Package: chromium, tiff, cups
Version: chromium 151.0.7922.173-1~deb13u1 / tiff 4.7.0-3+deb13u3 / cups 
2.4.10-3+deb13u2
Severity: grave
Tags: security

Hi Team,

I am reporting 121 unresolved CVEs affecting the chromium, chromium-common, 
chromium-sandbox, libtiff6, libtiff-dev, libtiffxx6, and libcups2t64 packages 
on Debian Trixie (Debian 13), identified via a container image security scan 
(Prisma).

-- CVE Details --

Critical (chromium 151.0.7922.173-1~deb13u1):
- CVE-2026-79152
- CVE-2026-79090
- CVE-2026-79290
- CVE-2026-79282
- CVE-2026-79275
- CVE-2026-79257
- CVE-2026-79235
- CVE-2026-79232
- CVE-2026-79200
- CVE-2026-79189
- CVE-2026-79188
- CVE-2026-79150
- CVE-2026-79149
- CVE-2026-79140
- CVE-2026-79138
- CVE-2026-79131
- CVE-2026-79130
- CVE-2026-79129
- CVE-2026-79128
- CVE-2026-79111
- CVE-2026-79091
- CVE-2026-79078
- CVE-2026-79064
- CVE-2026-79056
- CVE-2026-79052
- CVE-2026-79047
- CVE-2026-79043
- CVE-2026-79026
- CVE-2026-79019
- CVE-2026-79012
- CVE-2026-78989
- CVE-2026-78985
- CVE-2026-78964
- CVE-2026-78951
- CVE-2026-78948
- CVE-2026-78945
- CVE-2026-78939
- CVE-2026-78937
- CVE-2026-78935
- CVE-2026-78909
- CVE-2026-78904
- CVE-2026-78900
- CVE-2026-79148
- CVE-2026-79058

Critical (tiff 4.7.0-3+deb13u3):
- CVE-2026-52490

High (chromium 151.0.7922.173-1~deb13u1):
- CVE-2026-79266
- CVE-2026-79244
- CVE-2026-79240
- CVE-2026-79236
- CVE-2026-79231
- CVE-2026-79230
- CVE-2026-79227
- CVE-2026-79226
- CVE-2026-79223
- CVE-2026-79219
- CVE-2026-79215
- CVE-2026-79209
- CVE-2026-79202
- CVE-2026-79198
- CVE-2026-79197
- CVE-2026-79195
- CVE-2026-79187
- CVE-2026-79183
- CVE-2026-79182
- CVE-2026-79142
- CVE-2026-79127
- CVE-2026-79119
- CVE-2026-79097
- CVE-2026-79073
- CVE-2026-79069
- CVE-2026-79048
- CVE-2026-79045
- CVE-2026-79033
- CVE-2026-78990
- CVE-2026-78978
- CVE-2026-78963
- CVE-2026-78956
- CVE-2026-78950
- CVE-2026-78944
- CVE-2026-78938
- CVE-2026-78910
- CVE-2026-78905
- CVE-2026-78899
- CVE-2026-78891
- CVE-2026-79292
- CVE-2026-79256
- CVE-2026-79247
- CVE-2026-79224
- CVE-2026-79218
- CVE-2026-79210
- CVE-2026-79175
- CVE-2026-79155
- CVE-2026-79132
- CVE-2026-79121
- CVE-2026-79109
- CVE-2026-79071
- CVE-2026-79054
- CVE-2026-79008
- CVE-2026-78999
- CVE-2026-78983
- CVE-2026-78952
- CVE-2026-78934
- CVE-2026-78911
- CVE-2026-79263
- CVE-2026-79194
- CVE-2026-79072
- CVE-2026-79057
- CVE-2026-79039
- CVE-2026-79027
- CVE-2026-79020
- CVE-2026-78913
- CVE-2026-79245
- CVE-2026-79216
- CVE-2026-79139
- CVE-2026-79083
- CVE-2026-78915
- CVE-2026-78906
- CVE-2026-78901
- CVE-2026-79286
- CVE-2026-78892

High (cups 2.4.10-3+deb13u2):
- CVE-2026-34980

Base Image: debian:trixie
Affected Packages: chromium, chromium-common, chromium-sandbox, libtiff6, 
libtiff-dev, libtiffxx6, libcups2t64
Installation Method: apt-get install chromium (pulls in 
libtiff6/libtiff-dev/libtiffxx6 via libgdk-pixbuf-2.0-dev, and libcups2t64 via 
libgtk-3-0t64)
Scan Tool: Prisma (container image layer scan)

Notes:
- All chromium CVEs above are fixed upstream in Google Chrome 
152.0.7977.64/.65, but Debian's trixie and trixie-security repositories are 
still on 151.0.7922.173-1~deb13u1.
- CVE-2026-52490 (tiff): the vulnerable code (tiffcrop.c, 
process_command_opts()) ships in libtiff-tools, which we have already removed. 
libtiff6/libtiff-dev/libtiffxx6 remain flagged by source-package version 
despite not containing the vulnerable tool. Fixed upstream (v4.7.2rc2) and in 
Debian unstable (4.7.2-1), but trixie/trixie-security are still on 
4.7.0-3+deb13u3.
- CVE-2026-34980 (cups): we have already removed the cupsd daemon package, 
which this CVE requires to be network-exposed to be exploitable. libcups2t64 
(client library) cannot be removed without cascading into removal of chromium 
itself. Fixed upstream (cups v2.4.17), but trixie/trixie-security are still on 
2.4.10-3+deb13u2.

Please advise on the availability of patched versions of the above packages in 
Debian Trixie's apt repository, and the expected timeline for patch inclusion 
if not yet available.

Regards,
Joshua Aldwin L. Samonte
Software Prod & Plat Eng Specialist
Advanced Technology Centers in the Philippines
*: [email protected]<mailto:[email protected]>


________________________________

This message is for the designated recipient only and may contain privileged, 
proprietary, or otherwise confidential information. If you have received it in 
error, please notify the sender immediately and delete the original. Any other 
use of the e-mail by you is prohibited. Where allowed by local law, electronic 
communications with Accenture and its affiliates, including e-mail and instant 
messaging (including content), may be scanned by our systems for the purposes 
of information security, AI-powered support capabilities, and assessment of 
internal compliance with Accenture policy. Your privacy is important to us. 
Accenture uses your personal data only in compliance with data protection laws. 
For further information on how Accenture processes your personal data, please 
see our privacy statement at https://www.accenture.com/us-en/privacy-policy.
______________________________________________________________________________________

www.accenture.com

Reply via email to