Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
bdd9eb5e by Sylvain Beucler at 2026-07-15T09:08:12+02:00
lts: add python-tornado/bookworm
- - - - -
dd959f90 by Sylvain Beucler at 2026-07-15T09:08:14+02:00
CVE-2026-44169/mariadb: bookworm postponed
- - - - -
fc320748 by Sylvain Beucler at 2026-07-15T09:08:17+02:00
CVE-2026-12216/duktape: bookworm postponed
- - - - -
1966a059 by Sylvain Beucler at 2026-07-15T09:08:20+02:00
CVE-2026-14164/libarchive: bookworm,bullseye postponed
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -9593,6 +9593,8 @@ CVE-2026-28979 (An out-of-bounds access issue was
addressed with improved bounds
CVE-2026-14164 (A double free issue has been identified in libarchive's RAR5
reader. D ...)
- libarchive 3.8.8-1 (bug #1141180)
[trixie] - libarchive <no-dsa> (Minor issue)
+ [bookworm] - libarchive <postponed> (Minor issue, DoS)
+ [bullseye] - libarchive <postponed> (Minor issue, DoS)
NOTE: https://github.com/libarchive/libarchive/issues/3069
NOTE: https://github.com/libarchive/libarchive/pull/3071
NOTE:
https://github.com/libarchive/libarchive/commit/1c914cdfef533cbee1ae3aa21a89ba02ed4d5f61
(master)
@@ -20769,6 +20771,7 @@ CVE-2026-12217 (A security vulnerability has been
detected in DVDFab Virtual Dri
CVE-2026-12216 (A weakness has been identified in svaarala duktape up to
2.99.99. This ...)
- duktape <unfixed> (bug #1140485)
[trixie] - duktape <no-dsa> (Minor issue)
+ [bookworm] - duktape <postponed> (Minor issue, OOB read, revisit
when/if fixed upstream)
NOTE: https://github.com/hmKunlun/compileOOB/blob/main/api_bytecode.md
CVE-2026-12214 (A security flaw has been discovered in Qihoo 360 Total
Security 6.0. T ...)
NOT-FOR-US: Qihoo
@@ -25433,6 +25436,7 @@ CVE-2026-44170 (MariaDB server is a community developed
fork of MySQL server. Fr
CVE-2026-44169 (MariaDB server is a community developed fork of MySQL server.
From ver ...)
- mariadb 1:11.8.8-1
[trixie] - mariadb <no-dsa> (Will be fixed via point release)
+ [bookworm] - mariadb <postponed> (Minor issue, minor info leak)
NOTE:
https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7
NOTE:
https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2
NOTE: https://jira.mariadb.org/browse/MDEV-39288
=====================================
data/dla-needed.txt
=====================================
@@ -600,6 +600,10 @@ python-msgpack
python-oslo.messaging/bullseye
NOTE: 20260612: Added by Front-Desk (rouca)
--
+python-tornado/bookworm
+ NOTE: 20260715: Added by Front-Desk (Beuc)
+ NOTE: 20260715: See also
https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/322
(Beuc/front-desk)
+--
qemu
NOTE: 20260520: Added by Front-Desk (Beuc)
NOTE: 20260520: Many postponed CVEs piled up (Beuc/front-desk)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/820418de8e40c23ac25b7b382504d3c8b277b839...1966a059a4667414a7be475d8f05228f524a9042
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/820418de8e40c23ac25b7b382504d3c8b277b839...1966a059a4667414a7be475d8f05228f524a9042
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits