[Git][security-tracker-team/security-tracker][master] 2 commits: CVE-2024-58382/php-league-commonmark: bookworm postponed
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Tue Sep 15 14:17:24 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b11176d9 by Sylvain Beucler at 2026-09-15T13:34:32+02:00
CVE-2024-58382/php-league-commonmark: bookworm postponed
Just an old CVE popping up in our tooling because it was fixed in unstable before trixie was published.
- - - - -
4ebfb703 by Sylvain Beucler at 2026-09-15T13:34:35+02:00
pypdf2: bookworm postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5842,6 +5842,7 @@ CVE-2025-3271 (Documentum Webtop versions prior to 16.7.1 software is vulnerable
NOT-FOR-US: OpenText
CVE-2024-58382 (league/commonmark versions before 2.6.0 contain polynomial time comple ...)
- php-league-commonmark 2.6.0-1
+ [bookworm] - php-league-commonmark <postponed> (Minor issue, DoS)
NOTE: https://github.com/thephpleague/commonmark/security/advisories/GHSA-c2pc-g5qf-rfrf
CVE-2024-58381 (PocketMine-MP before 5.11.1 contains a denial of service vulnerability ...)
NOT-FOR-US: PocketMine-MP
@@ -14469,6 +14470,7 @@ CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior t
[trixie] - pypdf <no-dsa> (Minor issue)
[bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue, DoS)
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
NOTE: https://github.com/py-pdf/pypdf/pull/3964
NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/c9ba557d565d57c53a0b3a0be06c0a4c29b0559b (6.16.0)
@@ -14908,6 +14910,7 @@ CVE-2026-84311 (pypdf is a free and open-source pure-python PDF library. Prior t
[trixie] - pypdf <no-dsa> (Minor issue)
[bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue, DoS)
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-763m-79hh-57f2
NOTE: https://github.com/py-pdf/pypdf/pull/3966
NOTE: https://github.com/py-pdf/pypdf/commit/d91ab705fd81ed1a9cec175c6958600dea1a4942 (6.16.1)
@@ -14916,6 +14919,7 @@ CVE-2026-84310 (pypdf is a free and open-source pure-python PDF library. Prior t
[trixie] - pypdf <no-dsa> (Minor issue)
[bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue, DoS)
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-23w6-3w8w-8484
NOTE: https://github.com/py-pdf/pypdf/pull/3966
NOTE: https://github.com/py-pdf/pypdf/commit/d91ab705fd81ed1a9cec175c6958600dea1a4942 (6.16.1)
@@ -15930,6 +15934,7 @@ CVE-2026-82398 (pypdf is a free and open-source pure-python PDF library. Prior t
[trixie] - pypdf <no-dsa> (Minor issue)
[bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue, DoS)
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fc8x-2rww-xw9m
NOTE: https://github.com/py-pdf/pypdf/pull/3947
NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/4959848e057e37c218dccad7465259210923faaa (6.15.0)
@@ -47362,6 +47367,7 @@ CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior t
[trixie] - pypdf <no-dsa> (Minor issue)
[bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue, DoS)
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
NOTE: https://github.com/py-pdf/pypdf/pull/3944
NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/afba8080e19d29a3c256a742b340995e695b35aa (6.15.0)
@@ -47370,6 +47376,7 @@ CVE-2026-71852 (pypdf is a free and open-source pure-python PDF library. Prior t
[trixie] - pypdf <no-dsa> (Minor issue)
[bookworm] - pypdf <postponed> (Minor issue)
- pypdf2 <removed>
+ [bookworm] - pypdf2 <postponed> (Minor issue, DoS)
NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fwg2-594c-jp42
NOTE: https://github.com/py-pdf/pypdf/pull/3946
NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/51cb6acf9e8a35b77e90b4d87d28fe3e1416d7d7 (6.15.0)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00...4ebfb703b27d44263ed019f7fae07a498f9eb72b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00...4ebfb703b27d44263ed019f7fae07a498f9eb72b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/4303107a/attachment.htm>
More information about the debian-security-tracker-commits
mailing list