Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
78e637f1 by Utkarsh Gupta at 2026-07-12T06:45:13+05:30
lts: curl not-affected/postponed in bullseye/bookworm (9 CVEs)

- - - - -
2987309f by Utkarsh Gupta at 2026-07-12T06:46:29+05:30
lts: glib2.0 postponed in bullseye/bookworm (CVE-2026-58010 to CVE-2026-58016)

- - - - -
30119240 by Utkarsh Gupta at 2026-07-12T06:47:55+05:30
lts: lmdb postponed in bullseye/bookworm (CVE-2019-16224 to CVE-2019-16228)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7961,29 +7961,39 @@ CVE-2026-58116 (LLaMA-Factory through 0.9.5 contains a 
remote code execution vul
 CVE-2026-58016 (A flaw was found in GLib. A state confusion issue exists in 
g_dbus_nod ...)
        - glib2.0 <unfixed> (bug #1141316)
        [trixie] - glib2.0 <no-dsa> (Minor issue)
+       [bookworm] - glib2.0 <postponed> (Minor issue; GDBus introspection-XML 
OOB-read DoS; no upstream fix yet)
+       [bullseye] - glib2.0 <postponed> (Minor issue; GDBus introspection-XML 
OOB-read DoS; no upstream fix yet)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3932
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5156 (2.89.0)
 CVE-2026-58015 (A flaw was found in GLib. The D-Bus client-side implementation 
of the  ...)
        - glib2.0 2.88.1-2
        [trixie] - glib2.0 <no-dsa> (Minor issue)
+       [bookworm] - glib2.0 <postponed> (Minor issue; DBUS_COOKIE_SHA1 client 
path traversal, needs malicious D-Bus server)
+       [bullseye] - glib2.0 <postponed> (Minor issue; DBUS_COOKIE_SHA1 client 
path traversal, needs malicious D-Bus server)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3931
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5172 (2.89.0)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
 CVE-2026-58014 (A flaw was found in GLib. An off-by-one error can occur in the 
g_key_f ...)
        - glib2.0 2.88.1-2
        [trixie] - glib2.0 <no-dsa> (Minor issue)
+       [bookworm] - glib2.0 <postponed> (Minor issue; GKeyFile off-by-one 
1-byte OOB, reachability-gated)
+       [bullseye] - glib2.0 <postponed> (Minor issue; GKeyFile off-by-one 
1-byte OOB, reachability-gated)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3930
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5171 (2.89.0)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
 CVE-2026-58013 (A flaw was found in GLib. A buffer over-read can occur in 
g_io_channel ...)
        - glib2.0 2.88.1-2
        [trixie] - glib2.0 <no-dsa> (Minor issue)
+       [bookworm] - glib2.0 <postponed> (Minor issue; GIOChannel 
custom-terminator over-read, reachability-gated)
+       [bullseye] - glib2.0 <postponed> (Minor issue; GIOChannel 
custom-terminator over-read, reachability-gated)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3925
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5170 (2.89.0)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5174 (2.88.1)
 CVE-2026-58012 (A flaw was found in GLib. A buffer over-read can occur in the 
g_regex_ ...)
        - glib2.0 2.88.1-2
        [trixie] - glib2.0 <no-dsa> (Minor issue)
+       [bookworm] - glib2.0 <postponed> (Minor issue; g_regex_replace raw-mode 
over-read, needs G_REGEX_RAW)
+       [bullseye] - glib2.0 <postponed> (Minor issue; g_regex_replace raw-mode 
over-read, needs G_REGEX_RAW)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3918
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5132 (2.89.0)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5134 (2.88.1)
@@ -7991,6 +8001,8 @@ CVE-2026-58012 (A flaw was found in GLib. A buffer 
over-read can occur in the g_
 CVE-2026-58011 (A flaw was found in GLib. An out-of-bounds read of only 2 
bytes can oc ...)
        - glib2.0 2.88.1-2
        [trixie] - glib2.0 <no-dsa> (Minor issue)
+       [bookworm] - glib2.0 <postponed> (Minor issue; GDateTime 2-byte 
over-read, reachability-gated)
+       [bullseye] - glib2.0 <postponed> (Minor issue; GDateTime 2-byte 
over-read, reachability-gated)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3917
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5131 (2.89.0)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5134 (2.88.1)
@@ -7998,6 +8010,8 @@ CVE-2026-58011 (A flaw was found in GLib. An 
out-of-bounds read of only 2 bytes
 CVE-2026-58010 (A flaw was found in GLib. An off-by-one error can occur in the 
gvs_tup ...)
        - glib2.0 2.88.1-2
        [trixie] - glib2.0 <no-dsa> (Minor issue)
+       [bookworm] - glib2.0 <postponed> (Minor issue; GVariant deserialiser 
1-byte over-read, reachability-gated)
+       [bullseye] - glib2.0 <postponed> (Minor issue; GVariant deserialiser 
1-byte over-read, reachability-gated)
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3915
        NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5129 (2.89.0)
        NOTE: 
https://gitlab.gnome.org/GNOME/glib/-/commit/8338414f6560216efe67d3cbf549e32f8630252a
 (2.89.0)
@@ -13874,18 +13888,24 @@ CVE-2025-64105 (FOSSBilling is a billing and client 
management system that autom
 CVE-2026-8286 (A vulnerability exists where a new transfer that uses STARTTLS 
to upgr ...)
