[Git][security-tracker-team/security-tracker][master] incus DSA
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Sep 26 16:18:32 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0eee80d7 by Moritz Mühlenhoff at 2026-09-26T17:17:43+02:00
incus DSA
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -2374,6 +2374,7 @@ CVE-2026-85491 (Catalyst::Seal versions before 0.03 for Perl allow one request t
NOT-FOR-US: Catalyst::Seal Perl module
CVE-2026-XXXX [GHSA-4cph-ccqv-hm3c]
- incus 7.0.1-5
+ [trixie] - incus 6.0.4-2+deb13u11
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-4cph-ccqv-hm3c
CVE-2026-XXXX [GHSA-hpjh-q53p-f27r]
- incus 7.0.1-5
@@ -2381,9 +2382,11 @@ CVE-2026-XXXX [GHSA-hpjh-q53p-f27r]
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-hpjh-q53p-f27r
CVE-2026-XXXX [GHSA-579w-c4rw-c8q3]
- incus 7.0.1-5
+ [trixie] - incus 6.0.4-2+deb13u11
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-579w-c4rw-c8q3
CVE-2026-XXXX [GHSA-x8gj-2q73-qr6j]
- incus 7.0.1-5
+ [trixie] - incus 6.0.4-2+deb13u11
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-x8gj-2q73-qr6j
CVE-2026-XXXX [GHSA-mmj7-8rgf-mx2h]
- incus 7.0.1-5
@@ -2391,12 +2394,15 @@ CVE-2026-XXXX [GHSA-mmj7-8rgf-mx2h]
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-mmj7-8rgf-mx2h
CVE-2026-XXXX [GHSA-jh4v-j34r-2mgh]
- incus 7.0.1-5
+ [trixie] - incus 6.0.4-2+deb13u11
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-jh4v-j34r-2mgh
CVE-2026-XXXX [GHSA-mfwv-x733-9446]
- incus 7.0.1-5
+ [trixie] - incus 6.0.4-2+deb13u11
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-mfwv-x733-9446
CVE-2026-XXXX [GHSA-wfvq-qh87-gm4j]
- incus 7.0.1-5
+ [trixie] - incus 6.0.4-2+deb13u11
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-wfvq-qh87-gm4j
CVE-2026-XXXX [GHSA-443p-7392-h4v2]
- incus 7.0.1-5
@@ -2404,10 +2410,12 @@ CVE-2026-XXXX [GHSA-443p-7392-h4v2]
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-443p-7392-h4v2
CVE-2026-XXXX [GHSA-h85r-gjgx-g2rv]
- incus 7.0.1-5
+ [trixie] - incus 6.0.4-2+deb13u11
- lxd <unfixed>
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-h85r-gjgx-g2rv
CVE-2026-XXXX [GHSA-27q7-qwhm-c34p]
- incus 7.0.1-5
+ [trixie] - incus 6.0.4-2+deb13u11
- lxd <unfixed>
NOTE: https://github.com/lxc/incus/security/advisories/GHSA-27q7-qwhm-c34p
CVE-2026-92288 (Lemonldap::NG::Portal versions from 2.20.0 before 2.21.6, from 2.22.0 ...)
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,5 @@
+[26 Sep 2026] DSA-6518-1 incus - security update
+ [trixie] - incus 6.0.4-2+deb13u11
[26 Sep 2026] DSA-6517-1 nodejs - security update
{CVE-2026-48617 CVE-2026-48618 CVE-2026-48619 CVE-2026-48928 CVE-2026-48930 CVE-2026-48931 CVE-2026-48933 CVE-2026-48934 CVE-2026-48935 CVE-2026-48937 CVE-2026-56846 CVE-2026-56847 CVE-2026-56848 CVE-2026-56850 CVE-2026-58039}
[trixie] - nodejs 20.19.2+dfsg-1+deb13u3
=====================================
data/dsa-needed.txt
=====================================
@@ -62,9 +62,6 @@ gst-plugins-good1.0
hplip
security patches first need to be isolated
--
-incus (jmm)
- Maintainer prepared update for review
---
jackson-databind
--
jetty9
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eee80d7a1a8b1e3cbb1755cf9e6cc943bdeb543
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0eee80d7a1a8b1e3cbb1755cf9e6cc943bdeb543
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/5c5e028f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list