Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
64405243 by Utkarsh Gupta at 2026-07-12T06:14:26+05:30
lts: ack postponed in bullseye/bookworm (CVE-2026-49145)
- - - - -
a5f045f4 by Utkarsh Gupta at 2026-07-12T06:14:27+05:30
lts: acl postponed in bullseye/bookworm (CVE-2026-54369, CVE-2026-54370)
- - - - -
4ba3df32 by Utkarsh Gupta at 2026-07-12T06:14:29+05:30
lts: angular.js postponed in bullseye/bookworm (CVE-2026-11998)
- - - - -
fd8bef76 by Utkarsh Gupta at 2026-07-12T06:14:30+05:30
lts: assimp postponed in bullseye/bookworm (CVE-2026-14610, CVE-2026-14604,
CVE-2025-15666)
- - - - -
e6b822be by Utkarsh Gupta at 2026-07-12T06:14:32+05:30
lts: attr postponed in bullseye/bookworm (CVE-2026-54371)
- - - - -
a8b14913 by Utkarsh Gupta at 2026-07-12T06:14:33+05:30
lts: botan postponed in bullseye/bookworm (CVE-2026-32884, CVE-2026-32877)
- - - - -
0fb5f7c0 by Utkarsh Gupta at 2026-07-12T06:14:35+05:30
lts: note v3.10.0 only partially fixes CVE-2026-49145/ack
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2181,8 +2181,11 @@ CVE-2026-49146 (App::Ack versions before 3.10.0 for Perl
allow memory exhaustion
CVE-2026-49145 (App::Ack versions through 3.10.0 for Perl read arbitrary files
via --f ...)
- ack <unfixed>
[trixie] - ack <no-dsa> (Minor issue)
+ [bookworm] - ack <postponed> (Minor issue; local-only, needs untrusted
project .ackrc; --files-from still unfixed upstream)
+ [bullseye] - ack <postponed> (Minor issue; local-only, needs untrusted
project .ackrc; --files-from still unfixed upstream)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41643327/
NOTE: Fixed by:
https://github.com/beyondgrep/ack3/commit/45ff5fe77dbd96f7332f31943102291f878f30b8
(v3.10.0)
+ NOTE: 45ff5fe (v3.10.0) is only a partial fix: it adds --follow to the
project .ackrc blocklist but --files-from remains accepted, so arbitrary file
read via --files-from is still unfixed upstream.
CVE-2026-44840 (Dgraph is an open source distributed GraphQL database. Prior
to versio ...)
TODO: check
CVE-2026-41122 (Dell PowerProtect Data Domain, versions 7.7.1.0 through 8.7,
LTS2026 r ...)
@@ -4058,6 +4061,8 @@ CVE-2026-14611 (A vulnerability has been found in
DeepMyst Mysti up to 0.4.0. Th
CVE-2026-14610 (A flaw has been found in Open Asset Import Library Assimp up
to 6.0.5. ...)
- assimp <unfixed> (bug #1141496)
[trixie] - assimp <no-dsa> (Minor issue)
+ [bookworm] - assimp <postponed> (Minor issue)
+ [bullseye] - assimp <postponed> (Minor issue)
NOTE: https://github.com/assimp/assimp/issues/6622
NOTE: https://github.com/assimp/assimp/pull/6649
NOTE:
https://github.com/assimp/assimp/commit/eb84eec580d3f4ba2f0fd87409b7d0744620f11e
@@ -4260,6 +4265,8 @@ CVE-2026-14612 (Two off-by-one errors in the FreeIPA
ipa-otpd daemon's OAuth2 de
CVE-2026-14604 (A vulnerability was determined in Open Asset Import Library
Assimp up ...)
- assimp <unfixed> (bug #1141494)
[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - assimp <postponed> (Minor issue, revisit when fixed
upstream)
+ [bullseye] - assimp <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://github.com/assimp/assimp/issues/6620
CVE-2026-14544 (A flaw was found in HPLIP (HP Linux Imaging and Printing
Software). Th ...)
- hplip <unfixed>
@@ -6330,6 +6337,8 @@ CVE-2025-36319 (IBM watsonx.data intelligence 5.2.0,
5.2.1, 5.2.2, 5.3.0 could a
CVE-2025-15666 (A security vulnerability has been detected in Open Asset
Import Librar ...)
- assimp <unfixed> (bug #1141389)
[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - assimp <postponed> (Minor issue, revisit when fixed
upstream)
+ [bullseye] - assimp <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://github.com/assimp/assimp/issues/6079
CVE-2025-12530 (IBM watsonx.data intelligence 5.2.2, 5.3.0, 5.3.1, 5.3.1
through patch ...)
NOT-FOR-US: IBM
@@ -8813,6 +8822,8 @@ CVE-2026-11720 (A path traversal vulnerability exists in
the HTTP tool URL build
CVE-2026-54371 (attr before version 2.6.0 contains a symlink traversal
vulnerability i ...)
