Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4a5ade44 by Sylvain Beucler at 2026-07-15T15:45:39+02:00
Reserve DLA-4686-1 for dhcpcd5

- - - - -


3 changed files:

- data/CVE/list
- data/DLA/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -17308,7 +17308,6 @@ CVE-2026-56114 (dhcpcd through 10.3.2, fixed in commit 
2f00c7b, contains a one-b
        [trixie] - dhcpcd 1:10.1.0-11+deb13u3
        - dhcpcd5 <removed>
        [bookworm] - dhcpcd5 9.4.1-24~deb12u5
-       [bullseye] - dhcpcd5 <postponed> (Minor issue; needs non-default IA_PD 
config + adjacent DHCPv6 server; 1-byte OOB, availability-only)
        NOTE: Fixed by: 
https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029
 CVE-2026-56113 (dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a 
heap use-af ...)
        - dhcpcd 1:10.3.2-4 (bug #1140767)
@@ -22386,7 +22385,6 @@ CVE-2025-70102 (A NULL pointer dereference occurs in 
Roy Marples NetworkConfigur
        [trixie] - dhcpcd 1:10.1.0-11+deb13u3
        - dhcpcd5 <removed>
        [bookworm] - dhcpcd5 9.4.1-24~deb12u5
-       [bullseye] - dhcpcd5 <postponed> (Minor issue; NULL deref only via 
malformed local dhcpcd.conf; not network-reachable)
        NOTE: https://github.com/NetworkConfiguration/dhcpcd/issues/567
        NOTE: Fixed by: 
https://github.com/NetworkConfiguration/dhcpcd/commit/117742d755b591764036dd4218f314f748a3d2b7
 (v10.3.1)
 CVE-2025-69332 (Subscriber Broken Access Control in Bookify <= 1.1.1 versions.)


=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[15 Jul 2026] DLA-4686-1 dhcpcd5 - security update
+       {CVE-2025-70102 CVE-2026-56114}
+       [bullseye] - dhcpcd5 7.1.0-2+deb11u1
 [15 Jul 2026] DLA-4685-1 grub2 - security update
        {CVE-2024-45774 CVE-2024-45775 CVE-2024-45776 CVE-2024-45777 
CVE-2024-45778 CVE-2024-45779 CVE-2024-45780 CVE-2024-45781 CVE-2024-45782 
CVE-2024-45783 CVE-2025-0622 CVE-2025-0624 CVE-2025-0677 CVE-2025-0678 
CVE-2025-0684 CVE-2025-0685 CVE-2025-0686 CVE-2025-0689 CVE-2025-0690 
CVE-2025-1118 CVE-2025-1125}
        [bullseye] - grub2 2.06-3~deb11u7


=====================================
data/dla-needed.txt
=====================================
@@ -134,11 +134,6 @@ cups (Thorsten Alteholz)
   NOTE: 20260615: bookworm also need the same fixes as bullseye. (charles)
   NOTE: 20260705: still trying to find a solution to fix a CVE without 
changing the functionality of lpadmin
 --
-dhcpcd5/bullseye (Sylvain Beucler)
-  NOTE: 20260715: Added by Front-Desk (Beuc)
-  NOTE: 20260715: Maintainer proposed an update (Beuc/front-desk)
-  NOTE: 20260715: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1140767#42
---
 docker-registry/bullseye
   NOTE: 20260419: Added by Front-Desk (rouca)
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4a5ade447aea94d550208934fc0446f4454041bb

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4a5ade447aea94d550208934fc0446f4454041bb
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to