[Git][security-tracker-team/security-tracker][master] 3 commits: lts: xen status update

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Sat Sep 19 10:51:52 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8e4954f6 by Sylvain Beucler at 2026-09-19T11:51:42+02:00
lts: xen status update

- - - - -
c9545a55 by Sylvain Beucler at 2026-09-19T11:51:44+02:00
node-undici: follow trixie triage

- - - - -
29883521 by Sylvain Beucler at 2026-09-19T11:51:45+02:00
lts: add libvirt

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -21418,26 +21418,32 @@ CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whethe
 CVE-2026-85152 (undici 8.10.0 omits the destination origin from the cache and request- ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm
 CVE-2026-85024 (undici bundles a WebSocket client whose permessage-deflate size-limit  ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v
 CVE-2026-85014 (undici's experimental WebSocketStream client crashes the whole Node.js ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq
 CVE-2026-85008 (undici's cache interceptor documents that only safe HTTP methods are c ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv
 CVE-2026-84961 (undici's BalancedPool constructor passes its entire options object thr ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3
 CVE-2026-84947 (undici's dump interceptor reads and discards a response body up to a c ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968
 CVE-2026-84937 (The Video Player for YouTube  WordPress plugin before 2.1.0 does not p ...)
 	NOT-FOR-US: WordPress plugin
@@ -21450,6 +21456,7 @@ CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not perform
 CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie response hea ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j
 CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does not sani ...)
 	NOT-FOR-US: WordPress plugin
@@ -21470,6 +21477,7 @@ CVE-2026-84896 (The King Addons for Elementor  WordPress plugin before 51.1.77 d
 CVE-2026-84890 (undici's decompress interceptor decompresses response bodies according ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm
 CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not restrict ...)
 	NOT-FOR-US: WordPress plugin
@@ -21528,6 +21536,7 @@ CVE-2026-81832 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1
 CVE-2026-81666 (An integer overflow was found in Corosync's handling of membership com ...)
 	- corosync <unfixed> (bug #1146872)
 	[trixie] - corosync <no-dsa> (Minor issue)
+	[bookworm] - corosync <postponed> (Minor issue, DoS)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524923
 	NOTE: Fixed by: https://github.com/corosync/corosync/commit/83920f2e36b5f1acd7dcf033c0820043cc29f82a
 CVE-2026-81665 (A heap-based buffer overflow was found in Corosync's Totem Process Gro ...)
@@ -21828,6 +21837,7 @@ CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated
 CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process during the ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5
 CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker ...)
 	NOT-FOR-US: IBM
@@ -21882,6 +21892,7 @@ CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attac
 CVE-2026-18540 (undici's retry interceptor can append the body of a ranged retry respo ...)
 	- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
 	[trixie] - node-undici <no-dsa> (Minor issue)
+	[bookworm] - node-undici <postponed> (Minor issue)
 	NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r
 CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context  ...)
 	NOT-FOR-US: IBM


=====================================
data/dla-needed.txt
=====================================
@@ -374,6 +374,9 @@ libsoup2.4
 libssh
   NOTE: 20260731: Added by Front-Desk (ta)
 --
+libvirt
+  NOTE: 20260919: Added by Front-Desk (Beuc)
+--
 libwebsockets
   NOTE: 20260718: Added by Front-Desk (Beuc)
   NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
@@ -817,7 +820,7 @@ wordpress
 xen
   NOTE: 20260714: Added by Front-Desk (Beuc)
   NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie (Beuc/front-desk)
-  NOTE: 20260918: Maintainers are preparing an update, please review and coordinate,
+  NOTE: 20260918: Maintainers prepared an update, please review and coordinate,
   NOTE: 20260918: they need help with the upload and DLA process: (Beuc/front-desk)
   NOTE: 20260918: https://lists.debian.org/debian-lts/2026/08/msg00028.html
   NOTE: 20260918: https://lists.debian.org/debian-lts/2026/09/threads.html#00073



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d409b9101179b026cade45eeb9c482fb7ad768dd...2988352154cd5363e25c710a33410f87be5ef55f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d409b9101179b026cade45eeb9c482fb7ad768dd...2988352154cd5363e25c710a33410f87be5ef55f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/1762196f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list