Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
7726eee7 by Sylvain Beucler at 2026-07-14T18:22:31+02:00
lts: add frr/bookworm
- - - - -
40433cb7 by Sylvain Beucler at 2026-07-14T18:43:19+02:00
lts: add pgextwlist
- - - - -
97b481f2 by Sylvain Beucler at 2026-07-14T18:43:25+02:00
CVE-2026-54590/python-asyncssh: bookworm,bullseye not-affected
- - - - -
2d97b835 by Sylvain Beucler at 2026-07-14T18:43:25+02:00
CVE-2026-33154/python-dynaconf: bookworm,bullseye postponed
- - - - -
9ddc0290 by Sylvain Beucler at 2026-07-14T19:14:24+02:00
CVE-2026-48682/fastnetmon: bookworm postponed
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -2582,6 +2582,8 @@ CVE-2026-54591 (AsyncSSH is a Python package which
provides an asynchronous clie
CVE-2026-54590 (AsyncSSH is a Python package which provides an asynchronous
client and ...)
- python-asyncssh <unfixed> (bug #1141817)
[trixie] - python-asyncssh <not-affected> (Incomplete fix for
CVE-2026-45309 not applied)
+ [bookworm] - python-asyncssh <not-affected> (Incomplete fix for
CVE-2026-45309 not applied)
+ [bullseye] - python-asyncssh <not-affected> (Incomplete fix for
CVE-2026-45309 not applied)
NOTE:
https://github.com/ronf/asyncssh/security/advisories/GHSA-qr67-gv47-xwwh
NOTE: Fixed by:
https://github.com/ronf/asyncssh/commit/3d515ba9ba0cd9990d248bdf62bcf05d51261a88
(v2.23.1)
CVE-2026-45309
@@ -28678,6 +28680,7 @@ CVE-2026-49120 (Medplum before 5.1.14 contains a
server-side request forgery vul
CVE-2026-48682 (FastNetMon Community Edition through 1.2.9 contains an
out-of-bounds r ...)
- fastnetmon <unfixed>
[trixie] - fastnetmon <no-dsa> (Minor issue)
+ [bookworm] - fastnetmon <postponed> (Minor issue, OOB read)
NOTE:
https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48682-ipv4-parser-oob
CVE-2026-48598 (Improper Encoding or Escaping of Output vulnerability in
elixir-tesla ...)
- elixir-tesla <itp> (bug #960541)
@@ -75060,6 +75063,8 @@ CVE-2026-33155 (DeepDiff is a project focused on Deep
Difference and search of a
CVE-2026-33154 (dynaconf is a configuration management tool for Python. Prior
to versi ...)
- python-dynaconf 3.2.13-1 (bug #1131476)
[trixie] - python-dynaconf 3.1.7-2+deb13u1
+ [bookworm] - python-dynaconf <postponed> (Minor issue)
+ [bullseye] - python-dynaconf <postponed> (Minor issue)
NOTE:
https://github.com/dynaconf/dynaconf/security/advisories/GHSA-pxrr-hq57-q35p
NOTE: Fixed by:
https://github.com/dynaconf/dynaconf/commit/2fbb45ee36b8c0caa5b924fe19f3c1a5e8603fa7
(3.2.13)
CVE-2026-33151 (Socket.IO is an open source, real-time, bidirectional,
event-based, co ...)
=====================================
data/dla-needed.txt
=====================================
@@ -186,8 +186,10 @@ freerdp2
NOTE: 20260127: Many CVEs fixed in 3.20.1 and 3.21, but missing fix commits
(Beuc/front-desk)
NOTE: 20260713: Also add for bookworm-lts (Beuc/front-desk)
--
-frr/bullseye
+frr
NOTE: 20251102: Added by Front-Desk (apo)
+ NOTE: 20260714: Also add for bookworm.
+ NOTE: 20260714: Many CVEs fixed in bullseye but not in bookworm (low pri)
(Beuc/front-desk)
--
gdal/bullseye
NOTE: 20260419: Added by Front-Desk (rouca)
@@ -536,6 +538,10 @@ perl
NOTE: 20260527: Added by Front-Desk (santiago)
NOTE: 20260527: wait for the DSA before releasing
--
+pgextwlist
+ NOTE: 20260714: Added by Front-Desk (Beuc)
+ NOTE: 20260714: Follow DSA-6385-1 (1 CVE) (Beuc/front-desk)
+--
php-horde-imp/bullseye
NOTE: 20260714: Added by Front-Desk (Beuc)
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fc8ab07233cca9a3389d590eec6a85ed98777482...9ddc0290cd18048249757d7918480d50b2cc9942
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fc8ab07233cca9a3389d590eec6a85ed98777482...9ddc0290cd18048249757d7918480d50b2cc9942
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits