Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ab780b70 by Utkarsh Gupta at 2026-07-13T02:01:42+05:30
lts: freetype not-affected in bullseye/bookworm (CVE-2026-50811)
- - - - -
de0e289a by Utkarsh Gupta at 2026-07-13T02:01:44+05:30
lts: gnupg2 not-affected/postponed in bullseye/bookworm
(CVE-2026-57062)
- - - - -
8838fb9c by Utkarsh Gupta at 2026-07-13T02:01:45+05:30
lts: gst-libav1.0 postponed in bullseye/bookworm (CVE-2026-12893)
- - - - -
26d6f3d6 by Utkarsh Gupta at 2026-07-13T02:01:47+05:30
lts: gzip postponed in bullseye/bookworm
(CVE-2026-41991, CVE-2026-41992)
- - - - -
5fd334fa by Utkarsh Gupta at 2026-07-13T02:01:48+05:30
lts: haproxy postponed in bullseye/bookworm
(CVE-2026-55203, CVE-2026-55204)
- - - - -
1f6976e7 by Utkarsh Gupta at 2026-07-13T02:01:50+05:30
lts: libhttp-date-perl postponed in bullseye/bookworm
(CVE-2026-14741)
- - - - -
d05acf85 by Utkarsh Gupta at 2026-07-13T02:01:51+05:30
lts: libidn postponed in bullseye/bookworm (CVE-2026-57053)
- - - - -
d421c210 by Utkarsh Gupta at 2026-07-13T02:01:53+05:30
lts: libxml2 postponed in bullseye/bookworm (CVE-2026-6653)
- - - - -
81a24224 by Utkarsh Gupta at 2026-07-13T02:01:55+05:30
lts: nghttp2 postponed in bullseye/bookworm (CVE-2026-58055)
- - - - -
5b224b3c by Utkarsh Gupta at 2026-07-13T02:01:56+05:30
lts: openssh postponed in bullseye/bookworm (8 CVEs)
- - - - -
8fc64418 by Utkarsh Gupta at 2026-07-13T02:01:58+05:30
lts: p11-kit postponed in bullseye/bookworm (CVE-2026-13757)
- - - - -
207bf6d4 by Utkarsh Gupta at 2026-07-13T02:01:59+05:30
lts: pam postponed in bullseye/bookworm (CVE-2026-54411)
- - - - -
db882698 by Utkarsh Gupta at 2026-07-13T02:02:01+05:30
lts: pillow postponed in bullseye/bookworm (4 CVEs)
- - - - -
a20e0052 by Utkarsh Gupta at 2026-07-13T02:02:02+05:30
lts: pulseaudio postponed in bullseye/bookworm (CVE-2026-14330)
- - - - -
4f358345 by Utkarsh Gupta at 2026-07-13T02:02:04+05:30
lts: pyjwt not-affected/postponed in bullseye/bookworm (5 CVEs)
- - - - -
e073aaed by Utkarsh Gupta at 2026-07-13T02:02:05+05:30
lts: python-django not-affected/postponed in bullseye/bookworm
(CVE-2026-48588, CVE-2026-53877, CVE-2026-53878)
- - - - -
89621927 by Utkarsh Gupta at 2026-07-13T02:02:07+05:30
lts: python-webob postponed in bullseye/bookworm (CVE-2026-44889)
- - - - -
888d638e by Utkarsh Gupta at 2026-07-13T02:02:08+05:30
lts: rpm postponed in bullseye/bookworm (CVE-2026-44605)
- - - - -
c2293c8d by Utkarsh Gupta at 2026-07-13T02:02:10+05:30
lts: rrdtool postponed in bullseye/bookworm (CVE-2026-43958)
- - - - -
bd5db2b6 by Utkarsh Gupta at 2026-07-13T02:02:11+05:30
lts: socat not-affected in bullseye/bookworm (CVE-2026-56123)
- - - - -
46c425b7 by Utkarsh Gupta at 2026-07-13T02:02:13+05:30
lts: sssd postponed in bullseye/bookworm
(CVE-2026-12610, CVE-2026-14474, CVE-2026-14476)
- - - - -
0f6de9a7 by Utkarsh Gupta at 2026-07-13T02:02:14+05:30
lts: wget postponed in bullseye/bookworm (4 CVEs)
- - - - -
f72b44ee by Utkarsh Gupta at 2026-07-13T02:02:16+05:30
lts: libdbi-perl postponed in bullseye/bookworm
(CVE-2026-14380, CVE-2026-14739, CVE-2026-14740)
- - - - -
d6f1e3fd by Utkarsh Gupta at 2026-07-13T02:02:16+05:30
dla-needed: add libass
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1190,6 +1190,8 @@ CVE-2025-45422 (Incorrect access control in Proximus
b-box v8c.725A allows authe
CVE-2026-14741
- libhttp-date-perl 6.08-1
[trixie] - libhttp-date-perl <no-dsa> (Minor issue)
+ [bookworm] - libhttp-date-perl <postponed> (Minor issue)
+ [bullseye] - libhttp-date-perl <postponed> (Minor issue)
NOTE:
https://github.com/libwww-perl/HTTP-Date/commit/78c20952cdfbf11e03cf1199ad70f13298a84c5c
(v6.08)
CVE-2026-9253 (The WP Cost Estimation & Payment Forms Builder (E&P Forms)
plugin for ...)
NOT-FOR-US: WordPress plugin
@@ -2475,14 +2477,20 @@ CVE-2026-6101 (The AMP for WP \u2013 Accelerated Mobile
Pages plugin for WordPre
CVE-2026-60002 (ssh in OpenSSH before 10.4 can have a use-after-free when a
server cha ...)
- openssh 1:10.4p1-1
[trixie] - openssh <no-dsa> (Minor issue)
+ [bookworm] - openssh <postponed> (Minor issue)
+ [bullseye] - openssh <postponed> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.4p1
CVE-2026-60001 (sshd in OpenSSH before 10.4 does not always honor the minimum
authenti ...)
- openssh 1:10.4p1-1
[trixie] - openssh <no-dsa> (Minor issue)
+ [bookworm] - openssh <postponed> (Minor issue)
+ [bullseye] - openssh <postponed> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.4p1
CVE-2026-60000 (sshd in OpenSSH before 10.4 allows remote attackers to cause a
denial ...)
- openssh 1:10.4p1-1
[trixie] - openssh <no-dsa> (Minor issue)
+ [bookworm] - openssh <postponed> (Minor issue)
+ [bullseye] - openssh <postponed> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.4p1
CVE-2026-5799 (Authorization bypass through User-Controlled key vulnerability
in Idvl ...)
NOT-FOR-US: Idvlabs Ontime
@@ -2491,22 +2499,32 @@ CVE-2026-5730 (Authorization bypass through
User-Controlled key vulnerability in
CVE-2026-59999 (In sshd in OpenSSH before 10.4, DisableForwarding=yes was
supposed to ...)
- openssh 1:10.4p1-1
[trixie] - openssh <no-dsa> (Minor issue)
+ [bookworm] - openssh <postponed> (Minor issue)
+ [bullseye] - openssh <postponed> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.4p1
CVE-2026-59998 (sshd in OpenSSH before 10.4 has an undocumented
security-relevant beha ...)
- openssh 1:10.4p1-1
[trixie] - openssh <no-dsa> (Minor issue)
+ [bookworm] - openssh <postponed> (Minor issue)
+ [bullseye] - openssh <postponed> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.4p1
CVE-2026-59997 (internal-sftp in sshd in OpenSSH before 10.4 recognizes only
the first ...)
- openssh 1:10.4p1-1
[trixie] - openssh <no-dsa> (Minor issue)
+ [bookworm] - openssh <postponed> (Minor issue)
+ [bullseye] - openssh <postponed> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.4p1
CVE-2026-59996 (scp in OpenSSH before 10.4 may place a file in the parent
directory of ...)
- openssh 1:10.4p1-1
[trixie] - openssh <no-dsa> (Minor issue)
+ [bookworm] - openssh <postponed> (Minor issue)
+ [bullseye] - openssh <postponed> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.4p1
CVE-2026-59995 (sftp in OpenSSH before 10.4 does not properly constrain the
location o ...)
- openssh 1:10.4p1-1
[trixie] - openssh <no-dsa> (Minor issue)
+ [bookworm] - openssh <postponed> (Minor issue)
+ [bullseye] - openssh <postponed> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.4p1
CVE-2026-59800 (9Router before 0.4.44 contains an OS command injection
vulnerability i ...)
NOT-FOR-US: 9Router
@@ -2534,18 +2552,26 @@ CVE-2026-58473 (Cognee before 1.2.0 contains an
improper access control vulnerab
CVE-2026-58472 (GNU Wget through 1.25.0, fixed in commit dd692d9, contains a
heap buff ...)
- wget <unfixed> (bug #1141689)
[trixie] - wget <no-dsa> (Minor issue)
+ [bookworm] - wget <postponed> (Minor issue)
+ [bullseye] - wget <postponed> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812
CVE-2026-58471 (GNU Wget through 1.25.0, fixed in commit c2640fe, contains a
heap buff ...)
- wget <unfixed> (bug #1141689)
[trixie] - wget <no-dsa> (Minor issue)
+ [bookworm] - wget <postponed> (Minor issue)
+ [bullseye] - wget <postponed> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee
CVE-2026-58470 (GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an
integer ...)
- wget <unfixed> (bug #1141689)
[trixie] - wget <no-dsa> (Minor issue)
+ [bookworm] - wget <postponed> (Minor issue)
+ [bullseye] - wget <postponed> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf
CVE-2026-58469 (GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a
heap buff ...)
- wget <unfixed> (bug #1141689)
[trixie] - wget <no-dsa> (Minor issue)
+ [bookworm] - wget <postponed> (Minor issue)
+ [bullseye] - wget <postponed> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826
CVE-2026-58468 (NocoBase through 2.1.20 contains a server-side request forgery
vulnera ...)
NOT-FOR-US: NocoBase
@@ -2656,6 +2682,8 @@ CVE-2026-51937 (An issue in Oneblog V2.3.9 allows a
remote attacker to obtain se
CVE-2026-50811 (An out-of-bounds read vulnerability exists in FreeType 2.14.3
and vers ...)
- freetype <unfixed> (bug #1141704)
[trixie] - freetype <no-dsa> (Minor issue)
+ [bookworm] - freetype <not-affected> (TT_Get_Var_Design OOB read
introduced in 2.14.0; shipped code uses safe coords[i]=0)
+ [bullseye] - freetype <not-affected> (TT_Get_Var_Design OOB read
introduced in 2.14.0; shipped code uses safe coords[i]=0)
NOTE: https://gitlab.freedesktop.org/freetype/freetype/-/work_items/1436
NOTE: Fixed by:
https://gitlab.freedesktop.org/freetype/freetype/-/commit/5a280ecde6f324de0d226261036e736e0cb49a71
CVE-2026-50810 (A NULL pointer dereference in smooth_parse_stream_index() in
src/media ...)
@@ -2763,6 +2791,8 @@ CVE-2026-14482 (The
\u591a\u8bf4\u793e\u4f1a\u5316\u8bc4\u8bba\u6846 plugin for
CVE-2026-14476 (A path traversal flaw was found in SSSD's AD GPO provider. The
ad_gpo_ ...)
- sssd <unfixed> (bug #1141769)
[trixie] - sssd <no-dsa> (Minor issue)
+ [bookworm] - sssd <postponed> (Minor issue)
+ [bullseye] - sssd <postponed> (Minor issue)
NOTE: https://github.com/SSSD/sssd/pull/8896
NOTE: Fixed by:
https://github.com/SSSD/sssd/commit/ba207eab76ff5253662a763b9b6e9ea42f03d31b
(master)
NOTE: Fixed by:
https://github.com/SSSD/sssd/commit/3c1a31ab668b1ed7b97eb72d915a4187e549d86c
(sssd-2-12 branch)
@@ -2771,6 +2801,8 @@ CVE-2026-14476 (A path traversal flaw was found in SSSD's
AD GPO provider. The a
CVE-2026-14474 (A flaw was found in SSSD's LDAP sudo provider. When the
ldap_sudo_sear ...)
- sssd <unfixed> (bug #1141769)
[trixie] - sssd <no-dsa> (Minor issue)
+ [bookworm] - sssd <postponed> (Minor issue)
+ [bullseye] - sssd <postponed> (Minor issue)
NOTE: https://github.com/SSSD/sssd/pull/8897
NOTE: Fixed by:
https://github.com/SSSD/sssd/commit/aa74f8b06b974796dfc4760f2363ab78fbb8cc56
(sssd-2-12 branch)
NOTE: Fixed by:
https://github.com/SSSD/sssd/commit/0dd9e45e7cde18a3b7c2975b587d48a82eb5d830
(sssd-2-10 branch)
@@ -2851,17 +2883,23 @@ CVE-2026-14895 (String::Util versions before 1.36 for
Perl are susceptible to a
CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code
injection vi ...)
- libdbi-perl 1.650-1 (bug #1141667)
[trixie] - libdbi-perl <no-dsa> (Minor issue)
+ [bookworm] - libdbi-perl <postponed> (Minor issue)
+ [bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625527/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259
(1.650)
CVE-2026-14739 (DBI versions before 1.650 for Perl have a heap overflow when
preparsin ...)
- libdbi-perl 1.650-1 (bug #1141667)
[trixie] - libdbi-perl <no-dsa> (Minor issue)
+ [bookworm] - libdbi-perl <postponed> (Minor issue)
+ [bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625530/
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395
(1.650)
CVE-2026-14740 (DBI versions before 1.650 for Perl read one byte out-of-bounds
in prep ...)
- libdbi-perl 1.650-1 (bug #1141667)
[trixie] - libdbi-perl <no-dsa> (Minor issue)
+ [bookworm] - libdbi-perl <postponed> (Minor issue)
+ [bullseye] - libdbi-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625532/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01
(1.650)
@@ -3000,16 +3038,22 @@ CVE-2026-7017 (HTTP::Tiny versions before 0.095 for
Perl forward credential head
CVE-2026-53878 (An issue was discovered in Django 6.0 before 6.0.7 and 5.2
before 5.2. ...)
- python-django 3:5.2.16-1 (bug #1141629)
[trixie] - python-django <no-dsa> (Minor issue)
+ [bookworm] - python-django <not-affected> (DomainNameValidator
introduced in Django 5.1)
+ [bullseye] - python-django <not-affected> (DomainNameValidator
introduced in Django 5.1)
NOTE:
https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
NOTE: Fixed by:
https://github.com/django/django/commit/d5d60ed0323cddaa0ce0237a26a3d49ac21ee05e
(5.2.16)
CVE-2026-53877 (An issue was discovered in Django 6.0 before 6.0.7 and 5.2
before 5.2. ...)
- python-django 3:5.2.16-1 (bug #1141629)
[trixie] - python-django <no-dsa> (Minor issue)
+ [bookworm] - python-django <postponed> (Minor issue)
+ [bullseye] - python-django <postponed> (Minor issue)
NOTE:
https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
NOTE: Fixed by:
https://github.com/django/django/commit/6c66eb8cec52b303af85c2c6e4dd00aa37654dbc
(5.2.16)
CVE-2026-48588 (An issue was discovered in Django 6.0 before 6.0.7 and 5.2
before 5.2. ...)
- python-django 3:5.2.16-1 (bug #1141629)
[trixie] - python-django <no-dsa> (Minor issue)
+ [bookworm] - python-django <postponed> (Minor issue)
+ [bullseye] - python-django <postponed> (Minor issue)
NOTE:
https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
NOTE: Fixed by:
https://github.com/django/django/commit/721685aa7799cc9327bd202cd1f70bd012ca95a7
(5.2.16)
CVE-2026-XXXX [InspIRCd Security Advisory 2026-01]
@@ -3419,11 +3463,15 @@ CVE-2026-55798 (Pillow is a Python imaging library.
Prior to 12.3.0, WindowsView
CVE-2026-55380 (Pillow is a Python imaging library. Prior to 12.3.0,
PIL/GdImageFile.p ...)
- pillow <unfixed>
[trixie] - pillow <no-dsa> (Minor issue)
+ [bookworm] - pillow <postponed> (Minor issue)
+ [bullseye] - pillow <postponed> (Minor issue)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675
(12.3.0)
CVE-2026-55379 (Pillow is a Python imaging library. Prior to 12.3.0,
PIL/BdfFontFile.p ...)
- pillow <unfixed>
[trixie] - pillow <no-dsa> (Minor issue)
+ [bookworm] - pillow <postponed> (Minor issue)
+ [bullseye] - pillow <postponed> (Minor issue)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
(12.3.0)
CVE-2026-54893 (URL path injection in the Microsoft Graph adapter of Swoosh.
Swoosh.Ad ...)
@@ -3436,11 +3484,15 @@ CVE-2026-54291 (pgjdbc is an open source postgresql
JDBC Driver. In releases 42.
CVE-2026-54060 (Pillow is a Python imaging library. Prior to 12.3.0,
PIL/FontFile.py F ...)
- pillow <unfixed>
[trixie] - pillow <no-dsa> (Minor issue)
+ [bookworm] - pillow <postponed> (Minor issue)
+ [bullseye] - pillow <postponed> (Minor issue)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
(12.3.0)
CVE-2026-54059 (Pillow is a Python imaging library. Prior to 12.3.0,
PIL/PcfFontFile.p ...)
- pillow <unfixed>
[trixie] - pillow <no-dsa> (Minor issue)
+ [bookworm] - pillow <postponed> (Minor issue)
+ [bullseye] - pillow <postponed> (Minor issue)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
(12.3.0)
CVE-2026-53913 (Improper Authentication, Missing Authentication for Critical
Function, ...)
@@ -4290,6 +4342,8 @@ CVE-2025-71342 (picklescan before 0.0.30 fails to detect
malicious pickle files
CVE-2026-12893 [gstreamer1-libav: gstreamer1-libav: NULL pointer dereference
in gstavdemux.c error handler]
- gst-libav1.0 1.28.4-1
[trixie] - gst-libav1.0 <no-dsa> (Minor issue)
+ [bookworm] - gst-libav1.0 <postponed> (Minor issue)
+ [bullseye] - gst-libav1.0 <postponed> (Minor issue)
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0038.html
NOTE:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11802
NOTE: Fixed by:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f904dfda677a0c148de8c391f3dbb11490c7e026
(1.29.2)
@@ -5816,6 +5870,8 @@ CVE-2026-14358 (Improper neutralization of input during
web page generation ('cr
CVE-2026-14330 (Multiple unbounded alloca() calls in the PulseAudio protocol
server.)
- pulseaudio <unfixed> (bug #1141309)
[trixie] - pulseaudio <no-dsa> (Minor issue)
+ [bookworm] - pulseaudio <postponed> (Minor issue)
+ [bullseye] - pulseaudio <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2495907
CVE-2026-14324 (RAOP module accepts unbounded Content-Length values and does
not check ...)
- pipewire 1.6.8-1 (bug #1141308)
@@ -8337,6 +8393,8 @@ CVE-2026-13149 (brace-expansion through 5.0.6 is
vulnerable to denial of service
CVE-2026-12610 (A flaw was found in sssd. When authenticating with a YubiKey,
the SSSD ...)
- sssd <unfixed> (bug #1141323)
[trixie] - sssd <no-dsa> (Minor issue)
+ [bookworm] - sssd <postponed> (Minor issue)
+ [bullseye] - sssd <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490288
NOTE: https://github.com/SSSD/sssd/issues/8796
NOTE:
https://github.com/SSSD/sssd/commit/fa7a55949a30fed064a28ea6f0c801fc5e8c5ba7
(master)
@@ -8454,6 +8512,8 @@ CVE-2026-57964
CVE-2026-44605
- rpm <unfixed>
[trixie] - rpm <no-dsa> (Minor issue)
+ [bookworm] - rpm <postponed> (Minor issue)
+ [bullseye] - rpm <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2482481
CVE-2026-13606
- graphicsmagick <unfixed> (bug #1141493)
@@ -8828,10 +8888,14 @@ CVE-2026-46406 (Claude Code is an agentic coding tool.
From 2.1.59 until 2.1.12
CVE-2026-41992 (GNU gzip contains a global buffer overflow vulnerability in
the LZH de ...)
- gzip <unfixed> (bug #1141443)
[trixie] - gzip <no-dsa> (Minor issue)
+ [bookworm] - gzip <postponed> (Minor issue)
+ [bullseye] - gzip <postponed> (Minor issue)
NOTE:
https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681
CVE-2026-41991 (GNU gzip contains a vulnerability in the gzexe utility related
to inse ...)
- gzip <unfixed> (bug #1141442)
[trixie] - gzip <no-dsa> (Minor issue)
+ [bookworm] - gzip <postponed> (Minor issue)
+ [bullseye] - gzip <postponed> (Minor issue)
NOTE:
https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269
CVE-2026-41052 (Improper privilege handling could be used by users withProject
Owner r ...)
NOT-FOR-US: Rancher
@@ -8854,6 +8918,8 @@ CVE-2026-22078 (Because O+ Connect's IPC service does not
authenticate clients,
CVE-2026-13757 (A flaw was found in p11-kit. The RPC message attribute parsing
functio ...)
- p11-kit 0.26.4-1 (bug #1141184)
[trixie] - p11-kit <no-dsa> (Minor issue)
+ [bookworm] - p11-kit <postponed> (Minor issue)
+ [bullseye] - p11-kit <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2494556
NOTE: https://github.com/p11-glue/p11-kit/issues/767
NOTE: https://github.com/p11-glue/p11-kit/pull/768
@@ -9199,6 +9265,8 @@ CVE-2026-58056 (RustDesk gates incoming control messages
on per-capability flags
CVE-2026-58055 (nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1
Upgrade re ...)
- nghttp2 <unfixed> (bug #1140917)
[trixie] - nghttp2 <no-dsa> (Minor issue)
+ [bookworm] - nghttp2 <postponed> (Minor issue)
+ [bullseye] - nghttp2 <postponed> (Minor issue)
NOTE:
https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc
NOTE:
https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e
CVE-2026-58054 (MyBB 1.8.40 does not restrict which usergroup a limited Admin
Control ...)
@@ -10802,6 +10870,8 @@ CVE-2026-56129 (Generic IO & Memory Access driver for
PCs provided by TOSHIBA CO
CVE-2026-56123 (socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based
buffer ove ...)
- socat 1.8.1.3-1
[trixie] - socat <no-dsa> (Minor issue)
+ [bookworm] - socat <not-affected> (SOCKS5 client (xio-socks5.c)
introduced in 1.8.0.0)
+ [bullseye] - socat <not-affected> (SOCKS5 client (xio-socks5.c)
introduced in 1.8.0.0)
CVE-2026-56122 (Winstone Servlet Engine through 0.9.10 contains a path
traversal vulne ...)
NOT-FOR-US: Winstone Servlet Container
CVE-2026-56091 (When using Apache Shiro with the shiro-guice module in a web
servlet c ...)
@@ -14255,6 +14325,8 @@ CVE-2026-55099
CVE-2026-57062 (CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG
through 2 ...)
- gnupg2 2.4.9-5
[trixie] - gnupg2 <no-dsa> (Minor issue)
+ [bookworm] - gnupg2 <postponed> (Minor issue)
+ [bullseye] - gnupg2 <not-affected> (gpgsm GCM CMS-decrypt path not
present; introduced after 2.2.27)
NOTE: https://blog.calif.io/p/how-to-format-a-ciphertext
NOTE: Fixed by:
https://github.com/gpg/gnupg/commit/4c7e68cf3d335328821bdbb70db309a60d0e4fd4
CVE-2026-56815 (pwnlift before d7a9544, in a privileged deployment, contains a
symlink ...)
@@ -14855,6 +14927,8 @@ CVE-2026-45034 (PhpSpreadsheet is a pure PHP library
for reading and writing spr
CVE-2026-44889 (WebOb provides objects for HTTP requests and responses. Prior
to 1.8.1 ...)
- python-webob 1:1.8.10-1
[trixie] - python-webob 1:1.8.10-0+deb13u1
+ [bookworm] - python-webob <postponed> (Minor issue)
+ [bullseye] - python-webob <postponed> (Minor issue)
NOTE:
https://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95
CVE-2026-44727 (Jupyter Server is the backend for Jupyter web applications.
Prior to 2 ...)
- jupyter-server 2.20.0-1
@@ -15293,6 +15367,8 @@ CVE-2026-11373 (Net::Statsite::Client versions through
1.1.0 for Perl allow metr
CVE-2026-6653 (Use After Free in libxml2's xmlParseInternalSubset from GNOME
libxml2 ...)
- libxml2 2.14.5+dfsg-0.1
[trixie] - libxml2 <no-dsa> (Minor issue)
+ [bookworm] - libxml2 <postponed> (Minor issue; UAF present via
CVE-2021-3541 backport, fix only in 2.11.0)
+ [bullseye] - libxml2 <postponed> (Minor issue; UAF present via
CVE-2021-3541 backport, fix only in 2.11.0)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/22/3
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/libxml2/-/commit/463bbeeca1805b5c4828f50d0fefc4eebaf620df
(v2.11.0)
@@ -16286,11 +16362,15 @@ CVE-2026-55204 (HAProxy through 3.4.0, fixed in
commit 9a6d1fe, contains a null
[experimental] - haproxy 3.4.1-1
- haproxy 3.2.20-1 (bug #1140430)
[trixie] - haproxy <no-dsa> (Minor issue)
+ [bookworm] - haproxy <postponed> (Minor issue)
+ [bullseye] - haproxy <postponed> (Minor issue)
NOTE:
https://github.com/haproxy/haproxy/commit/9a6d1fe3f00d86ab4ea6ea6ea0a5d48fc058a513
CVE-2026-55203 (HAProxy through 3.4.0, fixed in commit 5985276, contains an
integer ov ...)
[experimental] - haproxy 3.4.1-1
- haproxy 3.2.20-1 (bug #1140430)
[trixie] - haproxy <no-dsa> (Minor issue)
+ [bookworm] - haproxy <postponed> (Minor issue)
+ [bullseye] - haproxy <postponed> (Minor issue)
NOTE:
https://github.com/haproxy/haproxy/commit/5985276735777634d8c85f1d73bb7764aab0d6dd
CVE-2026-54419 (claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management
System; no r ...)
NOT-FOR-US: PBX-In-A-Flash Hotel Management System
@@ -18716,6 +18796,8 @@ CVE-2024-22447 (Dell Peripheral Manager, versions prior
to 1.7.3, contain an unc
CVE-2026-57053 (GNU libidn before 1.44 is prone to out-of-bounds reads
ofuninitialized ...)
- libidn 1.44-1
[trixie] - libidn <no-dsa> (Minor issue)
+ [bookworm] - libidn <postponed> (Minor issue)
+ [bullseye] - libidn <postponed> (Minor issue)
NOTE:
https://lists.gnu.org/archive/html/help-libidn/2026-06/msg00001.html
NOTE:
https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html
CVE-2026-46448 (In OpenStack Nova before 33.0.2, the server create API does
not strip ...)
@@ -19629,6 +19711,8 @@ CVE-2026-54412 (LiamBindle MQTT-C through version 1.1.6
contains a heap-based ou
CVE-2026-54411 (Linux-PAM through 1.7.2 contains an observable timing
discrepancy (CWE ...)
- pam <unfixed> (bug #1140190)
[trixie] - pam <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - pam <postponed> (Minor issue)
+ [bullseye] - pam <postponed> (Minor issue)
NOTE: https://github.com/linux-pam/linux-pam/issues/992
NOTE: https://github.com/linux-pam/linux-pam/pull/991
CVE-2026-54410 (nanoMODBUS through v1.23.0 contains an off-by-one buffer
overflow in t ...)
@@ -28618,6 +28702,8 @@ CVE-2026-44211 (Cline is an autonomous coding agent as
an SDK, IDE extension, or
CVE-2026-43958 (A flaw was found in rrdcached, a component of rrdtool. A local
attacke ...)
- rrdtool <unfixed> (bug #1140106)
[trixie] - rrdtool <no-dsa> (Minor issue)
+ [bookworm] - rrdtool <postponed> (Minor issue)
+ [bullseye] - rrdtool <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460932
NOTE: Fixed by:
https://github.com/oetiker/rrdtool-1.x/commit/4218ec7127ba6c7ea1c20d7c8ea6e2b3f83df73a
(v1.10.0)
CVE-2026-43625 (CodexBar prior to 0.32.0 contains a session cookie leakage
vulnerabili ...)
@@ -30933,26 +31019,36 @@ CVE-2026-48735 (pypdf is a free and open-source
pure-python PDF library. Prior t
CVE-2026-48526 (PyJWT is a JSON Web Token implementation in Python. Prior to
2.13.0, w ...)
- pyjwt 2.13.0-1 (bug #1138191)
[trixie] - pyjwt <no-dsa> (Minor issue)
+ [bookworm] - pyjwt <postponed> (Minor issue)
+ [bullseye] - pyjwt <postponed> (Minor issue)
NOTE:
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx
NOTE:
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
(2.13.0)
CVE-2026-48525 (PyJWT is a JSON Web Token implementation in Python. From 2.8.0
to 2.12 ...)
- pyjwt 2.13.0-1 (bug #1138191)
[trixie] - pyjwt <no-dsa> (Minor issue)
+ [bookworm] - pyjwt <postponed> (Minor issue)
+ [bullseye] - pyjwt <not-affected> (RFC 7797 (b64=false) support not
present)
NOTE:
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39
NOTE:
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
(2.13.0)
CVE-2026-48524 (PyJWT is a JSON Web Token implementation in Python. Prior to
2.13.0, P ...)
- pyjwt 2.13.0-1 (bug #1138191)
[trixie] - pyjwt <no-dsa> (Minor issue)
+ [bookworm] - pyjwt <postponed> (Minor issue)
+ [bullseye] - pyjwt <not-affected> (PyJWKClient not present)
NOTE:
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8
NOTE:
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
(2.13.0)
CVE-2026-48523 (PyJWT is a JSON Web Token implementation in Python. From 2.9.0
to 2.12 ...)
- pyjwt 2.13.0-1 (bug #1138191)
[trixie] - pyjwt <no-dsa> (Minor issue)
+ [bookworm] - pyjwt <not-affected> (PyJWK algorithm binding introduced
in 2.9.0)
+ [bullseye] - pyjwt <not-affected> (PyJWK algorithm binding introduced
in 2.9.0)
NOTE:
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f
NOTE:
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
(2.13.0)
CVE-2026-48522 (PyJWT is a JSON Web Token implementation in Python. Prior to
2.13.0, P ...)
- pyjwt 2.13.0-1 (bug #1138191)
[trixie] - pyjwt <no-dsa> (Minor issue)
+ [bookworm] - pyjwt <postponed> (Minor issue)
+ [bullseye] - pyjwt <not-affected> (PyJWKClient not present)
NOTE:
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4
NOTE:
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
(2.13.0)
CVE-2026-48156 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.12 ...)
=====================================
data/dla-needed.txt
=====================================
@@ -328,6 +328,10 @@ knot-resolver/bullseye
ldap-account-manager/bullseye
NOTE: 20260418: Added by Front-Desk (rouca)
--
+libass
+ NOTE: 20260712: Added by Front-Desk (utkarsh)
+ NOTE: 20260712: TEMP-0000000-AA08BC (GHSA-pjjp-65r7-ppgm): OOB read+write in
wrap_lines_measure from untrusted subtitles; secteam fixed stable via point
release. Affected in bullseye (0.15.0) and bookworm (0.17.1).
(utkarsh/front-desk)
+--
libcaca/bullseye
NOTE: 20260519: Added by Front-Desk (Beuc)
NOTE: 20260519: Fix unstable first. (Beuc/front-desk)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/38ed1d8117293fed0861b93ea13f6b0e099a1ae1...d6f1e3fd6468126429268c77746c2ab520f343c9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/38ed1d8117293fed0861b93ea13f6b0e099a1ae1...d6f1e3fd6468126429268c77746c2ab520f343c9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits