[Git][security-tracker-team/security-tracker][master] 2 commits: Merge changes for updates with CVEs via trixie 13.7
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 12 08:21:27 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5458a020 by Salvatore Bonaccorso at 2026-09-12T08:12:40+02:00
Merge changes for updates with CVEs via trixie 13.7
- - - - -
4b2a32ed by Salvatore Bonaccorso at 2026-09-12T09:21:19+02:00
Merge branch 'trixie-13.7' into 'master'
Merge changes for updates with CVEs via trixie 13.7
See merge request security-tracker-team/security-tracker!328
- - - - -
2 changed files:
- data/CVE/list
- data/next-point-update.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -2101,14 +2101,14 @@ CVE-2026-89169 (live-boot ff8867c allows attackers to bypass the dm-verity-enfor
NOTE: In Debian context options are unused
CVE-2026-89162 (In PCRE2 before 10.48, pcre2_serialize_encode might disclose two bytes ...)
- pcre2 10.48-1
- [trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - pcre2 10.46-1~deb13u2
[bookworm] - pcre2 <not-affected> (Vulnerable code not present)
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q7rw-r7qq-2hx6
NOTE: https://github.com/PCRE2Project/pcre2/commit/edc111a6831591f68b5355a08cc9df8be8f35304 (pcre2-10.48-RC1)
CVE-2026-89161 (In PCRE2 before 10.48, pcre2_jit_match mishandles a previously copied ...)
{DLA-4772-1}
- pcre2 10.48-1
- [trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - pcre2 10.46-1~deb13u2
NOTE: https://github.com/PCRE2Project/pcre2/pull/937
NOTE: https://github.com/PCRE2Project/pcre2/commit/1dcd0cf42a6a7cb62cc9a7c024196733abcfda95 (pcre2-10.48-RC1)
CVE-2026-89151 (Forgejo before 16.0.4 allows use of restricted API tokens for unintend ...)
@@ -14430,31 +14430,31 @@ CVE-2023-31308 (A malicious virtual function can invoke the certain command hand
CVE-2026-89158 (PCRE2 before 10.48, on 32-bit platforms, has a pcre2_compile_32 intege ...)
{DLA-4772-1}
- pcre2 10.48-1
- [trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - pcre2 10.46-1~deb13u2
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-fmgr-6ggq-9859
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/ec9c286d5c10cf1c388b58a442ccefded42254fd (pcre2-10.48)
CVE-2026-89160 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read during the PCR ...)
{DLA-4772-1}
- pcre2 10.48-1
- [trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - pcre2 10.46-1~deb13u2
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-9qww-pwc4-77qq
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/4889caf31a4c5a6b3c051f0031bf2dbd78f2c287 (pcre2-10.48)
CVE-2026-89157 (PCRE2 before 10.48, on 32-bit platforms, has a pcre2_pattern_convert o ...)
{DLA-4772-1}
- pcre2 10.48-1
- [trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - pcre2 10.46-1~deb13u2
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-q8g2-wprr-34m9
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/8156b3989a82f2ddf9504d8248496e9b124be7f3 (pcre2-10.48-RC1)
CVE-2026-86145 (PCRE2 before 10.48 allows a pcre2_dfa_match out-of-bounds write becaus ...)
{DLA-4772-1}
- pcre2 10.48-1
- [trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - pcre2 10.46-1~deb13u2
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-3r4p-g7gg-ppmf
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/c932e70451eafef922ebef364ac25042f0031135 (pcre2-10.48)
CVE-2026-89156 (PCRE2 before 10.48 has a pcre2_match out-of-bounds read after a JIT fa ...)
{DLA-4772-1}
- pcre2 10.48-1
- [trixie] - pcre2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - pcre2 10.46-1~deb13u2
NOTE: https://github.com/PCRE2Project/pcre2/security/advisories/GHSA-2p8c-ff85-vh9x
NOTE: Fixed by: https://github.com/PCRE2Project/pcre2/commit/f67db227af31bba7cdf2a7a00b97af91b588c2f5 pcre2-10.48-RC1)
CVE-2026-57227 [mqtt: unbounded number of messages per tx]
@@ -14910,123 +14910,123 @@ CVE-2026-40463 (WaveSuite is affected by an insufficient role-based access contr
NOT-FOR-US: Nokia
CVE-2026-18054
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/1f24066fc88d33455ee54a20f29994d9e69997ba (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/5fbd2fe1cc54259d045d00d4966aa2db1ba990d6 (v11.0.4)
CVE-2026-15264
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a113e0c53fb50d78529fd5ea79e3b8313a7ddcaa (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/7cd760867bdf753ac8d41c9567a1d36eb6d7aee8 (v11.0.4)
CVE-2026-17516
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4085
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/95687639e647ec917226e6d3a6713a2b373e1ffe (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/3ecb483c4c727d382b856c70f47ff54a68ce2bf5 (v11.0.4)
CVE-2026-65928
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3846
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/370882d0869567e5f21b95229a763171e319d0db (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e00b9c9193de00f5782cb919d91eb80d255017fe (v11.0.4)
CVE-2026-65929
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3844
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/0c43f801c0d7a31ef05bc22914cca0b0e28210a8 (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/ffe6640f445cf27513627e9295fa3de23b000261 (v11.0.4)
CVE-2026-50624
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3917
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/0be94d8d9c28e6b7235b34133d057090fe93be6c (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/88a0e5e45b41d407cf9adf1f2cf6f20f394a578d (v11.0.4)
CVE-2026-66022
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4073
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/df12999cc81339ffb252875608919c72ccc37bcd (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/5b105521527ec01dc7cf2f3834ddef935ab127f0 (v11.0.4)
CVE-2026-61402
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/733a98a552e4bd68932de1f58bd6ea39b57b261c (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6680c5612401c1eaa49eba134d14d374fefeb9d4 (v11.0.4)
CVE-2026-63110
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/b9d248dfaca5e31377ea4f7204aae788a050bafd (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/82520d7759557062a5fae2211e3c79bbd5f01ed3 (v11.0.4)
CVE-2026-63323
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3938
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/5cc182ba39a3ca8ec9ba0576de9696be76dc087d (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a7f027cff81c8047707d574f0e4ec57e66c63452 (v11.0.4)
CVE-2026-61476
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3875
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/f404bf0e6504e0412a00ea64708f17d2a5e3f869 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a4abe1f1fa6f465b64fb400bea14c72bd5e32ac9 (v11.0.4)
CVE-2026-63320
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3626
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/772488562053c1299fc3667a49b3ff1858f83979 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/c159357f8c38cc4c64bacaebe8eeaf68af2a4b69 (v11.0.4)
CVE-2026-63321
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a6e0519ea8ed6fc84fab9bf9ca82c7a55780f880 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/52c7bb369b23dfcafb6e6d90665c777797b55e88 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/f348425fddae38e0c1d6823501890acfb2a3bfb1 (v11.0.4)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/9a06bb17256c0a38f0b53025bf804d2e2035f93f (v11.0.4)
CVE-2026-63322
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3607
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/4727cc883b7e81d2c30b9801af54482d65b84292 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/95b9a1bf26fef7c44f4925f78ade7fa824ed5e76 (v11.0.4)
CVE-2026-63109
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3989
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/861372428b05f74a1cf9a8af22a863aa7b46c7ce (v11.1.0-rc1)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/37cec1fe0e4e14385a19e3c13012e8b06387758a (v11.0.4)
CVE-2026-16288
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4039
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/bd9b3c50f458ce24fee084916cf0eba58bd9a33b (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/26d21226515b89a9039b168fd0511f1945fe8b72 (v11.0.4)
CVE-2026-61404
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/acba2d78176d8235b81fd886b37642ae6c464982 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d91e0141c52b0f39c8d0cb4b0f1cbb0d9aee6550 (v11.0.4)
CVE-2026-61405
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3890
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/8e0ddb4a6ebd1c3d2dfd067f82b6d92de5b23e30 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a7d7f39ddb6abf4cec8e6eed94599065855137bd (v11.0.4)
CVE-2026-61406
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3899
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/647ba95eda5a21518f84c6593ed97e0447f38a90 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/550725189217c23b31de47d917135303981c1f7c (v11.0.4)
CVE-2026-58582
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3615
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/ff5a9eb13c862ed274ea0d0682a6573411e31543 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/db51779dc442cab2d95d64795b0cec64da4d47b2 (v11.0.4)
CVE-2026-58581
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3614
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/702216619e2a1afd5039520114f4d245d7011f09 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e0397dbe1a295e037f16f154aaaa3cff3341fc3d (v11.0.4)
@@ -16802,12 +16802,12 @@ CVE-2026-81525 (The MongoDB client library for PHP does not sufficiently sanitiz
NOT-FOR-US: mongo-php-library (not same as php-mongodb)
CVE-2026-81524 (A weakness in the MongoDB C Driver allows special elements in caller-s ...)
- mongo-c-driver 2.5.1-1
- [trixie] - mongo-c-driver <no-dsa> (Minor issue)
+ [trixie] - mongo-c-driver 1.30.4-1+deb13u3
[bookworm] - mongo-c-driver <postponed> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6424
CVE-2026-81523 (A missing input-validation issue in MongoDB libmongocrypt's automatic- ...)
- libmongocrypt 1.20.3-1
- [trixie] - libmongocrypt <no-dsa> (Minor issue)
+ [trixie] - libmongocrypt 1.13.2-1+deb13u1
[bookworm] - libmongocrypt <postponed> (Minor issue)
NOTE: https://jira.mongodb.org/browse/MONGOCRYPT-977
CVE-2026-81522 (A weakness in the MongoDB C++ Driver's handling of caller-supplied nam ...)
@@ -17264,11 +17264,11 @@ CVE-2026-80179 (A flaw was found in jwcrypto. A remote attacker can send a speci
NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-96rv-c4vc-h4f4
CVE-2026-81501
- incus 7.0.1-3
- [trixie] - incus <no-dsa> (Minor issue)
+ [trixie] - incus 6.0.4-2+deb13u10
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-c6wx-8679-hpr9
CVE-2026-81500
- incus 7.0.1-3
- [trixie] - incus <no-dsa> (Minor issue)
+ [trixie] - incus 6.0.4-2+deb13u10
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-9pqw-c7m4-xvg7
CVE-2026-18374 (Passing an effectively empty string to the `,ccs=` syntax extension of ...)
- glibc 2.43-5 (bug #1146721)
@@ -17545,7 +17545,7 @@ CVE-2026-78257 (Contributor PHP Object Injection in Booking and Rental Manager <
NOT-FOR-US: WordPress plugin or theme
CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker can tr ...)
- rsyslog 8.2608.0-4 (bug #1145980)
- [trixie] - rsyslog <no-dsa> (Minor issue)
+ [trixie] - rsyslog 8.2504.0-1+deb13u2
[bookworm] - rsyslog <postponed> (Minor issue)
NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3
NOTE: https://github.com/rsyslog/rsyslog/pull/7525
@@ -22132,7 +22132,7 @@ CVE-2026-78166 (A security flaw has been discovered in provectus kafka-ui up to
NOT-FOR-US: provectus kafka-ui
CVE-2026-78161 (A vulnerability was found in warmcat libwebsockets 4.5.0. Impacted is ...)
- libwebsockets 4.3.5-6 (bug #1145789)
- [trixie] - libwebsockets <no-dsa> (Minor issue; will be fixed via point release)
+ [trixie] - libwebsockets 4.3.5-1+deb13u2
[bookworm] - libwebsockets <not-affected> (Vulnerable code introduced in v4.3.0)
[bullseye] - libwebsockets <not-affected> (Vulnerable code introduced in v4.3.0)
NOTE: Introduced by: https://github.com/warmcat/libwebsockets/commit/dcaa0013b425882aa71cfb1a5b350d67b6717608 (v4.3.0)
@@ -25037,7 +25037,7 @@ CVE-2026-19586 (A pre-authentication OS command injection vulnerability has been
NOT-FOR-US: TPLink
CVE-2026-18917 (A flaw was found in libvirt. An unprivileged local user could exploit ...)
- libvirt 12.7.0-1 (bug #1145069)
- [trixie] - libvirt <no-dsa> (Minor issue)
+ [trixie] - libvirt 11.3.0-3+deb13u3
[bookworm] - libvirt <postponed> (Minor issue)
NOTE: https://gitlab.com/libvirt/libvirt/-/work_items/903
NOTE: Introduced with: https://gitlab.com/libvirt/libvirt/-/commit/34f2d0319d2098c77c8cc27d8350616029125a2b (v1.2.6-rc1)
@@ -37106,12 +37106,12 @@ CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhausti
NOTE: Fixed by: https://github.com/golang/go/commit/8d01cbaad59021bd6d4f6e2dd864413872434250 (go1.25.13)
CVE-2026-16457
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3968
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6682ea3391277e732a6d74c5758206ba834e1615 (v11.1.0-rc2)
CVE-2026-50626
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3882
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3921
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3923
@@ -37120,12 +37120,12 @@ CVE-2026-50626
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d530f2dfbd2d973b17a6d0ffbfe2afb692bdd69c (v11.1.0-rc2)
CVE-2026-63318
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4000
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a0414545a212e27058fab7b057b018e75b8c4b13 (v11.1.0-rc2)
CVE-2026-66021
- qemu 1:11.1.0+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.13+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3945
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/241095547a5d87ad6fa68cd674fe524e6596b958 (v11.1.0-rc3)
CVE-2026-73671 (Saurus CMS Community Edition contains an unauthenticated open redirect ...)
@@ -38376,7 +38376,7 @@ CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side method that lacks authoriz
NOT-FOR-US: ScadaLTS
CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due to a flaw ...)
- rsyslog 8.2608.0-1 (bug #1144616)
- [trixie] - rsyslog <no-dsa> (Minor issue)
+ [trixie] - rsyslog 8.2504.0-1+deb13u1
[bookworm] - rsyslog <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/5
NOTE: https://github.com/rsyslog/rsyslog/pull/7410
@@ -39909,7 +39909,7 @@ CVE-2026-72712 (Nmap versions up to and including 7.99 contains a denial of serv
NOTE: Crash in CLI tool, no security impact
CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a root us ...)
- mrtg 2.17.10-15 (bug #1144393)
- [trixie] - mrtg <no-dsa> (Minor issue)
+ [trixie] - mrtg 2.17.10-13+deb13u2
[bookworm] - mrtg <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460973
NOTE: Fixed by: https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269
@@ -41817,7 +41817,7 @@ CVE-2026-66760 (SAP Approuter does not correctly validate client certificates in
NOT-FOR-US: SAP
CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a process ...)
