[Git][security-tracker-team/security-tracker][master] 3 commits: lts: add glibc
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Sat Sep 19 08:33:34 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2e3f67f6 by Sylvain Beucler at 2026-09-19T09:33:20+02:00
lts: add glibc
- - - - -
1770c158 by Sylvain Beucler at 2026-09-19T09:33:22+02:00
lts: imagemagick postponed (5 CVEs)
- - - - -
bd0e52eb by Sylvain Beucler at 2026-09-19T09:33:25+02:00
rclone: bookworm postponed (13 CVEs)
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -14593,6 +14593,7 @@ CVE-2026-88047 (Tesseract is an open source OCR engine. In version 5.5.3 and ear
CVE-2026-88046 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1147404)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-38xv-hf3p-h7mq
NOTE: Fixed by: https://github.com/rclone/rclone/commit/57842c5ee4e1407eda06a414a36510cce2db4252 (v1.75.1)
CVE-2026-88045 (rclone is a command-line program to sync files and directories to and ...)
@@ -14681,12 +14682,14 @@ CVE-2026-88017 (rclone is a command-line program to sync files and directories t
CVE-2026-88016 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1147404)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh
NOTE: Fixed by: https://github.com/rclone/rclone/commit/17b0c03338a857bcb0a68d2d4c82ddbdec3f7893 (v1.75.1)
NOTE: Fixed by: https://github.com/rclone/rclone/commit/a7ab39d3d1958afa1446982c1dc4e4a73a887e3e (v1.75.1)
CVE-2026-88015 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1147404)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw
NOTE: Fixed by: https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9 (v1.75.1)
CVE-2026-88014 (rclone is a command-line program to sync files and directories to and ...)
@@ -14697,6 +14700,7 @@ CVE-2026-88014 (rclone is a command-line program to sync files and directories t
CVE-2026-88013 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1147404)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-486v-q2wf-fp2r
NOTE: Fixed by: https://github.com/rclone/rclone/commit/22859b7e696cea3c563c6ba04c6b7f91f74456b4 (v1.75.1)
NOTE: Fixed by: https://github.com/rclone/rclone/commit/79fbc0842f74e02cb84f0e3e7261d169983c8831 (v1.75.1)
@@ -20150,18 +20154,21 @@ CVE-2026-86426 (LibreNMS before 26.8.0 contains an authentication bypass vulnera
CVE-2026-86425 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)
- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
[trixie] - imagemagick <no-dsa> (Minor issue)
+ [bookworm] - imagemagick <postponed> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/5bff96a5c8d0b3dafa4ad4fa7916db4cae72a11d (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/e006a69e03f3aff34e9a7af90a0793ec6d879b48 (6.9.13-55)
CVE-2026-86424 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ...)
- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
[trixie] - imagemagick <no-dsa> (Minor issue)
+ [bookworm] - imagemagick <postponed> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/a44ef50cc494253f7d9f0229bb25c064a8e2ae69 (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/0b47fb7e3d5650b2be88fd3a8c15096765970ce3 (6.9.13-55)
CVE-2026-86423 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)
- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
[trixie] - imagemagick <no-dsa> (Minor issue)
+ [bookworm] - imagemagick <postponed> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5m9j-96ff-j6qc
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/1d3e98913f6a8fa34b5a4180eadb9ed195b918a8 (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ed44f0ba6e2ab57983a6d030c868d009514dc470 (6.9.13-55)
@@ -20171,12 +20178,14 @@ CVE-2026-86422 (ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use
CVE-2026-86421 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in th ...)
- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
[trixie] - imagemagick <no-dsa> (Minor issue)
+ [bookworm] - imagemagick <postponed> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/c83153dfc128de8e7c538f879c532c7d36a75abb (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/d56cab9f2253373e57c2e77809ab12abbbbdd680 (6.9.13-55)
CVE-2026-86420 (ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the ...)
- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
[trixie] - imagemagick <no-dsa> (Minor issue)
+ [bookworm] - imagemagick <postponed> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/6ac07556a93b2de00c845cd535ca256f45a47154 (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/29f17f3fe5008fc56f00c1fbc96adf46169db245 (6.9.13-55)
@@ -33251,26 +33260,32 @@ CVE-2026-79784 (Vocos instantiates a class named by a configuration file without
CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits when applyi ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-945v-v9p3-v5xw
CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token header wh ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-gx4c-2hqx-cw2r
CVE-2026-79781 (rclone serve s3 before 1.74.4 contains a path traversal vulnerability ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8v25-v8p6-qf7v
CVE-2026-79780 (rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE- ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8mxv-9xhp-86h4
CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport downgrades in ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj
CVE-2026-79778 (rclone before v1.75.0 contains a denial of service vulnerability in th ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-3x6r-wxxg-53vv
CVE-2026-79777 (rclone before v1.75.0 includes full Go stack traces in RC API error re ...)
- rclone <unfixed> (bug #1145670)
@@ -80566,13 +80581,13 @@ CVE-2026-59835 (A exposure of resource to wrong sphere vulnerability in Fortinet
CVE-2026-59733 (Rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1142269)
[trixie] - rclone <no-dsa> (Minor issue)
- [bookworm] - rclone <postponed> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-fqj9-69pf-6pjg
NOTE: Fixed by: https://github.com/rclone/rclone/commit/015fd0eba1cb138eef081517795fed47a2873f2d (v1.74.4)
CVE-2026-59732 (Rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1142269)
[trixie] - rclone <no-dsa> (Minor issue)
- [bookworm] - rclone <postponed> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p
NOTE: Fixed by: https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c (v1.74.4)
CVE-2026-59674 (A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tum ...)
@@ -81102,7 +81117,7 @@ CVE-2026-54684 (jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicio
CVE-2026-54572 (Rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1142269)
[trixie] - rclone <no-dsa> (Minor issue)
- [bookworm] - rclone <postponed> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
NOTE: Fixed by: https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265 (v1.74.4)
CVE-2026-54429 (A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All ...)
=====================================
data/dla-needed.txt
=====================================
@@ -229,6 +229,10 @@ git-lfs
NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
NOTE: 20260914: Ivo Marino mentioned in debian-lts that has patches ready (santiago)
--
+glibc
+ NOTE: 20260919: Added by Front-Desk (Beuc)
+ NOTE: 20260918: At minimum, follow Debian 13.7 (2 CVEs) (Beuc/front-desk)
+--
gst-plugins-bad1.0
NOTE: 20260612: Added by Front-Desk (rouca)
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/61d59259241a61a7660b172f10fa77dcccb61600...bd0e52eb2fef55191eb48e5561db3a19575e1654
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/61d59259241a61a7660b172f10fa77dcccb61600...bd0e52eb2fef55191eb48e5561db3a19575e1654
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/cf8ba17c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list