[Git][security-tracker-team/security-tracker][master] Track fixes for logback issues via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 13 07:32:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
458854ad by Salvatore Bonaccorso at 2026-09-13T08:31:36+02:00
Track fixes for logback issues via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -36534,7 +36534,7 @@ CVE-2026-1621 (Authentication bypass by primary weakness vulnerability in Univer
 CVE-2026-19884 (In Eclipse Theia versions up to and including 1.69.0, opening a folder ...)
 	NOT-FOR-US: Eclipse
 CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (l ...)
-	- logback <unfixed> (bug #1146719)
+	- logback 1:1.6.3-1 (bug #1146719)
 	[trixie] - logback <no-dsa> (Minor issue)
 	NOTE: https://logback.qos.ch/news.html#1.6.3
 CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP response ...)
@@ -85955,7 +85955,7 @@ CVE-2026-39253 (An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to
 CVE-2026-23513 (FOSSBilling is a free, open-source billing and client management syste ...)
 	NOT-FOR-US: FOSSBilling
 CVE-2026-13006 (ACE vulnerability in conditional configuration file processing  by QOS ...)
-	- logback <unfixed> (bug #1140922)
+	- logback 1:1.6.3-1 (bug #1140922)
 	[trixie] - logback <no-dsa> (Minor issue)
 	NOTE: https://logback.qos.ch/news.html#1.5.35
 CVE-2026-12892 (A flaw was found in GStreamer's gst-plugins-bad package. When processi ...)
@@ -101114,7 +101114,7 @@ CVE-2026-20452 (In wlan AP driver, there is a possible memory corruption due to
 CVE-2026-10533 (A flaw was found in OpenShift Container Platform. Completed pods with  ...)
 	NOT-FOR-US: OpenShift
 CVE-2026-10532 (Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...)
-	- logback <unfixed> (bug #1139180)
+	- logback 1:1.6.3-1 (bug #1139180)
 	[trixie] - logback <no-dsa> (Minor issue)
 	[bookworm] - logback <no-dsa> (Minor issue)
 	[bullseye] - logback <postponed> (minor issue)
@@ -103204,7 +103204,7 @@ CVE-2026-42305 (Dulwich is a pure-Python implementation of the Git file formats
 	- dulwich <not-affected> (Windows-specific)
 	NOTE: https://github.com/jelmer/dulwich/security/advisories/GHSA-897w-fcg9-f6xj
 CVE-2026-9828 (Deserialization of untrusted data vulnerability in QOS.CH Sarl logback ...)
-	- logback <unfixed> (bug #1138632)
+	- logback 1:1.6.3-1 (bug #1138632)
 	[trixie] - logback <no-dsa> (Minor issue)
 	[bookworm] - logback <no-dsa> (Minor issue)
 	[bullseye] - logback <postponed> (Minor issue)
@@ -171811,7 +171811,7 @@ CVE-2026-1324 (A vulnerability was identified in Sangfor Operation and Maintenan
 CVE-2026-1260 (Invalid memory access in Sentencepiece versions less than 0.2.1 when u ...)
 	NOT-FOR-US: Sentencepiece
 CVE-2026-1225 (ACE vulnerability in configuration file processing  by QOS.CH logback- ...)
-	- logback <unfixed> (unimportant; bug #1126748)
+	- logback 1:1.6.3-1 (unimportant; bug #1126748)
 	NOTE: https://logback.qos.ch/news.html#1.5.25
 	NOTE: Does not cross any reasonable security boundary
 CVE-2026-1036 (The Photo Gallery by 10Web \u2013 Mobile-Friendly Image Gallery plugin ...)
@@ -214884,7 +214884,7 @@ CVE-2025-11233 (Starting from Rust 1.87.0 and before Rust 1.89.0, the tier 3 Cyg
 	[bullseye] - rustc <not-affected> (Introduced in 1.87)
 	NOTE: https://groups.google.com/g/rustlang-security-announcements/c/oT9zCvLLYkw
 CVE-2025-11226 (ACE vulnerability in conditional configuration file processing  by QOS ...)
-	- logback <unfixed> (bug #1140922)
+	- logback 1:1.6.3-1 (bug #1140922)
 	[trixie] - logback <no-dsa> (Minor issue)
 	NOTE: https://logback.qos.ch/news.html#1.5.19
 	NOTE: Fixed by: https://github.com/qos-ch/logback/commit/61f6a2544f36b3016e0efd434ee21f19269f1df7 (v_1.5.19)
@@ -308705,14 +308705,14 @@ CVE-2024-38864 (Incorrect permissions on the Checkmk Windows Agent's data direct
 CVE-2024-37962 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
 	NOT-FOR-US: Agency Dominion Fusion
 CVE-2024-12801 (Server-Side Request Forgery (SSRF) in SaxEventRecorder by QOS.CH logba ...)
-	- logback <unfixed> (bug #1091320)
+	- logback 1:1.6.3-1 (bug #1091320)
 	[trixie] - logback <no-dsa> (Minor issue)
 	[bookworm] - logback <no-dsa> (Minor issue)
 	[bullseye] - logback <postponed> (Minor issue; can be fixed in next update)
 	NOTE: https://logback.qos.ch/news.html#1.5.13
 	NOTE: Fixed by: https://github.com/qos-ch/logback/commit/5f05041cba4c4ac0a62748c5c527a2da48999f2d (v_1.5.13)
 CVE-2024-12798 (ACE vulnerability in JaninoEventEvaluator  by QOS.CH logback-core      ...)
-	- logback <unfixed> (bug #1091319)
+	- logback 1:1.6.3-1 (bug #1091319)
 	[trixie] - logback <no-dsa> (Minor issue)
 	[bookworm] - logback <no-dsa> (Minor issue)
 	[bullseye] - logback <postponed> (Minor issue; can be fixed in next update)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/458854ad2d2bfee87ca3464371a07d1671d790a5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/458854ad2d2bfee87ca3464371a07d1671d790a5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260913/de93bfc2/attachment.htm>


More information about the debian-security-tracker-commits mailing list