- libvirt 12.6.0-1
- [trixie] - libvirt <no-dsa> (Minor issue)
+ [trixie] - libvirt 11.3.0-3+deb13u3
[bookworm] - libvirt <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513065
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/801160fd414ca2cc402bc01ead09b7ed4c3b8f5b (v12.6.0-rc2)
@@ -42291,7 +42291,7 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory
NOT-FOR-US: Nishishi Factory
CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or convert op ...)
- libvirt 12.6.0-1
- [trixie] - libvirt <no-dsa> (Minor issue)
+ [trixie] - libvirt 11.3.0-3+deb13u3
[bookworm] - libvirt <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513066
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/69335a484768d550854da1133d5490074695e825 (v12.6.0-rc2)
@@ -46187,12 +46187,12 @@ CVE-2026-19177 (Insufficient validation of untrusted input in UI in Google Chrom
[bullseye] - chromium <end-of-life> (see #1061268)
CVE-2026-61478
- libvirt 12.6.0-1
- [trixie] - libvirt <no-dsa> (Minor issue)
+ [trixie] - libvirt 11.3.0-3+deb13u3
[bookworm] - libvirt <postponed> (Minor issue)
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/68da70aae766c6271b8d3b466374d3cc7d1a8afb (v12.6.0-rc1)
CVE-2026-61477 (An injection vulnerability was found in libvirt's virtual network driv ...)
- libvirt 12.6.0-1
- [trixie] - libvirt <no-dsa> (Minor issue)
+ [trixie] - libvirt 11.3.0-3+deb13u3
[bookworm] - libvirt <postponed> (Minor issue)
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/d44836a1dc6771ac22f69755fc69bf730f0eec87 (v12.6.0-rc1)
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/289ffa796d737a79a4c05d07232ebd75def9a12a (v12.6.0-rc1)
@@ -50419,14 +50419,14 @@ CVE-2026-56670 (ComfyUI is a modular diffusion model GUI, api and backend with a
NOT-FOR-US: ComfyUI
CVE-2026-55777 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess 1:1.11-1 (bug #1143181)
- [trixie] - goaccess <no-dsa> (Minor issue)
+ [trixie] - goaccess 1:1.9.3-1+deb13u1
[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5phr-qpgf-hgrg
NOTE: Fixed by: https://github.com/allinurl/goaccess/commit/ba813ed97d998dbdcb8d87e178799a4bb2da9e81 (v1.11)
CVE-2026-55768 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess 1:1.11-1 (bug #1143181)
- [trixie] - goaccess <no-dsa> (Minor issue)
+ [trixie] - goaccess 1:1.9.3-1+deb13u1
[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-5gm5-pvh2-wg46
@@ -50443,7 +50443,7 @@ CVE-2026-55495 (Cloudreve is a self-hosted file management and sharing system. P
NOT-FOR-US: Cloudreve
CVE-2026-54715 (GoAccess is a real-time web log analyzer and interactive viewer that r ...)
- goaccess 1:1.11-1 (bug #1143181)
- [trixie] - goaccess <no-dsa> (Minor issue)
+ [trixie] - goaccess 1:1.9.3-1+deb13u1
[bookworm] - goaccess <postponed> (minor issue; DoS; limited support for go language)
[bullseye] - goaccess <postponed> (minor issue; DoS; limited support for go language)
NOTE: https://github.com/allinurl/goaccess/security/advisories/GHSA-qcx5-vh2x-35fr
@@ -53584,7 +53584,7 @@ CVE-2026-7187 (Missing authentication for critical function vulnerability in Uni
CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhibit `O ...)
- python3.14 3.14.7-1
- python3.13 3.13.15-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u5
- python3.11 <removed>
[bookworm] - python3.11 <postponed> (Minor issue)
- python3.9 <removed>
@@ -55367,43 +55367,43 @@ CVE-2026-17457 (A vulnerability has been found in mf-yang openclaw-cn up to 0.2.
NOT-FOR-US: mf-yang openclaw-cn
CVE-2026-63319
- qemu 1:11.0.3+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.12+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3995
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/1e54185745ba896af2beb5259b61ba6473e9881e (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6970b91d905f72ba952c4d224ab8d6192ef9b39d (v10.0.12)
CVE-2026-61475
- qemu 1:11.0.3+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.12+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3935
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/24767bcf0fdcd19415cb07c06f637ea29a5cebbb (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6c2f9592dec667796dacdffd7adbd065948fe212 (v10.0.12)
CVE-2026-16043
- qemu 1:11.0.3+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.12+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4001
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/2a5bc4de0f544a3739c32a99b11a9e78e71472c2 (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/b0411a1747ac9b205633011f62ac85436f354f35 (v10.0.12)
CVE-2026-15705
- qemu 1:11.0.3+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.12+ds-0+deb13u1
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/b2d1fe67d09d2b6c7da647fbcea6ca0148c206d3 (v1.4.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6229fbcef1f878b2df081c7911c7eaae12e54da5 (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e3da91c85971de1d5a31f5f2a5b0f6ef34a4e8a7 (v10.0.12)
CVE-2026-15578
- qemu 1:11.0.3+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.12+ds-0+deb13u1
NOTE: https://gitlab.com/qemu-project/qemu/-/issues/3976
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/147e214e9cbd701c0569193004800c4f75bf9575 (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/7467c162c0b19a0ac1822172e131d34943ca54ad (v10.0.12)
CVE-2026-8348 [hw/9pfs: add xattr FID limit to prevent memory exhaustion]
- qemu 1:11.0.3+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.12+ds-0+deb13u1
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/10b468bdc5335b58f610817215f30847c1429f24 (v0.14.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/c57644a542b11e578309b07b3bf7623d566e6a81 (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/4f9e9601d0ec69748b2019a34dde148578b2c5a4 (v10.0.12)
CVE-2026-9238 [hw/9pfs: cap Treaddir allocation]
- qemu 1:11.0.3+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.12+ds-0+deb13u1
NOTE: Introduced with: https://gitlab.com/qemu-project/qemu/-/commit/2149675b195f2d9a1a4e3b966d45aba234def69b (v5.2.0-rc0)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d2a298f359477fd6fa30dd6aa7357115b596012d (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/169537e616a894175cd7c876c83b4801fe099232 (v10.0.12)
@@ -57091,7 +57091,7 @@ CVE-2026-66142 (Apache Neethi is vulnerable to uncontrolled recursion when parsi
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authen ...)
- libssh2 1.11.1-5 (bug #1142856)
- [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - libssh2 1.11.1-1+deb13u2
[bookworm] - libssh2 <not-affected> (Vulnerable code not present)
[bullseye] - libssh2 <not-affected> (Vulnerable code not present)
NOTE: https://github.com/libssh2/libssh2/pull/2198
@@ -57099,12 +57099,12 @@ CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-
CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bo ...)
{DLA-4773-1}
- libssh2 1.11.1-5 (bug #1142856)
- [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - libssh2 1.11.1-1+deb13u2
NOTE: https://github.com/libssh2/libssh2/pull/2202
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9
CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authen ...)
- libssh2 1.11.1-5 (bug #1142856)
- [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - libssh2 1.11.1-1+deb13u2
[bookworm] - libssh2 <not-affected> (Vulnerable code not present)
[bullseye] - libssh2 <not-affected> (Vulnerable code not present)
NOTE: https://github.com/libssh2/libssh2/pull/2401
@@ -57112,7 +57112,7 @@ CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-
CVE-2026-66032 (libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-fre ...)
{DLA-4773-1}
- libssh2 1.11.1-5 (bug #1142856)
- [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - libssh2 1.11.1-1+deb13u2
NOTE: https://github.com/libssh2/libssh2/pull/2180
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0
CVE-2026-66027 (Suna before 0.9.102 contains a broken access control vulnerability in ...)
@@ -57634,7 +57634,7 @@ CVE-2026-62825 (Improper authentication in Azure Key Vault allows an unauthorize
NOT-FOR-US: Microsoft
CVE-2026-60122 (gpsd through release-3.27.5, fixed at commit 4c06658, contains a code ...)
- gpsd 3.27.5-1
- [trixie] - gpsd <no-dsa> (Minor issue)
+ [trixie] - gpsd 3.25-5+deb13u2
[bookworm] - gpsd <postponed> (Minor issue; code injection confined to the gpsprof diagnostic client via a hostile gpsd JSON stream or replayed log, local and requires user interaction)
[bullseye] - gpsd <postponed> (Minor issue; code injection confined to the gpsprof diagnostic client via a hostile gpsd JSON stream or replayed log, local and requires user interaction)
NOTE: https://gitlab.com/gpsd/gpsd/-/work_items/406
@@ -57804,7 +57804,7 @@ CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious boot
NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
CVE-2026-58264 [heap-based buffer overrun in command handler]
- fluidsynth 2.5.6+dfsg-1
- [trixie] - fluidsynth <no-dsa> (Minor issue)
+ [trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
[bookworm] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
[bullseye] - fluidsynth <postponed> (Only reachable via the fluidsynth shell or TCP command server, which already grants unauthenticated control; one-line fix can ride a future upload)
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-mqmq-w63q-cj94
@@ -57813,7 +57813,7 @@ CVE-2026-58264 [heap-based buffer overrun in command handler]
NOTE: Fixed by: https://github.com/FluidSynth/fluidsynth/commit/762a3bd39a431cd45abf3bbcce7286c87909d087 (v2.5.6)
CVE-2026-61714 [heap-based buffer overflow in MIDI player]
- fluidsynth 2.5.6+dfsg-1
- [trixie] - fluidsynth <no-dsa> (Minor issue)
+ [trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
[bookworm] - fluidsynth <postponed> (Needs a non-default synth.midi-channels > 16; MIDI file channels are masked to 4 bits so a crafted file cannot reach it)
[bullseye] - fluidsynth <not-affected> (Vulnerable code not present)
NOTE: https://github.com/FluidSynth/fluidsynth/security/advisories/GHSA-976m-35rw-h3m6
@@ -62747,7 +62747,7 @@ CVE-2026-56452 (Path traversal in the sshd-scp component of Apache MINA SSHD.Apa
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/15
CVE-2026-61548 [rsyslog mmpstrucdata stack overflow]
- rsyslog 8.2606.0-4
- [trixie] - rsyslog <no-dsa> (Minor issue; can be fixed in a point release)
+ [trixie] - rsyslog 8.2504.0-1+deb13u2
[bookworm] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs module loaded + oversized RFC5424 structured-data)
[bullseye] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs module loaded + oversized RFC5424 structured-data)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/1
@@ -63107,7 +63107,7 @@ CVE-2026-15813 (A vulnerability was found in the network packet de-fragmentation
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500854
CVE-2026-15588 (A denial-of-service and resource exhaustion vulnerability exists withi ...)
- glib2.0 2.88.3-1 (bug #1142835)
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u4
[bookworm] - glib2.0 <postponed> (Minor issue; unbounded pre-auth SASL line read in GDBusServer lets an unauthenticated peer exhaust memory; DoS only, the system/session buses run dbus-daemon)
[bullseye] - glib2.0 <postponed> (Minor issue; unbounded pre-auth SASL line read in GDBusServer lets an unauthenticated peer exhaust memory; DoS only, the system/session buses run dbus-daemon)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/issues/3985
@@ -63232,7 +63232,7 @@ CVE-2026-57848 (Stoat for Android exports the chat.stoat.activities.ShareTargetA
NOT-FOR-US: Stoat for Android
CVE-2026-53994 (ProFTPD mod_sftp contains a heap-based buffer overflow reachable by an ...)
- proftpd-dfsg 1.3.9b~dfsg-1
- [trixie] - proftpd-dfsg <no-dsa> (Minor issue)
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
NOTE: https://github.com/proftpd/proftpd/issues/2115
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/8685930f5e2e448563ef31d8871553308b954785 (v1.3.9b)
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/a237fa62341bf882c7edc4e5e8cc492cec851d0b (v1.3.9b)
@@ -66166,7 +66166,7 @@ CVE-2026-36669 (An unauthenticated arbitrary file upload vulnerability in ck_upl
NOT-FOR-US: Feng Office
CVE-2026-16118 (A flaw was found in xdgmime. A heap-based buffer overflow can be trigg ...)
- glib2.0 2.88.3-3 (bug #1142717)
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u5
[bookworm] - glib2.0 <postponed> (Minor issue; 2-byte OOB write parsing the mime magic file in an XDG data dir, needs an attacker-writable XDG data dir; unfixed upstream)
[bullseye] - glib2.0 <postponed> (Minor issue; 2-byte OOB write parsing the mime magic file in an XDG data dir, needs an attacker-writable XDG data dir; unfixed upstream)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3992
@@ -66783,47 +66783,47 @@ CVE-2026-47751 (Claude Code Action is a general-purpose GitHub action that runs
CVE-2026-47089 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. L ...)
{DLA-4766-1}
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-47088 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
{DLA-4766-1}
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-47087 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. U ...)
{DLA-4766-1}
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-47086 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. G ...)
{DLA-4766-1}
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-47085 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. U ...)
{DLA-4766-1}
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-47084 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
{DLA-4766-1}
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-47083 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
[bookworm] - cyrus-imapd <postponed> (Will be fixed via point release)
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-47082 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
{DLA-4766-1}
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-47081 (An issue was discovered in cyrus-imapd in Cyrus IMAP through 3.12.2. T ...)
{DLA-4766-1}
- cyrus-imapd 3.12.3-1
- [trixie] - cyrus-imapd <no-dsa> (Will be fixed via point release)
+ [trixie] - cyrus-imapd 3.10.2-1+deb13u2
NOTE: https://www.cyrusimap.org/3.12/imap/download/release-notes/3.12/x/3.12.3.html
CVE-2026-46687 (Emlog is an open source website building system. In 2.6.13 and earlier ...)
NOT-FOR-US: Emlog
@@ -67499,13 +67499,13 @@ CVE-2026-61873 (Grav before 9.1.8 contains an arbitrary file write vulnerability
CVE-2026-61872 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h5r4-w88w-7ccr
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/ed143b98d72bba764b010eb822464f2a12b24ff1 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/3f0595f0778201326163253bfdc8bce9a4bbadf6 (6.9.13-51)
CVE-2026-61871 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
[bookworm] - imagemagick <not-affected> (vulnerable code not present)
[bullseye] - imagemagick <not-affected> (vulnerable code not present)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h58x-r7f7-rh84
@@ -67515,20 +67515,20 @@ CVE-2026-61871 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak
CVE-2026-61869 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r628-69v2-2f9c
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/b2dc602e175ee07b0794f3e31f1a29ae6b7267d1 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ca6c9da425880fde937da41d59666dedf5e719e1 (6.9.13-51)
CVE-2026-61868 (ImageMagick before 7.1.2-26 and 6.9.x before 6.9.13-51 contains a memo ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-h7f2-f9cc-h2gv
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/808506dc4d0cbf3972ce0d57544a06209b65009c (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/875bd8912b3b54a58e09c14085cf2b14a478a86b (6.9.13-51)
CVE-2026-61867 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...)
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
[bookworm] - imagemagick <not-affected> (vulnerable code introduced later)
[bullseye] - imagemagick <not-affected> (vulnerable code introduced later)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jfq9-q63x-rc63
@@ -67537,14 +67537,14 @@ CVE-2026-61867 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability
CVE-2026-61866 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-99w9-hv66-rfv7
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/0bb3578ee087f3c4f14bbf1d8883ae456fc99092 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/353e2604d1983b6d8ec4c04f4f38bbd4668ba0e1 (6.9.13-51)
CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in th ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-j8rh-v2r8-v94x
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/b535126ba5abf23f2693e62ed79f10277d938cf4 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
@@ -67552,7 +67552,7 @@ CVE-2026-61865 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak
CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak in co ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-7c7m-fpjw-gwcq
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/174275bc1b53e2f23bbff7cd013dc9faa8a99c5a (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
@@ -67560,7 +67560,7 @@ CVE-2026-61864 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a memory leak
CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains a memo ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6vxp-gfwf-hcr9
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/f3ff3afee942a19e3041568bfa740d48213a3dec (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
@@ -67568,7 +67568,7 @@ CVE-2026-61863 (ImageMagick before 7.1.2-26 (and 6.x before 6.9.13-51) contains
CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an information disc ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-hwf3-r46v-5ggx
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/4079949bae0cde7e683df2e63c40f2e36f52c1b6 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/47cf9792e3be1df42c63125c55870918403d10a8 (6.9.13-52)
@@ -67576,14 +67576,14 @@ CVE-2026-61862 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains an informatio
CVE-2026-61860 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a use-after-free vu ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6jwg-7q3p-5fqm
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/3fc646a498eecda9163164046189f90dc677ae64 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/eed471c1286aa27c076348b453b35a2e962967bc (6.9.13-51)
CVE-2026-61859 (ImageMagick before 7.1.2-26 and 6.9.13-x before 6.9.13-51 contains a p ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-vghg-5jrg-2398
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/e047ee2c7b937c1db92302fe3701e2e9c169de27 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ffc96e2a4cdc2fcbb9e0f18f082be52e1b4ca012 (6.9.13-51)
@@ -67622,7 +67622,7 @@ CVE-2026-61605
CVE-2026-61464 (ImageMagick before 7.1.2-26 and 6.9.13-51 contains a heap-based buffer ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-76q6-2p6h-xjqr
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/378bfc12bf7bbc4d9ab081120873efef935ebd85 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/d0aa5c9e09e0cf5e400309ca76ae886a980b0555 (6.9.13-51)
@@ -67747,7 +67747,7 @@ CVE-2026-56398 (Open WebUI before 0.9.5 contains a stored cross-site scripting v
NOT-FOR-US: Open WebUI
CVE-2026-56375 (ImageMagick through 7.1.2-18 contains a memory leak vulnerability in t ...)
- imagemagick 8:7.1.2.18+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
[bookworm] - imagemagick <not-affected> (ashlar coder introduced in im7)
[bullseye] - imagemagick <not-affected> (ashlar coder introduced in im7)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-6p22-q7w5-33pg
@@ -68054,19 +68054,19 @@ CVE-2026-59888 (jackson-databind contains the general-purpose data-binding funct
CVE-2026-59886 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ ...)
{DLA-4778-1}
- pyasn1 0.6.4-1 (bug #1142388)
- [trixie] - pyasn1 <no-dsa> (Minor issue)
+ [trixie] - pyasn1 0.6.1-1+deb13u3
NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r
NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886 (v0.6.4)
CVE-2026-59885 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, ...)
{DLA-4778-1}
- pyasn1 0.6.4-1 (bug #1142388)
- [trixie] - pyasn1 <no-dsa> (Minor issue)
+ [trixie] - pyasn1 0.6.1-1+deb13u3
NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj
NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9 (v0.6.4)
CVE-2026-59884 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER ...)
{DLA-4778-1}
- pyasn1 0.6.4-1 (bug #1142388)
- [trixie] - pyasn1 <no-dsa> (Minor issue)
+ [trixie] - pyasn1 0.6.1-1+deb13u3
NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j
NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 (v0.6.4)
CVE-2026-59841 (A improper restriction of communication channel to intended endpoints ...)
@@ -70302,12 +70302,12 @@ CVE-2026-58101 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial
NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2 (2.1.3)
CVE-2026-63090 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overf ...)
- proftpd-dfsg 1.3.9c~dfsg-1
- [trixie] - proftpd-dfsg <no-dsa> (Minor issue)
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
NOTE: https://github.com/proftpd/proftpd/issues/2190
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/ce13286900a7e25f1e3403620496868d73292f6b (v1.3.9c)
CVE-2026-63091 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a signed integer overflow ...)
- proftpd-dfsg 1.3.9c~dfsg-1
- [trixie] - proftpd-dfsg <no-dsa> (Minor issue)
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
NOTE: https://github.com/proftpd/proftpd/pull/2201
NOTE: Fixed by: https://github.com/proftpd/proftpd/commit/baf4b7929758c72cdb6cf16325fa25f435d23db6 (v1.3.9c)
CVE-2026-9824 (Mattermost versions 11.7.x <= 11.7.2, 11.6.x <= 11.6.4, 10.11.x <= 10. ...)
@@ -70559,13 +70559,13 @@ CVE-2026-57668 (Improper Neutralization of Input During Web Page Generation ('Cr
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57433 (Storable versions before 3.41 for Perl have a signed integer overflow ...)
- perl 5.40.1-8 (bug #1138906; bug #1142035)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
- libstorable-perl <removed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780100/
NOTE: Fixed by: https://github.com/Perl/perl5/commit/e4f681784bcdeaa91ff02a2fa4cdcae5c46779d7 (v5.43.11)
CVE-2026-57432 (Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5 ...)
- perl 5.40.1-8 (bug #1138905; bug #1142036)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780102/
NOTE: Fixed by: https://github.com/Perl/perl5/commit/5f7eb6bbbe0510964e3fb1d6bb691e5445913e55 (v5.43.11)
NOTE: Fixed by: https://github.com/Perl/perl5/commit/40754edc72dd3e513d758153c0e2f0215897740e (v5.43.11)
@@ -70787,7 +70787,7 @@ CVE-2026-14165 (An Authorization Bypass Through User-Controlled Key vulnerabilit
CVE-2026-13221 (Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5 ...)
[experimental] - perl 5.44.0-1
- perl 5.42.3-1 (bug #1142037)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41780104/
NOTE: https://github.com/Perl/perl5/issues/23388
NOTE: Introduced with: https://github.com/Perl/perl5/commit/acababb42be12ff2986b73c1bfa963b70bb5d54e (v5.37.10)
@@ -71021,13 +71021,13 @@ CVE-2026-15470 (A vulnerability has been found in Eleveo Call Recording Software
CVE-2026-61870 (ImageMagick before 7.1.2-26 contains a memory leak vulnerability in th ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-m596-67p7-69wh
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/fdbf39ba9a681e53e6025d40501ae5a2bfec3000 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/3c574f9ba5387f5f11669fdb4d4e8febc199dca3 (6.9.13-51)
CVE-2026-61861 (ImageMagick before 7.1.2-26 contains a use-after-free vulnerability in ...)
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
[bookworm] - imagemagick <not-affected> (vulnerable code not present)
[bullseye] - imagemagick <not-affected> (vulnerable code not present)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qvxh-prvr-85w2
@@ -71037,21 +71037,21 @@ CVE-2026-61861 (ImageMagick before 7.1.2-26 contains a use-after-free vulnerabil
CVE-2026-61858 (ImageMagick before 7.1.2-26 contains a policy bypass vulnerability in ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-v3j6-27vc-7pw2
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/19c11cb0aefbd627c95c4c08c44722e660025aa1 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/5fbcfe76fd8be554e30ec1d8723c00ae8b68f470 (6.9.13-51)
CVE-2026-61857 (ImageMagick before 7.1.2-26 contains a heap use-after-free vulnerabili ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-qh5g-q395-cx4j
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/150c9852402ac1aa1f223e5bf5109e3a2022ebbc (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/e1d94d92d985f8c0bb648ddbcd70ba3362a84674 (6.9.13-51)
CVE-2026-61465 (ImageMagick before 7.1.2-26 and 6.9.13-51 is missing a check for the a ...)
{DLA-4696-1}
- imagemagick 8:7.1.2.26+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-rvhp-75f6-9jqh
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/dd0dedbecff931e93c4e72a57f7108bb13f76cf7 (7.1.2-26)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/0bcf10763277cdf0f61cf85e786575ae8665f13b (7.1.2-26)
@@ -71087,7 +71087,7 @@ CVE-2026-56763 (Hono before 4.12.7 allows __proto__ key in parseBody with dot op
NOT-FOR-US: Hono
CVE-2026-56372 (ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerabil ...)
- imagemagick 8:7.1.2.19+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
[bookworm] - imagemagick <not-affected> (vulnerable code introduced later)
[bullseye] - imagemagick <not-affected> (vulnerable code introduced later)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-8vfj-q2cp-5m5j
@@ -71652,14 +71652,14 @@ CVE-2026-56664 (ZITADEL is an open source identity management platform. Prior to
CVE-2026-56373 (ImageMagick before 7.1.2-15 contains a use-after-free vulnerability in ...)
{DLA-4680-1}
- imagemagick 8:7.1.2.15+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-3j4x-rwrx-xxj9
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/168ffe18def968f886c023146a478897866fd621 (7.1.2-14)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/06a0867c1f5076b85577b6b1cf87af901f6d6a84 (6.9.13-39)
CVE-2026-56366 (ImageMagick before 7.1.2-18 contains a memory leak vulnerability in th ...)
{DLA-4680-1}
- imagemagick 8:7.1.2.18+dfsg1-1
- [trixie] - imagemagick <no-dsa> (Minor issue)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9r56-3gjq-hqf7
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/bee248ee853a686a969fae9cfb1e02dd5aae245b (7.1.2-18)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/1adc49fac3041620abe11fcb06524d33d9dbd035 (6.9.13-43)
@@ -72326,7 +72326,7 @@ CVE-2026-59148 (Mockoon provides way to design and run mock APIs. Prior to 9.7.0
NOT-FOR-US: Mockoon
CVE-2026-58459 (gpsd through release-3.27.5, fixed at commit 4c06658, contains a comma ...)
- gpsd 3.27.5-1 (bug #1141962)
- [trixie] - gpsd <no-dsa> (Minor issue)
+ [trixie] - gpsd 3.25-5+deb13u2
[bookworm] - gpsd <postponed> (Minor issue; command injection confined to the gpsprof diagnostic client via device-controlled subtype, local + user-interaction)
[bullseye] - gpsd <postponed> (Minor issue; command injection confined to the gpsprof diagnostic client via device-controlled subtype, local + user-interaction)
NOTE: https://gitlab.com/gpsd/gpsd/-/work_items/404#note_3534119267
@@ -73405,14 +73405,14 @@ CVE-2026-56401
REJECTED
CVE-2026-56374 (ImageMagick before 7.1.2-19 contains a heap buffer overflow vulnerabil ...)
- imagemagick 8:7.1.2.19+dfsg1-1
- [trixie] - imagemagick <postponed> (Minor issue, fix along in future update)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
[bookworm] - imagemagick <not-affected> (coder FTXT introduced later)
[bullseye] - imagemagick <not-affected> (coder FTXT introduced later)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-w54j-7wpm-crhj
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/22aef933133770706caafb93f814f5306dcca345 (7.1.2-19)
CVE-2026-56362 (ImageMagick before 7.1.2-15 contains a heap-buffer-overflow read vulne ...)
- imagemagick 8:7.1.2.15+dfsg1-1
- [trixie] - imagemagick <postponed> (Minor issue, fix along in future update)
+ [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
[bookworm] - imagemagick 8:6.9.11.60+dfsg-1.6+deb12u8
[bullseye] - imagemagick 8:6.9.11.60+dfsg-1.3+deb11u11
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-gq5v-qf8q-fp77
@@ -74262,11 +74262,11 @@ CVE-2011-10043 (Module::Load versions before 0.22 for Perl allow arbitrary modul
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41608305/
CVE-2026-7017 (HTTP::Tiny versions before 0.095 for Perl forward credential headers t ...)
- libhttp-tiny-perl 0.096-1 (bug #1141638)
- [trixie] - libhttp-tiny-perl <no-dsa> (Minor issue)
+ [trixie] - libhttp-tiny-perl 0.090-1+deb13u1
[bookworm] - libhttp-tiny-perl <postponed> (Minor issue; leak requires caller-supplied credential headers and an attacker-influenced redirect)
[experimental] - perl 5.44.0-1
- perl 5.42.3-1 (bug #1141639)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41618211/
NOTE: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/pull/36
NOTE: Fixed by: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/84984ef3930ddd4afcf5eb83b40d3cee200739c3 (release-0.095)
@@ -77224,7 +77224,7 @@ CVE-2026-14324 (RAOP module accepts unbounded Content-Length values and does not
NOTE: Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/c7fd5f935083f367d05d8f78ccbbd6e0dbc6fb07 (1.6.8)
CVE-2026-14258 (A flaw was found in dhcpcd's IPv6 Neighbor Discovery Router Advertisem ...)
- dhcpcd 1:10.2.4-3
- [trixie] - dhcpcd <no-dsa> (Minor issue)
+ [trixie] - dhcpcd 1:10.1.0-11+deb13u4
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462305
NOTE: https://github.com/NetworkConfiguration/dhcpcd/issues/415
NOTE: https://github.com/NetworkConfiguration/dhcpcd/commit/75289ca54211481d21b0c915db98dd733b30794f (v10.2.0)
@@ -77701,7 +77701,7 @@ CVE-2026-54500 (Oj (Optimized JSON) is a JSON parser and Object marshaller packa
NOTE: https://github.com/ohler55/oj/security/advisories/GHSA-fm7p-mprw-wjm9
CVE-2026-52868 (An unauthenticated attacker can read worklist records from a directory ...)
- dcmtk 3.7.0+really3.7.0-7 (bug #1141411)
- [trixie] - dcmtk <no-dsa> (Minor issue; exposing first in unstable, then via proposed-updates)
+ [trixie] - dcmtk 3.6.9-5+deb13u3
[bookworm] - dcmtk <postponed> (Minor issue; follow SPU)
[bullseye] - dcmtk <postponed> (Minor issue; follow SPU)
NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=e3878daf870cd2db50eadfde38615f0afae8a584
@@ -77717,7 +77717,7 @@ CVE-2026-52193 (Buffer Overflow vulnerability in UTT nv518G nv518GV3v3.2.7-21091
NOT-FOR-US: UTT
CVE-2026-50254 (An unauthenticated remote attacker can repeatedly send a single crafte ...)
- dcmtk 3.7.0+really3.7.0-7 (bug #1141411)
- [trixie] - dcmtk <no-dsa> (Minor issue; exposing first in unstable, then via proposed-updates)
+ [trixie] - dcmtk 3.6.9-5+deb13u3
[bookworm] - dcmtk <postponed> (Minor issue; follow SPU)
[bullseye] - dcmtk <postponed> (Minor issue; follow SPU)
NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=23f181f7a3cb8334056f751a3a0c2ddf01046752
@@ -77727,13 +77727,13 @@ CVE-2026-50040 (Storage Concentrator (SC & SCVM) is vulnerable to reflected cros
NOT-FOR-US: Storage Concentrator
CVE-2026-50003 (A malicious or compromised server can make a DCMTK client using bit-pr ...)
- dcmtk 3.7.0+really3.7.0-7 (bug #1141411)
- [trixie] - dcmtk <no-dsa> (Minor issue; exposing first in unstable, then via proposed-updates)
+ [trixie] - dcmtk 3.6.9-5+deb13u3
[bookworm] - dcmtk <postponed> (Minor issue; follow SPU)
[bullseye] - dcmtk <postponed> (Minor issue; follow SPU)
NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=eca9a03dda7d4fc1faa7e5a6dac9617938cf5803
CVE-2026-44628 (An unauthenticated attacker can crash the worklist server with a singl ...)
- dcmtk 3.7.0+really3.7.0-7 (bug #1141411)
- [trixie] - dcmtk <no-dsa> (Minor issue; exposing first in unstable, then via proposed-updates)
+ [trixie] - dcmtk 3.6.9-5+deb13u3
[bookworm] - dcmtk <postponed> (Minor issue; follow SPU)
[bullseye] - dcmtk <postponed> (Minor issue; follow SPU)
NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=f4e0074682645b1a4289d62581926c4394d5c6d5
@@ -77751,7 +77751,7 @@ CVE-2026-37106 (An issue in DokuWiki 2025-05-14b "Librarian" 56.2 allows a remot
NOTE: https://github.com/dokuwiki/dokuwiki/issues/4682
CVE-2026-35505 (An unauthenticated remote attacker can repeatedly send crafted connect ...)
- dcmtk 3.7.0+really3.7.0-7 (bug #1141411)
- [trixie] - dcmtk <no-dsa> (Minor issue; exposing first in unstable, then via proposed-updates)
+ [trixie] - dcmtk 3.6.9-5+deb13u3
[bookworm] - dcmtk <postponed> (Minor issue; follow SPU)
[bullseye] - dcmtk <postponed> (Minor issue; follow SPU)
NOTE: Fixed by: https://git.dcmtk.org/?p=dcmtk.git;a=commit;h=2312891a8d058c862e00bcbd636e5da26308658a
@@ -79558,14 +79558,14 @@ CVE-2026-58116 (LLaMA-Factory through 0.9.5 contains a remote code execution vul
NOT-FOR-US: LLaMA-Factory
CVE-2026-58016 (A flaw was found in GLib. A state confusion issue exists in g_dbus_nod ...)
- glib2.0 2.88.3-2 (bug #1141316)
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u4
[bookworm] - glib2.0 <postponed> (Minor issue; GDBus introspection-XML OOB-read DoS; no upstream fix yet)
[bullseye] - glib2.0 <postponed> (Minor issue; GDBus introspection-XML OOB-read DoS; no upstream fix yet)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3932
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5156 (2.89.0)
CVE-2026-58015 (A flaw was found in GLib. The D-Bus client-side implementation of the ...)
- glib2.0 2.88.1-2
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u4
[bookworm] - glib2.0 <postponed> (Minor issue; DBUS_COOKIE_SHA1 client path traversal, needs malicious D-Bus server)
[bullseye] - glib2.0 <postponed> (Minor issue; DBUS_COOKIE_SHA1 client path traversal, needs malicious D-Bus server)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3931
@@ -79573,7 +79573,7 @@ CVE-2026-58015 (A flaw was found in GLib. The D-Bus client-side implementation o
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
CVE-2026-58014 (A flaw was found in GLib. An off-by-one error can occur in the g_key_f ...)
- glib2.0 2.88.1-2
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u4
[bookworm] - glib2.0 <postponed> (Minor issue; GKeyFile off-by-one 1-byte OOB, reachability-gated)
[bullseye] - glib2.0 <postponed> (Minor issue; GKeyFile off-by-one 1-byte OOB, reachability-gated)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3930
@@ -79581,7 +79581,7 @@ CVE-2026-58014 (A flaw was found in GLib. An off-by-one error can occur in the g
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
CVE-2026-58013 (A flaw was found in GLib. A buffer over-read can occur in g_io_channel ...)
- glib2.0 2.88.1-2
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u4
[bookworm] - glib2.0 <postponed> (Minor issue; GIOChannel custom-terminator over-read, reachability-gated)
[bullseye] - glib2.0 <postponed> (Minor issue; GIOChannel custom-terminator over-read, reachability-gated)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3925
@@ -79589,7 +79589,7 @@ CVE-2026-58013 (A flaw was found in GLib. A buffer over-read can occur in g_io_c
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
CVE-2026-58012 (A flaw was found in GLib. A buffer over-read can occur in the g_regex_ ...)
- glib2.0 2.88.1-2
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u4
[bookworm] - glib2.0 <postponed> (Minor issue; g_regex_replace raw-mode over-read, needs G_REGEX_RAW)
[bullseye] - glib2.0 <postponed> (Minor issue; g_regex_replace raw-mode over-read, needs G_REGEX_RAW)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3918
@@ -79598,7 +79598,7 @@ CVE-2026-58012 (A flaw was found in GLib. A buffer over-read can occur in the g_
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5135 (2.86.5)
CVE-2026-58011 (A flaw was found in GLib. An out-of-bounds read of only 2 bytes can oc ...)
- glib2.0 2.88.1-2
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u4
[bookworm] - glib2.0 <postponed> (Minor issue; GDateTime 2-byte over-read, reachability-gated)
[bullseye] - glib2.0 <postponed> (Minor issue; GDateTime 2-byte over-read, reachability-gated)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3917
@@ -79607,7 +79607,7 @@ CVE-2026-58011 (A flaw was found in GLib. An out-of-bounds read of only 2 bytes
NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5135 (2.86.5)
CVE-2026-58010 (A flaw was found in GLib. An off-by-one error can occur in the gvs_tup ...)
- glib2.0 2.88.1-2
- [trixie] - glib2.0 <no-dsa> (Minor issue)
+ [trixie] - glib2.0 2.84.4-3~deb13u4
[bookworm] - glib2.0 <postponed> (Minor issue; GVariant deserialiser 1-byte over-read, reachability-gated)
[bullseye] - glib2.0 <postponed> (Minor issue; GVariant deserialiser 1-byte over-read, reachability-gated)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3915
@@ -79652,7 +79652,7 @@ CVE-2026-4629 (A flaw was found in Keycloak. A highly privileged user with `mana
CVE-2026-4360 (In the Tarfile.extract() function, the filter parameter is not passed ...)
- python3.14 3.14.7-1
- python3.13 3.13.15-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u5
- python3.11 <not-affected> (Vulnerable code didn't get backported to the version in Bookworm)
- python3.9 <not-affected> (extraction filters (PEP 706) absent in 3.9.2; extract() has no filter parameter)
- python2.7 <not-affected> (extraction filters (PEP 706) absent in py2; extract() has no filter parameter)
@@ -80444,14 +80444,14 @@ CVE-2026-46406 (Claude Code is an agentic coding tool. From 2.1.59 until 2.1.12
NOT-FOR-US: Claude Code
CVE-2026-41992 (GNU gzip contains a global buffer overflow vulnerability in the LZH de ...)
- gzip 1.14-1 (bug #1141443)
- [trixie] - gzip <no-dsa> (Minor issue)
+ [trixie] - gzip 1.13-1+deb13u1
[bookworm] - gzip <postponed> (Minor issue)
[bullseye] - gzip <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/23/1
NOTE: https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681
CVE-2026-41991 (GNU gzip contains a vulnerability in the gzexe utility related to inse ...)
- gzip 1.14-1 (bug #1141442)
- [trixie] - gzip <no-dsa> (Minor issue)
+ [trixie] - gzip 1.13-1+deb13u1
[bookworm] - gzip <postponed> (Minor issue)
[bullseye] - gzip <postponed> (Minor issue)
NOTE: https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269
@@ -80846,14 +80846,14 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-th
CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but ...)
{DLA-4773-1}
- libssh2 1.11.1-6 (bug #1144415)
- [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - libssh2 1.11.1-1+deb13u2
NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
NOTE: https://github.com/libssh2/libssh2/pull/2127
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...)
{DLA-4773-1}
- libssh2 1.11.1-6 (bug #1144415)
- [trixie] - libssh2 <no-dsa> (Minor issue; can be fixed via point release)
+ [trixie] - libssh2 1.11.1-1+deb13u2
NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
NOTE: https://github.com/libssh2/libssh2/pull/2128
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12
@@ -80877,7 +80877,7 @@ CVE-2026-10593 (The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-48002
- qemu 1:11.0.3+ds-1
- [trixie] - qemu <no-dsa> (Minor issue)
+ [trixie] - qemu 1:10.0.12+ds-0+deb13u1
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/00589953cc263ed8098fa9c0a007a9b04d470f85 (v11.0.2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/52155a6affd077f7e50fd0aca99a391d6e9e7066 (v11.0.2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/738927b263c7dcd14edff148826b28990b18ae46 (v11.0.3)
@@ -81153,7 +81153,7 @@ CVE-2026-31928 (The DMP-5000 devices are shipped with a default administrative w
NOT-FOR-US: Daktronics
CVE-2026-29509 (Patool before 4.0.5 contains a path traversal vulnerability in the saf ...)
- patool 4.0.5-0.1
- [trixie] - patool <no-dsa> (Minor issue)
+ [trixie] - patool 4.0.0-1+deb13u1
[bookworm] - patool <not-affected> (Vulnerable code introduced later)
[bullseye] - patool <not-affected> (Vulnerable code introduced later)
CVE-2026-28701 (Various versions of Daktronics Controller Firmware could allow authent ...)
@@ -81975,19 +81975,19 @@ CVE-2026-7531 (Use-after-free in PQC hybrid key-share handling. This is an incom
CVE-2026-7511 (PKCS7_verify signer confusion allows forged signatures, where the sign ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6731 (X.509 name constraint bypass via the Subject Common Name when treated ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10223 (v5.9.2-stable)
CVE-2026-6681 (The PKCS#7 decode path ignores the caller-supplied output buffer size ...)
{DLA-4683-1}
- wolfssl 5.9.2-1
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
CVE-2026-6679 (A heap buffer overflow could occur in the DTLS 1.3 ACK serialization p ...)
@@ -81999,13 +81999,13 @@ CVE-2026-6679 (A heap buffer overflow could occur in the DTLS 1.3 ACK serializat
CVE-2026-6678 (Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other R ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6450 (A CRL critical extension bypass exists in ParseCRL_Extensions where cr ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10239 (v5.9.2-stable)
CVE-2026-6412 (Certificate policy and RFC 8446 compliance concerns regarding the cont ...)
@@ -82017,7 +82017,7 @@ CVE-2026-6412 (Certificate policy and RFC 8446 compliance concerns regarding the
CVE-2026-6331 (HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-le ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext comparison only compares half of the ...)
@@ -82029,19 +82029,19 @@ CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext comparison only compares half of
CVE-2026-6329 (PKCS#12 MAC verification uses an attacker-controlled comparison length ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6325 (Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversiz ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10204 (v5.9.2-stable)
CVE-2026-6092 (When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fal ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10167 (v5.9.2-stable)
CVE-2026-57522 (Bitwarden Server before 2026.5.0 contains a JSON injection vulnerabili ...)
@@ -82061,12 +82061,12 @@ CVE-2026-55964 (Chain intermediate CA:TRUE without keyCertSign accepted as a sig
CVE-2026-55962 (TLS 1.3 post-handshake authentication (PHA) issue where a server could ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55960 (Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 ...)
- wolfssl 5.9.2-1 (bug #1140815)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
@@ -82369,7 +82369,7 @@ CVE-2026-6291 (Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When dec
CVE-2026-6094 (Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing craf ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140765)
- [trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10128 (v5.9.2-stable)
CVE-2026-6091 (Partial-chain certificate verification may accept chains that terminat ...)
@@ -82540,7 +82540,7 @@ CVE-2026-56129 (Generic IO & Memory Access driver for PCs provided by TOSHIBA CO
NOT-FOR-US: Dynabook Inc.
CVE-2026-56123 (socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer ove ...)
- socat 1.8.1.3-1
- [trixie] - socat <no-dsa> (Minor issue)
+ [trixie] - socat 1.8.0.3-1+deb13u1
[bookworm] - socat <not-affected> (SOCKS5 client (xio-socks5.c) introduced in 1.8.0.0)
[bullseye] - socat <not-affected> (SOCKS5 client (xio-socks5.c) introduced in 1.8.0.0)
CVE-2026-56122 (Winstone Servlet Engine through 0.9.10 contains a path traversal vulne ...)
@@ -82576,13 +82576,13 @@ CVE-2026-56005 (Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.
CVE-2026-55967 (AES-GCM encryption/decryption with extremely large cumulative single m ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140765)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10709 (v5.9.2-stable)
CVE-2026-55961 (wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) ...)
{DLA-4683-1}
- wolfssl 5.9.2-1 (bug #1140765)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55895 (Vim is an open source, command line text editor. Prior to 9.2.0663, a ...)
@@ -85853,7 +85853,7 @@ CVE-2026-11997 (The Bulk SEO Image plugin for WordPress is vulnerable to Cross-S
CVE-2026-11972 (When using the "tarfile" module with a file opened in "streaming mode" ...)
- python3.14 3.14.7-1
- python3.13 3.13.15-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u5
- python3.11 <removed>
[bookworm] - python3.11 <postponed> (Minor issue)
- python3.9 <removed>
@@ -86357,7 +86357,7 @@ CVE-2026-13007 (Tenable Identity Exposure contains multiple unauthenticated API
NOT-FOR-US: Tenable
CVE-2026-12969 (An out-of-bounds read vulnerability exists in dnsmasq's find_soa() fun ...)
- dnsmasq 2.93-1
- [trixie] - dnsmasq <no-dsa> (Minor issue)
+ [trixie] - dnsmasq 2.91-1+deb13u2
[bookworm] - dnsmasq <postponed> (Minor issue)
[bullseye] - dnsmasq <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2491663
@@ -86381,7 +86381,7 @@ CVE-2026-10521 (An high privileged remote attacker can access a hidden configura
CVE-2026-0864 (When using the "configparser" module to write configuration files cont ...)
- python3.14 3.14.7-1
- python3.13 3.13.15-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u5
- python3.11 <removed>
[bookworm] - python3.11 <postponed> (Minor issue)
- python3.9 <removed>
@@ -86504,7 +86504,7 @@ CVE-2026-44517 (Buildah is a tool that facilitates building OCI images. From 1.3
CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar' filter could be bypasse ...)
- python3.14 3.14.7-1
- python3.13 3.13.15-1
- [trixie] - python3.13 <no-dsa> (Minor issue)
+ [trixie] - python3.13 3.13.5-2+deb13u5
- python3.11 <removed>
[bookworm] - python3.11 <postponed> (Minor issue)
- python3.9 <removed>
@@ -87121,7 +87121,7 @@ CVE-2026-12862 (Untrusted user data was passed verbatim to Excel exports for adm
NOT-FOR-US: rami.io products
CVE-2026-12725 (A heap-based buffer overflow was found in dnsmasq. When DNSSEC validat ...)
- dnsmasq 2.93-1
- [trixie] - dnsmasq <no-dsa> (Minor issue)
+ [trixie] - dnsmasq 2.91-1+deb13u2
[bookworm] - dnsmasq <postponed> (Minor issue)
[bullseye] - dnsmasq <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490763
@@ -88119,7 +88119,7 @@ CVE-2025-15661 (libssh2 through 1.11.1, fixed in commit 2dae302, contains an out
NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/2dae3024897e1898d389835151f4e9606227721d
CVE-2026-55766 (guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. ...)
- php-guzzlehttp-psr7 2.12.1-1
- [trixie] - php-guzzlehttp-psr7 <no-dsa> (Minor issue)
+ [trixie] - php-guzzlehttp-psr7 2.7.1-1+deb13u2
[bookworm] - php-guzzlehttp-psr7 <postponed> (Minor issue; CR/LF accepted in method/protocol-version/reason-phrase)
[bullseye] - php-guzzlehttp-psr7 <postponed> (Minor issue; CR/LF accepted in method/protocol-version/reason-phrase)
NOTE: https://github.com/guzzle/psr7/security/advisories/GHSA-vm85-hxw5-5432
@@ -91449,12 +91449,12 @@ CVE-2026-53705 (A flaw was found in GStreamer's WavPack audio decoder in gst-plu
NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f7cb3e0288627cce919e656584b852ac8605c922 (1.28.4)
CVE-2026-12087 (Socket versions before 2.041 for Perl have an out-of-bounds heap read. ...)
- libsocket-perl 2.041-1 (bug #1146063)
- [trixie] - libsocket-perl <no-dsa> (Minor issue)
+ [trixie] - libsocket-perl 2.038-1+deb13u1
[bookworm] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
[bullseye] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
[experimental] - perl 5.44.0-1
- perl 5.42.3-1 (bug #1140152)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41020451/
NOTE: Fixed by: https://github.com/Perl/perl5/commit/de19a0b0ad1900fef976c5c1400bd8f11ec6c6cb (v5.43.11)
CVE-2026-11832 (Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to ...)
@@ -93261,7 +93261,7 @@ CVE-2026-53693 (A stored cross-site scripting vulnerability existed in MISPBSimV
CVE-2026-53689 (libnfs through 6.0.2 before 55c18ea does not validate a string size, l ...)
{DLA-4689-1}
- libnfs 5.0.2-1.1 (bug #1139731)
- [trixie] - libnfs <no-dsa> (Minor issue)
+ [trixie] - libnfs 5.0.2-1+deb13u1
NOTE: Fixed by: https://github.com/sahlberg/libnfs/commit/55c18ea33a83d667f79f0ef209c96895795c729f
CVE-2026-53476 (A flaw was found in assisted-migration-agent. An unauthenticated attac ...)
NOT-FOR-US: kubev2v/assisted-migration-agent
@@ -93511,13 +93511,13 @@ CVE-2024-58350 (Ghidra before 11.2 contains a use after free vulnerability in th
- ghidra <itp> (bug #923851)
CVE-2026-54706 (OnionShare is an open source tool that lets you securely and anonymous ...)
- onionshare 2.6.4-1 (bug #1139717)
- [trixie] - onionshare <no-dsa> (Minor issue)
+ [trixie] - onionshare 2.6.3-1+deb13u2
[bookworm] - onionshare <postponed> (Minor issue; requires sharing a directory containing untrusted symlinks)
[bullseye] - onionshare <postponed> (Minor issue; requires sharing a directory containing untrusted symlinks)
NOTE: https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf
CVE-2026-54707 (OnionShare is an open source tool that lets you securely and anonymous ...)
- onionshare 2.6.4-1 (bug #1139716)
- [trixie] - onionshare <no-dsa> (Minor issue)
+ [trixie] - onionshare 2.6.3-1+deb13u2
[bookworm] - onionshare <postponed> (Minor issue; policy bypass by a peer who already holds the onion address and key)
[bullseye] - onionshare <not-affected> (disable_files setting introduced in 2.6; 2.2 has no file-upload-disable feature to bypass)
NOTE: https://github.com/onionshare/onionshare/security/advisories/GHSA-v833-3823-cmhp
@@ -93855,14 +93855,14 @@ CVE-2026-11837 (A local privilege escalation vulnerability was found in the ansi
NOTE: Fixed by: https://github.com/ansible-collections/ansible.posix/commit/18f2f69c53ffe8014a3047ac8c523ae6671be63e
CVE-2026-11824 (SQLite before 3.53.2 contains a heap-based buffer overflow vulnerabili ...)
- sqlite3 3.53.2-1 (bug #1139960)
- [trixie] - sqlite3 <no-dsa> (Minor issue)
+ [trixie] - sqlite3 3.46.1-7+deb13u2
[bookworm] - sqlite3 <postponed> (Minor issue)
[bullseye] - sqlite3 <postponed> (Minor issue)
NOTE: https://sqlite.org/src/info/061febcf41ca
NOTE: https://sqlite.org/src/info/4a5ad516ea93
CVE-2026-11822 (SQLite before 3.53.2 contains memory corruption vulnerabilities in the ...)
- sqlite3 3.53.2-1 (bug #1139960)
- [trixie] - sqlite3 <no-dsa> (Minor issue)
+ [trixie] - sqlite3 3.46.1-7+deb13u2
[bookworm] - sqlite3 <postponed> (Minor issue)
[bullseye] - sqlite3 <postponed> (Minor issue)
NOTE: https://sqlite.org/src/info/061febcf41ca
@@ -96925,7 +96925,7 @@ CVE-2026-11333 (A security vulnerability has been detected in tittuvarghese Coll
NOT-FOR-US: tittuvarghese CollegeManagementSystem
CVE-2026-11332 (A flaw was found in ansible-core. The ansible-galaxy role install comm ...)
- ansible-core 2.21.1~rc1-1 (bug #1139175)
- [trixie] - ansible-core <no-dsa> (Minor issue)
+ [trixie] - ansible-core 2.19.11-0+deb13u1
[bookworm] - ansible-core <postponed> (Minor issue)
- ansible 5.4.0-1
[bookworm] - ansible <postponed> (Minor issue)
@@ -99215,21 +99215,21 @@ CVE-2026-XXXX [heap out-of-bounds write in fax backend on zero-length input]
NOTE: https://commits.kde.org/okular/466786c354d890e39a3871f80ed686958d2513a2
CVE-2026-49941 (Net::CIDR::Set versions through 0.20 for Perl did not validate IP addr ...)
- libnet-cidr-set-perl 0.21-1
- [trixie] - libnet-cidr-set-perl <no-dsa> (Minor issue)
+ [trixie] - libnet-cidr-set-perl 0.15-1+deb13u1
[bookworm] - libnet-cidr-set-perl <no-dsa> (Minor issue)
[bullseye] - libnet-cidr-set-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40702781/
NOTE: https://github.com/robrwo/perl-Net-CIDR-Set/commit/3a40b4c0d0e8ef996ccb7aee1d5f108187431c2b (0.21)
CVE-2026-49942 (Net::CIDR::Set versions through 0.20 for Perl did not validate network ...)
- libnet-cidr-set-perl 0.21-1
- [trixie] - libnet-cidr-set-perl <no-dsa> (Minor issue)
+ [trixie] - libnet-cidr-set-perl 0.15-1+deb13u1
[bookworm] - libnet-cidr-set-perl <no-dsa> (Minor issue)
[bullseye] - libnet-cidr-set-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40702816/
NOTE: https://github.com/robrwo/perl-Net-CIDR-Set/commit/875010b4217afe9a61cee519f0e0250847ecf699 (0.21)
CVE-2026-49940 (Net::CIDR::Set versions through 0.20 for Perl accept non-ASCII IP addr ...)
- libnet-cidr-set-perl 0.21-1
- [trixie] - libnet-cidr-set-perl <no-dsa> (Minor issue)
+ [trixie] - libnet-cidr-set-perl 0.15-1+deb13u1
[bookworm] - libnet-cidr-set-perl <no-dsa> (Minor issue)
[bullseye] - libnet-cidr-set-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40702749/
@@ -99890,7 +99890,7 @@ CVE-2026-10661 (A vulnerability has been found in ahujasid blender-mcp up to 763
NOT-FOR-US: ahujasid blender-mcp
CVE-2026-10650 (A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue ...)
- libwebsockets 4.3.5-5 (bug #1139178)
- [trixie] - libwebsockets <no-dsa> (Minor issue)
+ [trixie] - libwebsockets 4.3.5-1+deb13u2
[bookworm] - libwebsockets <no-dsa> (Minor issue)
[bullseye] - libwebsockets <postponed> (Minor issue)
NOTE: https://github.com/biniamf/pocs/tree/main/libwebsockets_sshd-parse-ic-unbounded-alloc
@@ -100146,7 +100146,7 @@ CVE-2026-39550 (Deserialization of Untrusted Data vulnerability in Elated-Themes
NOT-FOR-US: WordPress plugin or theme
CVE-2026-38978 (transmission through 4.1.1 was found to have a clickjacking weakness i ...)
- transmission 4.1.2+dfsg-1
- [trixie] - transmission <no-dsa> (Minor issue)
+ [trixie] - transmission 4.1.0~beta2+dfsg-3+deb13u2
[bookworm] - transmission <no-dsa> (Minor issue)
[bullseye] - transmission <postponed> (Minor issue)
NOTE: https://github.com/transmission/transmission/issues/8726
@@ -106999,33 +106999,33 @@ CVE-2026-46644 (Symfony Polyfill backports PHP features and provides compatibili
NOTE: https://github.com/symfony/polyfill/security/advisories/GHSA-2xf4-cg6j-vhgq
CVE-2026-48962 (IO::Compress versions before 2.220 for Perl can execute arbitrary code ...)
- libio-compress-perl 2.220-1 (bug #1138055)
- [trixie] - libio-compress-perl <no-dsa> (Minor issue)
+ [trixie] - libio-compress-perl 2.213-1+deb13u1
- perl 5.40.1-8 (bug #1138854)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40434385/
NOTE: Fixed by: https://github.com/pmqs/IO-Compress/commit/f2db247bf90d4cc7ee2710be384946081f3b4610 (v2.220)
CVE-2026-48961 (IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetai ...)
- libio-compress-perl 2.220-1 (bug #1138052)
- [trixie] - libio-compress-perl <no-dsa> (Minor issue)
+ [trixie] - libio-compress-perl 2.213-1+deb13u1
[bookworm] - libio-compress-perl <not-affected> (Vulnerable code introduced later)
[bullseye] - libio-compress-perl <not-affected> (Vulnerable code introduced later)
- perl 5.40.1-8 (bug #1138855)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40434383/
NOTE: Introduced with: https://github.com/pmqs/IO-Compress/commit/ddfe67584a228877e5d28840da75ff32e435a5e3 (v2.207)
NOTE: Fixed by: https://github.com/pmqs/IO-Compress/commit/33c89d03d6e746ed2ead4f2f6570d47864c61bc7 (v2.220)
CVE-2026-48959 (IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaust ...)
- libio-compress-perl 2.220-1 (bug #1138051)
- [trixie] - libio-compress-perl <no-dsa> (Minor issue)
+ [trixie] - libio-compress-perl 2.213-1+deb13u1
- perl 5.40.1-8 (bug #1138856)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40434381/
NOTE: Fixed by: https://github.com/pmqs/IO-Compress/commit/68db44076f4c1a86a2ffe53a958eac6cabaf72e2 (v2.220)
CVE-2025-15649 (IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaugh ...)
- libio-compress-perl 2.217-1 (bug #1146065)
- [trixie] - libio-compress-perl <no-dsa> (Minor issue)
+ [trixie] - libio-compress-perl 2.213-1+deb13u1
- perl 5.40.1-8 (bug #1138863)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40434380/
NOTE: https://github.com/pmqs/IO-Compress/issues/65
NOTE: Fixed by: https://github.com/pmqs/IO-Compress/commit/fd28c1d2374eee9811f6d0c5bddc0957abdf1da8 (v2.215)
@@ -107688,14 +107688,14 @@ CVE-2026-9538 (Archive::Tar versions before 3.10 for Perl allow memory exhaustio
CVE-2026-42497 (Archive::Tar versions before 3.08 for Perl extract hardlinks to attack ...)
[experimental] - perl 5.44.0-1
- perl 5.42.3-1 (bug #1138859)
- [trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
+ [trixie] - perl 5.40.1-6+deb13u1
[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396457/
NOTE: https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158 (3.08)
CVE-2026-42496 (Archive::Tar versions before 3.08 for Perl extract symlinks with attac ...)
[experimental] - perl 5.44.0-1
- perl 5.42.3-1 (bug #1138860)
- [trixie] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
+ [trixie] - perl 5.40.1-6+deb13u1
[bookworm] - perl <postponed> (Minor issue; wait for regressions upstream sorted out)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/40396459/
NOTE: https://github.com/jib/archive-tar-new/commit/17c873492a05eddc0de18c1485e0b2cccd5a9158 (3.08)
@@ -107834,7 +107834,7 @@ CVE-2026-5223 (Cargo incorrectly handled symlinks inside of crate tarballs downl
[bookworm] - rust-cargo <no-dsa> (Minor issue)
[bullseye] - rust-cargo <postponed> (Minor issue)
- rustc 1.95.0+dfsg1-2
- [trixie] - rustc <no-dsa> (Minor issue)
+ [trixie] - rustc 1.85.1+dfsg1-1+deb13u1
[bookworm] - rustc <no-dsa> (Minor issue)
[bullseye] - rustc <postponed> (Minor issue)
NOTE: https://groups.google.com/g/rustlang-security-announcements/c/IB74S7Yksg8
@@ -107849,7 +107849,7 @@ CVE-2026-5222 (Cargo between 1.68 and 1.96 incorrectly normalized the URLs of th
[bookworm] - rust-cargo <no-dsa> (Minor issue)
[bullseye] - rust-cargo <postponed> (Minor issue)
- rustc 1.95.0+dfsg1-2
- [trixie] - rustc <no-dsa> (Minor issue)
+ [trixie] - rustc 1.85.1+dfsg1-1+deb13u1
[bookworm] - rustc <no-dsa> (Minor issue)
[bullseye] - rustc <postponed> (Minor issue)
NOTE: https://groups.google.com/g/rustlang-security-announcements/c/SfUxOiIdY5s
@@ -108837,7 +108837,7 @@ CVE-2026-5091 (Catalyst::Plugin::Authentication versions through 0.10024 for Per
NOTE: https://github.com/perl-catalyst/Catalyst-Plugin-Authentication/commit/b0515f492257438cf07082acf1e10d06e8088a5e (v0.10_025)
CVE-2026-8376 (Perl versions before 5.40.5-RC1, from 5.41.0 before 5.42.3-RC1, from 5 ...)
- perl 5.40.1-8 (bug #1137345)
- [trixie] - perl <no-dsa> (Minor issue; can be fixed in point release)
+ [trixie] - perl 5.40.1-6+deb13u1
[bookworm] - perl <no-dsa> (Minor issue; can be fixed in point release)
[bullseye] - perl <postponed> (Minor issue; can be fixed in point release)
NOTE: https://github.com/Perl/perl5/pull/24433
@@ -110748,7 +110748,7 @@ CVE-2026-8843 (Creating a "2dsphere_bucket" index on a non-timeseries bucket col
NOTE: https://jira.mongodb.org/browse/SERVER-116327
CVE-2026-8836 (A vulnerability was found in lwIP up to 2.2.1. Affected is the functio ...)
- lwip 2.2.1+dfsg1-5 (bug #1137526)
- [trixie] - lwip <no-dsa> (Minor issue)
+ [trixie] - lwip 2.2.1+dfsg1-1+deb13u1
[bookworm] - lwip <no-dsa> (Minor issue)
[bullseye] - lwip <postponed> (Minor issue)
NOTE: https://savannah.nongnu.org/bugs/?68194
@@ -115349,10 +115349,10 @@ CVE-2026-0502 (Due to insufficient CSRF protection in SAP BusinessObjects Busine
NOT-FOR-US: SAP
CVE-2026-7010 (HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP ...)
- libhttp-tiny-perl 0.092-2 (bug #1146064)
- [trixie] - libhttp-tiny-perl <no-dsa> (Minor issue)
+ [trixie] - libhttp-tiny-perl 0.090-1+deb13u1
[bookworm] - libhttp-tiny-perl <no-dsa> (Minor issue)
- perl 5.40.1-8 (bug #1138858)
- [trixie] - perl <no-dsa> (Minor issue)
+ [trixie] - perl 5.40.1-6+deb13u1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/39952806/
NOTE: Fixed by: https://github.com/Perl-Toolchain-Gang/HTTP-Tiny/commit/d73c7651e82ace02693842df55928b6c3ae7c38d (release-0.093)
CVE-2026-6146 (Amazon::Credentials versions through 1.2.0 for Perl uses rand to gener ...)
@@ -115793,7 +115793,7 @@ CVE-2026-5084 (WebDyne::Session versions before 3.003_704 for Perl generate the
NOT-FOR-US: WebDyne::Session Perl module
CVE-2026-8276 (A flaw has been found in bettercap up to 2.41.5. Affected by this issu ...)
- bettercap 2.33.0-3 (bug #1136448)
- [trixie] - bettercap <no-dsa> (Minor issue)
+ [trixie] - bettercap 2.33.0-1+deb13u1
[bookworm] - bettercap <no-dsa> (Minor issue)
NOTE: https://github.com/bettercap/bettercap/issues/1265
NOTE: https://github.com/bettercap/bettercap/commit/0eaa375c5e5446bfba94a290eff92967a5deac9e (v2.41.7)
@@ -120677,7 +120677,7 @@ CVE-2026-44405 (In Paramiko through 4.0.0 before a448945, rsakey.py allows the S
NOTE: https://github.com/paramiko/paramiko/commit/a4489456b6f65281e172380cc4826cee5e851dbb
CVE-2026-44331 (In ProFTPD through 1.3.9a before 7666224, a SQL injection vulnerabilit ...)
- proftpd-dfsg 1.3.9a~dfsg-1 (bug #1135840)
- [trixie] - proftpd-dfsg <no-dsa> (Minor issue)
+ [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
[bookworm] - proftpd-dfsg <no-dsa> (Minor issue)
NOTE: https://github.com/proftpd/proftpd/issues/2057
NOTE: https://github.com/proftpd/proftpd/commit/766622456440fbca33abd7927c523673a11d1ed1
@@ -124890,7 +124890,7 @@ CVE-2026-7183 (A vulnerability has been found in aligungr UERANSIM up to 3.2.7.
NOT-FOR-US: aligungr UERANSIM
CVE-2026-7179 (A security vulnerability has been detected in OSPG binwalk up to 2.4.3 ...)
- binwalk 2.4.3+dfsg1-3 (bug #1136010)
- [trixie] - binwalk <no-dsa> (Minor issue)
+ [trixie] - binwalk 2.4.3+dfsg1-2+deb13u1
[bookworm] - binwalk <no-dsa> (Minor issue)
[bullseye] - binwalk <no-dsa> (Minor issue)
NOTE: https://github.com/dhabaleshwar/Open-Source-Vulnerabilities/blob/main/binwalk_path_traversal.md
@@ -129790,7 +129790,7 @@ CVE-2026-5358
REJECTED
CVE-2026-5450 (Calling the scanf family of functions with a %mc (malloc'd character m ...)
- glibc 2.42-17 (bug #1134543)
- [trixie] - glibc <no-dsa> (Minor issue)
+ [trixie] - glibc 2.41-12+deb13u4
[bookworm] - glibc <no-dsa> (Minor issue)
[bullseye] - glibc <postponed> (Minor issue)
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34008
@@ -129800,7 +129800,7 @@ CVE-2026-5450 (Calling the scanf family of functions with a %mc (malloc'd charac
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34008#c2
CVE-2026-5928 (Calling the ungetwc function on a FILE stream with wide characters enc ...)
- glibc 2.42-17 (bug #1134544)
- [trixie] - glibc <no-dsa> (Minor issue)
+ [trixie] - glibc 2.41-12+deb13u4
[bookworm] - glibc <no-dsa> (Minor issue)
[bullseye] - glibc <postponed> (Minor issue)
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=33998
@@ -130764,7 +130764,7 @@ CVE-2026-40255 (AdonisJS HTTP Server is a package for handling HTTP requests in
NOT-FOR-US: AdonisJS HTTP Server
CVE-2026-40253 (openCryptoki is a PKCS#11 library and provides tooling for Linux and A ...)
- opencryptoki 3.27.0-1 (bug #1136019)
- [trixie] - opencryptoki <no-dsa> (Minor issue)
+ [trixie] - opencryptoki 3.23.0+dfsg-0.3+deb13u1
[bookworm] - opencryptoki <no-dsa> (Minor issue)
[bullseye] - opencryptoki <postponed> (Minor issue; can be fixed in next update)
NOTE: https://github.com/opencryptoki/opencryptoki/security/advisories/GHSA-c9cf-6vr4-wfxm
@@ -134055,7 +134055,7 @@ CVE-2026-5263 (URI nameConstraints from constrained intermediate CAs are parsed
CVE-2026-5194 (Missing hash/digest size and OID checks allow digests smaller than all ...)
{DLA-4683-1}
- wolfssl 5.9.1-0.1 (bug #1133835)
- [trixie] - wolfssl <no-dsa> (Minor issue)
+ [trixie] - wolfssl 5.7.2-0.1+deb13u2
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10131
NOTE: Fixed by (merge): https://github.com/wolfSSL/wolfssl/commit/53a3d23ce67086861344711225667f14d794812f (v5.9.1-stable)
@@ -136634,13 +136634,13 @@ CVE-2026-27314 (Privilege escalationin Apache Cassandra 5.0 on an mTLS environme
CVE-2026-24660 (A heap-based buffer overflow vulnerability exists in the x3f_load_huff ...)
{DLA-4704-1}
- libraw 0.22.1-1 (bug #1133845)
- [trixie] - libraw <no-dsa> (Minor issue)
+ [trixie] - libraw 0.21.4-2+deb13u1
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2359
NOTE: https://github.com/LibRaw/LibRaw/commit/a4a0ab69d286c7638741e70a11f04fb3d7b49db2
NOTE: https://github.com/LibRaw/LibRaw/commit/ac151a829b8d3e4c74fa3aefa8a029c3cc3f857f (0.22.1)
CVE-2026-24450 (An integer overflow vulnerability exists in the uncompressed_fp_dng_lo ...)
- libraw 0.22.1-1 (bug #1133845)
- [trixie] - libraw <no-dsa> (Minor issue)
+ [trixie] - libraw 0.21.4-2+deb13u1
[bookworm] - libraw <not-affected> (Vulnerable code not present)
[bullseye] - libraw <not-affected> (Vulnerable code not present)
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2363
@@ -136677,7 +136677,7 @@ CVE-2026-22666 (Dolibarr ERP/CRM versions prior to 23.0.2 contain an authenticat
CVE-2026-21413 (A heap-based buffer overflow vulnerability exists in the lossless_jpeg ...)
{DLA-4704-1}
- libraw 0.22.1-1 (bug #1133845)
- [trixie] - libraw <no-dsa> (Minor issue)
+ [trixie] - libraw 0.21.4-2+deb13u1
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2331
NOTE: https://github.com/LibRaw/LibRaw/commit/32c7b783de262f21fa5e3f58a59031edf23ab3cb
NOTE: https://github.com/LibRaw/LibRaw/commit/75ed2c12a35b765b3b6ad695cc1f044f19efe644 (0.22.1)
@@ -136693,14 +136693,14 @@ CVE-2026-20911 (A heap-based buffer overflow vulnerability exists in the HuffTab
CVE-2026-20889 (A heap-based buffer overflow vulnerability exists in the x3f_thumb_loa ...)
{DLA-4704-1}
- libraw 0.22.1-1 (bug #1133845)
- [trixie] - libraw <no-dsa> (Minor issue)
+ [trixie] - libraw 0.21.4-2+deb13u1
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2358
NOTE: https://github.com/LibRaw/LibRaw/commit/657b68d20456eaeb9639976f328827195ff41383
NOTE: https://github.com/LibRaw/LibRaw/commit/b9809e410d07ca7bf408e6d036615fb34f8c47cc (0.22.1)
CVE-2026-20884 (An integer overflow vulnerability exists in the deflate_dng_load_raw f ...)
{DLA-4704-1}
- libraw 0.22.1-1 (bug #1133845)
- [trixie] - libraw <no-dsa> (Minor issue)
+ [trixie] - libraw 0.21.4-2+deb13u1
NOTE: https://talosintelligence.com/vulnerability_reports/TALOS-2026-2364
NOTE: https://github.com/LibRaw/LibRaw/commit/39873163faa29ed5dfc3bb5aab1b46ed807b210f
NOTE: https://github.com/LibRaw/LibRaw/commit/aa4458eb511daeae90676c1ce5c587106e4aaec1 (0.22.1)
@@ -136865,11 +136865,11 @@ CVE-2026-35448 (WWBN AVideo is an open source video platform. In versions 26.0 a
NOT-FOR-US: WWBN AVideo
CVE-2026-35444 (SDL_image is a library to load images of various formats as SDL surfac ...)
- libsdl2-image 2.8.10+dfsg-1 (bug #1133010)
- [trixie] - libsdl2-image <no-dsa> (Minor issue)
+ [trixie] - libsdl2-image 2.8.8+dfsg-1+deb13u1
[bookworm] - libsdl2-image <no-dsa> (Minor issue)
[bullseye] - libsdl2-image <postponed> (Minor issue)
- libsdl3-image 3.4.2+ds-1 (bug #1133011)
- [trixie] - libsdl3-image <no-dsa> (Minor issue)
+ [trixie] - libsdl3-image 3.2.4+ds-1+deb13u1
- sdl-image1.2 <unfixed> (bug #1133012)
[trixie] - sdl-image1.2 <no-dsa> (Minor issue)
[bookworm] - sdl-image1.2 <no-dsa> (Minor issue)
@@ -138722,7 +138722,7 @@ CVE-2026-5344 (A security vulnerability has been detected in Textpattern up to 4
CVE-2026-5342 (A flaw has been found in LibRaw up to 0.22.0. This affects the functio ...)
{DLA-4704-1}
- libraw 0.22.1-1 (bug #1132655)
- [trixie] - libraw <no-dsa> (Minor issue)
+ [trixie] - libraw 0.21.4-2+deb13u1
NOTE: https://github.com/LibRaw/LibRaw/issues/795
NOTE: Fixed by: https://github.com/LibRaw/LibRaw/commit/b8397cd45657b84e88bd1202528d1764265f185c
NOTE: Fixed by: https://github.com/LibRaw/LibRaw/commit/2468614a9cbcab6b75ca279ab60cac62156f7aeb (0.22.1)
@@ -138830,7 +138830,7 @@ CVE-2026-34877 (An issue was discovered in Mbed TLS versions from 2.19.0 up to 3
NOTE: Fixed by clarified documentation.
CVE-2026-34876 (An issue was discovered in Mbed TLS 3.x before 3.6.6. An out-of-bounds ...)
- mbedtls 3.6.6-0.1 (bug #1132577)
- [trixie] - mbedtls <no-dsa> (Minor issue)
+ [trixie] - mbedtls 3.6.6-0.1~deb13u1
[bookworm] - mbedtls <no-dsa> (Minor issue)
[bullseye] - mbedtls <not-affected> (Vulnerable code not present)
NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ccm-finish-boundary-check/
@@ -139390,12 +139390,12 @@ CVE-2026-3882
REJECTED
CVE-2026-34873 (An issue was discovered in Mbed TLS 3.5.0 through 4.0.0. Client impers ...)
- mbedtls 3.6.6-0.1 (bug #1132577)
- [trixie] - mbedtls <no-dsa> (Minor issue)
+ [trixie] - mbedtls 3.6.6-0.1~deb13u1
[bookworm] - mbedtls <no-dsa> (Minor issue)
NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-client-impersonation-while-resuming-tls13-session/
CVE-2026-34872 (An issue was discovered in Mbed TLS 3.5.x and 3.6.x through 3.6.5 and ...)
- mbedtls 3.6.6-0.1 (bug #1132577)
- [trixie] - mbedtls <no-dsa> (Minor issue)
+ [trixie] - mbedtls 3.6.6-0.1~deb13u1
[bookworm] - mbedtls <no-dsa> (Minor issue)
NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ffdh-peerkey-checks/
CVE-2026-34750 (Payload is a free and open source headless content management system. ...)
@@ -139643,12 +139643,12 @@ CVE-2026-34889 (Improper Neutralization of Input During Web Page Generation ('Cr
NOT-FOR-US: WordPress plugin or theme
CVE-2026-34875 (An issue was discovered in Mbed TLS through 3.6.5 and TF-PSA-Crypto 1. ...)
- mbedtls 3.6.6-0.1 (bug #1132577)
- [trixie] - mbedtls <no-dsa> (Minor issue)
+ [trixie] - mbedtls 3.6.6-0.1~deb13u1
[bookworm] - mbedtls <no-dsa> (Minor issue)
NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-ffdh-buffer-overflow/
CVE-2026-34874 (An issue was discovered in Mbed TLS through 3.6.5 and 4.x through 4.0. ...)
- mbedtls 3.6.6-0.1 (bug #1132577)
- [trixie] - mbedtls <no-dsa> (Minor issue)
+ [trixie] - mbedtls 3.6.6-0.1~deb13u1
[bookworm] - mbedtls <no-dsa> (Minor issue)
NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-null-pointer-dereference-x509/
CVE-2026-34871 (An issue was discovered in Mbed TLS before 3.6.6 and 4.x before 4.1.0 ...)
@@ -139752,12 +139752,12 @@ CVE-2026-27101 (Dell Secure Connect Gateway (SCG) 5.0 Appliance and Application
NOT-FOR-US: Dell / EMC
CVE-2026-25835 (Mbed TLS before 3.6.6 and TF-PSA-Crypto before 1.1.0 misuse seeds in a ...)
- mbedtls 3.6.6-0.1 (bug #1133841)
- [trixie] - mbedtls <no-dsa> (Minor issue)
+ [trixie] - mbedtls 3.6.6-0.1~deb13u1
[bookworm] - mbedtls <no-dsa> (Minor issue)
NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-rng-cloning/
CVE-2026-25834 (Mbed TLS v3.3.0 up to 3.6.5 and 4.0.0 allows Algorithm Downgrade.)
- mbedtls 3.6.6-0.1 (bug #1133841)
- [trixie] - mbedtls <no-dsa> (Minor issue)
+ [trixie] - mbedtls 3.6.6-0.1~deb13u1
[bookworm] - mbedtls <not-affected> (Vulnerable code introduced later)
[bullseye] - mbedtls <not-affected> (Vulnerable code introduced later)
NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-03-sigalg-injection/
@@ -139999,7 +139999,7 @@ CVE-2026-4818 (In Search Guard FLX versions from 3.0.0 up to 4.0.1, there exists
CVE-2026-4800 (Impact: The fix for CVE-2021-23337 (https://github.com/advisories/GHS ...)
{DLA-4663-1}
- node-lodash 4.18.1+dfsg-1 (bug #1132500)
- [trixie] - node-lodash <no-dsa> (Minor issue)
+ [trixie] - node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1
[bookworm] - node-lodash <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/lodash/lodash/commit/879aaa93132d78c2f8d20c60279da9f8b21576d6 (4.18.0)
NOTE: Followup for tests: https://github.com/lodash/lodash/commit/af634573030f979194871da7c68f79420992f53d (4.18.0)
@@ -140407,7 +140407,7 @@ CVE-2026-30276 (An arbitrary file overwrite vulnerability in DeftPDF Document Tr
CVE-2026-2950 (Impact: Lodash versions 4.17.23 and earlier are vulnerable to prototy ...)
{DLA-4663-1}
- node-lodash 4.18.1+dfsg-1
- [trixie] - node-lodash <no-dsa> (Minor issue)
+ [trixie] - node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1
[bookworm] - node-lodash <no-dsa> (Minor issue)
NOTE: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg
NOTE: https://github.com/lodash/lodash/commit/edadd452146f7e4bad4ea684e955708931d84d81 (4.17.23)
@@ -141618,7 +141618,7 @@ CVE-2026-33937 (Handlebars provides the power necessary to let users build seman
NOTE: https://github.com/handlebars-lang/handlebars.js/commit/68d8df5a88e0a26fe9e6084c5c6aaebe67b07da2 (v4.7.9)
CVE-2026-33936 (The `ecdsa` PyPI package is a pure Python implementation of ECC (Ellip ...)
- python-ecdsa 0.19.2-1 (bug #1132164)
- [trixie] - python-ecdsa <no-dsa> (Minor issue)
+ [trixie] - python-ecdsa 0.19.1-1+deb13u1
[bookworm] - python-ecdsa <no-dsa> (Minor issue)
[bullseye] - python-ecdsa <postponed> (Minor issue)
NOTE: https://github.com/tlsfuzzer/python-ecdsa/security/advisories/GHSA-9f5j-8jwj-x28g
@@ -143667,7 +143667,7 @@ CVE-2026-33515 (Squid is a caching proxy for the Web. Prior to version 7.5, due
NOTE: Fxied by: https://github.com/squid-cache/squid/commit/8138e909d2058d4401e0ad49b583afaec912b165 (SQUID_7_5)
CVE-2026-32748 (Squid is a caching proxy for the Web. Prior to version 7.5, due to pre ...)
- squid 7.5-1
- [trixie] - squid <no-dsa> (Minor issue)
+ [trixie] - squid 6.13-2+deb13u3
[bookworm] - squid <no-dsa> (Minor issue)
[bullseye] - squid <postponed> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/03/25/3
@@ -146382,7 +146382,7 @@ CVE-2026-33251 (Discourse is an open-source discussion platform. Prior to versio
CVE-2026-46728 (Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verif ...)
{DLA-4642-1}
- u-boot 2025.01-3.2 (bug #1136954)
- [trixie] - u-boot <no-dsa> (Minor issue)
+ [trixie] - u-boot 2025.01-3+deb13u1
NOTE: Fixed by: https://github.com/u-boot/u-boot/commit/2092322b31cc8b1f8c9e2e238d1043ae0637b241 (v2026.04-rc4)
CVE-2026-33243 (barebox is a bootloader. In barebox from version 2016.03.0 to before v ...)
- barebox <itp> (bug #900958)
@@ -147168,7 +147168,7 @@ CVE-2026-33057 (Mesop is a Python-based UI framework that allows users to build
NOT-FOR-US: Mesop
CVE-2026-33056 (tar-rs is a tar archive reading/writing library for Rust. In versions ...)
- rustc 1.92.0+dfsg1-2
- [trixie] - rustc <no-dsa> (Minor issue)
+ [trixie] - rustc 1.85.1+dfsg1-1+deb13u1
[bookworm] - rustc <postponed> (Minor issue, parsing inconsistencies among tar libraries, requires recompiling rdeps)
[bullseye] - rustc <postponed> (Minor issue, parsing inconsistencies among tar libraries, requires recompiling rdeps)
- rust-tar 0.4.45-1 (bug #1131481)
@@ -147180,7 +147180,7 @@ CVE-2026-33056 (tar-rs is a tar archive reading/writing library for Rust. In ver
NOTE: Fixed by: https://github.com/alexcrichton/tar-rs/commit/17b1fd84e632071cb8eef9d3709bf347bd266446 (0.4.45)
CVE-2026-33055 (tar-rs is a tar archive reading/writing library for Rust. Versions 0.4 ...)
- rustc 1.92.0+dfsg1-2 (bug #1135225)
- [trixie] - rustc <no-dsa> (Minor issue)
+ [trixie] - rustc 1.85.1+dfsg1-1+deb13u1
[bookworm] - rustc <postponed> (Minor issue, path traversal, requires recompiling rdeps)
[bullseye] - rustc <postponed> (Minor issue, path traversal, requires recompiling rdeps)
- rust-tar 0.4.45-1 (bug #1131480)
@@ -159250,7 +159250,7 @@ CVE-2026-27210 (Pannellum is a lightweight, free, and open source panorama viewe
NOT-FOR-US: Pannellum
CVE-2026-27205 (Flask is a web server gateway interface (WSGI) web application framewo ...)
- flask 3.1.3-1 (bug #1128620)
- [trixie] - flask <no-dsa> (Minor issue)
+ [trixie] - flask 3.1.1-1+deb13u1
[bookworm] - flask <no-dsa> (Minor issue)
[bullseye] - flask <postponed> (Minor issue, hard to trigger)
NOTE: https://github.com/pallets/flask/security/advisories/GHSA-68rp-wp8r-4726
@@ -168702,7 +168702,7 @@ CVE-2026-25210 (In libexpat before 2.7.4, the doContent function does not proper
CVE-2026-25068 (alsa-lib versions 1.2.2 up to and including 1.2.15.2, prior to commit ...)
{DLA-4469-1}
- alsa-lib 1.2.16-1 (bug #1126629)
- [trixie] - alsa-lib <no-dsa> (Minor issue)
+ [trixie] - alsa-lib 1.2.14-1+deb13u1
[bookworm] - alsa-lib <no-dsa> (Minor issue)
NOTE: Introduced by: https://github.com/alsa-project/alsa-lib/commit/b6c9afb4f59bb678dc834028680d579f47dc273b (v1.2.2)
NOTE: Fixed by: https://github.com/alsa-project/alsa-lib/commit/5f7fe33002d2d98d84f72e381ec2cccc0d5d3d40 (v1.2.16)
@@ -171480,7 +171480,7 @@ CVE-2026-23946 (Tendenci is an open source content management system built for n
NOT-FOR-US: Tendenci CMS
CVE-2026-23893 (openCryptoki is a PKCS#11 library and provides tooling for Linux and A ...)
- opencryptoki 3.27.0-1 (bug #1126268)
- [trixie] - opencryptoki <no-dsa> (Minor issue)
+ [trixie] - opencryptoki 3.23.0+dfsg-0.3+deb13u1
[bookworm] - opencryptoki <no-dsa> (Minor issue)
[bullseye] - opencryptoki <postponed> (Minor issue)
NOTE: https://github.com/opencryptoki/opencryptoki/security/advisories/GHSA-j6c7-mvpx-jx5q
@@ -172353,7 +172353,7 @@ CVE-2025-13878 (Malformed BRID/HHIT records can cause `named` to terminate unexp
CVE-2025-13465 (Lodash versions 4.0.0 through 4.17.22 are vulnerable to prototype poll ...)
{DLA-4663-1}
- node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-10 (bug #1126265)
- [trixie] - node-lodash <no-dsa> (Minor issue)
+ [trixie] - node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1
[bookworm] - node-lodash <no-dsa> (Minor issue)
NOTE: https://github.com/lodash/lodash/security/advisories/GHSA-xxjr-mmjv-4gpg
CVE-2025-12781 (When passing data to the b64decode(), standard_b64decode(), and urlsaf ...)
@@ -340116,7 +340116,7 @@ CVE-2024-42364 (Homepage is a highly customizable homepage with Docker and servi
CVE-2024-42040 (Buffer Overflow vulnerability in the net/bootp.c in DENEX U-Boot from ...)
{DLA-4642-1}
- u-boot 2025.01-3.2 (bug #1081557)
- [trixie] - u-boot <postponed> (Minor issue, revisit when fixed upstream)
+ [trixie] - u-boot 2025.01-3+deb13u1
NOTE: https://lists.denx.de/pipermail/u-boot/2024-August/562528.html
NOTE: https://www.schutzwerk.com/advisories/SCHUTZWERK-SA-2024-004.txt
NOTE: Fixed by: https://github.com/u-boot/u-boot/commit/81e5708cc2c865df606e49aed5415adb2a662171 (v2026.01-rc1)
@@ -817939,7 +817939,7 @@ CVE-2018-0500 (Curl_smtp_escape_eob in lib/smtp.c in curl 7.54.1 to and includin
NOTE: https://curl.haxx.se/docs/adv_2018-70a2.html
CVE-2026-77643 (A cross-site scripting vulnerability in queryparser/termgenerator_int ...)