- attr 1:2.6.0-1 (bug #1141107)
[trixie] - attr <no-dsa> (Will be fixed first in unstable, then point
release update; not to be backported by individual patches)
+ [bookworm] - attr <postponed> (Minor issue; local symlink-traversal in
recursive getfattr/setfattr; fix is a complete walk_tree rewrite, high
regression risk)
+ [bullseye] - attr <postponed> (Minor issue; local symlink-traversal in
recursive getfattr/setfattr; fix is a complete walk_tree rewrite, high
regression risk)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
NOTE: Fixed by:
https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=641ea6fcc556c1f34b77efb9cd3f876dff0a0a07
(v2.6.0)
NOTE: Fixed by:
https://cgit.git.savannah.nongnu.org/cgit/attr.git/commit/?id=3fb06b9ba314d37035d0877e6de313de754f1ac8
(v2.6.0)
@@ -8820,6 +8831,8 @@ CVE-2026-54371 (attr before version 2.6.0 contains a
symlink traversal vulnerabi
CVE-2026-54370 (acl before version 2.4.0 contains a time-of-check to
time-of-use (TOCT ...)
- acl 2.4.0-1 (bug #1141110)
[trixie] - acl <no-dsa> (Will be fixed first in unstable, then point
release update; not to be backported by individual patches)
+ [bookworm] - acl <postponed> (Minor issue; local TOCTOU in recursive
setfacl/chacl; fix needs 2.4.0 acl_*_at() ABI + walk_tree rewrite, not
individually backportable)
+ [bullseye] - acl <postponed> (Minor issue; local TOCTOU in recursive
setfacl/chacl; fix needs 2.4.0 acl_*_at() ABI + walk_tree rewrite, not
individually backportable)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
NOTE: Fixed by:
https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=601cc884a548ae9e9d246ae749e54b3272e4b1d7
(v2.4.0)
NOTE: Fixed by:
https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=54e14e9bc545f505b379d0792a2748d9baf88700
(v2.4.0)
@@ -8829,6 +8842,8 @@ CVE-2026-54370 (acl before version 2.4.0 contains a
time-of-check to time-of-use
CVE-2026-54369 (acl before version 2.4.0 contains a symlink traversal
vulnerability in ...)
- acl 2.4.0-1 (bug #1141110)
[trixie] - acl <no-dsa> (Will be fixed first in unstable, then point
release update; not to be backported by individual patches)
+ [bookworm] - acl <postponed> (Minor issue; libacl acl_*_file() follow
symlinks; fix adds new acl_*_at() ABI, not individually backportable)
+ [bullseye] - acl <postponed> (Minor issue; libacl acl_*_file() follow
symlinks; fix adds new acl_*_at() ABI, not individually backportable)
NOTE: https://www.openwall.com/lists/oss-security/2026/06/29/1
NOTE: Fixed by:
https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=5906d2868ec8d3b08be556153696e6b1122eeeda
(v2.4.0)
NOTE: Fixed by:
https://cgit.git.savannah.nongnu.org/cgit/acl.git/commit/?id=0071c6d1fea0a8a6270333baa85fb609be325c26
(v2.4.0)
@@ -12089,6 +12104,8 @@ CVE-2026-12053 (GitLab has remediated an issue in
GitLab EE affecting all versio
CVE-2026-11998 (A flaw in AngularJS' Strict Contextual Escaping (SCE) logic
allows byp ...)
- angular.js <unfixed> (bug #1141314)
[trixie] - angular.js <no-dsa> (Minor issue)
+ [bookworm] - angular.js <postponed> (Minor issue; EOL upstream, no fix
available; only reachable with custom RegExp trustedResourceUrlList matchers
using alternation)
+ [bullseye] - angular.js <postponed> (Minor issue; EOL upstream, no fix
available; only reachable with custom RegExp trustedResourceUrlList matchers
using alternation)
NOTE:
https://www.herodevs.com/vulnerability-directory/cve-2026-11998?nes-for-angularjs
CVE-2026-11379 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
@@ -67894,6 +67911,8 @@ CVE-2026-32884 (Botan is a C++ cryptography library.
Prior to version 3.11.0, du
- botan3 3.11.0+dfsg-2
- botan <removed>
[trixie] - botan <no-dsa> (Minor issue)
+ [bookworm] - botan <postponed> (Minor issue; case-sensitive CN fallback
in DNS name-constraint check; fix only in 3.11.0)
+ [bullseye] - botan <postponed> (Minor issue; case-sensitive CN fallback
in DNS name-constraint check; fix only in 3.11.0)
NOTE:
https://github.com/randombit/botan/security/advisories/GHSA-7c3g-7763-ggj5
CVE-2026-32883 (Botan is a C++ cryptography library. From version 3.0.0 to
before vers ...)
[experimental] - botan3 3.11.0+dfsg-1
@@ -67906,6 +67925,8 @@ CVE-2026-32877 (Botan is a C++ cryptography library.
From version 2.3.0 to befor
- botan3 3.11.0+dfsg-2
- botan <removed>
[trixie] - botan <no-dsa> (Minor issue)
+ [bookworm] - botan <postponed> (Minor issue; SM2 C3 heap over-read; fix
only in 3.11.0)
+ [bullseye] - botan <postponed> (Minor issue; SM2 C3 heap over-read; fix
only in 3.11.0)
NOTE:
https://github.com/randombit/botan/security/advisories/GHSA-7jj6-4r42-w9h6
NOTE:
https://github.com/randombit/botan/commit/f3c31f96f58f1d1d482032d8f4286dc9ebbc6712
(3.11.0)
CVE-2026-32794 (Improper Certificate Validation vulnerability in Apache
Airflow Provid ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3469ea93fa5284f9bf13d4eace8370296a721e02...0fb5f7c0d4bcd97009727268e60dcca34420c93d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/3469ea93fa5284f9bf13d4eace8370296a721e02...0fb5f7c0d4bcd97009727268e60dcca34420c93d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits