[Git][security-tracker-team/security-tracker][master] Reserve DLA-4795-1 for openssl
Arnaud Rebillout (@arnaudr)
arnaudr at debian.org
Fri Sep 25 03:14:51 BST 2026
Arnaud Rebillout pushed to branch master at Debian Security Tracker / security-tracker
Commits:
cb21d733 by Arnaud Rebillout at 2026-09-25T09:14:32+07:00
Reserve DLA-4795-1 for openssl
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -113266,7 +113266,6 @@ CVE-2026-42768 (Issue summary: The CMS_decrypt and PKCS7_decrypt functions are v
CVE-2026-42767 (Issue summary: An attacker-controlled CMP (Certificate Management Prot ...)
- openssl 3.6.3-1 (bug #1139674)
[trixie] - openssl 3.5.6-1~deb13u2
- [bookworm] - openssl <no-dsa> (Minor issue; can be fixed in next update)
[bullseye] - openssl <not-affected> (Vulnerable code introduced later)
NOTE: https://openssl-library.org/news/secadv/20260609.txt
NOTE: Fixed by: https://github.com/openssl/openssl/commit/61a86a8cd73546c9fea916f3d304c1293e05c046 (openssl-3.0.21)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[25 Sep 2026] DLA-4795-1 openssl - security update
+ {CVE-2026-42767 CVE-2026-54874 CVE-2026-63072 CVE-2026-63074 CVE-2026-63076 CVE-2026-75803}
+ [bookworm] - openssl 3.0.22-1~deb12u1
[24 Sep 2026] DLA-4794-1 redis - security update
{CVE-2026-81934 CVE-2026-92925}
[bookworm] - redis 5:7.0.15-1~deb12u10
=====================================
data/dla-needed.txt
=====================================
@@ -512,11 +512,6 @@ opensc
NOTE: 20260731: Added by Front-Desk (ta)
NOTE: 20260731: lots of no-dsa issues piled up (ta)
--
-openssl (arnaudr)
- NOTE: 20260830: Added by Front-Desk (dleidert)
- NOTE: 20260830: Another round of CVEs; follow DSA-6465-1 (dleidert/front-desk)
- NOTE: 20260830: For Bookworm, 3.0.22 should contain all fixes (dleidert/front-desk)
---
pacemaker
NOTE: 20260618: Added by Front-Desk (charles)
NOTE: 20260618: Package is in dsa-needed (charles)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb21d7339ac0419ca300acca0f155782c792d14a
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb21d7339ac0419ca300acca0f155782c792d14a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/05eeee7d/attachment.htm>
More information about the debian-security-tracker-commits
mailing list