[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2026-90781/alsa-lib: bookworm postponed
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Fri Sep 18 09:30:05 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9c8f34f0 by Sylvain Beucler at 2026-09-18T10:29:50+02:00
CVE-2026-90781/alsa-lib: bookworm postponed
- - - - -
de205814 by Sylvain Beucler at 2026-09-18T10:29:51+02:00
lts: unbound status update
- - - - -
3afbbc99 by Sylvain Beucler at 2026-09-18T10:29:54+02:00
CVE-2026-16658/ansible: bookworm not-affected
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -10442,6 +10442,7 @@ CVE-2026-90782 (S2OPC through 1.7.3 contains a null pointer dereference in msg_s
CVE-2026-90781 (alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __sn ...)
- alsa-lib <unfixed> (bug #1147619)
[trixie] - alsa-lib <no-dsa> (Minor issue)
+ [bookworm] - alsa-lib <postponed> (Minor issue, CLI crash)
NOTE: https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/
NOTE: Fixed by: https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020
CVE-2026-90780 (SIPp through 3.7.7 contains a buffer overflow vulnerability in the get ...)
@@ -23917,6 +23918,7 @@ CVE-2026-73553
CVE-2026-16658
- ansible <unfixed> (bug #1146701)
[trixie] - ansible <no-dsa> (Minor issue)
+ [bookworm] - ansible <not-affected> (proxmox_pct_remote not present)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506209
CVE-2026-84353 (Use after free in Shared Tab Groups in Google Chrome on on Android pri ...)
{DSA-6482-1 DLA-4771-1}
=====================================
data/dla-needed.txt
=====================================
@@ -770,6 +770,7 @@ unbound
NOTE: 20260520: Added by Front-Desk (Beuc)
NOTE: 20260520: 11 new CVEs including 2 memory corruption (Beuc/front-desk)
NOTE: 20260611: For bookworm, sync with maintainer (Michael Tokarev) who had looked into initial backport.
+ NOTE: 20260918: 9 new CVEs including RCEs (Beuc/front-desk)
--
util-linux (eamanu)
NOTE: 20260619: Added by Front-Desk (charles)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6c106d5a26e553251808fdff9b4dbdae44d14737...3afbbc99794b8330fbd842bf830fb914c9277010
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6c106d5a26e553251808fdff9b4dbdae44d14737...3afbbc99794b8330fbd842bf830fb914c9277010
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/f92f6a15/attachment.htm>
More information about the debian-security-tracker-commits
mailing list