Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c37f60e0 by Moritz Muehlenhoff at 2026-02-16T11:49:00+01:00
trixie/bookworm triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -843,7 +843,11 @@ CVE-2023-45291
REJECTED
CVE-2026-2443 (A flaw was identified in libsoup, a widely used HTTP library in
GNOME- ...)
- libsoup3 3.6.6-1 (bug #1127905)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
+ [bookworm] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
+ [bookworm] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/487
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/508
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/libsoup/-/commit/b9964993a32b2fa734a6b5ba2d465c2c14e22de17
(3.6.6)
@@ -1868,7 +1872,10 @@ CVE-2025-69874 (nanotar through 0.2.0 has a path
traversal vulnerability in pars
NOT-FOR-US: nanotar Node.js module
CVE-2025-69873 (ajv (Another JSON Schema Validator) through version 8.17.1 is
vulnerab ...)
- node-ajv <unfixed> (bug #1128140)
+ [trixie] - node-ajv <no-dsa> (Minor issue)
+ [bookworm] - node-ajv <no-dsa> (Minor issue)
NOTE:
https://github.com/EthanKim88/ethan-cve-disclosures/blob/main/CVE-2025-69873-ajv-ReDoS.md
+ NOTE: https://github.com/ajv-validator/ajv/issues/2581
NOTE: Fixed by:
https://github.com/ajv-validator/ajv/commit/720a23fa453ffae8340e92c9b0fe886c54cfe0d5
(v8.18.0)
CVE-2025-69872 (DiskCache (python-diskcache) through 5.6.3 uses Python pickle
for seri ...)
- diskcache <unfixed>
=====================================
data/dsa-needed.txt
=====================================
@@ -65,7 +65,7 @@ php8.2/oldstable (jmm)
--
php-laravel-framework/oldstable
--
-pillow/stable
+pillow/stable (jmm)
--
python-aiohttp
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c37f60e059b615f95c84c52cd89b044014dd9656
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c37f60e059b615f95c84c52cd89b044014dd9656
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits