Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
64405243 by Utkarsh Gupta at 2026-07-12T06:14:26+05:30
lts: ack postponed in bullseye/bookworm (CVE-2026-49145)

- - - - -
a5f045f4 by Utkarsh Gupta at 2026-07-12T06:14:27+05:30
lts: acl postponed in bullseye/bookworm (CVE-2026-54369, CVE-2026-54370)

- - - - -
4ba3df32 by Utkarsh Gupta at 2026-07-12T06:14:29+05:30
lts: angular.js postponed in bullseye/bookworm (CVE-2026-11998)

- - - - -
fd8bef76 by Utkarsh Gupta at 2026-07-12T06:14:30+05:30
lts: assimp postponed in bullseye/bookworm (CVE-2026-14610, CVE-2026-14604, 
CVE-2025-15666)

- - - - -
e6b822be by Utkarsh Gupta at 2026-07-12T06:14:32+05:30
lts: attr postponed in bullseye/bookworm (CVE-2026-54371)

- - - - -
a8b14913 by Utkarsh Gupta at 2026-07-12T06:14:33+05:30
lts: botan postponed in bullseye/bookworm (CVE-2026-32884, CVE-2026-32877)

- - - - -
0fb5f7c0 by Utkarsh Gupta at 2026-07-12T06:14:35+05:30
lts: note v3.10.0 only partially fixes CVE-2026-49145/ack

