[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-58382/php-league-commonmark: bookworm postponed

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Tue Sep 15 14:17:24 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b11176d9 by Sylvain Beucler at 2026-09-15T13:34:32+02:00
CVE-2024-58382/php-league-commonmark: bookworm postponed

Just an old CVE popping up in our tooling because it was fixed in unstable before trixie was published.

- - - - -
4ebfb703 by Sylvain Beucler at 2026-09-15T13:34:35+02:00
pypdf2: bookworm postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -5842,6 +5842,7 @@ CVE-2025-3271 (Documentum Webtop versions prior to 16.7.1 software is vulnerable
 	NOT-FOR-US: OpenText
 CVE-2024-58382 (league/commonmark versions before 2.6.0 contain polynomial time comple ...)
 	- php-league-commonmark 2.6.0-1
+	[bookworm] - php-league-commonmark <postponed> (Minor issue, DoS)
 	NOTE: https://github.com/thephpleague/commonmark/security/advisories/GHSA-c2pc-g5qf-rfrf
 CVE-2024-58381 (PocketMine-MP before 5.11.1 contains a denial of service vulnerability ...)
 	NOT-FOR-US: PocketMine-MP
@@ -14469,6 +14470,7 @@ CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior t
 	[trixie] - pypdf <no-dsa> (Minor issue)
 	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
+	[bookworm] - pypdf2 <postponed> (Minor issue, DoS)
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
 	NOTE: https://github.com/py-pdf/pypdf/pull/3964
 	NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/c9ba557d565d57c53a0b3a0be06c0a4c29b0559b (6.16.0)
@@ -14908,6 +14910,7 @@ CVE-2026-84311 (pypdf is a free and open-source pure-python PDF library. Prior t
 	[trixie] - pypdf <no-dsa> (Minor issue)
 	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
+	[bookworm] - pypdf2 <postponed> (Minor issue, DoS)
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-763m-79hh-57f2
 	NOTE: https://github.com/py-pdf/pypdf/pull/3966
 	NOTE: https://github.com/py-pdf/pypdf/commit/d91ab705fd81ed1a9cec175c6958600dea1a4942 (6.16.1)
@@ -14916,6 +14919,7 @@ CVE-2026-84310 (pypdf is a free and open-source pure-python PDF library. Prior t
 	[trixie] - pypdf <no-dsa> (Minor issue)
 	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
+	[bookworm] - pypdf2 <postponed> (Minor issue, DoS)
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-23w6-3w8w-8484
 	NOTE: https://github.com/py-pdf/pypdf/pull/3966
 	NOTE: https://github.com/py-pdf/pypdf/commit/d91ab705fd81ed1a9cec175c6958600dea1a4942 (6.16.1)
@@ -15930,6 +15934,7 @@ CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior t
 	[trixie] - pypdf <no-dsa> (Minor issue)
 	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
+	[bookworm] - pypdf2 <postponed> (Minor issue, DoS)
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m
 	NOTE: https://github.com/py-pdf/pypdf/pull/3947
 	NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/4959848e057e37c218dccad7465259210923faaa (6.15.0)
@@ -47362,6 +47367,7 @@ CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior t
 	[trixie] - pypdf <no-dsa> (Minor issue)
 	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
+	[bookworm] - pypdf2 <postponed> (Minor issue, DoS)
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
 	NOTE: https://github.com/py-pdf/pypdf/pull/3944
 	NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/afba8080e19d29a3c256a742b340995e695b35aa (6.15.0)
@@ -47370,6 +47376,7 @@ CVE-2026-71852 (pypdf is a free and open-source pure-python PDF library. Prior t
 	[trixie] - pypdf <no-dsa> (Minor issue)
 	[bookworm] - pypdf <postponed> (Minor issue)
 	- pypdf2 <removed>
+	[bookworm] - pypdf2 <postponed> (Minor issue, DoS)
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fwg2-594c-jp42
 	NOTE: https://github.com/py-pdf/pypdf/pull/3946
 	NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/51cb6acf9e8a35b77e90b4d87d28fe3e1416d7d7 (6.15.0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00...4ebfb703b27d44263ed019f7fae07a498f9eb72b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00...4ebfb703b27d44263ed019f7fae07a498f9eb72b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/4303107a/attachment.htm>


More information about the debian-security-tracker-commits mailing list