Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
0b53268d by Sylvain Beucler at 2026-07-17T22:29:13+02:00
CVE-2026-43966,CVE-2026-44839/rabbitmq-server: bookworm,bullseye postponed
- - - - -
15b5536d by Sylvain Beucler at 2026-07-17T22:29:14+02:00
lts: add memcached/bookworm
- - - - -
890e8b30 by Sylvain Beucler at 2026-07-17T22:29:14+02:00
lts: add bouncycastle/bookworm
- - - - -
8620b66b by Sylvain Beucler at 2026-07-17T22:29:16+02:00
CVE-2026-14461/mtr: bookworm,bullseye postponed
- - - - -
5ffeea36 by Sylvain Beucler at 2026-07-17T22:29:19+02:00
CVE-2026-6658/nbconvert: bookworm,bullseye postponed
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -5290,6 +5290,8 @@ CVE-2026-14475 (The Cookie Banner for GDPR / CCPA \u2013
WPLP Cookie Consent plu
CVE-2026-14461 (mtr is vulnerable to Out-of-bound read vulnerability in
ipinfo_lookup( ...)
- mtr <unfixed>
[trixie] - mtr <no-dsa> (Minor issue)
+ [bookworm] - mtr <postponed> (Minor issue, OOB read)
+ [bullseye] - mtr <postponed> (Minor issue, OOB read)
NOTE: Fixed by:
https://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3
CVE-2026-13710 (The Jeg Kit for Elementor \u2013 Powerful Addons for
Elementor, Widget ...)
NOT-FOR-US: WordPress plugin
@@ -14443,6 +14445,8 @@ CVE-2026-9639 (Nil-pointer dereference in
CreateCustomVolumeFromBackup in LXD up
CVE-2026-6658 (A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows
for Cro ...)
- nbconvert <unfixed>
[trixie] - nbconvert <no-dsa> (Minor issue)
+ [bookworm] - nbconvert <postponed> (Minor issue, XSS)
+ [bullseye] - nbconvert <postponed> (Minor issue, XSS)
NOTE: https://huntr.com/bounties/47570290-3b26-4477-8cfa-fdef7db5aefe
CVE-2026-5757 (Unauthenticated remote information disclosure vulnerability in
Ollama' ...)
- ollama <itp> (bug #1094806)
@@ -28474,6 +28478,8 @@ CVE-2026-43972 (Origin Validation Error vulnerability
in ninenines gun (gun_http
CVE-2026-43966 (Improper Neutralization of CRLF Sequences in HTTP Headers
('HTTP Reque ...)
- rabbitmq-server <unfixed>
[trixie] - rabbitmq-server <no-dsa> (Minor issue)
+ [bookworm] - rabbitmq-server <postponed> (Minor issue, response
splitting, mitigations exist)
+ [bullseye] - rabbitmq-server <postponed> (Minor issue, response
splitting, mitigations exist)
NOTE: Appears to be bundled in rabbitmq-server
NOTE: https://cna.erlef.org/cves/CVE-2026-43966.html
NOTE:
https://github.com/ninenines/cowboy/commit/f77cb9b5e730e300fffb551db1ba5d1c4ed878ef
@@ -37229,6 +37235,8 @@ CVE-2026-44902 (opentelemetry-js is the OpenTelemetry
JavaScript Client. Prior t
CVE-2026-44839 (RabbitMQ is a messaging and streaming broker. From 3.7.0 to
before 4.1 ...)
- rabbitmq-server 4.3.0-2
[trixie] - rabbitmq-server <no-dsa> (Minor issue)
+ [bookworm] - rabbitmq-server <postponed> (Minor issue, XSS)
+ [bullseye] - rabbitmq-server <postponed> (Minor issue, XSS)
NOTE:
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-fh5r-jpm3-fjwp
CVE-2026-44838 (RabbitMQ is a messaging and streaming broker. From 4.2.0 to
before 4.2 ...)
- rabbitmq-server <not-affected> (Vulnerable code never in Debian
released version)
=====================================
data/dla-needed.txt
=====================================
@@ -70,9 +70,10 @@ bind9/bullseye (eamanu)
NOTE: 20260629: finishing backporting patches (eamanu)
NOTE: 20260713: still in review (eamanu)
--
-bouncycastle/bullseye
+bouncycastle
NOTE: 20260417: Added by Front-Desk (rouca)
NOTE: 20260417: Priority: Fix CVE-2026-5588 then try to fix other pilled CVE
(rouca/FD)
+ NOTE: 20260717: Also add for bookworm (Beuc/front-desk)
--
busybox/bullseye
NOTE: 20260511: Added by Front-Desk (dleidert)
@@ -423,6 +424,11 @@ mediawiki
NOTE: 20260713: Added by Front-Desk (Beuc)
NOTE: 20260713: Follow DSA-6380-1 (10 CVEs) (Beuc/front-desk)
--
+memcached/bookworm
+ NOTE: 20260717: Added by Front-Desk (Beuc)
+ NOTE: 20260717: Follow DLA-4601-1 (2 CVEs)
+ NOTE: 20260717: Fix other postponed issues while we're at it
(Beuc/front-desk)
+--
mimetex/bullseye
NOTE: 20250422: Added by Front-Desk (rouca)
NOTE: 20250629: There doesn't seem to be a fix so far according to #1103801
(dleidert)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419...5ffeea364ba59c16583a84feba58ca522a4ce34f
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419...5ffeea364ba59c16583a84feba58ca522a4ce34f
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits