Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1319fd4c by Chris Lamb at 2026-08-22T10:59:45-07:00
Update triage reason for CVE-2026-46603/golang-golang-x-image in
{bullseye,bookworm}
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13070,8 +13070,8 @@ CVE-2026-48528 (Metacat is data repository software
that helps researchers prese
CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an
excessive amo ...)
- golang-golang-x-image 0.45.0-1 (bug #1144496)
[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
- [bookworm] - golang-golang-x-image <postponed> (Minor issue; can be
fixed in next update)
- [bullseye] - golang-golang-x-image <postponed> (Minor issue; can be
fixed in next update)
+ [bookworm] - golang-golang-x-image <postponed> (Minor issue; out of LTS
support)
+ [bullseye] - golang-golang-x-image <postponed> (Minor issue; out of LTS
support)
NOTE: https://github.com/golang/go/issues/80069
NOTE: Fixed by:
https://github.com/golang/image/commit/981eaa05a5065f5dd09c3139029c0d7dbda956d8
(v0.45.0)
CVE-2026-46439 (compliance-trestle is a tooling platform for managing
compliance as co ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1319fd4c6d559a66972000f04a96f19f5dfd6fb8
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1319fd4c6d559a66972000f04a96f19f5dfd6fb8
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits