[Git][security-tracker-team/security-tracker][master] 4 commits: lts: golang-* bookworm postponed/limited (6 CVEs)
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Thu Sep 17 00:13:02 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
42be2fc4 by Sylvain Beucler at 2026-09-17T01:12:45+02:00
lts: golang-* bookworm postponed/limited (6 CVEs)
- - - - -
cafdc52b by Sylvain Beucler at 2026-09-17T01:12:48+02:00
lts: tidy libsoup3/libsoup2.4 (10 CVEs)
- - - - -
ff2e39d1 by Sylvain Beucler at 2026-09-17T01:12:51+02:00
lts: rust-*: follow no-dsa triage (7 CVEs)
- - - - -
aeb3ebf4 by Sylvain Beucler at 2026-09-17T01:12:51+02:00
lts: add network-manager-fortisslvpn
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -3782,10 +3782,12 @@ CVE-2026-80217 (Hidden functionality issue exists in FF-RFI079I4 and FF-RFI078I4
CVE-2026-79705 (A flaw was found in the buildah/copier Go package. When used outside o ...)
- golang-github-containers-buildah <unfixed>
[trixie] - golang-github-containers-buildah <no-dsa> (Minor issue)
+ [bookworm] - golang-github-containers-buildah <postponed> (Limited support, minor issue, uncommon use case)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523419
CVE-2026-79699 (A flaw was found in the containers/storage library. A crafted tar arch ...)
- golang-github-containers-storage <unfixed>
[trixie] - golang-github-containers-storage <no-dsa> (Minor issue)
+ [bookworm] - golang-github-containers-storage <postponed> (Limited support, minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523408
CVE-2026-79551 (Tenda Technology Co., Ltd NVR_4H CH3 v2.1 V27.5.58.6 was discovered to ...)
NOT-FOR-US: Tenda
@@ -5910,6 +5912,7 @@ CVE-2026-85892 (Concurrent execution using shared resource with improper synchro
NOT-FOR-US: Microsoft
CVE-2026-84445 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and ...)
- golang-google-grpc <unfixed>
+ [bookworm] - golang-google-grpc <postponed> (Limited support, minor issue; DoS, clean crash)
NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj
NOTE: https://github.com/grpc/grpc-go/issues/9354
NOTE: https://github.com/grpc/grpc-go/pull/9365
@@ -9656,6 +9659,7 @@ CVE-2026-88032 (A use-after-free in the reactive client-side encryption componen
CVE-2026-88031 (Improper neutralization of special elements in data query logic in the ...)
- golang-mongodb-mongo-driver <unfixed> (bug #1147410)
[trixie] - golang-mongodb-mongo-driver <no-dsa> (Minor issue)
+ [bookworm] - golang-mongodb-mongo-driver <postponed> (Limited support, minor issue)
NOTE: https://jira.mongodb.org/browse/GODRIVER-4081
NOTE: Fixed by: https://github.com/mongodb/mongo-go-driver/commit/806e132f9501a2665d05ebaba3b6f0d787ceaa96 (v1.17.10)
CVE-2026-88030 (Improper neutralization of special elements in data query logic in the ...)
@@ -16086,8 +16090,8 @@ CVE-2026-85538 (An incorrect authorization vulnerability in MISP allowed authent
CVE-2026-85534 (A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...)
- libsoup3 <unfixed> (bug #1146878)
[trixie] - libsoup3 <no-dsa> (Minor issue)
- - libsoup2.4 <removed>
- [trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup3 <postponed> (Minor issue)
+ - libsoup2.4 <not-affected> (HTTP/2 support introduced in libsoup3)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/551
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/561
CVE-2026-85533 (An authorization flaw in MISP allowed an authenticated user to submit ...)
@@ -16118,8 +16122,8 @@ CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper neutralization of input
CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...)
- libsoup3 <unfixed> (bug #1146877)
[trixie] - libsoup3 <no-dsa> (Minor issue)
- - libsoup2.4 <removed>
- [trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup3 <postponed> (Minor issue)
+ - libsoup2.4 <not-affected> (HTTP/2 support introduced in libsoup3)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/552
CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
NOT-FOR-US: fastify/middie
@@ -19942,7 +19946,7 @@ CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior
CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
- golang-google-grpc <unfixed> (bug #1146639)
[trixie] - golang-google-grpc <no-dsa> (Minor issue)
- [bookworm] - golang-google-grpc <postponed> (Limited support)
+ [bookworm] - golang-google-grpc <postponed> (Limited support, minor issue; OOM DoS)
NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc
NOTE: https://github.com/grpc/grpc-go/pull/9331
NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/7354d9c8debb4bcf2225bf429857078de310c176 (master)
@@ -19951,7 +19955,7 @@ CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83
CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ...)
- golang-google-grpc <unfixed> (bug #1146639)
[trixie] - golang-google-grpc <no-dsa> (Minor issue)
- [bookworm] - golang-google-grpc <postponed> (Limited support)
+ [bookworm] - golang-google-grpc <postponed> (Limited support, minor issue)
NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3
NOTE: https://github.com/grpc/grpc-go/pull/9332
NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/db9482836c298f234c896cf82ab68cafc78237f8 (master)
@@ -27605,9 +27609,10 @@ CVE-2026-77693 (The Order Tip for WooCommerce WordPress plugin before 1.6.0 does
CVE-2026-77680 (An algorithmic complexity flaw exists in libsoup's HTTP Range header p ...)
- libsoup3 <unfixed> (bug #1145785)
[trixie] - libsoup3 <no-dsa> (Minor issue)
- [bookworm] - libsoup3 <postponed> (Limited support)
+ [bookworm] - libsoup3 <postponed> (Minor issue, DoS)
- libsoup2.4 <removed>
[trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <postponed> (Minor issue, DoS)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/538
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
CVE-2026-77585 (The Okta Privileged Access client does not reject a leading hyphen in ...)
@@ -31692,9 +31697,10 @@ CVE-2026-77019 (A vulnerability was determined in CodeAstro Apartment Visitor Ma
CVE-2026-77014 (A flaw was found in libsoup's SoupServer HTTP Range header processing. ...)
- libsoup3 <unfixed> (bug #1144976)
[trixie] - libsoup3 <no-dsa> (Minor issue)
- [bookworm] - libsoup3 <postponed> (Limited support)
+ [bookworm] - libsoup3 <postponed> (Minor issue, DoS)
- libsoup2.4 <removed>
[trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <postponed> (Minor issue, DoS)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/e82c13ba03defcee10f981ac964f4d570b21a251
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/6ece9e52d918cefa1e99b5f359a22b111bdced75
@@ -43626,6 +43632,7 @@ CVE-2026-XXXX [RUSTSEC-2025-0167]
CVE-2026-XXXX [RUSTSEC-2026-0213]
- rust-ammonia 4.1.4-1
[trixie] - rust-ammonia <no-dsa> (Minor issue)
+ [bookworm] - rust-ammonia <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0213.html
CVE-2026-XXXX [RUSTSEC-2026-0223]
- rust-wasmtime <not-affected> (Only affects 46.0.0 and later)
@@ -43636,6 +43643,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0222]
CVE-2026-XXXX [RUSTSEC-2026-0244]
- rust-gettext-rs <unfixed> (bug #1144394)
[trixie] - rust-gettext-rs <no-dsa> (Minor issue)
+ [bookworm] - rust-gettext-rs <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0244.html
NOTE: https://github.com/gettext-rs/gettext-rs/issues/64
CVE-2026-XXXX [RUSTSEC-2026-0218]
@@ -43645,6 +43653,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0218]
CVE-2026-XXXX [RUSTSEC-2026-0221]
- rust-event-listener 5.4.2+ds-1 (bug #1144395)
[trixie] - rust-event-listener <no-dsa> (Minor issue)
+ [bookworm] - rust-event-listener <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0221.html
NOTE: https://github.com/smol-rs/event-listener/pull/163
CVE-2026-12876
@@ -43665,6 +43674,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0257]
CVE-2026-XXXX [RUSTSEC-2026-0253]
- rust-lru <unfixed> (bug #1144397)
[trixie] - rust-lru <no-dsa> (Minor issue)
+ [bookworm] - rust-lru <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
NOTE: https://github.com/jeromefroe/lru-rs/pull/238
NOTE: https://github.com/jeromefroe/lru-rs/commit/2776ded569ee89a99c515bca8194f65639182c96 (0.18.2)
@@ -43675,6 +43685,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0256]
CVE-2026-XXXX [RUSTSEC-2026-0255]
- rust-sized-chunks <unfixed> (bug #1144399)
[trixie] - rust-sized-chunks <no-dsa> (Minor issue)
+ [bookworm] - rust-sized-chunks <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0255.html
CVE-2026-8715 (Vault Secrets Operator 1.3.0 up to 1.4.1 is vulnerable to an arbitrary ...)
