[Git][security-tracker-team/security-tracker][master] 3 commits: dla-needed: add tor

Emmanuel Arias (@eamanu) eamanu at debian.org
Thu Sep 10 19:36:20 BST 2026



Emmanuel Arias pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7fe8b2a5 by Emmanuel Arias at 2026-09-10T15:04:54-03:00
dla-needed: add tor

- - - - -
d8cd3edd by Emmanuel Arias at 2026-09-10T15:20:26-03:00
dla-needed: add zlib

- - - - -
608ca83e by Emmanuel Arias at 2026-09-10T15:36:04-03:00
CVE-2026-78323: mark as postponed for bookworm

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -18876,6 +18876,7 @@ CVE-2026-78329 (Improper input validation vulnerability in Apache Camel Undertow
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78323 (A flaw was found in JSS (Java Security Services). The JSSTrustManager  ...)
 	- jss <unfixed> (bug #1145877)
+	[bookworm] - jss <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2521775
 	NOTE: Fixed by: https://github.com/dogtagpki/jss/commit/cffadbb2b53157014bc2ffb46d5a8fd4979623d1 (master)
 CVE-2026-78321 (The HTTP media server on DJI drones does not enforce sufficient limits ...)


=====================================
data/dla-needed.txt
=====================================
@@ -694,6 +694,9 @@ tomcat10
   NOTE: 20260714: Added by Front-Desk (Beuc)
   NOTE: 20260714: Upcoming DSA (Beuc/front-desk)
 --
+tor
+  NOTE: 20260910: Added by Front-Desk (eamanu)
+--
 tryton-server
   NOTE: 20260909: Added by Front-Desk (eamanu)
 --
@@ -750,3 +753,7 @@ zfs-linux
 zip
   NOTE: 20260809: Added by Front-Desk. Track #1143866 (rouca)
 --
+zlib
+  NOTE: 20260910: Added by Front-Desk (eamanu)
+  NOTE: 20260910: New CVE without activity from upstream yet (eamanu)
+--



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/89663f330fdbae5a3939c4b721952f2f2a5123c9...608ca83ec5f8d58a7fd82a6da0fd9363f56e000d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/89663f330fdbae5a3939c4b721952f2f2a5123c9...608ca83ec5f8d58a7fd82a6da0fd9363f56e000d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260910/93c1d7a5/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list