        - curl 8.21.0~rc2-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <postponed> (Minor issue; STARTTLS connection reuse 
config mismatch)
+       [bullseye] - curl <postponed> (Minor issue; STARTTLS connection reuse 
config mismatch)
        NOTE: https://curl.se/docs/CVE-2026-8286.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/a1701eea289fe7ea80651f801cf992838a491dde 
(curl-7_30_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/a86efdd7ca5433de9231e650f18247de8319ad16 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-8458 (libcurl might in some circumstances reuse the wrong connection 
when as ...)
        - curl 8.21.0~rc2-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <postponed> (Minor issue; needs HTTP Negotiate auth 
with differing service names)
+       [bullseye] - curl <postponed> (Minor issue; needs HTTP Negotiate auth 
with differing service names)
        NOTE: https://curl.se/docs/CVE-2026-8458.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/97c272e5d173ad5f706443e2477f0a84f0044edd 
(curl-7_43_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/5e99b73cf441d9c369768b9cd48b5389b9a2503d 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-8924 (A flaw in curl\u2019s cookie parsing logic allows a malicious 
HTTP ser ...)
        - curl 8.21.0~rc2-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <postponed> (Minor issue; trailing-dot super cookie; 
PSL-enabled build mitigates)
+       [bullseye] - curl <postponed> (Minor issue; trailing-dot super cookie; 
PSL-enabled build mitigates)
        NOTE: https://curl.se/docs/CVE-2026-8924.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 
(curl-7_46_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/51beed175dbfc37da3113f6acce60c630c070ce8 
(rc-8_21_0-1, curl-8_21_0)
@@ -13908,12 +13928,16 @@ CVE-2026-8926 (When asking curl to use a `.netrc` 
file to find credentials and a
 CVE-2026-8927 (When reusing a libcurl handle for sequential transfers driven 
by envir ...)
        - curl 8.21.0~rc2-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <postponed> (Minor issue; libcurl env-proxy Digest 
auth handle reuse)
+       [bullseye] - curl <postponed> (Minor issue; libcurl env-proxy Digest 
auth handle reuse)
        NOTE: https://curl.se/docs/CVE-2026-8927.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/fc6eff13b5414caf6edf22d73a3239e074a04216 
(curl-7_12_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/5c225384b8d52c67ce8259c6e4203bc57aacb567 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-8932 (libcurl would reuse a previously created connection even when 
some mTL ...)
        - curl 8.21.0~rc2-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <postponed> (Minor issue; libcurl mTLS handle-reuse 
config mismatch)
+       [bullseye] - curl <postponed> (Minor issue; libcurl mTLS handle-reuse 
config mismatch)
        NOTE: https://curl.se/docs/CVE-2026-8932.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/a1d6ad26100bc493c7b04f1301b1634b7f5aa8b4 
(curl-7_7)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/7541ae569d82fb308a5e2d94916027da4fa3ba3e 
(rc-8_21_0-1, curl-8_21_0)
@@ -13952,12 +13976,16 @@ CVE-2026-9546 (A vulnerability in libcurl caused the 
HTTP `Referer:` header to p
 CVE-2026-9547 (When a libcurl-based application performs transfers via 
`SCP://` or `S ...)
        - curl 8.21.0~rc2-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <not-affected> (Debian builds --without-libssh 
--with-libssh2; flaw only affects the libssh backend)
+       [bullseye] - curl <not-affected> (Debian builds curl with libssh2, not 
the libssh backend the flaw requires)
        NOTE: https://curl.se/docs/CVE-2026-9547.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/507cf6a13db0375eadd4655b4c64710db29e9cf2 
(curl-7_69_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/0b8dbbc63c98777e4584cb9fbd71df3464008ad1 
(rc-8_21_0-1, curl-8_21_0)
 CVE-2026-10536 (A use-after-free vulnerability exists in libcurl when an 
application c ...)
        - curl 8.21.0~rc2-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <postponed> (Minor issue; needs rare 
CURLOPT_STREAM_DEPENDS + reset/cleanup)
+       [bullseye] - curl <not-affected> (Vulnerable code introduced in 7.88.0; 
bullseye ships 7.74.0)
        NOTE: https://curl.se/docs/CVE-2026-10536.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/71b7e0161032927cdfb4e75ea40f65b8898b3956 
(curl-7_88_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/bfbff7852f050232edd3e5ca5c6bf2021c340f5a 
(rc-8_21_0-1, curl-8_21_0)
@@ -13988,12 +14016,16 @@ CVE-2026-11586 (By default, curl automatically 
responds to WebSocket PING frames
 CVE-2026-11856 (Successfully using libcurl to do a transfer to a specific HTTP 
origin  ...)