- xapian-core 1.4.32-1 (bug #1144490)
- [trixie] - xapian-core <no-dsa> (Minor issue)
+ [trixie] - xapian-core 1.4.29-3+deb13u1
[bookworm] - xapian-core <postponed> (Minor issue)
NOTE: https://lists.xapian.org/pipermail/xapian-devel/2026-August/003429.html
NOTE: https://trac.xapian.org/wiki/SecurityFixes/2018-07-02#a2026-08-13update
=====================================
data/next-point-update.txt
=====================================
@@ -1,435 +1,3 @@
-CVE-2026-11822
- [trixie] - sqlite3 3.46.1-7+deb13u2
-CVE-2026-11824
- [trixie] - sqlite3 3.46.1-7+deb13u2
-CVE-2025-13465
- [trixie] - node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1
-CVE-2026-2950
- [trixie] - node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1
-CVE-2026-4800
- [trixie] - node-lodash 4.17.21+dfsg+~cs8.31.198.20210220-9+deb13u1
-CVE-2026-27205
- [trixie] - flask 3.1.1-1+deb13u1
-CVE-2026-35444
- [trixie] - libsdl2-image 2.8.8+dfsg-1+deb13u1
-CVE-2026-5194
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-55960
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-55961
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-55962
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-55967
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6092
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6094
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6325
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6329
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6331
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6450
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6678
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6681
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-6731
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-7511
- [trixie] - wolfssl 5.7.2-0.1+deb13u2
-CVE-2026-8836
- [trixie] - lwip 2.2.1+dfsg1-1+deb13u1
-CVE-2026-25834
- [trixie] - mbedtls 3.6.6-0.1~deb13u1
-CVE-2026-25835
- [trixie] - mbedtls 3.6.6-0.1~deb13u1
-CVE-2026-34872
- [trixie] - mbedtls 3.6.6-0.1~deb13u1
-CVE-2026-34873
- [trixie] - mbedtls 3.6.6-0.1~deb13u1
-CVE-2026-34874
- [trixie] - mbedtls 3.6.6-0.1~deb13u1
-CVE-2026-34875
- [trixie] - mbedtls 3.6.6-0.1~deb13u1
-CVE-2026-34876
- [trixie] - mbedtls 3.6.6-0.1~deb13u1
-CVE-2026-55766
- [trixie] - php-guzzlehttp-psr7 2.7.1-1+deb13u2
-CVE-2026-49940
- [trixie] - libnet-cidr-set-perl 0.15-1+deb13u1
-CVE-2026-49941
- [trixie] - libnet-cidr-set-perl 0.15-1+deb13u1
-CVE-2026-49942
- [trixie] - libnet-cidr-set-perl 0.15-1+deb13u1
-CVE-2026-33936
- [trixie] - python-ecdsa 0.19.1-1+deb13u1
-CVE-2026-11332
- [trixie] - ansible-core 2.19.11-0+deb13u1
-CVE-2026-25068
- [trixie] - alsa-lib 1.2.14-1+deb13u1
-CVE-2024-42040
- [trixie] - u-boot 2025.01-3+deb13u1
-CVE-2026-46728
- [trixie] - u-boot 2025.01-3+deb13u1
-CVE-2026-5928
- [trixie] - glibc 2.41-12+deb13u4
-CVE-2026-5450
- [trixie] - glibc 2.41-12+deb13u4
-CVE-2026-29509
- [trixie] - patool 4.0.0-1+deb13u1
-CVE-2026-54707
- [trixie] - onionshare 2.6.3-1+deb13u2
-CVE-2026-54706
- [trixie] - onionshare 2.6.3-1+deb13u2
-CVE-2026-56362
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-56366
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-56372
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-56373
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-56374
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-56375
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61464
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61465
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61857
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61858
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61859
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61860
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61861
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61862
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61863
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61864
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61865
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61866
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61867
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61868
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61869
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61870
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61871
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-61872
- [trixie] - imagemagick 8:7.1.1.43+dfsg1-1+deb13u12
-CVE-2026-53689
- [trixie] - libnfs 5.0.2-1+deb13u1
-CVE-2026-33055
- [trixie] - rustc 1.85.1+dfsg1-1+deb13u1
-CVE-2026-33056
- [trixie] - rustc 1.85.1+dfsg1-1+deb13u1
-CVE-2026-5222
- [trixie] - rustc 1.85.1+dfsg1-1+deb13u1
-CVE-2026-5223
- [trixie] - rustc 1.85.1+dfsg1-1+deb13u1
-CVE-2026-50003
- [trixie] - dcmtk 3.6.9-5+deb13u3
-CVE-2026-50254
- [trixie] - dcmtk 3.6.9-5+deb13u3
-CVE-2026-35505
- [trixie] - dcmtk 3.6.9-5+deb13u3
-CVE-2026-52868
- [trixie] - dcmtk 3.6.9-5+deb13u3
-CVE-2026-44628
- [trixie] - dcmtk 3.6.9-5+deb13u3
-CVE-2026-58459
- [trixie] - gpsd 3.25-5+deb13u2
-CVE-2026-60122
- [trixie] - gpsd 3.25-5+deb13u2
-CVE-2026-8348
- [trixie] - qemu 1:10.0.12+ds-0+deb13u1
-CVE-2026-9238
- [trixie] - qemu 1:10.0.12+ds-0+deb13u1
-CVE-2026-15578
- [trixie] - qemu 1:10.0.12+ds-0+deb13u1
-CVE-2026-15705
- [trixie] - qemu 1:10.0.12+ds-0+deb13u1
-CVE-2026-16043
- [trixie] - qemu 1:10.0.12+ds-0+deb13u1
-CVE-2026-48002
- [trixie] - qemu 1:10.0.12+ds-0+deb13u1
-CVE-2026-61475
- [trixie] - qemu 1:10.0.12+ds-0+deb13u1
-CVE-2026-63319
- [trixie] - qemu 1:10.0.12+ds-0+deb13u1
-CVE-2026-44331
- [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
-CVE-2026-53994
- [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
-CVE-2026-63091
- [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
-CVE-2026-63090
- [trixie] - proftpd-dfsg 1.3.8.c+dfsg-4+deb13u3
-CVE-2026-5342
- [trixie] - libraw 0.21.4-2+deb13u1
-CVE-2026-20884
- [trixie] - libraw 0.21.4-2+deb13u1
-CVE-2026-20889
- [trixie] - libraw 0.21.4-2+deb13u1
-CVE-2026-21413
- [trixie] - libraw 0.21.4-2+deb13u1
-CVE-2026-24450
- [trixie] - libraw 0.21.4-2+deb13u1
-CVE-2026-24660
- [trixie] - libraw 0.21.4-2+deb13u1
-CVE-2026-47084
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-47086
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-47087
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-47081
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-47089
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-47085
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-47083
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-47088
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-47082
- [trixie] - cyrus-imapd 3.10.2-1+deb13u2
-CVE-2026-8276
- [trixie] - bettercap 2.33.0-1+deb13u1
-CVE-2026-14258
- [trixie] - dhcpcd 1:10.1.0-11+deb13u4
-CVE-2026-58010
- [trixie] - glib2.0 2.84.4-3~deb13u4
-CVE-2026-58011
- [trixie] - glib2.0 2.84.4-3~deb13u4
-CVE-2026-58012
- [trixie] - glib2.0 2.84.4-3~deb13u4
-CVE-2026-58013
- [trixie] - glib2.0 2.84.4-3~deb13u4
-CVE-2026-58014
- [trixie] - glib2.0 2.84.4-3~deb13u4
-CVE-2026-58015
- [trixie] - glib2.0 2.84.4-3~deb13u4
-CVE-2026-15588
- [trixie] - glib2.0 2.84.4-3~deb13u4
-CVE-2026-58016
- [trixie] - glib2.0 2.84.4-3~deb13u4
-CVE-2026-16118
- [trixie] - glib2.0 2.84.4-3~deb13u5
-CVE-2026-6879
- [trixie] - python3.13 3.13.5-2+deb13u5
-CVE-2026-0864
- [trixie] - python3.13 3.13.5-2+deb13u5
-CVE-2026-4360
- [trixie] - python3.13 3.13.5-2+deb13u5
-CVE-2026-11940
- [trixie] - python3.13 3.13.5-2+deb13u5
-CVE-2026-11972
- [trixie] - python3.13 3.13.5-2+deb13u5
-CVE-2026-77643
- [trixie] - xapian-core 1.4.29-3+deb13u1
-CVE-2026-55777
- [trixie] - goaccess 1:1.9.3-1+deb13u1
-CVE-2026-54715
- [trixie] - goaccess 1:1.9.3-1+deb13u1
-CVE-2026-55768
- [trixie] - goaccess 1:1.9.3-1+deb13u1
-CVE-2026-72694
- [trixie] - mrtg 2.17.10-13+deb13u2
-CVE-2026-66032
- [trixie] - libssh2 1.11.1-1+deb13u2
-CVE-2026-66033
- [trixie] - libssh2 1.11.1-1+deb13u2
-CVE-2026-66034
- [trixie] - libssh2 1.11.1-1+deb13u2
-CVE-2026-66035
- [trixie] - libssh2 1.11.1-1+deb13u2
-CVE-2026-58050
- [trixie] - libssh2 1.11.1-1+deb13u2
-CVE-2026-58051
- [trixie] - libssh2 1.11.1-1+deb13u2
-CVE-2026-19654
- [trixie] - rsyslog 8.2504.0-1+deb13u1
-CVE-2026-78002
- [trixie] - rsyslog 8.2504.0-1+deb13u2
-CVE-2026-61548
- [trixie] - rsyslog 8.2504.0-1+deb13u2
-CVE-2026-35444
- [trixie] - libsdl3-image 3.2.4+ds-1+deb13u1
-CVE-2026-41991
- [trixie] - gzip 1.13-1+deb13u1
-CVE-2026-41992
- [trixie] - gzip 1.13-1+deb13u1
-CVE-2026-59884
- [trixie] - pyasn1 0.6.1-1+deb13u3
-CVE-2026-59885
- [trixie] - pyasn1 0.6.1-1+deb13u3
-CVE-2026-59886
- [trixie] - pyasn1 0.6.1-1+deb13u3
-CVE-2026-10650
- [trixie] - libwebsockets 4.3.5-1+deb13u2
-CVE-2026-78161
- [trixie] - libwebsockets 4.3.5-1+deb13u2
-CVE-2026-81523
- [trixie] - libmongocrypt 1.13.2-1+deb13u1
-CVE-2026-81524
- [trixie] - mongo-c-driver 1.30.4-1+deb13u3
-CVE-2026-18054
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-15264
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-17516
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-66021
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-65928
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-65929
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-50626
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-16457
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-50624
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-66022
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-61402
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-63110
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-63323
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-61476
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-63320
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-63321
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-63322
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-63109
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-63318
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-16288
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-61404
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-61405
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-61406
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-58582
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-58581
- [trixie] - qemu 1:10.0.13+ds-0+deb13u1
-CVE-2026-7179
- [trixie] - binwalk 2.4.3+dfsg1-2+deb13u1
-CVE-2026-18917
- [trixie] - libvirt 11.3.0-3+deb13u3
-CVE-2026-61477
- [trixie] - libvirt 11.3.0-3+deb13u3
-CVE-2026-61478
- [trixie] - libvirt 11.3.0-3+deb13u3
-CVE-2026-63622
- [trixie] - libvirt 11.3.0-3+deb13u3
-CVE-2026-63623
- [trixie] - libvirt 11.3.0-3+deb13u3
-CVE-2026-40253
- [trixie] - opencryptoki 3.23.0+dfsg-0.3+deb13u1
-CVE-2026-23893
- [trixie] - opencryptoki 3.23.0+dfsg-0.3+deb13u1
-CVE-2026-58264
- [trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
-CVE-2026-61714
- [trixie] - fluidsynth 2.4.4+dfsg-1+deb13u3
-CVE-2026-7017
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-42496
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-42497
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-12087
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-13221
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2025-15649
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-7010
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-8376
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-48959
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-48961
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-48962
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-57432
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-57433
- [trixie] - perl 5.40.1-6+deb13u1
-CVE-2026-7010
- [trixie] - libhttp-tiny-perl 0.090-1+deb13u1
-CVE-2026-7017
- [trixie] - libhttp-tiny-perl 0.090-1+deb13u1
-CVE-2025-15649
- [trixie] - libio-compress-perl 2.213-1+deb13u1
-CVE-2026-48959
- [trixie] - libio-compress-perl 2.213-1+deb13u1
-CVE-2026-48961
- [trixie] - libio-compress-perl 2.213-1+deb13u1
-CVE-2026-48962
- [trixie] - libio-compress-perl 2.213-1+deb13u1
-CVE-2026-12087
- [trixie] - libsocket-perl 2.038-1+deb13u1
-CVE-2026-12725
- [trixie] - dnsmasq 2.91-1+deb13u2
-CVE-2026-12969
- [trixie] - dnsmasq 2.91-1+deb13u2
-CVE-2026-89162
- [trixie] - pcre2 10.46-1~deb13u2
-CVE-2026-89161
- [trixie] - pcre2 10.46-1~deb13u2
-CVE-2026-89158
- [trixie] - pcre2 10.46-1~deb13u2
-CVE-2026-89160
- [trixie] - pcre2 10.46-1~deb13u2
-CVE-2026-89157
- [trixie] - pcre2 10.46-1~deb13u2
-CVE-2026-86145
- [trixie] - pcre2 10.46-1~deb13u2
-CVE-2026-89156
- [trixie] - pcre2 10.46-1~deb13u2
-CVE-2026-81500
- [trixie] - incus 6.0.4-2+deb13u10
-CVE-2026-81501
- [trixie] - incus 6.0.4-2+deb13u10
-CVE-2026-38978
- [trixie] - transmission 4.1.0~beta2+dfsg-3+deb13u2
-CVE-2026-56123
- [trixie] - socat 1.8.0.3-1+deb13u1
-CVE-2026-32748
- [trixie] - squid 6.13-2+deb13u3
CVE-2026-13401
[trixie] - libxml-bare-perl 0.53-4+deb13u1
CVE-2026-57074
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/bbf0919e8adc909649f6ef4cadf0ad89cd5d1f29...4b2a32ed414adb3b010749eeb7270e2c505c3615
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/bbf0919e8adc909649f6ef4cadf0ad89cd5d1f29...4b2a32ed414adb3b010749eeb7270e2c505c3615
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/0a56a25a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list