[Git][security-tracker-team/security-tracker][master] Reserve DLA-4784-1 for nginx

Carlos Henrique Lima Melara (@charles) gitlab at salsa.debian.org
Fri Sep 18 03:25:35 BST 2026



Carlos Henrique Lima Melara pushed to branch master at Debian Security Tracker / security-tracker


Commits:
664bd4bc by Carlos Henrique Lima Melara at 2026-09-17T23:06:42-03:00
Reserve DLA-4784-1 for nginx

- - - - -


2 changed files:

- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[17 Sep 2026] DLA-4784-1 nginx - security update
+	{CVE-2026-42533 CVE-2026-56434 CVE-2026-60005}
+	[bookworm] - nginx 1.22.1-9+deb12u10
 [17 Sep 2026] DLA-4783-1 xz-utils - security update
 	[bookworm] - xz-utils 5.4.1-1+deb12u2
 [17 Sep 2026] DLA-4782-1 thunderbird - security update


=====================================
data/dla-needed.txt
=====================================
@@ -435,15 +435,6 @@ network-manager-l2tp
   NOTE: 20260915: Added by Front-Desk (Beuc)
   NOTE: 20260915: Follow DSA-6498-1 (3 CVEs) (Beuc/front-desk)
 --
-nginx (charles)
-  NOTE: 20260618: Added by Front-Desk (charles)
-  NOTE: 20260618: Special care is needed for the HTTP2 Bomb (TEMP-1138794-BADE22)
-  NOTE: 20260618: as it caused an ABI break on ubuntu land. Debian patches are safe,
-  NOTE: 20260618: so they should be preferred, but do test if they don't cause problems.
-  NOTE: 20260618: There was also a customer request to fix it. (charles)
-  NOTE: 20260630: Bullseye fix release with 2 CVE fixes + http2 bomb fix. Bookworm coming soon. (charles)
-  NOTE: 20260914: 3 CVEs applied, need to check against released PoC before issuing DLA. (charles)
---
 node-dompurify
   NOTE: 20260715: Added by Front-Desk (Beuc)
   NOTE: 20260715: Upcoming DSA (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/664bd4bc48eed8d011c14db567e292c5c1eee514

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/664bd4bc48eed8d011c14db567e292c5c1eee514
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/3a62d8ec/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list