Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0b53268d by Sylvain Beucler at 2026-07-17T22:29:13+02:00
CVE-2026-43966,CVE-2026-44839/rabbitmq-server: bookworm,bullseye postponed

- - - - -
15b5536d by Sylvain Beucler at 2026-07-17T22:29:14+02:00
lts: add memcached/bookworm

- - - - -
890e8b30 by Sylvain Beucler at 2026-07-17T22:29:14+02:00
lts: add bouncycastle/bookworm

- - - - -
8620b66b by Sylvain Beucler at 2026-07-17T22:29:16+02:00
CVE-2026-14461/mtr: bookworm,bullseye postponed

- - - - -
5ffeea36 by Sylvain Beucler at 2026-07-17T22:29:19+02:00
CVE-2026-6658/nbconvert: bookworm,bullseye postponed

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -5290,6 +5290,8 @@ CVE-2026-14475 (The Cookie Banner for GDPR / CCPA \u2013 
WPLP Cookie Consent plu
 CVE-2026-14461 (mtr is vulnerable to Out-of-bound read vulnerability in 
ipinfo_lookup( ...)
        - mtr <unfixed>
        [trixie] - mtr <no-dsa> (Minor issue)
+       [bookworm] - mtr <postponed> (Minor issue, OOB read)
+       [bullseye] - mtr <postponed> (Minor issue, OOB read)
        NOTE: Fixed by: 
https://github.com/traviscross/mtr/commit/48e1794414d338ce47abc0f27c25ade8788af9c3
 CVE-2026-13710 (The Jeg Kit for Elementor \u2013 Powerful Addons for 
Elementor, Widget ...)
        NOT-FOR-US: WordPress plugin
@@ -14443,6 +14445,8 @@ CVE-2026-9639 (Nil-pointer dereference in 
CreateCustomVolumeFromBackup in LXD up
 CVE-2026-6658 (A vulnerability in jupyter/nbconvert versions <= 7.17.0 allows 
for Cro ...)
        - nbconvert <unfixed>
        [trixie] - nbconvert <no-dsa> (Minor issue)
+       [bookworm] - nbconvert <postponed> (Minor issue, XSS)
+       [bullseye] - nbconvert <postponed> (Minor issue, XSS)
        NOTE: https://huntr.com/bounties/47570290-3b26-4477-8cfa-fdef7db5aefe
 CVE-2026-5757 (Unauthenticated remote information disclosure vulnerability in 
Ollama' ...)
        - ollama <itp> (bug #1094806)
@@ -28474,6 +28478,8 @@ CVE-2026-43972 (Origin Validation Error vulnerability 
in ninenines gun (gun_http
 CVE-2026-43966 (Improper Neutralization of CRLF Sequences in HTTP Headers 
('HTTP Reque ...)
        - rabbitmq-server <unfixed>
        [trixie] - rabbitmq-server <no-dsa> (Minor issue)
+       [bookworm] - rabbitmq-server <postponed> (Minor issue, response 
splitting, mitigations exist)
+       [bullseye] - rabbitmq-server <postponed> (Minor issue, response 
splitting, mitigations exist)
        NOTE: Appears to be bundled in rabbitmq-server
        NOTE: https://cna.erlef.org/cves/CVE-2026-43966.html
        NOTE: 
https://github.com/ninenines/cowboy/commit/f77cb9b5e730e300fffb551db1ba5d1c4ed878ef
@@ -37229,6 +37235,8 @@ CVE-2026-44902 (opentelemetry-js is the OpenTelemetry 
JavaScript Client. Prior t
 CVE-2026-44839 (RabbitMQ is a messaging and streaming broker. From 3.7.0 to 
before 4.1 ...)
        - rabbitmq-server 4.3.0-2
        [trixie] - rabbitmq-server <no-dsa> (Minor issue)
+       [bookworm] - rabbitmq-server <postponed> (Minor issue, XSS)
+       [bullseye] - rabbitmq-server <postponed> (Minor issue, XSS)
        NOTE: 
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-fh5r-jpm3-fjwp
 CVE-2026-44838 (RabbitMQ is a messaging and streaming broker. From 4.2.0 to 
before 4.2 ...)
        - rabbitmq-server <not-affected> (Vulnerable code never in Debian 
released version)


=====================================
data/dla-needed.txt
=====================================
@@ -70,9 +70,10 @@ bind9/bullseye (eamanu)
   NOTE: 20260629: finishing backporting patches (eamanu)
   NOTE: 20260713: still in review (eamanu)
 --
-bouncycastle/bullseye
+bouncycastle
   NOTE: 20260417: Added by Front-Desk (rouca)
   NOTE: 20260417: Priority: Fix CVE-2026-5588 then try to fix other pilled CVE 
(rouca/FD)
+  NOTE: 20260717: Also add for bookworm (Beuc/front-desk)
 --
 busybox/bullseye
   NOTE: 20260511: Added by Front-Desk (dleidert)
@@ -423,6 +424,11 @@ mediawiki
   NOTE: 20260713: Added by Front-Desk (Beuc)
   NOTE: 20260713: Follow DSA-6380-1 (10 CVEs) (Beuc/front-desk)
 --
+memcached/bookworm
+  NOTE: 20260717: Added by Front-Desk (Beuc)
+  NOTE: 20260717: Follow DLA-4601-1 (2 CVEs)
+  NOTE: 20260717: Fix other postponed issues while we're at it 
(Beuc/front-desk)
+--
 mimetex/bullseye
   NOTE: 20250422: Added by Front-Desk (rouca)
   NOTE: 20250629: There doesn't seem to be a fix so far according to #1103801 
(dleidert)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419...5ffeea364ba59c16583a84feba58ca522a4ce34f

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6a696b5eddd846cf4d56eda2f0ae5ddf6aafb419...5ffeea364ba59c16583a84feba58ca522a4ce34f
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to