[Git][security-tracker-team/security-tracker][master] Reserve DLA-4795-1 for openssl

Arnaud Rebillout (@arnaudr) arnaudr at debian.org
Fri Sep 25 03:14:51 BST 2026



Arnaud Rebillout pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cb21d733 by Arnaud Rebillout at 2026-09-25T09:14:32+07:00
Reserve DLA-4795-1 for openssl

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -113266,7 +113266,6 @@ CVE-2026-42768 (Issue summary: The CMS_decrypt and PKCS7_decrypt functions are v
 CVE-2026-42767 (Issue summary: An attacker-controlled CMP (Certificate Management Prot ...)
 	- openssl 3.6.3-1 (bug #1139674)
 	[trixie] - openssl 3.5.6-1~deb13u2
-	[bookworm] - openssl <no-dsa> (Minor issue; can be fixed in next update)
 	[bullseye] - openssl <not-affected> (Vulnerable code introduced later)
 	NOTE: https://openssl-library.org/news/secadv/20260609.txt
 	NOTE: Fixed by: https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046 (openssl-3.0.21)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[25 Sep 2026] DLA-4795-1 openssl - security update
+	{CVE-2026-42767 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803}
+	[bookworm] - openssl 3.0.22-1~deb12u1
 [24 Sep 2026] DLA-4794-1 redis - security update
 	{CVE-2026-81934 CVE-2026-92925}
 	[bookworm] - redis 5:7.0.15-1~deb12u10


=====================================
data/dla-needed.txt
=====================================
@@ -512,11 +512,6 @@ opensc
   NOTE: 20260731: Added by Front-Desk (ta)
   NOTE: 20260731: lots of no-dsa issues piled up (ta)
 --
-openssl (arnaudr)
-  NOTE: 20260830: Added by Front-Desk (dleidert)
-  NOTE: 20260830: Another round of CVEs; follow DSA-6465-1 (dleidert/front-desk)
-  NOTE: 20260830: For Bookworm, 3.0.22 should contain all fixes (dleidert/front-desk)
---
 pacemaker
   NOTE: 20260618: Added by Front-Desk (charles)
   NOTE: 20260618: Package is in dsa-needed (charles)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb21d7339ac0419ca300acca0f155782c792d14a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb21d7339ac0419ca300acca0f155782c792d14a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/05eeee7d/attachment.htm>


More information about the debian-security-tracker-commits mailing list