Daniel Leidert pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
5433112b by Daniel Leidert at 2026-03-13T01:08:54+01:00
dla-needed: add note about python-aiohttp
- - - - -
599e667a by Daniel Leidert at 2026-03-13T01:15:58+01:00
dla-needed: add python-tornado
- - - - -
d824e0a5 by Daniel Leidert at 2026-03-13T01:16:54+01:00
dla-needed: claim python-tornado
- - - - -
17f4d1c7 by Daniel Leidert at 2026-03-13T01:25:55+01:00
Add patch link for CVE-2026-31958/python-tornado
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -611,6 +611,7 @@ CVE-2026-31959 (Quill provides simple mac binary signing
and notarization from a
CVE-2026-31958 (Tornado is a Python web framework and asynchronous networking
library. ...)
- python-tornado <unfixed> (bug #1130507)
NOTE:
https://github.com/tornadoweb/tornado/security/advisories/GHSA-qjxf-f2mg-c6mc
+ NOTE: Fixed by:
https://github.com/tornadoweb/tornado/commit/119a195e290c43ad2d63a2cf012c29d43d6ed839
(v6.5.5)
CVE-2026-31957 (Himmelblau is an interoperability suite for Microsoft Azure
Entra ID a ...)
NOT-FOR-US: Himmelblau
CVE-2026-31954 (Emlog is an open source website building system. In 2.6.6 and
earlier, ...)
=====================================
data/dla-needed.txt
=====================================
@@ -364,6 +364,7 @@ postgresql-13 (jspricke)
--
python-aiohttp (dleidert)
NOTE: 20260106: Added by Front-Desk (lamby)
+ NOTE: 20260301: WIP: making progress backporting the patches (dleidert)
--
python-authlib (eamanu)
NOTE: 20260216: Added by Front-Desk (rouca)
@@ -371,6 +372,9 @@ python-authlib (eamanu)
python-geopandas
NOTE: 20260216: Added by Front-Desk (rouca)
--
+python-tornado (dleidert)
+ NOTE: 20260313: Added by Front-Desk (dleidert)
+--
python3.9
NOTE: 20260307: Added by Front-Desk (lamby)
NOTE: 20260307: Added re. CVE-2025-69534 but please also check
CVE-2026-2297. (lamby)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3d51ede5861bfec3e52f29312c7526ea7bc8b1b7...17f4d1c74f4f7945cd7c5f291cbec9d8e233e20e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3d51ede5861bfec3e52f29312c7526ea7bc8b1b7...17f4d1c74f4f7945cd7c5f291cbec9d8e233e20e
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits