[Git][security-tracker-team/security-tracker][master] 3 commits: lts: add glibc

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Sat Sep 19 08:33:34 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2e3f67f6 by Sylvain Beucler at 2026-09-19T09:33:20+02:00
lts: add glibc

- - - - -
1770c158 by Sylvain Beucler at 2026-09-19T09:33:22+02:00
lts: imagemagick postponed (5 CVEs)

- - - - -
bd0e52eb by Sylvain Beucler at 2026-09-19T09:33:25+02:00
rclone: bookworm postponed (13 CVEs)

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -14593,6 +14593,7 @@ CVE-2026-88047 (Tesseract is an open source OCR engine. In version 5.5.3 and ear
 CVE-2026-88046 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-38xv-hf3p-h7mq
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/57842c5ee4e1407eda06a414a36510cce2db4252 (v1.75.1)
 CVE-2026-88045 (rclone is a command-line program to sync files and directories to and  ...)
@@ -14681,12 +14682,14 @@ CVE-2026-88017 (rclone is a command-line program to sync files and directories t
 CVE-2026-88016 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/17b0c03338a857bcb0a68d2d4c82ddbdec3f7893 (v1.75.1)
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/a7ab39d3d1958afa1446982c1dc4e4a73a887e3e (v1.75.1)
 CVE-2026-88015 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9 (v1.75.1)
 CVE-2026-88014 (rclone is a command-line program to sync files and directories to and  ...)
@@ -14697,6 +14700,7 @@ CVE-2026-88014 (rclone is a command-line program to sync files and directories t
 CVE-2026-88013 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-486v-q2wf-fp2r
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/22859b7e696cea3c563c6ba04c6b7f91f74456b4 (v1.75.1)
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/79fbc0842f74e02cb84f0e3e7261d169983c8831 (v1.75.1)
@@ -20150,18 +20154,21 @@ CVE-2026-86426 (LibreNMS before 26.8.0 contains an authentication bypass vulnera
 CVE-2026-86425 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)
 	- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
 	[trixie] - imagemagick <no-dsa> (Minor issue)
+	[bookworm] - imagemagick <postponed> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/5bff96a5c8d0b3dafa4ad4fa7916db4cae72a11d (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/e006a69e03f3aff34e9a7af90a0793ec6d879b48 (6.9.13-55)
 CVE-2026-86424 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ...)
 	- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
 	[trixie] - imagemagick <no-dsa> (Minor issue)
+	[bookworm] - imagemagick <postponed> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/a44ef50cc494253f7d9f0229bb25c064a8e2ae69 (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/0b47fb7e3d5650b2be88fd3a8c15096765970ce3 (6.9.13-55)
 CVE-2026-86423 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)
 	- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
 	[trixie] - imagemagick <no-dsa> (Minor issue)
+	[bookworm] - imagemagick <postponed> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5m9j-96ff-j6qc
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/1d3e98913f6a8fa34b5a4180eadb9ed195b918a8 (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ed44f0ba6e2ab57983a6d030c868d009514dc470 (6.9.13-55)
@@ -20171,12 +20178,14 @@ CVE-2026-86422 (ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use
 CVE-2026-86421 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in th ...)
 	- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
 	[trixie] - imagemagick <no-dsa> (Minor issue)
+	[bookworm] - imagemagick <postponed> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/c83153dfc128de8e7c538f879c532c7d36a75abb (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/d56cab9f2253373e57c2e77809ab12abbbbdd680 (6.9.13-55)
 CVE-2026-86420 (ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the  ...)
 	- imagemagick 8:7.1.2.31+dfsg1-1 (bug #1147176)
 	[trixie] - imagemagick <no-dsa> (Minor issue)
+	[bookworm] - imagemagick <postponed> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/6ac07556a93b2de00c845cd535ca256f45a47154 (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/29f17f3fe5008fc56f00c1fbc96adf46169db245 (6.9.13-55)
@@ -33251,26 +33260,32 @@ CVE-2026-79784 (Vocos instantiates a class named by a configuration file without
 CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits when applyi ...)
 	- rclone <unfixed> (bug #1145670)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-945v-v9p3-v5xw
 CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token header wh ...)
 	- rclone <unfixed> (bug #1145670)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-gx4c-2hqx-cw2r
 CVE-2026-79781 (rclone serve s3 before 1.74.4 contains a path traversal vulnerability  ...)
 	- rclone <unfixed> (bug #1145670)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8v25-v8p6-qf7v
 CVE-2026-79780 (rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE- ...)
 	- rclone <unfixed> (bug #1145670)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8mxv-9xhp-86h4
 CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport downgrades in  ...)
 	- rclone <unfixed> (bug #1145670)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj
 CVE-2026-79778 (rclone before v1.75.0 contains a denial of service vulnerability in th ...)
 	- rclone <unfixed> (bug #1145670)
 	[trixie] - rclone <no-dsa> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-3x6r-wxxg-53vv
 CVE-2026-79777 (rclone before v1.75.0 includes full Go stack traces in RC API error re ...)
 	- rclone <unfixed> (bug #1145670)
@@ -80566,13 +80581,13 @@ CVE-2026-59835 (A exposure of resource to wrong sphere vulnerability in Fortinet
 CVE-2026-59733 (Rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1142269)
 	[trixie] - rclone <no-dsa> (Minor issue)
-	[bookworm] - rclone <postponed> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-fqj9-69pf-6pjg
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/015fd0eba1cb138eef081517795fed47a2873f2d (v1.74.4)
 CVE-2026-59732 (Rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1142269)
 	[trixie] - rclone <no-dsa> (Minor issue)
-	[bookworm] - rclone <postponed> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c (v1.74.4)
 CVE-2026-59674 (A UNIX Symbolic Link (Symlink) Following vulnerability in openSUSE Tum ...)
@@ -81102,7 +81117,7 @@ CVE-2026-54684 (jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a malicio
 CVE-2026-54572 (Rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1142269)
 	[trixie] - rclone <no-dsa> (Minor issue)
-	[bookworm] - rclone <postponed> (Minor issue)
+	[bookworm] - rclone <postponed> (Limited support, minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265 (v1.74.4)
 CVE-2026-54429 (A vulnerability has been identified in SIMATIC S7-PLCSIM Advanced (All ...)


=====================================
data/dla-needed.txt
=====================================
@@ -229,6 +229,10 @@ git-lfs
   NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
   NOTE: 20260914: Ivo Marino mentioned in debian-lts that has patches ready (santiago)
 --
+glibc
+  NOTE: 20260919: Added by Front-Desk (Beuc)
+  NOTE: 20260918: At minimum, follow Debian 13.7 (2 CVEs) (Beuc/front-desk)
+--
 gst-plugins-bad1.0
   NOTE: 20260612: Added by Front-Desk (rouca)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/61d59259241a61a7660b172f10fa77dcccb61600...bd0e52eb2fef55191eb48e5561db3a19575e1654

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/61d59259241a61a7660b172f10fa77dcccb61600...bd0e52eb2fef55191eb48e5561db3a19575e1654
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/cf8ba17c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list