Package: chromium, tiff, cups Version: chromium 151.0.7922.173-1~deb13u1 / tiff 4.7.0-3+deb13u3 / cups 2.4.10-3+deb13u2 Severity: grave Tags: security
Hi Team, I am reporting 121 unresolved CVEs affecting the chromium, chromium-common, chromium-sandbox, libtiff6, libtiff-dev, libtiffxx6, and libcups2t64 packages on Debian Trixie (Debian 13), identified via a container image security scan (Prisma). -- CVE Details -- Critical (chromium 151.0.7922.173-1~deb13u1): - CVE-2026-79152 - CVE-2026-79090 - CVE-2026-79290 - CVE-2026-79282 - CVE-2026-79275 - CVE-2026-79257 - CVE-2026-79235 - CVE-2026-79232 - CVE-2026-79200 - CVE-2026-79189 - CVE-2026-79188 - CVE-2026-79150 - CVE-2026-79149 - CVE-2026-79140 - CVE-2026-79138 - CVE-2026-79131 - CVE-2026-79130 - CVE-2026-79129 - CVE-2026-79128 - CVE-2026-79111 - CVE-2026-79091 - CVE-2026-79078 - CVE-2026-79064 - CVE-2026-79056 - CVE-2026-79052 - CVE-2026-79047 - CVE-2026-79043 - CVE-2026-79026 - CVE-2026-79019 - CVE-2026-79012 - CVE-2026-78989 - CVE-2026-78985 - CVE-2026-78964 - CVE-2026-78951 - CVE-2026-78948 - CVE-2026-78945 - CVE-2026-78939 - CVE-2026-78937 - CVE-2026-78935 - CVE-2026-78909 - CVE-2026-78904 - CVE-2026-78900 - CVE-2026-79148 - CVE-2026-79058 Critical (tiff 4.7.0-3+deb13u3): - CVE-2026-52490 High (chromium 151.0.7922.173-1~deb13u1): - CVE-2026-79266 - CVE-2026-79244 - CVE-2026-79240 - CVE-2026-79236 - CVE-2026-79231 - CVE-2026-79230 - CVE-2026-79227 - CVE-2026-79226 - CVE-2026-79223 - CVE-2026-79219 - CVE-2026-79215 - CVE-2026-79209 - CVE-2026-79202 - CVE-2026-79198 - CVE-2026-79197 - CVE-2026-79195 - CVE-2026-79187 - CVE-2026-79183 - CVE-2026-79182 - CVE-2026-79142 - CVE-2026-79127 - CVE-2026-79119 - CVE-2026-79097 - CVE-2026-79073 - CVE-2026-79069 - CVE-2026-79048 - CVE-2026-79045 - CVE-2026-79033 - CVE-2026-78990 - CVE-2026-78978 - CVE-2026-78963 - CVE-2026-78956 - CVE-2026-78950 - CVE-2026-78944 - CVE-2026-78938 - CVE-2026-78910 - CVE-2026-78905 - CVE-2026-78899 - CVE-2026-78891 - CVE-2026-79292 - CVE-2026-79256 - CVE-2026-79247 - CVE-2026-79224 - CVE-2026-79218 - CVE-2026-79210 - CVE-2026-79175 - CVE-2026-79155 - CVE-2026-79132 - CVE-2026-79121 - CVE-2026-79109 - CVE-2026-79071 - CVE-2026-79054 - CVE-2026-79008 - CVE-2026-78999 - CVE-2026-78983 - CVE-2026-78952 - CVE-2026-78934 - CVE-2026-78911 - CVE-2026-79263 - CVE-2026-79194 - CVE-2026-79072 - CVE-2026-79057 - CVE-2026-79039 - CVE-2026-79027 - CVE-2026-79020 - CVE-2026-78913 - CVE-2026-79245 - CVE-2026-79216 - CVE-2026-79139 - CVE-2026-79083 - CVE-2026-78915 - CVE-2026-78906 - CVE-2026-78901 - CVE-2026-79286 - CVE-2026-78892 High (cups 2.4.10-3+deb13u2): - CVE-2026-34980 Base Image: debian:trixie Affected Packages: chromium, chromium-common, chromium-sandbox, libtiff6, libtiff-dev, libtiffxx6, libcups2t64 Installation Method: apt-get install chromium (pulls in libtiff6/libtiff-dev/libtiffxx6 via libgdk-pixbuf-2.0-dev, and libcups2t64 via libgtk-3-0t64) Scan Tool: Prisma (container image layer scan) Notes: - All chromium CVEs above are fixed upstream in Google Chrome 152.0.7977.64/.65, but Debian's trixie and trixie-security repositories are still on 151.0.7922.173-1~deb13u1. - CVE-2026-52490 (tiff): the vulnerable code (tiffcrop.c, process_command_opts()) ships in libtiff-tools, which we have already removed. libtiff6/libtiff-dev/libtiffxx6 remain flagged by source-package version despite not containing the vulnerable tool. Fixed upstream (v4.7.2rc2) and in Debian unstable (4.7.2-1), but trixie/trixie-security are still on 4.7.0-3+deb13u3. - CVE-2026-34980 (cups): we have already removed the cupsd daemon package, which this CVE requires to be network-exposed to be exploitable. libcups2t64 (client library) cannot be removed without cascading into removal of chromium itself. Fixed upstream (cups v2.4.17), but trixie/trixie-security are still on 2.4.10-3+deb13u2. Please advise on the availability of patched versions of the above packages in Debian Trixie's apt repository, and the expected timeline for patch inclusion if not yet available. Regards, Joshua Aldwin L. Samonte Software Prod & Plat Eng Specialist Advanced Technology Centers in the Philippines *: [email protected]<mailto:[email protected]> ________________________________ This message is for the designated recipient only and may contain privileged, proprietary, or otherwise confidential information. If you have received it in error, please notify the sender immediately and delete the original. Any other use of the e-mail by you is prohibited. Where allowed by local law, electronic communications with Accenture and its affiliates, including e-mail and instant messaging (including content), may be scanned by our systems for the purposes of information security, AI-powered support capabilities, and assessment of internal compliance with Accenture policy. Your privacy is important to us. Accenture uses your personal data only in compliance with data protection laws. For further information on how Accenture processes your personal data, please see our privacy statement at https://www.accenture.com/us-en/privacy-policy. ______________________________________________________________________________________ www.accenture.com