        - curl 8.21.0~rc3-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <postponed> (Minor issue; needs Digest auth + libcurl 
handle reuse across origins)
+       [bullseye] - curl <postponed> (Minor issue; needs Digest auth + libcurl 
handle reuse across origins)
        NOTE: https://curl.se/docs/CVE-2026-11856.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/334d78cd18a7310144383929bdcef34ffbf6159b 
(curl-7_10_6)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/5c6b4880357ab3e72967c1c45cae0f96ffabc535 
(rc-8_21_0-3, curl-8_21_0)
 CVE-2026-12064 (When a user invokes curl using a schemeless URL combined with 
`--proto ...)
        - curl 8.21.0~rc3-1
        [trixie] - curl <no-dsa> (Minor issue)
+       [bookworm] - curl <postponed> (Minor issue; needs schemeless URL with 
--proto-default sftp/scp)
+       [bullseye] - curl <not-affected> (Vulnerable code introduced in 7.81.0; 
bullseye ships 7.74.0)
        NOTE: https://curl.se/docs/CVE-2026-12064.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/18270893abdb19f0ca170c118f8a2847dbd304be 
(curl-7_81_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/ab3bb8cd8be8f9d4acb97da0418abc279182041e 
(rc-8_21_0-3, curl-8_21_0)
@@ -642739,6 +642771,8 @@ CVE-2019-16229 
(drivers/gpu/drm/amd/amdkfd/kfd_interrupt.c in the Linux kernel 5
 CVE-2019-16228 (An issue was discovered in py-lmdb 0.97. There is a 
divide-by-zero err ...)
        - lmdb <unfixed> (bug #1141312)
        [trixie] - lmdb <no-dsa> (Minor issue)
+       [bookworm] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
+       [bullseye] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
        - py-lmdb <unfixed> (bug #1132719; unimportant)
        NOTE: src:py-lmdb uses system version of liblmdb
        NOTE: https://github.com/jnwatson/py-lmdb/issues/210
@@ -642746,6 +642780,8 @@ CVE-2019-16228 (An issue was discovered in py-lmdb 
0.97. There is a divide-by-ze
 CVE-2019-16227 (An issue was discovered in py-lmdb 0.97. For certain values of 
mn_flag ...)
        - lmdb <unfixed> (bug #1141312)
        [trixie] - lmdb <no-dsa> (Minor issue)
+       [bookworm] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
+       [bullseye] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
        - py-lmdb <unfixed> (bug #1132719; unimportant)
        NOTE: src:py-lmdb uses system version of liblmdb
        NOTE: https://github.com/jnwatson/py-lmdb/issues/210
@@ -642753,6 +642789,8 @@ CVE-2019-16227 (An issue was discovered in py-lmdb 
0.97. For certain values of m
 CVE-2019-16226 (An issue was discovered in py-lmdb 0.97. mdb_node_del does not 
validat ...)
        - lmdb <unfixed> (bug #1141312)
        [trixie] - lmdb <no-dsa> (Minor issue)
+       [bookworm] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
+       [bullseye] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
        - py-lmdb <unfixed> (bug #1132719; unimportant)
        NOTE: src:py-lmdb uses system version of liblmdb
        NOTE: https://github.com/jnwatson/py-lmdb/issues/210
@@ -642760,6 +642798,8 @@ CVE-2019-16226 (An issue was discovered in py-lmdb 
0.97. mdb_node_del does not v
 CVE-2019-16225 (An issue was discovered in py-lmdb 0.97. For certain values of 
mp_flag ...)
        - lmdb <unfixed> (bug #1141312)
        [trixie] - lmdb <no-dsa> (Minor issue)
+       [bookworm] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
+       [bullseye] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
        - py-lmdb <unfixed> (bug #1132719; unimportant)
        NOTE: src:py-lmdb uses system version of liblmdb
        NOTE: https://github.com/jnwatson/py-lmdb/issues/210
@@ -642767,6 +642807,8 @@ CVE-2019-16225 (An issue was discovered in py-lmdb 
0.97. For certain values of m
 CVE-2019-16224 (An issue was discovered in py-lmdb 0.97. For certain values of 
md_flag ...)
        - lmdb <unfixed> (bug #1141312)
        [trixie] - lmdb <no-dsa> (Minor issue)
+       [bookworm] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
+       [bullseye] - lmdb <postponed> (Minor issue; only reachable via 
attacker-supplied/corrupted LMDB database file; unfixed upstream)
        - py-lmdb <unfixed> (bug #1132719; unimportant)
        NOTE: src:py-lmdb uses system version of liblmdb
        NOTE: https://github.com/jnwatson/py-lmdb/issues/210



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0fb5f7c0d4bcd97009727268e60dcca34420c93d...30119240530fdc8251accb8664553efeeaae3ddf

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/0fb5f7c0d4bcd97009727268e60dcca34420c93d...30119240530fdc8251accb8664553efeeaae3ddf
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to