Sylvain Beucler pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ade9de80 by Sylvain Beucler at 2026-07-18T12:19:07+02:00
lts: add git-lfs/bookworm libwebsockets/bookworm python-eventlet/bookworm
- - - - -
7e63c070 by Sylvain Beucler at 2026-07-18T12:23:22+02:00
CVE-2026-55599/*phpseclib*: bookworm,bullseye postponed
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -19737,10 +19737,15 @@ CVE-2026-55599 (phpseclib is a PHP secure
communications library. From 0.1.1 unt
{DLA-4670-1}
- php-phpseclib3 3.0.55-1
[trixie] - php-phpseclib3 <no-dsa> (Minor issue)
+ [bookworm] - php-phpseclib3 <postponed> (Minor issue, SSRF)
- php-phpseclib 2.0.55-1
[trixie] - php-phpseclib <no-dsa> (Minor issue)
+ [bookworm] - php-phpseclib <postponed> (Minor issue, SSRF)
+ [bullseye] - php-phpseclib <postponed> (Minor issue, SSRF)
- phpseclib 1.0.30-1
[trixie] - phpseclib <no-dsa> (Minor issue)
+ [bookworm] - phpseclib <postponed> (Minor issue, SSRF)
+ [bullseye] - phpseclib <postponed> (Minor issue, SSRF)
NOTE:
https://github.com/phpseclib/phpseclib/security/advisories/GHSA-m557-wrgg-6rp4
NOTE: Fixed by:
https://github.com/phpseclib/phpseclib/commit/0987dd98832b20fcdc223148c35e22de0f521de9
(3.0.54, 2.0.55, 1.0.30)
CVE-2026-55409 (Filament is a collection of full-stack components for
accelerated Lara ...)
=====================================
data/dla-needed.txt
=====================================
@@ -219,6 +219,10 @@ gimp
NOTE: 20260709: PSP/PNM/PSD parser overflows CVE-2026-58379..58388 (crafted
image); TIM-loader
NOTE: 20260709: CVE-2026-59089 not-affected (GIMP 3.x-only).
--
+git-lfs/bookworm
+ NOTE: 20260718: Added by Front-Desk (Beuc)
+ NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
+--
glances/bullseye
NOTE: 20260518: Added by Front-Desk (Beuc)
NOTE: 20260518: Many postponed vulnerabilities piled-up (Beuc/front-desk)
@@ -403,6 +407,10 @@ libstb/bullseye
libvncserver
NOTE: 20260612: Added by Front-Desk (rouca)
--
+libwebsockets/bookworm
+ NOTE: 20260718: Added by Front-Desk (Beuc)
+ NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
+--
libxmltok/bullseye
NOTE: 20250421: Added by Front-Desk (ta)
NOTE: 20250421: Also review all other expat CVEs. (bunk)
@@ -609,6 +617,10 @@ python-authlib (andrewsh)
NOTE: 20260709: CVE-2026-41479 (<1.6.10) + CVE-2026-44681 (<=1.6.11); Debian
0.15.4/1.2.0 in range.
NOTE: 20260709: See also
https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/330
--
+python-eventlet/bookworm
+ NOTE: 20260718: Added by Front-Desk (Beuc)
+ NOTE: 20260718: 1 CVE fixed in both bullseye and trixie (Beuc/front-desk)
+--
python-httplib2 (eamanu)
NOTE: 20260709: Added by Front-Desk (utkarsh)
NOTE: 20260709: CVE-2026-59939 (fixed 0.32.0); Debian <=0.20.4 affected.
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/04dda5656129887271caa7cf6cb34c46213d2f5a...7e63c07066eaf1b4f7ef6b69e48ab14c7936140a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/04dda5656129887271caa7cf6cb34c46213d2f5a...7e63c07066eaf1b4f7ef6b69e48ab14c7936140a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits