Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
3d1d55e0 by Utkarsh Gupta at 2026-07-15T06:20:52+05:30
Reserve DLA-4683-1 for wolfssl

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -11328,19 +11328,16 @@ CVE-2026-7531 (Use-after-free in PQC hybrid key-share 
handling. This is an incom
 CVE-2026-7511 (PKCS7_verify signer confusion allows forged signatures, where 
the sign ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
 CVE-2026-6731 (X.509 name constraint bypass via the Subject Common Name when 
treated  ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10223 (v5.9.2-stable)
 CVE-2026-6681 (The PKCS#7 decode path ignores the caller-supplied output 
buffer size  ...)
        - wolfssl 5.9.2-1
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
 CVE-2026-6679 (A heap buffer overflow could occur in the DTLS 1.3 ACK 
serialization p ...)
@@ -11352,13 +11349,11 @@ CVE-2026-6679 (A heap buffer overflow could occur in 
the DTLS 1.3 ACK serializat
 CVE-2026-6678 (Integer underflow in wc_PKCS7_DecryptOri when handling crafted 
Other R ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
 CVE-2026-6450 (A CRL critical extension bypass exists in ParseCRL_Extensions 
where cr ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10239 (v5.9.2-stable)
 CVE-2026-6412 (Certificate policy and RFC 8446 compliance concerns regarding 
the cont ...)
@@ -11370,7 +11365,6 @@ CVE-2026-6412 (Certificate policy and RFC 8446 
compliance concerns regarding the
 CVE-2026-6331 (HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a 
zero-le ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
 CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext comparison only compares half 
of the  ...)
@@ -11382,19 +11376,16 @@ CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext 
comparison only compares half of
 CVE-2026-6329 (PKCS#12 MAC verification uses an attacker-controlled comparison 
length ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
 CVE-2026-6325 (Out-of-bounds write in SetSuitesHashSigAlgo when processing an 
oversiz ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10204 (v5.9.2-stable)
 CVE-2026-6092 (When HAVE_ENCRYPT_THEN_MAC is configured, the implementation 
could fal ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10167 (v5.9.2-stable)
 CVE-2026-57522 (Bitwarden Server before 2026.5.0 contains a JSON injection 
vulnerabili ...)
@@ -11414,7 +11405,6 @@ CVE-2026-55964 (Chain intermediate CA:TRUE without 
keyCertSign accepted as a sig
 CVE-2026-55962 (TLS 1.3 post-handshake authentication (PHA) issue where a 
server could ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
 CVE-2026-55960 (Un-negotiated Raw Public Key (RFC 7250) accepted in place of 
an X.509  ...)
@@ -11691,7 +11681,6 @@ CVE-2026-6291 (Bleichenbacher padding oracle in PKCS#7 
KTRI decryption. When dec
 CVE-2026-6094 (Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when 
parsing craf ...)
        - wolfssl 5.9.2-1 (bug #1140765)
        [trixie] - wolfssl <no-dsa> (Can be fixed in point release)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10128 (v5.9.2-stable)
 CVE-2026-6091 (Partial-chain certificate verification may accept chains that 
terminat ...)
@@ -11887,13 +11876,11 @@ CVE-2026-56005 (Subscriber Cross Site Scripting (XSS) 
in WP Activity Log <= 5.6.
 CVE-2026-55967 (AES-GCM encryption/decryption with extremely large cumulative 
single m ...)
        - wolfssl 5.9.2-1 (bug #1140765)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10709 (v5.9.2-stable)
 CVE-2026-55961 (wolfSSL_PKCS7_verify() returning success for a degenerate 
(certs-only) ...)
        - wolfssl 5.9.2-1 (bug #1140765)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
 CVE-2026-55895 (Vim is an open source, command line text editor. Prior to 
9.2.0663, a  ...)
@@ -62699,7 +62686,6 @@ CVE-2026-5263 (URI nameConstraints from constrained 
intermediate CAs are parsed
 CVE-2026-5194 (Missing hash/digest size and OID checks allow digests smaller 
than all ...)
        - wolfssl 5.9.1-0.1 (bug #1133835)
        [trixie] - wolfssl <no-dsa> (Minor issue)
-       [bookworm] - wolfssl <no-dsa> (Minor issue)
        [bullseye] - wolfssl <postponed> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10131
        NOTE: Fixed by (merge): 
https://github.com/wolfSSL/wolfssl/commit/53a3d23ce67086861344711225667f14d794812f
 (v5.9.1-stable)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[15 Jul 2026] DLA-4683-1 wolfssl - security update
+       {CVE-2026-5194 CVE-2026-6092 CVE-2026-6094 CVE-2026-6325 CVE-2026-6329 
CVE-2026-6331 CVE-2026-6450 CVE-2026-6678 CVE-2026-6681 CVE-2026-6731 
CVE-2026-7511 CVE-2026-55961 CVE-2026-55962 CVE-2026-55967}
+       [bookworm] - wolfssl 5.5.4-2+deb12u3
 [13 Jul 2026] DLA-4682-1 redis - security update
        {CVE-2026-23631 CVE-2026-25243}
        [bookworm] - redis 5:7.0.15-1~deb12u8


=====================================
data/dla-needed.txt
=====================================
@@ -787,11 +787,6 @@ watcher/bullseye
 wireshark/bullseye
   NOTE: 20260430: Added by Front-Desk (lamby)
 --
-wolfssl/bookworm
-  NOTE: 20260714: Added by Front-Desk (Beuc)
-  NOTE: 20260714: Upstream interested in helping with bookworm 
(Beuc/front-desk)
-  NOTE: 20260714: https://lists.debian.org/debian-lts/2026/07/msg00020.html
---
 xen/bookworm
   NOTE: 20260714: Added by Front-Desk (Beuc)
   NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie 
(Beuc/front-desk)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d1d55e0c3084c9b283233b68da750fbc1450423

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d1d55e0c3084c9b283233b68da750fbc1450423
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to