Aron Xu pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bf4ea76f by Aron Xu at 2026-08-25T12:19:56+08:00
DSA for erlang

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -106573,7 +106573,6 @@ CVE-2026-32311 (Flowsint is an open-source OSINT 
graph exploration tool designed
        NOT-FOR-US: Flowsint
 CVE-2026-32147 (Improper Limitation of a Pathname to a Restricted Directory 
('Path Tra ...)
        - erlang 1:27.3.4.11+dfsg-1
-       [trixie] - erlang <no-dsa> (Minor issue)
        [bookworm] - erlang <no-dsa> (Minor issue)
        [bullseye] - erlang <postponed> (Minor issue, can be fixed with next 
update)
        NOTE: 
https://github.com/erlang/otp/security/advisories/GHSA-28jg-mw9x-hpm5
@@ -113720,7 +113719,6 @@ CVE-2026-32588 (Authenticated DoS over CQL in Apache 
Cassandra 4.0, 4.1, 5.0 all
        - cassandra <itp> (bug #585905)
 CVE-2026-32144 (Improper Certificate Validation vulnerability in Erlang OTP 
public_key ...)
        - erlang 1:27.3.4.10+dfsg-1
-       [trixie] - erlang <no-dsa> (Minor issue)
        [bookworm] - erlang <not-affected> (Vulnerable code not present, only 
affects 27 and later)
        [bullseye] - erlang <not-affected> (Vulnerable code not present, only 
affects 27 and later)
        NOTE: 
https://github.com/erlang/otp/security/advisories/GHSA-gxrm-pf64-99xm
@@ -113745,7 +113743,6 @@ CVE-2026-30079 (In OpenAirInterface V2.2.0 AMF, Out 
of sequence messages causes
        NOT-FOR-US: OpenAirInterface
 CVE-2026-28810 (Generation of Predictable Numbers or Identifiers vulnerability 
in Erla ...)
        - erlang 1:27.3.4.10+dfsg-1
-       [trixie] - erlang <no-dsa> (Minor issue)
        [bookworm] - erlang <no-dsa> (Minor issue)
        [bullseye] - erlang <postponed> (Minor issue, can be fixed with next 
update)
        NOTE: 
https://github.com/erlang/otp/security/advisories/GHSA-v884-5jg5-whj8
@@ -113754,7 +113751,6 @@ CVE-2026-28810 (Generation of Predictable Numbers or 
Identifiers vulnerability i
        NOTE: https://cna.erlef.org/cves/CVE-2026-28810.html
 CVE-2026-28808 (Incorrect Authorization vulnerability in Erlang OTP (inets 
modules) al ...)
        - erlang 1:27.3.4.10+dfsg-1
-       [trixie] - erlang <no-dsa> (Minor issue)
        [bookworm] - erlang <no-dsa> (Minor issue)
        [bullseye] - erlang <postponed> (Minor issue, can be fixed with next 
update)
        NOTE: 
https://github.com/erlang/otp/security/advisories/GHSA-3vhp-h532-mc3f


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,6 @@
+[25 Aug 2026] DSA-6464-1 erlang - security update
+       {CVE-2026-28808 CVE-2026-28810 CVE-2026-32144 CVE-2026-32147 
CVE-2026-42789 CVE-2026-42790 CVE-2026-42791 CVE-2026-42792 CVE-2026-47078 
CVE-2026-48855 CVE-2026-48856 CVE-2026-48858 CVE-2026-48860 CVE-2026-49759 
CVE-2026-49760 CVE-2026-53422 CVE-2026-54886 CVE-2026-54887 CVE-2026-54890 
CVE-2026-54891 CVE-2026-55737 CVE-2026-55950 CVE-2026-55952 CVE-2026-55953 
CVE-2026-58227 CVE-2026-59250 CVE-2026-59251}
+       [trixie] - erlang 1:27.3.4.1+dfsg-1+deb13u3
 [24 Aug 2026] DSA-6463-1 webkit2gtk - security update
        {CVE-2026-43804 CVE-2026-64713 CVE-2026-64719 CVE-2026-64728 
CVE-2026-64730 CVE-2026-64757 CVE-2026-64783}
        [trixie] - webkit2gtk 2.52.6-1~deb13u1


=====================================
data/dsa-needed.txt
=====================================
@@ -38,8 +38,6 @@ dulwich
 --
 emacs (jmm)
 --
-erlang (aron)
---
 firebird3.0
 --
 firebird4.0



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf4ea76f741fe0942e18b5a9eb05f39f9bf811ca

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf4ea76f741fe0942e18b5a9eb05f39f9bf811ca
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to