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2181,8 +2181,11 @@ CVE-2026-49146 (App::Ack versions before 3.10.0 for Perl 
allow memory exhaustion
 CVE-2026-49145 (App::Ack versions through 3.10.0 for Perl read arbitrary files 
via --f ...)
        - ack <unfixed>
        [trixie] - ack <no-dsa> (Minor issue)
+       [bookworm] - ack <postponed> (Minor issue; local-only, needs untrusted 
project .ackrc; --files-from still unfixed upstream)
+       [bullseye] - ack <postponed> (Minor issue; local-only, needs untrusted 
project .ackrc; --files-from still unfixed upstream)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41643327/
        NOTE: Fixed by: 
https://github.com/beyondgrep/ack3/commit/45ff5fe77dbd96f7332f31943102291f878f30b8
 (v3.10.0)
+       NOTE: 45ff5fe (v3.10.0) is only a partial fix: it adds --follow to the 
project .ackrc blocklist but --files-from remains accepted, so arbitrary file 
read via --files-from is still unfixed upstream.
 CVE-2026-44840 (Dgraph is an open source distributed GraphQL database. Prior 
to versio ...)
        TODO: check
 CVE-2026-41122 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7, 
LTS2026 r ...)
@@ -4058,6 +4061,8 @@ CVE-2026-14611 (A vulnerability has been found in 
DeepMyst Mysti up to 0.4.0. Th
 CVE-2026-14610 (A flaw has been found in Open Asset Import Library Assimp up 
to 6.0.5. ...)
        - assimp <unfixed> (bug #1141496)
        [trixie] - assimp <no-dsa> (Minor issue)
+       [bookworm] - assimp <postponed> (Minor issue)
+       [bullseye] - assimp <postponed> (Minor issue)
        NOTE: https://github.com/assimp/assimp/issues/6622
        NOTE: https://github.com/assimp/assimp/pull/6649
        NOTE: 
https://github.com/assimp/assimp/commit/eb84eec580d3f4ba2f0fd87409b7d0744620f11e
@@ -4260,6 +4265,8 @@ CVE-2026-14612 (Two off-by-one errors in the FreeIPA 
ipa-otpd daemon's OAuth2 de
 CVE-2026-14604 (A vulnerability was determined in Open Asset Import Library 
Assimp up  ...)
        - assimp <unfixed> (bug #1141494)
        [trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+       [bookworm] - assimp <postponed> (Minor issue, revisit when fixed 
upstream)
+       [bullseye] - assimp <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/assimp/assimp/issues/6620
 CVE-2026-14544 (A flaw was found in HPLIP (HP Linux Imaging and Printing 
Software). Th ...)
        - hplip <unfixed>
@@ -6330,6 +6337,8 @@ CVE-2025-36319 (IBM watsonx.data intelligence 5.2.0, 
5.2.1, 5.2.2, 5.3.0 could a
 CVE-2025-15666 (A security vulnerability has been detected in Open Asset 
Import Librar ...)
        - assimp <unfixed> (bug #1141389)
        [trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+       [bookworm] - assimp <postponed> (Minor issue, revisit when fixed 
upstream)
+       [bullseye] - assimp <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/assimp/assimp/issues/6079
 CVE-2025-12530 (IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1 
through patch ...)
        NOT-FOR-US: IBM
@@ -8813,6 +8822,8 @@ CVE-2026-11720 (A path traversal vulnerability exists in 
the HTTP tool URL build
 CVE-2026-54371 (attr before version 2.6.0 contains a symlink traversal 
vulnerability i ...)
        - attr 1:2.6.0-1 (bug #1141107)
        [trixie] - attr <no-dsa> (Will be fixed first in unstable, then point 
release update; not to be backported by individual patches)
+       [bookworm] - attr <postponed> (Minor issue; local symlink-traversal in 
recursive getfattr/setfattr; fix is a complete walk_tree rewrite, high 
regression risk)
+       [bullseye] - attr <postponed> (Minor issue; local symlink-traversal in 
recursive getfattr/setfattr; fix is a complete walk_tree rewrite, high 
regression risk)
        NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
        NOTE: Fixed by: 
https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=641ea6fcc556c1f34b77efb9cd3f876dff0a0a07
 (v2.6.0)
        NOTE: Fixed by: 
https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=3fb06b9ba314d37035d0877e6de313de754f1ac8
 (v2.6.0)
@@ -8820,6 +8831,8 @@ CVE-2026-54371 (attr before version 2.6.0 contains a 
symlink traversal vulnerabi
 CVE-2026-54370 (acl before version 2.4.0 contains a time-of-check to 
time-of-use (TOCT ...)
        - acl 2.4.0-1 (bug #1141110)
        [trixie] - acl <no-dsa> (Will be fixed first in unstable, then point 
release update; not to be backported by individual patches)
+       [bookworm] - acl <postponed> (Minor issue; local TOCTOU in recursive 
setfacl/chacl; fix needs 2.4.0 acl_*_at() ABI + walk_tree rewrite, not 
individually backportable)
+       [bullseye] - acl <postponed> (Minor issue; local TOCTOU in recursive 
setfacl/chacl; fix needs 2.4.0 acl_*_at() ABI + walk_tree rewrite, not 
individually backportable)
        NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
        NOTE: Fixed by: 
https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=601cc884a548ae9e9d246ae749e54b3272e4b1d7
 (v2.4.0)
        NOTE: Fixed by: 
https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=54e14e9bc545f505b379d0792a2748d9baf88700
 (v2.4.0)
@@ -8829,6 +8842,8 @@ CVE-2026-54370 (acl before version 2.4.0 contains a 
time-of-check to time-of-use
 CVE-2026-54369 (acl before version 2.4.0 contains a symlink traversal 
vulnerability in ...)
        - acl 2.4.0-1 (bug #1141110)
        [trixie] - acl <no-dsa> (Will be fixed first in unstable, then point 
release update; not to be backported by individual patches)
+       [bookworm] - acl <postponed> (Minor issue; libacl acl_*_file() follow 
symlinks; fix adds new acl_*_at() ABI, not individually backportable)
+       [bullseye] - acl <postponed> (Minor issue; libacl acl_*_file() follow 
symlinks; fix adds new acl_*_at() ABI, not individually backportable)
        NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
        NOTE: Fixed by: 
https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=5906d2868ec8d3b08be556153696e6b1122eeeda
 (v2.4.0)
        NOTE: Fixed by: 
https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=0071c6d1fea0a8a6270333baa85fb609be325c26
 (v2.4.0)
@@ -12089,6 +12104,8 @@ CVE-2026-12053 (GitLab has remediated an issue in 
GitLab EE affecting all versio
 CVE-2026-11998 (A flaw in AngularJS' Strict Contextual Escaping (SCE) logic 
allows byp ...)
        - angular.js <unfixed> (bug #1141314)
        [trixie] - angular.js <no-dsa> (Minor issue)
+       [bookworm] - angular.js <postponed> (Minor issue; EOL upstream, no fix 
available; only reachable with custom RegExp trustedResourceUrlList matchers 
using alternation)
+       [bullseye] - angular.js <postponed> (Minor issue; EOL upstream, no fix 
available; only reachable with custom RegExp trustedResourceUrlList matchers 
using alternation)
        NOTE: 
https://www.herodevs.com/vulnerability-directory/cve-2026-11998?nes-for-angularjs
 CVE-2026-11379 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
@@ -67894,6 +67911,8 @@ CVE-2026-32884 (Botan is a C++ cryptography library. 
Prior to version 3.11.0, du
        - botan3 3.11.0+dfsg-2
        - botan <removed>
        [trixie] - botan <no-dsa> (Minor issue)
+       [bookworm] - botan <postponed> (Minor issue; case-sensitive CN fallback 
in DNS name-constraint check; fix only in 3.11.0)
+       [bullseye] - botan <postponed> (Minor issue; case-sensitive CN fallback 
in DNS name-constraint check; fix only in 3.11.0)
        NOTE: 
https://github.com/randombit/botan/security/advisories/GHSA-7c3g-7763-ggj5
 CVE-2026-32883 (Botan is a C++ cryptography library. From version 3.0.0 to 
before vers ...)
        [experimental] - botan3 3.11.0+dfsg-1
@@ -67906,6 +67925,8 @@ CVE-2026-32877 (Botan is a C++ cryptography library. 
From version 2.3.0 to befor
        - botan3 3.11.0+dfsg-2
        - botan <removed>
        [trixie] - botan <no-dsa> (Minor issue)
+       [bookworm] - botan <postponed> (Minor issue; SM2 C3 heap over-read; fix 
only in 3.11.0)
+       [bullseye] - botan <postponed> (Minor issue; SM2 C3 heap over-read; fix 
only in 3.11.0)
        NOTE: 
https://github.com/randombit/botan/security/advisories/GHSA-7jj6-4r42-w9h6
        NOTE: 
https://github.com/randombit/botan/commit/f3c31f96f58f1d1d482032d8f4286dc9ebbc6712
 (3.11.0)
 CVE-2026-32794 (Improper Certificate Validation vulnerability in Apache 
Airflow Provid ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3469ea93fa5284f9bf13d4eace8370296a721e02...0fb5f7c0d4bcd97009727268e60dcca34420c93d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3469ea93fa5284f9bf13d4eace8370296a721e02...0fb5f7c0d4bcd97009727268e60dcca34420c93d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to