[Git][security-tracker-team/security-tracker][master] 2 commits: lts: add ansible

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Fri Sep 18 19:02:15 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5ca8e095 by Sylvain Beucler at 2026-09-18T20:02:06+02:00
lts: add ansible

- - - - -
0df6f4dd by Sylvain Beucler at 2026-09-18T20:02:08+02:00
CVE-2026-78254/ant: bookworm postponed

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -19383,6 +19383,7 @@ CVE-2022-51010 (PocketMine-MP versions before 4.4.2 fail to properly validate it
 CVE-2026-78254 (The ftp and scp tasks of Apache Ant can download files from a remote s ...)
 	- ant 1.10.18-1 (bug #1147425)
 	[trixie] - ant <no-dsa> (Minor issue)
+	[bookworm] - ant <postponed> (Minor issue, need to compromise a server trusted in Ant-based builds)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/09/06/2
 	NOTE: https://github.com/apache/ant/commit/07ee9c418e3bd3e7d0287fc9aaba3011e88f0dc2 (ANT_1.10.18_RC1)
 	NOTE: https://github.com/apache/ant/commit/9252566cab812c59a5695679ba11f497e85aabb0 (ANT_1.10.18_RC1)


=====================================
data/dla-needed.txt
=====================================
@@ -53,6 +53,10 @@ amd64-microcode
   NOTE: 20251224: I think the required kernel microcode driver patch are: https://lists.openwall.net/linux-kernel/2025/10/27/1012
   NOTE: 20260615: bookworm (now lts) also needs fixes. (charles)
 --
+ansible
+  NOTE: 20260918: Added by Front-Desk (Beuc)
+  NOTE: 20260918: Multiple privilege escalation vulnerabilities (Beuc/front-desk)
+--
 antiword
   NOTE: 20260917: Added by Front-Desk (Beuc)
   NOTE: 20260917: Dead upstream but Debian maintainer provided patches (Beuc/front-desk)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3ab4533ebd86a18b50bc62ebac64a69933cc793b...0df6f4dd9064005315899892ccdfa78afc67fcbc

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3ab4533ebd86a18b50bc62ebac64a69933cc793b...0df6f4dd9064005315899892ccdfa78afc67fcbc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/2f56671f/attachment.htm>


More information about the debian-security-tracker-commits mailing list