Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bdd9eb5e by Sylvain Beucler at 2026-07-15T09:08:12+02:00
lts: add python-tornado/bookworm

- - - - -
dd959f90 by Sylvain Beucler at 2026-07-15T09:08:14+02:00
CVE-2026-44169/mariadb: bookworm postponed

- - - - -
fc320748 by Sylvain Beucler at 2026-07-15T09:08:17+02:00
CVE-2026-12216/duktape: bookworm postponed

- - - - -
1966a059 by Sylvain Beucler at 2026-07-15T09:08:20+02:00
CVE-2026-14164/libarchive: bookworm,bullseye postponed

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -9593,6 +9593,8 @@ CVE-2026-28979 (An out-of-bounds access issue was 
addressed with improved bounds
 CVE-2026-14164 (A double free issue has been identified in libarchive's RAR5 
reader. D ...)
        - libarchive 3.8.8-1 (bug #1141180)
        [trixie] - libarchive <no-dsa> (Minor issue)
+       [bookworm] - libarchive <postponed> (Minor issue, DoS)
+       [bullseye] - libarchive <postponed> (Minor issue, DoS)
        NOTE: https://github.com/libarchive/libarchive/issues/3069
        NOTE: https://github.com/libarchive/libarchive/pull/3071
        NOTE: 
https://github.com/libarchive/libarchive/commit/1c914cdfef533cbee1ae3aa21a89ba02ed4d5f61
 (master)
@@ -20769,6 +20771,7 @@ CVE-2026-12217 (A security vulnerability has been 
detected in DVDFab Virtual Dri
 CVE-2026-12216 (A weakness has been identified in svaarala duktape up to 
2.99.99. This ...)
        - duktape <unfixed> (bug #1140485)
        [trixie] - duktape <no-dsa> (Minor issue)
+       [bookworm] - duktape <postponed> (Minor issue, OOB read, revisit 
when/if fixed upstream)
        NOTE: https://github.com/hmKunlun/compileOOB/blob/main/api_bytecode.md
 CVE-2026-12214 (A security flaw has been discovered in Qihoo 360 Total 
Security 6.0. T ...)
        NOT-FOR-US: Qihoo
@@ -25433,6 +25436,7 @@ CVE-2026-44170 (MariaDB server is a community developed 
fork of MySQL server. Fr
 CVE-2026-44169 (MariaDB server is a community developed fork of MySQL server. 
From ver ...)
        - mariadb 1:11.8.8-1
        [trixie] - mariadb <no-dsa> (Will be fixed via point release)
+       [bookworm] - mariadb <postponed> (Minor issue, minor info leak)
        NOTE: 
https://mariadb.com/docs/release-notes/community-server/11.8/11.8.7
        NOTE: 
https://github.com/MariaDB/server/security/advisories/GHSA-22xq-vq3f-87x2
        NOTE: https://jira.mariadb.org/browse/MDEV-39288


=====================================
data/dla-needed.txt
=====================================
@@ -600,6 +600,10 @@ python-msgpack
 python-oslo.messaging/bullseye
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
+python-tornado/bookworm
+  NOTE: 20260715: Added by Front-Desk (Beuc)
+  NOTE: 20260715: See also 
https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/322 
(Beuc/front-desk)
+--
 qemu
   NOTE: 20260520: Added by Front-Desk (Beuc)
   NOTE: 20260520: Many postponed CVEs piled up (Beuc/front-desk)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/820418de8e40c23ac25b7b382504d3c8b277b839...1966a059a4667414a7be475d8f05228f524a9042

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/820418de8e40c23ac25b7b382504d3c8b277b839...1966a059a4667414a7be475d8f05228f524a9042
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to