[Git][security-tracker-team/security-tracker][master] Reserve DLA-4784-1 for nginx
Carlos Henrique Lima Melara (@charles)
gitlab at salsa.debian.org
Fri Sep 18 03:25:35 BST 2026
Carlos Henrique Lima Melara pushed to branch master at Debian Security Tracker / security-tracker
Commits:
664bd4bc by Carlos Henrique Lima Melara at 2026-09-17T23:06:42-03:00
Reserve DLA-4784-1 for nginx
- - - - -
2 changed files:
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Sep 2026] DLA-4784-1 nginx - security update
+ {CVE-2026-42533 CVE-2026-56434 CVE-2026-60005}
+ [bookworm] - nginx 1.22.1-9+deb12u10
[17 Sep 2026] DLA-4783-1 xz-utils - security update
[bookworm] - xz-utils 5.4.1-1+deb12u2
[17 Sep 2026] DLA-4782-1 thunderbird - security update
=====================================
data/dla-needed.txt
=====================================
@@ -435,15 +435,6 @@ network-manager-l2tp
NOTE: 20260915: Added by Front-Desk (Beuc)
NOTE: 20260915: Follow DSA-6498-1 (3 CVEs) (Beuc/front-desk)
--
-nginx (charles)
- NOTE: 20260618: Added by Front-Desk (charles)
- NOTE: 20260618: Special care is needed for the HTTP2 Bomb (TEMP-1138794-BADE22)
- NOTE: 20260618: as it caused an ABI break on ubuntu land. Debian patches are safe,
- NOTE: 20260618: so they should be preferred, but do test if they don't cause problems.
- NOTE: 20260618: There was also a customer request to fix it. (charles)
- NOTE: 20260630: Bullseye fix release with 2 CVE fixes + http2 bomb fix. Bookworm coming soon. (charles)
- NOTE: 20260914: 3 CVEs applied, need to check against released PoC before issuing DLA. (charles)
---
node-dompurify
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/664bd4bc48eed8d011c14db567e292c5c1eee514
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/664bd4bc48eed8d011c14db567e292c5c1eee514
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/3a62d8ec/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list