NOT-FOR-US: Vault Secrets Operator
@@ -52069,6 +52080,7 @@ CVE-2026-19266 (A vulnerability was determined in Kirachon context-engine up to
CVE-2026-XXXX [RUSTSEC-2026-0235]
- rust-rkyv 0.8.17-1
[trixie] - rust-rkyv <no-dsa> (Minor issue)
+ [bookworm] - rust-rkyv <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0235.html
CVE-2026-XXXX [RUSTSEC-2026-0233]
- rust-rkyv 0.8.17-1
@@ -55533,6 +55545,7 @@ CVE-2026-15307 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 befo
CVE-2026-XXXX [RUSTSEC-2026-0204]
- rust-crossbeam-epoch 0.9.20-1
[trixie] - rust-crossbeam-epoch <no-dsa> (Minor issue)
+ [bookworm] - rust-crossbeam-epoch <postponed> (Limited support, minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0204.html
NOTE: https://github.com/crossbeam-rs/crossbeam/pull/1276
CVE-2026-8508 (An improper authentication vulnerability in the "social_login.cgi" CGI ...)
@@ -64165,25 +64178,28 @@ CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated a
CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is established thr ...)
- libsoup3 <unfixed> (bug #1142846)
[trixie] - libsoup3 <no-dsa> (Minor issue)
- [bookworm] - libsoup3 <postponed> (Limited support)
+ [bookworm] - libsoup3 <postponed> (Minor issue)
- libsoup2.4 <removed>
[trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506951
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/534
CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding parser uses ...)
- libsoup3 <unfixed> (bug #1142845)
[trixie] - libsoup3 <no-dsa> (Minor issue)
- [bookworm] - libsoup3 <postponed> (Limited support)
+ [bookworm] - libsoup3 <ignored> (Limited support, server unsupported)
- libsoup2.4 <removed>
[trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <ignored> (Limited support, server unsupported)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506950
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/533
CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in the soup ...)
- libsoup3 <unfixed> (bug #1142844)
[trixie] - libsoup3 <no-dsa> (Minor issue)
- [bookworm] - libsoup3 <postponed> (Limited support)
+ [bookworm] - libsoup3 <postponed> (Minor issue)
- libsoup2.4 <removed>
[trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506949
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/532
CVE-2026-66041 (FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a heap out ...)
@@ -69236,16 +69252,20 @@ CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor Temp
CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...)
- libsoup3 <unfixed> (bug #1142838)
[trixie] - libsoup3 <no-dsa> (Minor issue)
+ [bookworm] - libsoup3 <postponed> (Minor issue, OOB read)
- libsoup2.4 <removed>
[trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <postponed> (Minor issue, OOB read)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/512
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/524
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/commit/7334c38f1f6aa5e64207cb415cf2509838c52b37 (3.7.1)
CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without scopin ...)
- libsoup3 <unfixed> (bug #1142837)
[trixie] - libsoup3 <no-dsa> (Minor issue)
+ [bookworm] - libsoup3 <postponed> (Minor issue, credentials leak between trusted proxies)
- libsoup2.4 <removed>
[trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <postponed> (Minor issue, credentials leak between trusted proxies)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...)
NOT-FOR-US: zenml
@@ -77023,6 +77043,7 @@ CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implement
[trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499941
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/541
+ NOTE: While the above issue references this CVE, it doesn't match the CVE description at all.
CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in libsoup's (ver ...)
- libsoup3 <unfixed> (bug #1142841)
[trixie] - libsoup3 <no-dsa> (Minor issue)
=====================================
data/dla-needed.txt
=====================================
@@ -418,6 +418,10 @@ netty (rouca)
NOTE: 20260114: fix remaining CVE wait DSA (rouca)
NOTE: 20260331: release DLA-4519-1 netty. Unfortunatly partial due to new CVEs (rouca)
--
+network-manager-fortisslvpn
+ NOTE: 20260917: Added by Front-Desk (Beuc)
+ NOTE: 20260917: LPE; package only present in LTS (Beuc/front-desk)
+--
network-manager-l2tp
NOTE: 20260915: Added by Front-Desk (Beuc)
NOTE: 20260915: Follow DSA-6498-1 (3 CVEs) (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b49a06395b49389cf68252ff425af34704f7df03...aeb3ebf43e3f48eefa5a4255229827ebd2466085
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b49a06395b49389cf68252ff425af34704f7df03...aeb3ebf43e3f48eefa5a4255229827ebd2466085
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/5c00de3c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list