Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ade9de80 by Sylvain Beucler at 2026-07-18T12:19:07+02:00
lts: add git-lfs/bookworm libwebsockets/bookworm python-eventlet/bookworm

- - - - -
7e63c070 by Sylvain Beucler at 2026-07-18T12:23:22+02:00
CVE-2026-55599/*phpseclib*: bookworm,bullseye postponed

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -19737,10 +19737,15 @@ CVE-2026-55599 (phpseclib is a PHP secure 
communications library. From 0.1.1 unt
        {DLA-4670-1}
        - php-phpseclib3 3.0.55-1
        [trixie] - php-phpseclib3 <no-dsa> (Minor issue)
+       [bookworm] - php-phpseclib3 <postponed> (Minor issue, SSRF)
        - php-phpseclib 2.0.55-1
        [trixie] - php-phpseclib <no-dsa> (Minor issue)
+       [bookworm] - php-phpseclib <postponed> (Minor issue, SSRF)
+       [bullseye] - php-phpseclib <postponed> (Minor issue, SSRF)
        - phpseclib 1.0.30-1
        [trixie] - phpseclib <no-dsa> (Minor issue)
+       [bookworm] - phpseclib <postponed> (Minor issue, SSRF)
+       [bullseye] - phpseclib <postponed> (Minor issue, SSRF)
        NOTE: 
https://github.com/phpseclib/phpseclib/security/advisories/GHSA-m557-wrgg-6rp4
        NOTE: Fixed by: 
https://github.com/phpseclib/phpseclib/commit/0987dd98832b20fcdc223148c35e22de0f521de9
 (3.0.54, 2.0.55, 1.0.30)
 CVE-2026-55409 (Filament is a collection of full-stack components for 
accelerated Lara ...)


=====================================
data/dla-needed.txt
=====================================
@@ -219,6 +219,10 @@ gimp
   NOTE: 20260709: PSP/PNM/PSD parser overflows CVE-2026-58379..58388 (crafted 
image); TIM-loader
   NOTE: 20260709: CVE-2026-59089 not-affected (GIMP 3.x-only).
 --
+git-lfs/bookworm
+  NOTE: 20260718: Added by Front-Desk (Beuc)
+  NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
+--
 glances/bullseye
   NOTE: 20260518: Added by Front-Desk (Beuc)
   NOTE: 20260518: Many postponed vulnerabilities piled-up (Beuc/front-desk)
@@ -403,6 +407,10 @@ libstb/bullseye
 libvncserver
   NOTE: 20260612: Added by Front-Desk (rouca)
 --
+libwebsockets/bookworm
+  NOTE: 20260718: Added by Front-Desk (Beuc)
+  NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
+--
 libxmltok/bullseye
   NOTE: 20250421: Added by Front-Desk (ta)
   NOTE: 20250421: Also review all other expat CVEs. (bunk)
@@ -609,6 +617,10 @@ python-authlib (andrewsh)
   NOTE: 20260709: CVE-2026-41479 (<1.6.10) + CVE-2026-44681 (<=1.6.11); Debian 
0.15.4/1.2.0 in range.
   NOTE: 20260709: See also 
https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/330
 --
+python-eventlet/bookworm
+  NOTE: 20260718: Added by Front-Desk (Beuc)
+  NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
+--
 python-httplib2 (eamanu)
   NOTE: 20260709: Added by Front-Desk (utkarsh)
   NOTE: 20260709: CVE-2026-59939 (fixed 0.32.0); Debian <=0.20.4 affected.



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/04dda5656129887271caa7cf6cb34c46213d2f5a...7e63c07066eaf1b4f7ef6b69e48ab14c7936140a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/04dda5656129887271caa7cf6cb34c46213d2f5a...7e63c07066eaf1b4f7ef6b69e48ab14c7936140a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to