some certificates #1095913 (rouca/FD)
-  NOTE: 20250613: Coordinate with bookworm PU if needed (rouca/FD)
-  NOTE: 20250613: Document carefully changes in backport, particularly removed certificates (rouca/FD)
-  NOTE: 20250731: will likely need an upload of ca-certificates-jave before and breaks/update (rouca)
-  NOTE: 20250731: WIP break piuparts (rouca)
-  NOTE: 20250801: Propose for review a ca-certificates-java (rouca)
-  NOTE: 20250811: upload ca-certificates-java (rouca)
-  NOTE: 20250811: wait for direction from security team about bookworm update first (rouca)
-  NOTE: 20260216: partial update under debusine https://debusine.debian.net/debian/developers/work-request/446642/
-  NOTE: 20260220: Release partial DLA 4485-1
-  NOTE: 20260710: bookworm update seems to be required: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1107237#48 (santiago)
-  NOTE: 20260810: made a release from trixie DLA-4726-1 (rouca). Will need last sid version to go to trixie (rouca)
---
 cacti
   NOTE: 20260630: Added by Front-Desk (dleidert)
   NOTE: 20260630: A new bunch of issues and in DSA list (dleidert/front-desk)
 --
-caddy/bookworm
+caddy
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
@@ -114,18 +91,11 @@ containerd
   NOTE: 20260621: Added by Front-Desk (charles)
   NOTE: 20260621: Also in dsa-needed, sync with secteam or follow DSA (charles)
 --
-coturn/bullseye
-  NOTE: 20260414: Added by Front-Desk (rouca)
---
 cups (Thorsten Alteholz)
   NOTE: 20260404: Added by Front-Desk (ta)
   NOTE: 20260615: bookworm also need the same fixes as bullseye. (charles)
   NOTE: 20260705: still trying to find a solution to fix a CVE without changing the functionality of lpadmin
 --
-cyrus-imapd
-  NOTE: 20260717: Added by Front-Desk (Beuc)
-  NOTE: 20260717: Upcoming DSA (Beuc/front-desk)
---
 designate
   NOTE: 20260818: Added by Front-Desk (lamby)
   NOTE: 20260823: Maintainer uploaded fixes for bookworm. (Charles)
@@ -134,7 +104,7 @@ docker.io
   NOTE: 20250805: Added by Front-Desk (rouca)
   NOTE: 20260714: Also add for bookworm (Beuc/front-desk)
 --
-dovecot
+dovecot (guilhem)
   NOTE: 20260829: Added by Front-Desk (dleidert)
   NOTE: 20260829: Upcoming DSA (dleidert/front-desk)
 --
@@ -145,10 +115,6 @@ dracut
 dulwich
   NOTE: 20260613: Added by Front-Desk (rouca)
 --
-edk2/bullseye
-  NOTE: 20251230: Added by Front-Desk (Beuc)
-  NOTE: 20251230: Lots of postponed issues piled-up (Beuc/front-desk)
---
 emacs
   NOTE: 20260822: Added by Front-Desk (lamby)
 --
@@ -160,7 +126,7 @@ erlang
   NOTE: 20260519: Fix ELTS at the same time. (Beuc/front-desk)
   NOTE: 20260702: Another round of issues and upcoming DSA (dleidert/front-desk)
 --
-evolution-data-server/bookworm
+evolution-data-server
   NOTE: 20260717: Added by Front-Desk (Beuc)
   NOTE: 20260717: Follow DLA-4503-1/bullseye (1 CVE) (Beuc/front-desk)
 --
@@ -170,8 +136,9 @@ exim4
 --
 expat (andrewsh)
   NOTE: 20260518: Added by Front-Desk (Beuc)
-  NOTE: 20260518: Upcoming DSA + many postponed CVE.
+  NOTE: 20260518: Many postponed CVE.
   NOTE: 20260518: CVE-2026-41080 fix requires for python's CVE-2026-7210.
+  NOTE: 20260831: CVE-2026-45186 and CVE-2026-66046 require more work (andrewsh)
 --
 ffmpeg
   NOTE: 20260710: Added by Front-Desk (utkarsh)
@@ -187,15 +154,15 @@ firebird3.0
   NOTE: 20260418: Added by Front-Desk (rouca)
   NOTE: 20260702: Upcoming DSA (dleidert/front-desk)
 --
-firmware-nonfree/bullseye
-  NOTE: 20251130: Added by Front-Desk. Moreover, take care of postponed issue (rouca)
---
 flatpak
   NOTE: 20260413: Added by Front-Desk (rouca)
   NOTE: 20260811: A bunch of new vulnerabilities were released that can be
   NOTE: 20260811: chained to RCE. In DSA needed, maintainer taking care of
   NOTE: 20260811: trixie update, follow DSA. (charles)
 --
+fort-validator
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 freecad
   NOTE: 20260821: Added by Front-Desk (lamby)
 --
@@ -209,19 +176,14 @@ frr
   NOTE: 20260714: Also add for bookworm.
   NOTE: 20260714: Many CVEs fixed in bullseye but not in bookworm (low pri) (Beuc/front-desk)
 --
-gawk
+gawk (ah)
   NOTE: 20260801: Added by Front-Desk (ta)
 --
-gdal/bullseye
-  NOTE: 20260419: Added by Front-Desk (rouca)
-  NOTE: 20260419: Investigate why embded zblib and maybe deemded beginning from sid (rouca/FD)
-  NOTE: 20260419: check other zlib CVE (rouca/FD)
---
 gegl
   NOTE: 20260821: Added by Front-Desk (lamby)
   NOTE: 20260821: Not immediately clear how the changes to libs/ctx/ctx.h (not present in bullseye LTS) interact with libs/rgbe/rgbe.c, so this may not be vulnerable in bullseye or earlier. (lamby)
 --
-gh/bookworm
+gh
   NOTE: 20241230: Added by Security Team (carnil)
   NOTE: 20260611: bookworm LTS handover.
 --
@@ -230,20 +192,10 @@ gimp
   NOTE: 20260709: PSP/PNM/PSD parser overflows CVE-2026-58379..58388 (crafted image); TIM-loader
   NOTE: 20260709: CVE-2026-59089 not-affected (GIMP 3.x-only).
 --
-git-lfs/bookworm
+git-lfs
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
 --
-glances/bullseye
-  NOTE: 20260518: Added by Front-Desk (Beuc)
-  NOTE: 20260518: Many postponed vulnerabilities piled-up (Beuc/front-desk)
---
-golang-glog/bullseye
-  NOTE: 20250209: Added by Front-Desk (apo)
-  NOTE: 20251107: Re-add as binNMUs are not all properly Installed in the archive:
-  NOTE: 20251107: https://buildd.debian.org/status/package.php?p=+golang-github-grpc-ecosystem-grpc-gateway&suite=bullseye-security
-  NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
---
 gst-plugins-bad1.0
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
@@ -259,7 +211,7 @@ icinga2
   NOTE: 20260702: Follow DSA and/or support security team with DSA (dleidert/front-desk)
   NOTE: 20260702: also care about outstanding CVEs (dleidert/front-desk)
 --
-inkscape/bookworm
+inkscape
   NOTE: 20260522: Added by Security Team (jmm)
   NOTE: 20260611: bookworm LTS handover.
 --
@@ -267,7 +219,7 @@ ironic
   NOTE: 20260610: Added by Front-Desk (rouca)
   NOTE: 20260816: Partial release by maintainer (charles)
 --
-isc-kea/bookworm
+isc-kea
   NOTE: 20260224: Added by Security Team (jmm)
   NOTE: 20260611: bookworm LTS handover.
 --
@@ -285,17 +237,13 @@ jetty9
 jline3
   NOTE: 20260801: Added by Front-Desk (ta)
 --
-jpeg-xl/bookworm
+jpeg-xl
   NOTE: 20260619: Added by Front-Desk (charles)
   NOTE: 20260619: Follow DSA-6342-1 (charles)
 --
 kamailio
   NOTE: 20260413: Added by Front-Desk (rouca)
 --
-keystone
-  NOTE: 20260830: Added by Front-Desk (dleidert)
-  NOTE: 20260830: Upcoming DSA (dleidert/front-desk)
---
 kitty
   NOTE: 20260522: Added by Front-Desk (Beuc)
   NOTE: 20260522: Upcoming DSA (Beuc/front-desk)
@@ -303,33 +251,11 @@ kitty
   NOTE: 20260523: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1137210#45
   NOTE: 20260528: DSA-6307-1 (2 CVEs)
 --
-knot-resolver/bullseye
-  NOTE: 20251206: Added by Front-Desk (rouca)
-  NOTE: 20251206: Close CVE-2022-40188 buster regression. Try to fix other non ignored CVEs.
-  NOTE: 20251223: complicated to backport no-dsa CVEs as CVE-2023-46317 reverts much of the patch
-  NOTE: 20251223: for CVE-2023-26249 and then needs to be re-adjusted a bit for v5.3.1. nonetheless,
-  NOTE: 20251223: update prepared @ https://salsa.debian.org/lts-team/packages/knot-resolver/-/tree/debian/bullseye?ref_type=heads.
-  NOTE: 20251223: but have reached out to Jakub and Santiago, as maintainers, for a review. (utkarsh)
-  NOTE: 20250104: still waiting to hear back. will upload to debusine for extra pipelines to run. (utkarsh)
-  NOTE: 20250119: still waiting to hear back. (utkarsh)
---
 ldap-account-manager
   NOTE: 20260418: Added by Front-Desk (rouca)
   NOTE: 20260725: Also add for bookworm (8.3); CVE-2026-27894 PDF-export LFI,
   NOTE: 20260725: unvalidated pdf_structure/pdf_font identical to bullseye. (utkarsh/front-desk)
 --
-libapache2-mod-auth-openidc (dleidert)
-  NOTE: 20260830: Added by Front-Desk (dleidert)
---
-libass
-  NOTE: 20260712: Added by Front-Desk (utkarsh)
-  NOTE: 20260712: TEMP-0000000-AA08BC (GHSA-pjjp-65r7-ppgm): OOB read+write in wrap_lines_measure from untrusted subtitles; secteam fixed stable via point release. Affected in bullseye (0.15.0) and bookworm (0.17.1). (utkarsh/front-desk)
---
-libcaca/bullseye
-  NOTE: 20260519: Added by Front-Desk (Beuc)
-  NOTE: 20260519: Fix unstable first. (Beuc/front-desk)
-  NOTE: 20260601: Unstable fixed and OSPU ready https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1138538
---
 libcrypt-pbkdf2-perl
   NOTE: 20260612: Added by Front-Desk (rouca)
   NOTE: 20260613: you MUST follow #1139897 and coordinate (rouca/FD)
@@ -345,6 +271,9 @@ libde265
   NOTE: 20260709: HEVC decoder overflow/UAF (CVE-2026-45382/45383/49295/49337/49346/54240/54241);
   NOTE: 20260709: upstream fixes v1.0.19-v1.1.1 newer than Debian 1.0.11.
 --
+libevent
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 libgd-securityimage-perl
   NOTE: 20260806: Added by Front-Desk (rouca)
 --
@@ -362,14 +291,10 @@ libio-compress-perl
 libmojo-jwt-perl
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
-libreoffice/bullseye (santiago)
-  NOTE: 20260508: Added by Front-Desk (dleidert)
-  NOTE: 20260508: Follow DSA-6251-1 (dleidert/front-desk)
---
 librest
   NOTE: 20260802: Added by Front-Desk (ta)
 --
-libreswan/bookworm
+libreswan
   NOTE: 20230301: Added by Security Team (jmm)
   NOTE: 20260611: bookworm LTS handover.
   NOTE: 20260611: Sync with maintainer (dkg), hard to test.
@@ -415,32 +340,10 @@ libsoup2.4
 libssh
   NOTE: 20260731: Added by Front-Desk (ta)
 --
-libssh2 (eamanu)
-  NOTE: 20260625: Added by Front-Desk (lamby)
-  NOTE: 20260702: patches are under review (eamanu)
-  NOTE: 20260713: Still in review (eamanu)
-  NOTE: 20260808: mark CVE-2026-55200 and CVE-2026-55199 as not affected in bullseye
-  NOTE: 20260808: working in bookworm and in the new CVEs
-  NOTE: 20260809: bookworm and bullseye are ready, now will work on trixie-pu (eamanu)
-  NOTE: 20260812: asked to upstream for more information about CVE-2026-58051 and CVE-2026-58050 (eamanu)
-  NOTE: 20260821: patches ready, waiting for trixie-pu (eamanu)
---
-libstb/bullseye
-  NOTE: 20251206: Added by Front-Desk (rouca)
-  NOTE: 20251206: avoid regresion from buster (rouca/front-desk)
-  NOTE: 20251206: try to fix other CVEs and help with PU if needed (rouca/front-desk)
-  NOTE: 20260226: Fixed CVE-2021-28021 CVE-2021-37789 CVE-2021-42715 CVE-2022-28041 CVE-2022-28042 with DLA-4493-1 (abhijith)
-  NOTE: 20260429: Revisit when upstream merge the proposed fixes. Though other embed libstb projects patched (abhijith)
---
-libwebsockets/bookworm
+libwebsockets
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
 --
-libxslt/bullseye
-  NOTE: 20250930: Added by Front-Desk (rouca)
-  NOTE: 20251020: In progress, waiting for upstream action (guilhem)
-  NOTE: 20251104: Done, but waiting for upstream to merge before uploading and issuing the DLA (guilhem)
---
 linux (Ben Hutchings)
   NOTE: 20230111: Perma-added, Linux package specifically delegated to bwh (LTS Team)
 --
@@ -452,66 +355,35 @@ logback
   NOTE: 20260726: LTS too. Also fix the other postponed logback CVEs, and it
   NOTE: 20260726: should be fixed for trixie too (1.2.11-6 affected). (utkarsh/front-desk)
 --
-lrzip/bookworm
+lrzip
   NOTE: 20260725: Added by Front-Desk (utkarsh)
   NOTE: 20260725: CVE-2025-15570; fixed in bullseye via DLA-4567-1. bookworm
   NOTE: 20260725: 0.651-2 has the same UAF (thread_count guard absent); fix is
   NOTE: 20260725: upstream 96931e70 (0.660). Should be fixed for trixie too,
   NOTE: 20260725: which still ships an affected 0.651-3. (utkarsh/front-desk)
 --
-lxml
+lxml (guilhem)
   NOTE: 20260614: Added by Front-Desk (rouca)
 --
-mbedtls/bullseye
-  NOTE: 20260427: Added by Front-Desk (lamby)
-  NOTE: 20260531: bookworm EOL.
---
 mediawiki
   NOTE: 20260713: Added by Front-Desk (Beuc)
   NOTE: 20260713: Follow DSA-6380-1 (10 CVEs) (Beuc/front-desk)
 --
-memcached/bookworm
+memcached
   NOTE: 20260717: Added by Front-Desk (Beuc)
   NOTE: 20260717: Follow DLA-4601-1/bullseye (2 CVEs)
   NOTE: 20260717: Fix other postponed issues while we're at it (Beuc/front-desk)
 --
-mimetex/bullseye
-  NOTE: 20250422: Added by Front-Desk (rouca)
-  NOTE: 20250629: There doesn't seem to be a fix so far according to #1103801 (dleidert)
-  NOTE: 20250629: Best course of action seems to be some kind of mitigation similar to https://moodle.org/mod/forum/discuss.php?d=467592 (dleidert)
-  NOTE: 20260531: bookworm EOL.
---
 mistral
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
-mongo-c-driver/bullseye
-  NOTE: 20260522: Added by Front-Desk (Beuc)
-  NOTE: 20260522: Follow bookworm 12.14 (4+1 CVEs) (Beuc/front-desk)
---
-nagios4/bullseye
-  NOTE: 20260529: Added by Front-Desk (dleidert)
-  NOTE: 20260529: Follow recent upload of 4.4.6-4+deb12u1/4.4.6-4.1+deb13u1 (dleidert/front-desk)
---
-nagvis/bullseye
-  NOTE: 20250117: Added by Front-Desk (rouca)
-  NOTE: 20250119: Also check/fix https://bugs.debian.org/1061044
-  NOTE: 20250119: when testing your fix for bookworm. (bunk)
-  NOTE: 20250221: https://salsa.debian.org/lts-team/lts-updates-tasks/-/issues/193 (ah)
-  NOTE: 20250501: DLA released; but we really should discuss #193 and I'll maybe take it (dleidert)
-  NOTE: 20250625: To be clear, this package requires a PU for bookworm, to avoid upgrade regressions. (roberto)
-  NOTE: 20250629: Next DLA for 2 new issues has been released (dleidert)
-  NOTE: 20250629: PU is ready and will be tested before sending the PU request (dleidert)
---
-nats-server/bookworm
+nagios4
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
+nats-server
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
-netatalk/bullseye
-  NOTE: 20260518: Added by Front-Desk (Beuc)
-  NOTE: 20260518: DSA-6280-1 released fixing 20 patches for trixie.
-  NOTE: 20260518: ~low popcon, no sponsors, only fix if backporting the single
-  NOTE: 20260518: consolidated patch is straightforward enough (Beuc/front-desk)
---
 netty (rouca)
   NOTE: 20250814: Added by Front-Desk (lamby)
   NOTE: 20251115: Partial release for sid. Fix all CVEs except CVE-2025-58056 (rouca)
@@ -527,14 +399,14 @@ nginx (charles)
   NOTE: 20260618: There was also a customer request to fix it. (charles)
   NOTE: 20260630: Bullseye fix release with 2 CVE fixes + http2 bomb fix. Bookworm coming soon. (charles)
 --
-node-dompurify/bookworm
+node-dompurify
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
 --
 node-ip-address
   NOTE: 20260804: Added by Front-Desk (rouca)
 --
-node-lodash/bookworm (utkarsh)
+node-lodash (utkarsh)
   NOTE: 20260703: Added by Front-Desk (dleidert)
   NOTE: 20260703: Follow DLA 4663-1; assigned to Utkarsh to grab this (dleidert/front-desk)
 --
@@ -545,20 +417,13 @@ node-re2
 nodejs
   NOTE: 20260622: Added by Front-Desk (lamby)
 --
+nsd
+  NOTE: 20260904: Added by Front-Desk (pochu)
+--
 ntfs-3g
   NOTE: 20260716: Added by Front-Desk (Beuc)
   NOTE: 20260716: Follow DSA-6389-1 (9 CVEs) (Beuc/front-desk)
 --
-nvidia-cuda-toolkit/bullseye
-  NOTE: 20241004: Added by Front-Desk (Beuc)
---
-ocaml/bullseye
-  NOTE: 20260419: Added by Front-Desk (rouca)
---
-opam/bullseye
-  NOTE: 20260716: Added by Front-Desk (Beuc)
-  NOTE: 20260716: Follow DSA-6386-1 and DLA-4684-1 (1 CVE) (Beuc/front-desk)
---
 open-iscsi
   NOTE: 20260802: Added by Front-Desk (ta)
 --
@@ -592,19 +457,6 @@ openssl
   NOTE: 20260830: Another round of CVEs; follow DSA-6465-1 (dleidert/front-desk)
   NOTE: 20260830: For Bookworm, 3.0.22 should contain all fixes (dleidert/front-desk)
 --
-openvpn/bullseye
-  NOTE: 20260703: Added by Front-Desk (dleidert)
-  NOTE: 20260703: A regression has been reported; and a new set of CVEs is out (dleidert/front-desk)
-  NOTE: 20260706: The regression has been fixed. (dleidert)
-  NOTE: 20260731: The new CVEs require a more thorough examination. (dleidert)
---
-openvswitch/bullseye
-  NOTE: 20260405: Added by Front-Desk (ta)
-  NOTE: 20260422: Cf. OSPU (if approved) https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1133882 (Beuc)
---
-orthanc/bullseye
-  NOTE: 20260419: Added by Front-Desk (rouca)
---
 pacemaker
   NOTE: 20260618: Added by Front-Desk (charles)
   NOTE: 20260618: Package is in dsa-needed (charles)
@@ -631,9 +483,6 @@ pglogical
 php-dompdf
   NOTE: 20260804: Added by Front-Desk (rouca)
 --
-php-horde-imp/bullseye
-  NOTE: 20260714: Added by Front-Desk (Beuc)
---
 php-laravel-framework
   NOTE: 20250307: Added by Front-Desk (rouca)
   NOTE: 20251027: History of upstream branch fixing v12: git log 9de75259..2d133034^2.
@@ -643,15 +492,6 @@ php-laravel-framework
   NOTE: 20251027: tests is required to prevent regressions, but I could not get the upstream
   NOTE: 20251027: test suite to work. It is not exercised as part of Debian packages build. (paride)
 --
-php-twig/bullseye
-  NOTE: 20260521: Added by Front-Desk (Beuc)
-  NOTE: 20260521: Cf. symfony batch of CVEs, upcoming DSA (Beuc/front-desk)
---
-phpseclib/bullseye (Utkarsh)
-  NOTE: 20260518: Added by Front-Desk (Beuc)
-  NOTE: 20260518: Follow bookworm 12.14 (2 CVEs) (Beuc/front-desk)
-  NOTE: 20260720: will get back to this after releasing squid. (utkarsh)
---
 pipewire
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
@@ -661,11 +501,7 @@ proftpd-dfsg
   NOTE: 20260511: https://salsa.debian.org/debian-proftpd-team/proftpd/-/commits/bullseye
   NOTE: 20260715: Also add for bookworm; upcoming DSA (Beuc/front-desk)
 --
-prosody/bullseye
-  NOTE: 20260511: Added by Front-Desk (dleidert)
-  NOTE: 20260511: Follow DSA 6252-1 fixing 4 CVEs (dleidert/front-desk)
---
-puma
+puma (Abhijith PA)
   NOTE: 20260804: Added by Front-Desk (rouca)
 --
 py7zr
@@ -676,10 +512,6 @@ pyasn1 (eamanu)
   NOTE: 20260802: Added by Front-Desk (ta)
   NOTE: 20260825: patches for bookworm and bullseye are ready, waiting for trixie-pu being accepted (eamanu)
 --
-pypdf2/bullseye (dleidert)
-  NOTE: 20260328: Added by Front-Desk (Beuc)
-  NOTE: 20260328: 6 new CVEs, and lots of postponed issues piled-up (Beuc/front-desk)
---
 python-aiohttp (dleidert)
   NOTE: 20260611: Added by Front-Desk (rouca)
   NOTE: 20260602: Daniel Leidert is proposing to work on the update and provide debdiffs for bookworm and trixie (carnil)
@@ -690,11 +522,11 @@ python-asyncssh
 python-cryptography
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
-python-eventlet/bookworm
+python-eventlet
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
 --
-python-geopandas/bookworm
+python-geopandas
   NOTE: 20260725: Added by Front-Desk (utkarsh)
   NOTE: 20260725: CVE-2025-69662; fixed in bullseye via DLA-4523-1. bookworm
   NOTE: 20260725: 0.12.2-1 still builds the Find_SRID query with .format(); fix
@@ -702,7 +534,7 @@ python-geopandas/bookworm
   NOTE: 20260725: Should be fixed for trixie too, which still ships an
   NOTE: 20260725: affected 1.0.1-2. (utkarsh/front-desk)
 --
-python-git
+python-git (eamanu)
   NOTE: 20260726: Added by Front-Desk (utkarsh)
   NOTE: 20260726: CVE-2026-42215 bypasses the check_unsafe_options guard
   NOTE: 20260726: that DLA-3939-1 itself backported, so our own earlier fix
@@ -722,9 +554,6 @@ python-msgpack
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: CVE-2026-57585 (fixed 1.2.1; <=1.2.0 affected); Debian 1.0.x.
 --
-python-oslo.messaging/bullseye
-  NOTE: 20260612: Added by Front-Desk (rouca)
---
 python-tornado
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: See also https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/322 (Beuc/front-desk)
@@ -740,21 +569,14 @@ qemu
   NOTE: 20260520: Also SPU/OSPU included a rebuild with updated glibc/glib2.0 (Beuc/front-desk)
   NOTE: 20260713: New SPU/OSPU included a rebuild with updated gnutls28 (Beuc/front-desk)
 --
-qtsvg-opensource-src/bullseye
-  NOTE: 20260522: Added by Front-Desk (Beuc)
-  NOTE: 20260522: Many postponed CVEs piled up (Beuc/front-desk)
---
-rabbitmq-server/bullseye
-  NOTE: 20260504: Added by coordinator (santiago)
-  NOTE: 20260504: Added to address out-standing minor issues
+rabbitmq-server
+  NOTE: 20260904: Added by Front-Desk (pochu)
 --
 rails
   NOTE: 20260805: Added by Front-Desk (rouca)
 --
-request-tracker4/bullseye (Andrew Ruthven)
-  NOTE: 20260529: Added by Front-Desk (dleidert)
-  NOTE: 20260529: Follow DSA in preparation by maintainer (dleidert/front-desk)
-  NOTE: 20260607: Andrew Ruthven (maintainer) is working on a DLA.
+redis
+  NOTE: 20260904: Added by Front-Desk (pochu)
 --
 rsync (Thorsten Alteholz)
   NOTE: 20260615: Added by Front-Desk (charles)
@@ -771,14 +593,7 @@ ruby-oj
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: Oj JSON parser memory-safety batch CVE-2026-54500..54903 (GHSA); affects 2.17-3.14.
 --
-ruby2.7/bullseye (Abhijith PA)
-  NOTE: 20260419: Added by Front-Desk (rouca)
-  NOTE: 20260608: https://people.debian.org/~abhijith/upload/ruby2.7_patches/ (abhijith)
-  NOTE: 20260731: Prepared an upload with already triaged issues. Group Net::IMAP issues
-  NOTE: 20260731: and do upload later (abhijith)
-  NOTE: 20260804: Uploaded 2.7.4-1+deb11u6 and released DLA-4716-1 (abhijith)
---
-ruby3.1/bookworm
+ruby3.1
   NOTE: 20260713: Added by Front-Desk (Beuc)
   NOTE: 20260523: Bumping to new upstream rejected by SRM, do backport patches:
   NOTE: 20260523: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1103854
@@ -799,13 +614,6 @@ runc
   NOTE: 20260223: Updated #1120140 with some thoughts, asking for more opinions (kanashiro)
   NOTE: 20260706: Please handle Bookworm as well (dleidert/front-desk)
 --
-rust-openssl/bullseye
-  NOTE: 20250209: Added by Front-Desk (apo)
-  NOTE: 20251107: Re-add as binNMUs are not all properly Installed in the archive:
-  NOTE: 20251107: https://buildd.debian.org/status/package.php?p=rust-condure&suite=bullseye-security
-  NOTE: 20251107: https://buildd.debian.org/status/package.php?p=rust-debcargo&suite=bullseye-security
-  NOTE: 20251107: Please coordinate with FTP masters to unblock the situation (Beuc/front-desk)
---
 sabnzbdplus
   NOTE: 20260830: Added by Front-Desk (dleidert)
   NOTE: 20260830: Follow DSA 6454-1 (dleidert/front-desk)
@@ -829,10 +637,6 @@ shiro
   NOTE: 20260726: Should be fixed for trixie too, which ships the same
   NOTE: 20260726: affected 1.3.2. (utkarsh/front-desk)
 --
-smb4k/bullseye
-  NOTE: 20251217: Added by Front-Desk (pochu)
-  NOTE: 20260531: bookworm EOL.
---
 snapd
   NOTE: 20260324: Added by Front-Desk (Beuc)
   NOTE: 20260324: See DSA-6170-1 (root LPE) (Beuc/front-desk)
@@ -849,12 +653,8 @@ snapd
   NOTE: 20260726: in 2.71-1. Entry was bullseye-only as bookworm was not yet
   NOTE: 20260726: LTS when it was filed in 2026-03. (utkarsh/front-desk)
 --
-spip/bullseye
-  NOTE: 20260220: Added by Front-Desk (rouca)
-  NOTE: 20260326: EOL candidate? Many issues pile-up, 3.2 EOL'd upstream,
-  NOTE: 20260326: not in bookworm, trixie updated through upstream 4.4 LTS releases,
-  NOTE: 20260326: very low popcon (Beuc/front-desk)
-  NOTE: 20260422: https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/342
+sogo
+  NOTE: 20260904: Added by Front-Desk (pochu)
 --
 srt
   NOTE: 20260809: Added by Front-Desk (rouca)
@@ -864,12 +664,8 @@ sssd
   NOTE: 20260804: Crash or DoS of sssd may lead to user lockdown (rouca/FD)
   NOTE: 20260804: SSSD should be tested carefully, with integration test (rouca/FD)
 --
-strongswan/bullseye
-  NOTE: 20260423: Added by Front-Desk (pochu)
---
-suricata/bullseye
-  NOTE: 20250331: re added to fix next bunch of CVEs (ta)
-  NOTE: 20250825: testing package (ta)
+strongswan
+  NOTE: 20260907: Added by Front-Desk (eamanu)
 --
 suricata-update
   NOTE: 20260830: Added by Front-Desk (dleidert)
@@ -887,40 +683,15 @@ swift
   NOTE: 20260819: Maintainer uploaded 2.30.1-0+deb12u2 fixing CVE-2026-50221
   NOTE: 20260819: and CVE-2026-71190. (charles)
 --
-symfony/bullseye
-  NOTE: 20260521: Added by Front-Desk (Beuc)
-  NOTE: 20260521: >20 CVEs disclosed, 10 not-affected,
-  NOTE: 20260521: at least 1 SQLI and 1 stored XSS.
-  NOTE: 20260521: Upcoming DSA (Beuc/front-desk)
---
-tiff
+tiff (eamanu)
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: CVE-2026-12912 (fixed 4.7.2rc2) + CVE-2026-36849 (read-buffer alloc);
   NOTE: 20260709: read-path, both suites.
 --
-tomcat10/bookworm
+tomcat10
   NOTE: 20260714: Added by Front-Desk (Beuc)
   NOTE: 20260714: Upcoming DSA (Beuc/front-desk)
 --
-tomcat9/bullseye
-  NOTE: 20260714: Added by Front-Desk (Beuc)
-  NOTE: 20260714: bookworm/9.0.70-2 is a stripped-down version and marks most CVEs as fixed.
-  NOTE: 20260714: Unfortunately we now ship 9.0.118 in bullseye, which breaks upgrades,
-  NOTE: 20260714: and also makes the tracker believe everything is fixed
-  NOTE: 20260714: (as bullseye is now > 9.0.70-2). Check carefully.
-  NOTE: 20260714: Upcoming DSA for tomcat10 (Beuc/front-desk)
---
-trafficserver/bullseye
-  NOTE: 20241120: Added by Front-Desk (Beuc)
-  NOTE: 20241120: Upcoming DSA (Beuc/front-desk)
-  NOTE: 20241203: Upstream announcement does not mention 8.1 for any of the 3 CVEs.
-  NOTE: 20241203: AFAIR upstream 8.1 support ended with the release of 10.0 (bunk)
-  NOTE: 20250216: DLA released fixing CVE-2024-38479 and CVE-2024-50306 (dleidert)
-  NOTE: 20250216: IMHO CVE-2024-50305 does not affect 8.x due to affected code being introduced later (dleidert)
-  NOTE: 20250216: Bookworm-PU necessary, but issues not fixed in Sid yet; contacted maintainer (dleidert)
-  NOTE: 20250403: There are multiple new CVEs. But none of them is addresses in Sid and maintainers didn't reply to me last time (dleidert)
-  NOTE: 20250405: DSA 5896-1 is out (Beuc/front-desk)
---
 u-boot
   NOTE: 20260804: Added by Front-Desk (rouca)
 --
@@ -929,10 +700,6 @@ unbound
   NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
   NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
 --
-uriparser/bullseye
-  NOTE: 20260519: Added by Front-Desk (Beuc)
-  NOTE: 20260519: Many postponed CVEs piled-up (Beuc/front-desk)
---
 urwid
   NOTE: 20260802: Added by Front-Desk (ta)
   NOTE: 20260802: not the same code but the same reasoning (ta)
@@ -954,16 +721,8 @@ vips
   NOTE: 20260812: Four news CVEs published, already in dsa-needed, sync with
   NOTE: 20260812: secteam or follow DSA.  (charles/front-desk)
 --
-vitrage/bullseye
-  NOTE: 20260419: Added by Front-Desk. Get in touch with zigo/upstream before (rouca)
-  NOTE: 20260419: CVE-2026-28370 is RCE
---
-watcher/bullseye
-  NOTE: 20250908: Added by Front-Desk (apo)
-  NOTE: 20250908: See also nova. (apo)
-  NOTE: 20251023: See notes <aPqc5NoWRLG3jKLw at isildor2.loewenhoehle.ip>
-  NOTE: 20251027: Maintainer contacted (tobi)
-  NOTE: 20251106: Part of OpenStack (Beuc/front-desk)
+weechat
+  NOTE: 20260904: Added by Front-Desk (pochu)
 --
 wireshark
   NOTE: 20260430: Added by Front-Desk (lamby)
@@ -972,27 +731,13 @@ wireshark
 wordpress
   NOTE: 20260807: Added by Front-Desk. Follow DSA (rouca)
 --
-xen/bookworm
+xen
   NOTE: 20260714: Added by Front-Desk (Beuc)
   NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie (Beuc/front-desk)
 --
-xmlrpc-c/bullseye
-  NOTE: 20250411: Added by Front-Desk (Beuc)
-  NOTE: 20250411: See issues with old embedded expat library:
-  NOTE: 20250411: https://www.openwall.com/lists/oss-security/2025/04/09/4
-  NOTE: 20250411: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1102554
-  NOTE: 20250413: General options investigated, posted to the bug and debian-lts (bunk)
-  NOTE: 20250705: See also libxmltok above, a similarly old expat version.
-  NOTE: 20250705: Ping'd secteam asking for current bookworm plans. (Beuc)
-  NOTE: 20250705: https://lists.debian.org/debian-lts/2025/07/msg00006.html
---
 xorg-server
   NOTE: 20260818: Added by Front-Desk (lamby)
 --
-zabbix/bullseye
-  NOTE: 20260328: Added by Front-Desk (Beuc)
-  NOTE: 20260328: CVE-2026-23919->24 appear to be in supported scope (Beuc/front-desk)
---
 zfs-linux
   NOTE: 20260830: Added by Front-Desk (dleidert)
   NOTE: 20260830: Follow DSA-6462-1 (dleidert/front-desk)


=====================================
data/dsa-needed.txt
=====================================
@@ -26,8 +26,6 @@ bouncycastle
 cacti
   probably best to move to 1.2.31
 --
-chromium (dilinger)
---
 containerd
 --
 cups
@@ -36,6 +34,10 @@ dovecot
 --
 dulwich
 --
+emacs (jmm)
+--
+erlang
+--
 firebird3.0
 --
 firebird4.0
@@ -44,8 +46,9 @@ fort-validator (jmm)
   Maintainer preparing update
 --
 gegl (jmm)
+  move to 0.4.72
 --
-gst-plugins-base1.0
+gst-plugins-base1.0 (jmm)
 --
 gst-plugins-good1.0
 --
@@ -55,6 +58,8 @@ jetty9
 --
 jetty12
 --
+jpeg-xl (jmm)
+--
 jq (aron)
   For regression in #1144075
 --
@@ -62,15 +67,13 @@ jupyterlab
 --
 kamailio
 --
-keystone (jmm)
---
 kitty
 --
 libapache2-mod-auth-openidc (jmm)
 --
-libde265 (jmm)
+libevent (aron)
 --
-libevent
+libheif (aron)
 --
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
@@ -87,9 +90,6 @@ netatalk
 --
 netty
 --
-nginx (aron)
-  Maintainer is working on updates
---
 nodejs
   Bastien Roucaries will work on updates
 --
@@ -104,9 +104,6 @@ pacemaker
 pdfminer (carnil)
   Required followup for CVE-2025-64512 as original fix was incomplete.
 --
-perl (carnil)
-  Comment from maintainer: I'd prefer to wait until upstream gets the point releases out
---
 podman
 --
 prometheus
@@ -119,6 +116,7 @@ python-authlib
 python-django
 --
 python-git
+  Emmanuel Arias is proposing to prepare an update for open issues
 --
 python-msgpack
   Problems with autopkgtests, maintainer pinged and waiting for feedback
@@ -129,6 +127,8 @@ rails
 --
 redis
 --
+roundcube (carnil)
+--
 rsync
   for regression fixes and new batch of CVEs, Samuel Henrique working on updates, likely to move to 3.5.0
 --
@@ -139,7 +139,7 @@ ruby3.3
 --
 ruby-oj
 --
-ruby-rack
+ruby-rack (jmm)
 --
 ruby-rack-session
 --
@@ -152,9 +152,13 @@ sabnzbdplus
 --
 shaarli
 --
+slurm-wlm (aron)
+--
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --
+spip (carnil)
+--
 tomcat10
 --
 tomcat11
@@ -162,6 +166,8 @@ tomcat11
 unbound
   Michael Tokarev is working on rebasing to 1.25.2 (possibly 1.26.0)
 --
+valkey
+--
 vim
   some of the issues seem worth fixing
   Lee Garrett is interested in contributing an update for stable
@@ -173,5 +179,7 @@ weechat
 --
 wordpress
 --
-xorg-server
+xorg-server (carnil)
+--
+zlib
 --


=====================================
data/next-point-update.txt
=====================================
@@ -270,6 +270,12 @@ CVE-2026-54279
 	[trixie] - python-aiohttp 3.11.16-1+deb13u2
 CVE-2026-54280
 	[trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-59881
+	[trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-69243
+	[trixie] - python-aiohttp 3.11.16-1+deb13u2
+CVE-2026-69244
+	[trixie] - python-aiohttp 3.11.16-1+deb13u2
 CVE-2025-68276
 	[trixie] - avahi 0.8-18~deb13u1
 CVE-2025-68468
@@ -420,6 +426,8 @@ CVE-2026-59947
 	[trixie] - composer 2.8.8-1+deb13u4
 CVE-2026-59944
 	[trixie] - composer 2.8.8-1+deb13u4
+CVE-2026-84361
+	[trixie] - composer 2.8.8-1+deb13u4
 CVE-2026-81523
 	[trixie] - libmongocrypt 1.13.2-1+deb13u1
 CVE-2026-81524
@@ -494,3 +502,143 @@ CVE-2026-40253
 	[trixie] - opencryptoki 3.23.0+dfsg-0.3+deb13u1
 CVE-2026-23893
 	[trixie] - opencryptoki 3.23.0+dfsg-0.3+deb13u1
+CVE-2026-58264
+	[trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
+CVE-2026-61714
+	[trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
+CVE-2026-7017
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-42496
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-42497
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-12087
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-13221
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2025-15649
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-7010
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-8376
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-48959
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-48961
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-48962
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-57432
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-57433
+	[trixie] - perl 5.40.1-6+deb13u1
+CVE-2026-14191
+	[trixie] - unrar-nonfree 1:7.1.8-1+deb13u1
+CVE-2026-7010
+	[trixie] - libhttp-tiny-perl 0.090-1+deb13u1
+CVE-2026-7017
+	[trixie] - libhttp-tiny-perl 0.090-1+deb13u1
+CVE-2025-15649
+	[trixie] - libio-compress-perl 2.213-1+deb13u1
+CVE-2026-48959
+	[trixie] - libio-compress-perl 2.213-1+deb13u1
+CVE-2026-48961
+	[trixie] - libio-compress-perl 2.213-1+deb13u1
+CVE-2026-48962
+	[trixie] - libio-compress-perl 2.213-1+deb13u1
+CVE-2026-12087
+	[trixie] - libsocket-perl 2.038-1+deb13u1
+CVE-2026-44517
+	[trixie] - golang-github-containers-buildah 1.39.3+ds1-1+deb13u1
+CVE-2026-12725
+	[trixie] - dnsmasq 2.91-1+deb13u2
+CVE-2026-12969
+	[trixie] - dnsmasq 2.91-1+deb13u2
+CVE-2026-XXXX [GHSA-fmgr-6ggq-9859: PCRE2: integer overflow in pcre2_compile_32() causes out-of-bounds write on 32-bit systems]
+	[trixie] - pcre2 10.46-1~deb13u2
+CVE-2026-XXXX [GHSA-9qww-pwc4-77qq: PCRE2: out-of-bounds reads in pcre2_match() when matching invalid UTF subjects with PCRE2_MATCH_INVALID_UTF]
+	[trixie] - pcre2 10.46-1~deb13u2
+CVE-2026-86145 [GHSA-q8g2-wprr-34m9: PCRE2: out-of-bounds write in pcre2_pattern_convert() with large patterns on 32-bit systems]
+	[trixie] - pcre2 10.46-1~deb13u2
+CVE-2026-XXXX [GHSA-3r4p-g7gg-ppmf: out-of-bounds write in pcre2_dfa_match() with recursive patterns under a low heap limit]
+	[trixie] - pcre2 10.46-1~deb13u2
+CVE-2026-XXXX [GHSA-2p8c-ff85-vh9x: PCRE2: out-of-bounds read in pcre2_match() after JIT fallback with invalid UTF]
+	[trixie] - pcre2 10.46-1~deb13u2
+CVE-2026-81500
+	[trixie] - incus 6.0.4-2+deb13u10
+CVE-2026-81501
+	[trixie] - incus 6.0.4-2+deb13u10
+CVE-2026-38978
+	[trixie] - transmission 4.1.0~beta2+dfsg-3+deb13u2
+CVE-2026-8286
+	[trixie] - curl 8.14.1-2+deb13u6
+CVE-2026-8924
+	[trixie] - curl 8.14.1-2+deb13u6
+CVE-2026-8927
+	[trixie] - curl 8.14.1-2+deb13u6
+CVE-2026-56434
+	[trixie] - nginx 1.26.3-3+deb13u8
+CVE-2026-60005
+	[trixie] - nginx 1.26.3-3+deb13u8
+CVE-2026-42533
+	[trixie] - nginx 1.26.3-3+deb13u8
+CVE-2026-56123
+	[trixie] - socat 1.8.0.3-1+deb13u1
+CVE-2026-32748
+	[trixie] - squid 6.13-2+deb13u3
+CVE-2026-13401
+	[trixie] - libxml-bare-perl 0.53-4+deb13u1
+CVE-2026-57074
+	[trixie] - libxml-bare-perl 0.53-4+deb13u1
+CVE-2026-77781
+	[trixie] - libtie-hash-regex-perl 1.14-3~deb13u1
+CVE-2026-20031
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20217
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20213
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20216
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20214
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20243
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20215
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20244
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20345
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20339
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20346
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20347
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-20348
+	[trixie] - clamav 1.4.6+dfsg-1~deb13u1
+CVE-2026-63676
+	[trixie] - libyaml-perl 1.31-1+deb13u1
+CVE-2026-81928
+	[trixie] - libnet-dns-perl 1.57-0+deb13u1
+CVE-2026-5090
+	[trixie] - libtemplate-perl 2.27-1+deb13u1
+CVE-2022-4993
+	[trixie] - libhtml-formhandler-perl 0.40068-3~deb13u1
+CVE-2025-11561
+	[trixie] - sssd 2.10.1-2+deb13u1
+CVE-2026-6245
+	[trixie] - sssd 2.10.1-2+deb13u1
+CVE-2026-12610
+	[trixie] - sssd 2.10.1-2+deb13u1
+CVE-2026-14474
+	[trixie] - sssd 2.10.1-2+deb13u1
+CVE-2026-14476
+	[trixie] - sssd 2.10.1-2+deb13u1
+CVE-2026-68742
+	[trixie] - sssd 2.10.1-2+deb13u1
+CVE-2026-68743
+	[trixie] - sssd 2.10.1-2+deb13u1
+CVE-2026-68744
+	[trixie] - sssd 2.10.1-2+deb13u1


=====================================
data/packages/nfu.yaml
=====================================
@@ -83,6 +83,8 @@
   cna: CrowdStrike
 - reason: Dahua
   cna: dahua
+- reason: Delinea
+  cna: Delinea
 - reason: Dell / EMC
   cna: dell
 - reason: Delta Electronics
@@ -97,6 +99,8 @@
   cna: drupal
 - reason: Eaton
   cna: Eaton
+- reason: Elastic
+  cna: elastic
 - reason: Everpure
   cna: Everpure
 - reason: Ericsson
@@ -125,6 +129,8 @@
   cna: GitHub_P
 - reason: Google devices
   cna: Google_Devices
+- reason: Grafana
+  cna: GRAFANA
 - reason: Hanwha Vision
   cna: Hanwha_Vision
 - reason: HCL
@@ -211,6 +217,8 @@
   cna: ProgressSoftware
 - reason: Proofpoint
   cna: Proofpoint
+- reason: OpenAI
+  cna: OAI
 - reason: OMRON
   cna: OMRON
 - reason: OpenHarmony
@@ -421,6 +429,11 @@
       - product: Check Point SmartConsole
       - product: Identity Agent
       - product: Identity Awareness
+- reason: Checkmk
+  allOf:
+    - cna: Checkmk
+    - anyOf:
+      - product: Checkmk
 - reason: Cisco
   allOf:
     - cna: cisco
@@ -446,6 +459,7 @@
       - product: Cisco Nexus Dashboard
       - product: Cisco Prime Infrastructure
       - product: Cisco RoomOS Software
+      - product: Cisco Secure Email
       - product: Cisco Secure Firewall Adaptive Security Appliance (ASA) Software
       - product: Cisco Secure Firewall Threat Defense (FTD) Software
       - product: Cisco Secure Network Analytics
@@ -467,6 +481,7 @@
     - cna: eclipse
     - anyOf:
       - product: Eclipse 4diac
+      - product: Eclipse Arrowhead
       - product: Eclipse BaSyx
       - product: Eclipse BaSyx Go Components
       - product: Eclipse CSI - PIA
@@ -493,11 +508,6 @@
       - product: ThreadX
       - product: USBX
       - product: Vert.x
-- reason: Elasticsearch
-  allOf:
-    - cna: elastic
-    - anyOf:
-      - product: Elasticsearch
 - reason: Esri
   allOf:
     - cna: Esri
@@ -517,6 +527,7 @@
       - product: F5 BIG-IP Container Ingress Services
       - product: F5OS - Appliance
       - product: F5OS - Chassis
+      - product: NGINX Gateway Fabric
       - product: NGINX Ingress Controller
 - reason: Fortra
   allOf:
@@ -535,14 +546,6 @@
     - cna: Google
     - anyOf:
       - product: Gemini
-- reason: Grafana Labs
-  allOf:
-    - cna: GRAFANA
-    - anyOf:
-      - product: Grafana
-      - product: Grafana Enterprise
-      - product: Grafana OSS
-      - product: Snowflake Datasource
 - reason: Hashicorp products not packaged in Debian
   allOf:
     - cna: HashiCorp
@@ -607,6 +610,7 @@
       - product: Isaac Launchable
       - product: KAI Scheduler
       - product: Megatron LM
+      - product: Megatron Bridge
       - product: Megatron-Bridge
       - product: Megatron-LM
       - product: Merlin Transformers4Rec
@@ -830,6 +834,7 @@
       - product: Cloud Foundry
       - product: Micrometer
       - product: Pinniped
+      - product: Reactor Core
       - product: Reactor Netty
       - product: Spring AI
       - product: Spring AMQP
@@ -843,6 +848,7 @@
       - product: Spring Cloud Sleuth
       - product: Spring Cloud Stream
       - product: Spring Data Commons
+      - product: Spring Data JPA
       - product: Spring Data KeyValue
       - product: Spring Data MongoDB
       - product: Spring Data REST
@@ -852,6 +858,7 @@
       - product: Spring LDAP
       - product: Spring REST Docs
       - product: Spring Retry
+      - product: Spring Security
       - product: Spring Statemachine
       - product: Spring Tools for Eclipse
       - product: Spring Web Flow


=====================================
data/packages/removed-packages
=====================================
@@ -1096,3 +1096,74 @@ gypsy
 gitlab
 golang-github-sigstore-cosign-v2
 mysql-8.0
+android-platform-dalvik
+at-spi2-atk
+cowbell
+cryptcat
+debian-lan-config
+dhis-tools-dns
+dpkg-sig
+empathy
+enigmail
+exfat-utils
+ez-ipupdate
+fam
+flexbackup
+freelan
+gcc-10
+gcc-9
+geneweb
+gfbgraph
+gnome-desktop3
+gnu-smalltalk
+golang-github-appc-docker2aci
+guacamole-server
+hardlink
+havp
+https-everywhere
+ksh
+latd
+ldb
+libapache-mod-auth-radius
+libapache2-mod-auth-openid
+libnfsidmap
+libnss-ldap
+libpam-ldap
+libzapojit
+linux-6.1
+lua50
+lurker
+microcode.ctl
+midori
+monkeysphere
+myspell
+netcf
+netkit-ftp
+netkit-telnet
+ninka
+nuitka
+ogre-1.9
+photoflow
+php-doctrine-bundle
+php-radius
+php-xajax
+postgresql-multicorn
+prayer
+prboom-plus
+pypy
+pysha3
+python-defaults
+roaraudio
+ruby-omniauth-auth0
+rust-lock-api-0.1
+sanitizer
+sgml2x
+sleekxmpp
+steam
+tangerine
+transifex-client
+webauth
+wesnoth-1.14
+xcal
+xfstt
+xqilla


=====================================
doc/DLA.template
=====================================
@@ -9,15 +9,12 @@ $SPACEDDATE                        https://wiki.debian.org/LTS
 -------------------------------------------------------------------------
 
 Package        : $PACKAGE
-Version        : $bullseye_VERSION $bookworm_VERSION
+Version        : $bookworm_VERSION
 CVE ID         : $CVE
 Debian Bug     : $BUGNUM
 
 $TEXT
 
-For Debian 11 bullseye, this problem has been fixed in version
-$bullseye_VERSION.
-
 For Debian 12 bookworm, this problem has been fixed in version
 $bookworm_VERSION.
 


=====================================
static/distributions.json
=====================================
@@ -21,8 +21,8 @@
   },
   "bullseye": {
     "major-version": "11",
-    "support": "lts",
-    "contact": "debian-lts at lists.debian.org"
+    "support": "end-of-life",
+    "contact": ""
   },
   "bookworm": {
     "major-version": "12",



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2c2131e1bfe14048b08a5174e748622619f11d97...e8083a3e0ab76b2b54aceb190572f86066e1d084

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/2c2131e1bfe14048b08a5174e748622619f11d97...e8083a3e0ab76b2b54aceb190572f86066e1d084
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/23e40da2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list