Daniel Leidert pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5433112b by Daniel Leidert at 2026-03-13T01:08:54+01:00
dla-needed: add note about python-aiohttp

- - - - -
599e667a by Daniel Leidert at 2026-03-13T01:15:58+01:00
dla-needed: add python-tornado

- - - - -
d824e0a5 by Daniel Leidert at 2026-03-13T01:16:54+01:00
dla-needed: claim python-tornado

- - - - -
17f4d1c7 by Daniel Leidert at 2026-03-13T01:25:55+01:00
Add patch link for CVE-2026-31958/python-tornado

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -611,6 +611,7 @@ CVE-2026-31959 (Quill provides simple mac binary signing 
and notarization from a
 CVE-2026-31958 (Tornado is a Python web framework and asynchronous networking 
library. ...)
        - python-tornado <unfixed> (bug #1130507)
        NOTE: 
https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc
+       NOTE: Fixed by: 
https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839
 (v6.5.5)
 CVE-2026-31957 (Himmelblau is an interoperability suite for Microsoft Azure 
Entra ID a ...)
        NOT-FOR-US: Himmelblau
 CVE-2026-31954 (Emlog is an open source website building system. In 2.6.6 and 
earlier, ...)


=====================================
data/dla-needed.txt
=====================================
@@ -364,6 +364,7 @@ postgresql-13 (jspricke)
 --
 python-aiohttp (dleidert)
   NOTE: 20260106: Added by Front-Desk (lamby)
+  NOTE: 20260301: WIP: making progress backporting the patches (dleidert)
 --
 python-authlib (eamanu)
   NOTE: 20260216: Added by Front-Desk (rouca)
@@ -371,6 +372,9 @@ python-authlib (eamanu)
 python-geopandas
   NOTE: 20260216: Added by Front-Desk (rouca)
 --
+python-tornado (dleidert)
+  NOTE: 20260313: Added by Front-Desk (dleidert)
+--
 python3.9
   NOTE: 20260307: Added by Front-Desk (lamby)
   NOTE: 20260307: Added re. CVE-2025-69534 but please also check 
CVE-2026-2297. (lamby)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3d51ede5861bfec3e52f29312c7526ea7bc8b1b7...17f4d1c74f4f7945cd7c5f291cbec9d8e233e20e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3d51ede5861bfec3e52f29312c7526ea7bc8b1b7...17f4d1c74f4f7945cd7c5f291cbec9d8e233e20e
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to