[Git][security-tracker-team/security-tracker][master] incus DSA

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Sep 26 16:18:32 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0eee80d7 by Moritz Mühlenhoff at 2026-09-26T17:17:43+02:00
incus DSA

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2374,6 +2374,7 @@ CVE-2026-85491 (Catalyst::Seal versions before 0.03 for Perl allow one request t
 	NOT-FOR-US: Catalyst::Seal Perl module
 CVE-2026-XXXX [GHSA-4cph-ccqv-hm3c]
 	- incus 7.0.1-5
+	[trixie] - incus 6.0.4-2+deb13u11
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-4cph-ccqv-hm3c
 CVE-2026-XXXX [GHSA-hpjh-q53p-f27r]
 	- incus 7.0.1-5
@@ -2381,9 +2382,11 @@ CVE-2026-XXXX [GHSA-hpjh-q53p-f27r]
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-hpjh-q53p-f27r
 CVE-2026-XXXX [GHSA-579w-c4rw-c8q3]
 	- incus 7.0.1-5
+	[trixie] - incus 6.0.4-2+deb13u11
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-579w-c4rw-c8q3
 CVE-2026-XXXX [GHSA-x8gj-2q73-qr6j]
 	- incus 7.0.1-5
+	[trixie] - incus 6.0.4-2+deb13u11
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-x8gj-2q73-qr6j
 CVE-2026-XXXX [GHSA-mmj7-8rgf-mx2h]
 	- incus 7.0.1-5
@@ -2391,12 +2394,15 @@ CVE-2026-XXXX [GHSA-mmj7-8rgf-mx2h]
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-mmj7-8rgf-mx2h
 CVE-2026-XXXX [GHSA-jh4v-j34r-2mgh]
 	- incus 7.0.1-5
+	[trixie] - incus 6.0.4-2+deb13u11
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-jh4v-j34r-2mgh
 CVE-2026-XXXX [GHSA-mfwv-x733-9446]
 	- incus 7.0.1-5
+	[trixie] - incus 6.0.4-2+deb13u11
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-mfwv-x733-9446
 CVE-2026-XXXX [GHSA-wfvq-qh87-gm4j]
 	- incus 7.0.1-5
+	[trixie] - incus 6.0.4-2+deb13u11
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-wfvq-qh87-gm4j
 CVE-2026-XXXX [GHSA-443p-7392-h4v2]
 	- incus 7.0.1-5
@@ -2404,10 +2410,12 @@ CVE-2026-XXXX [GHSA-443p-7392-h4v2]
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-443p-7392-h4v2
 CVE-2026-XXXX [GHSA-h85r-gjgx-g2rv]
 	- incus 7.0.1-5
+	[trixie] - incus 6.0.4-2+deb13u11
 	- lxd <unfixed>
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-h85r-gjgx-g2rv
 CVE-2026-XXXX [GHSA-27q7-qwhm-c34p]
 	- incus 7.0.1-5
+	[trixie] - incus 6.0.4-2+deb13u11
 	- lxd <unfixed>
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-27q7-qwhm-c34p
 CVE-2026-92288 (Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0  ...)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,5 @@
+[26 Sep 2026] DSA-6518-1 incus - security update
+	[trixie] - incus 6.0.4-2+deb13u11
 [26 Sep 2026] DSA-6517-1 nodejs - security update
 	{CVE-2026-48617 CVE-2026-48618 CVE-2026-48619 CVE-2026-48928 CVE-2026-48930 CVE-2026-48931 CVE-2026-48933 CVE-2026-48934 CVE-2026-48935 CVE-2026-48937 CVE-2026-56846 CVE-2026-56847 CVE-2026-56848 CVE-2026-56850 CVE-2026-58039}
 	[trixie] - nodejs 20.19.2+dfsg-1+deb13u3


=====================================
data/dsa-needed.txt
=====================================
@@ -62,9 +62,6 @@ gst-plugins-good1.0
 hplip
   security patches first need to be isolated
 --
-incus (jmm)
-  Maintainer prepared update for review
---
 jackson-databind
 --
 jetty9



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eee80d7a1a8b1e3cbb1755cf9e6cc943bdeb543

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eee80d7a1a8b1e3cbb1755cf9e6cc943bdeb543
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/5c5e028f/attachment.htm>


More information about the debian-security-tracker-commits mailing list