Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7726eee7 by Sylvain Beucler at 2026-07-14T18:22:31+02:00
lts: add frr/bookworm

- - - - -
40433cb7 by Sylvain Beucler at 2026-07-14T18:43:19+02:00
lts: add pgextwlist

- - - - -
97b481f2 by Sylvain Beucler at 2026-07-14T18:43:25+02:00
CVE-2026-54590/python-asyncssh: bookworm,bullseye not-affected

- - - - -
2d97b835 by Sylvain Beucler at 2026-07-14T18:43:25+02:00
CVE-2026-33154/python-dynaconf: bookworm,bullseye postponed

- - - - -
9ddc0290 by Sylvain Beucler at 2026-07-14T19:14:24+02:00
CVE-2026-48682/fastnetmon: bookworm postponed

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2582,6 +2582,8 @@ CVE-2026-54591 (AsyncSSH is a Python package which 
provides an asynchronous clie
 CVE-2026-54590 (AsyncSSH is a Python package which provides an asynchronous 
client and ...)
        - python-asyncssh <unfixed> (bug #1141817)
        [trixie] - python-asyncssh <not-affected> (Incomplete fix for 
CVE-2026-45309 not applied)
+       [bookworm] - python-asyncssh <not-affected> (Incomplete fix for 
CVE-2026-45309 not applied)
+       [bullseye] - python-asyncssh <not-affected> (Incomplete fix for 
CVE-2026-45309 not applied)
        NOTE: 
https://github.com/ronf/asyncssh/security/advisories/GHSA-qr67-gv47-xwwh
        NOTE: Fixed by: 
https://github.com/ronf/asyncssh/commit/3d515ba9ba0cd9990d248bdf62bcf05d51261a88
 (v2.23.1)
 CVE-2026-45309
@@ -28678,6 +28680,7 @@ CVE-2026-49120 (Medplum before 5.1.14 contains a 
server-side request forgery vul
 CVE-2026-48682 (FastNetMon Community Edition through 1.2.9 contains an 
out-of-bounds r ...)
        - fastnetmon <unfixed>
        [trixie] - fastnetmon <no-dsa> (Minor issue)
+       [bookworm] - fastnetmon <postponed> (Minor issue, OOB read)
        NOTE: 
https://lorikeetsecurity.com/blog/fastnetmon-cve-2026-48682-ipv4-parser-oob
 CVE-2026-48598 (Improper Encoding or Escaping of Output vulnerability in 
elixir-tesla  ...)
        - elixir-tesla <itp> (bug #960541)
@@ -75060,6 +75063,8 @@ CVE-2026-33155 (DeepDiff is a project focused on Deep 
Difference and search of a
 CVE-2026-33154 (dynaconf is a configuration management tool for Python. Prior 
to versi ...)
        - python-dynaconf 3.2.13-1 (bug #1131476)
        [trixie] - python-dynaconf 3.1.7-2+deb13u1
+       [bookworm] - python-dynaconf <postponed> (Minor issue)
+       [bullseye] - python-dynaconf <postponed> (Minor issue)
        NOTE: 
https://github.com/dynaconf/dynaconf/security/advisories/GHSA-pxrr-hq57-q35p
        NOTE: Fixed by: 
https://github.com/dynaconf/dynaconf/commit/2fbb45ee36b8c0caa5b924fe19f3c1a5e8603fa7
 (3.2.13)
 CVE-2026-33151 (Socket.IO is an open source, real-time, bidirectional, 
event-based, co ...)


=====================================
data/dla-needed.txt
=====================================
@@ -186,8 +186,10 @@ freerdp2
   NOTE: 20260127: Many CVEs fixed in 3.20.1 and 3.21, but missing fix commits 
(Beuc/front-desk)
   NOTE: 20260713: Also add for bookworm-lts (Beuc/front-desk)
 --
-frr/bullseye
+frr
   NOTE: 20251102: Added by Front-Desk (apo)
+  NOTE: 20260714: Also add for bookworm.
+  NOTE: 20260714: Many CVEs fixed in bullseye but not in bookworm (low pri) 
(Beuc/front-desk)
 --
 gdal/bullseye
   NOTE: 20260419: Added by Front-Desk (rouca)
@@ -536,6 +538,10 @@ perl
   NOTE: 20260527: Added by Front-Desk (santiago)
   NOTE: 20260527: wait for the DSA before releasing
 --
+pgextwlist
+  NOTE: 20260714: Added by Front-Desk (Beuc)
+  NOTE: 20260714: Follow DSA-6385-1 (1 CVE) (Beuc/front-desk)
+--
 php-horde-imp/bullseye
   NOTE: 20260714: Added by Front-Desk (Beuc)
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fc8ab07233cca9a3389d590eec6a85ed98777482...9ddc0290cd18048249757d7918480d50b2cc9942

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fc8ab07233cca9a3389d590eec6a85ed98777482...9ddc0290cd18048249757d7918480d50b2cc9942
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to