Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
03cd64c4 by Utkarsh Gupta at 2026-07-12T08:25:06+05:30
lts: golang-1.19 not-affected in bookworm (CVE-2026-42505, CVE-2026-39822)

- - - - -
efd20b4a by Utkarsh Gupta at 2026-07-12T08:25:07+05:30
lts: golang-github-cli-go-gh postponed in bookworm (CVE-2026-48501)

- - - - -
07e8df86 by Utkarsh Gupta at 2026-07-12T08:25:08+05:30
lts: golang-github-go-git-go-billy postponed in bookworm (CVE-2026-44973, 
CVE-2026-44740)

- - - - -
39dea7f8 by Utkarsh Gupta at 2026-07-12T08:25:09+05:30
lts: golang-github-go-git-go-git postponed in bookworm (CVE-2026-45571, 
CVE-2026-45570, CVE-2026-45022, CVE-2026-41506)

- - - - -
cc0effdd by Utkarsh Gupta at 2026-07-12T08:25:10+05:30
lts: golang-github-labstack-echo postponed in bookworm (CVE-2026-55677)

- - - - -
fb31396d by Utkarsh Gupta at 2026-07-12T08:25:11+05:30
lts: golang-github-pion-dtls.v2 postponed in bookworm (CVE-2026-54908)

- - - - -
e44a7125 by Utkarsh Gupta at 2026-07-12T08:25:12+05:30
lts: golang-golang-x-image postponed in bookworm (CVE-2026-42500)

- - - - -
1e381bdc by Utkarsh Gupta at 2026-07-12T08:25:13+05:30
lts: golang-golang-x-net postponed in bookworm (6 CVEs)

- - - - -
a311f4f7 by Utkarsh Gupta at 2026-07-12T08:25:14+05:30
lts: golang-go.crypto postponed in bookworm (13 CVEs)

- - - - -
9dc1d322 by Utkarsh Gupta at 2026-07-12T08:25:30+05:30
lts: jython not-affected in bookworm (CVE-2026-4360)

- - - - -
f3a799d9 by Utkarsh Gupta at 2026-07-12T08:25:31+05:30
lts: rust-tar postponed in bookworm (CVE-2026-33056, CVE-2026-33055)

- - - - -
65907e9b by Utkarsh Gupta at 2026-07-12T08:25:33+05:30
lts: rustc postponed in bookworm (CVE-2026-33056, CVE-2026-33055)

- - - - -
e30029b6 by Utkarsh Gupta at 2026-07-12T08:32:08+05:30
lts: rust RUSTSEC issues postponed in bookworm (14 entries)

- - - - -
6284fc7f by Utkarsh Gupta at 2026-07-12T08:32:25+05:30
lts: lxd end-of-life in bookworm (28 CVEs)

- - - - -
d5f0aa12 by Utkarsh Gupta at 2026-07-12T08:32:27+05:30
lts: wolfssl end-of-life in bookworm (24 CVEs)

- - - - -
c17cb4f3 by Utkarsh Gupta at 2026-07-12T08:32:30+05:30
lts: php-horde-imp end-of-life in bookworm (CVE-2026-58451)

- - - - -
ae5ec562 by Utkarsh Gupta at 2026-07-12T08:32:32+05:30
lts: php-horde-vfs end-of-life in bookworm (CVE-2026-60102)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1868,6 +1868,7 @@ CVE-2026-60124 (An authorization bypass in MISP\u2019s 
EventsController::importM
        NOT-FOR-US: MISP
 CVE-2026-60102 (Horde Virtual File System (VFS) API before 3.0.1 contains an 
OS comman ...)
        - php-horde-vfs <unfixed>
+       [bookworm] - php-horde-vfs <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/horde/Vfs/pull/10
        NOTE: 
https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361 
(v3.0.1)
 CVE-2026-60092 (AVideo (Meet plugin) through commit 
e8d6119f3cb1b849149906efeb0a41fc02 ...)
@@ -2712,6 +2713,7 @@ CVE-2026-39822 (On Unix systems, opening a file in an 
os.Root improperly follows
        - golang-1.24 <removed>
        [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
+       [bookworm] - golang-1.19 <not-affected> (os.Root API introduced in Go 
1.24; absent in 1.19)
        - golang-1.15 <not-affected> (Vulnerable code introduced later)
        NOTE: golang-1.15: os.Root API introduced in Go 1.24 
(go.dev/doc/go1.24); absent in 1.15
        NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
@@ -2725,6 +2727,7 @@ CVE-2026-42505 (Handshakes which used Encrypted Client 
Hello could be de-anonymi
        - golang-1.24 <removed>
        [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
+       [bookworm] - golang-1.19 <not-affected> (crypto/tls client ECH 
introduced in Go 1.23; absent in 1.19)
        - golang-1.15 <not-affected> (Vulnerable code introduced later)
        NOTE: golang-1.15: crypto/tls client Encrypted Client Hello introduced 
in Go 1.23 (issue #63369); absent in 1.15
        NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
@@ -3430,15 +3433,18 @@ CVE-2024-6228 (The Notifications for Forms & WordPress 
Actions WordPress plugin
 CVE-2026-XXXX [RUSTSEC-2026-0190]
        - rust-anyhow <unfixed> (bug #1141593)
        [trixie] - rust-anyhow <no-dsa> (Minor issue)
+       [bookworm] - rust-anyhow <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0190.html
        NOTE: https://github.com/dtolnay/anyhow/issues/451
 CVE-2026-XXXX [RUSTSEC-2026-0193]
        - rust-ammonia <unfixed> (bug #1141594)
        [trixie] - rust-ammonia <no-dsa> (Minor issue)
+       [bookworm] - rust-ammonia <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0193.html
 CVE-2026-XXXX [RUSTSEC-2026-0194]
        - rust-quick-xml <unfixed> (bug #1141595)
        [trixie] - rust-quick-xml <no-dsa> (Minor issue)
+       [bookworm] - rust-quick-xml <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0194.html
        NOTE: https://github.com/tafia/quick-xml/issues/969
        NOTE: https://github.com/tafia/quick-xml/pull/971
@@ -3456,6 +3462,7 @@ CVE-2026-13705 (Imager versions before 1.032 for Perl 
have a heap out-of-bounds
 CVE-2026-XXXX [RUSTSEC-2026-0195]
        - rust-quick-xml <unfixed> (bug #1141588)
        [trixie] - rust-quick-xml <no-dsa> (Minor issue)
+       [bookworm] - rust-quick-xml <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0195.html
        NOTE: https://github.com/tafia/quick-xml/issues/970
        NOTE: 
https://github.com/tafia/quick-xml/commit/7ca25266e94987210daa864889ab15c9332c8a2a
 (v0.41.0)
@@ -3470,11 +3477,13 @@ CVE-2026-XXXX [RUSTSEC-2026-0199]
 CVE-2026-XXXX [RUSTSEC-2026-0202]
        - rust-cxx <unfixed> (bug #1141591)
        [trixie] - rust-cxx <no-dsa> (Minor issue)
+       [bookworm] - rust-cxx <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0202.html
        NOTE: https://github.com/dtolnay/cxx/issues/1729
 CVE-2026-XXXX [RUSTSEC-2026-0166]
        - rust-stackvector <unfixed> (bug #1141592)
        [trixie] - rust-stackvector <no-dsa> (Minor issue)
+       [bookworm] - rust-stackvector <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0166.html
        NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/3
        NOTE: https://github.com/Alexhuszagh/rust-stackvector/issues/5
@@ -3842,6 +3851,7 @@ CVE-2025-13475 (In multi-tenanted deployments, the 
application consent managemen
 CVE-2026-XXXX [RUSTSEC-2026-0185]
        - rust-quinn-proto <unfixed> (bug #1141481)
        [trixie] - rust-quinn-proto <no-dsa> (Minor issue)
+       [bookworm] - rust-quinn-proto <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0185.html
        NOTE: https://github.com/quinn-rs/quinn/pull/2694
 CVE-2026-XXXX [RUSTSEC-2026-0187]
@@ -3854,6 +3864,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0187]
 CVE-2026-XXXX [RUSTSEC-2026-0186]
        - rust-memmap2 <unfixed> (bug #1141479)
        [trixie] - rust-memmap2 <no-dsa> (Minor issue)
+       [bookworm] - rust-memmap2 <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0186.html
        NOTE: 
https://github.com/RazrFalcon/memmap2-rs/commit/cee7cf03a9ee095982a3c37b7aac8e3f68f1a00c
 (v0.9.11)
 CVE-2026-53360 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
@@ -4986,6 +4997,7 @@ CVE-2026-55153 (mchange-commons-java is a Java library of 
shared utility classes
 CVE-2026-54908 (Pion DTLS is a Go implementation of Datagram Transport Layer 
Security. ...)
        - golang-github-pion-dtls.v2 <unfixed> (bug #1141306)
        [trixie] - golang-github-pion-dtls.v2 <no-dsa> (Minor issue)
+       [bookworm] - golang-github-pion-dtls.v2 <postponed> (Minor issue; 
remote DoS via crafted ServerKeyExchange)
        - golang-github-pion-dtls-v3 <unfixed> (bug #1141307)
        NOTE: 
https://github.com/pion/dtls/security/advisories/GHSA-wg4g-wm44-ch5j
        NOTE: https://github.com/pion/dtls/pull/839
@@ -5376,6 +5388,7 @@ CVE-2026-58452 (JAIOTlink C492A-W6 Wi-Fi IP cameras 
running firmware 4.8.30.5770
 CVE-2026-58451 (Horde IMP before 7.0.1 contains a path traversal vulnerability 
in lib/ ...)
        - horde3 <removed>
        - php-horde-imp <unfixed> (bug #1141341)
+       [bookworm] - php-horde-imp <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/horde/imp/pull/85
        NOTE: Fixed by: 
https://github.com/horde/imp/commit/fba972fab72ee6871e5d56e6390bee38593085de 
(v7.0.1)
 CVE-2026-58399 (@acastellon/auth is an authentication control system for 
microservices ...)
@@ -8062,6 +8075,7 @@ CVE-2026-4360 (In the Tarfile.extract() function, the 
filter parameter is not pa
        [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
        - jython <unfixed>
        [trixie] - jython <no-dsa> (Minor issue)
+       [bookworm] - jython <not-affected> (extraction filters/PEP 706 absent 
in bundled python2.7 stdlib; tarfile.extract() has no filter parameter)
        [bullseye] - jython <end-of-life> (EOL in bullseye LTS)
        - pypy3 <unfixed> (bug #1141531)
        [trixie] - pypy3 <no-dsa> (Minor issue)
@@ -9623,6 +9637,7 @@ CVE-2026-9699 (Mattermost Plugins versions <=11.6 
10.18.11 11.3.6 11.6.5.0 fail
 CVE-2026-9640 (A privilege escalation vulnerability exists in LXD from 6.0 
before 6.9 ...)
        {DSA-6373-1}
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-ppq7-4492-5552
        NOTE: https://github.com/canonical/lxd/pull/18301
        NOTE: https://github.com/canonical/lxd/pull/18303
@@ -9630,6 +9645,7 @@ CVE-2026-9640 (A privilege escalation vulnerability 
exists in LXD from 6.0 befor
 CVE-2026-9639 (Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD 
up to v ...)
        {DSA-6373-1}
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-j93m-3j9p-m5m8
        NOTE: https://github.com/canonical/lxd/pull/18320
        NOTE: https://github.com/canonical/lxd/pull/18390
@@ -9913,6 +9929,7 @@ CVE-2026-55686 (Podman is a tool for managing OCI 
containers and pods. From 3.0.
 CVE-2026-55677 (Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's 
router a ...)
        - golang-github-labstack-echo <unfixed> (bug #1141444)
        [trixie] - golang-github-labstack-echo <no-dsa> (Minor issue)
+       [bookworm] - golang-github-labstack-echo <postponed> (Minor issue; 
encoded-slash %2F static route bypass)
        - golang-github-labstack-echo.v3 <removed>
        [bullseye] - golang-github-labstack-echo.v3 <postponed> (Minor issue; 
limited/case-by-case golang support, no upstream v3 fix)
        - golang-github-labstack-echo.v2 <removed>
@@ -10033,6 +10050,7 @@ CVE-2026-2053 (The WSO2 API Manager's message flow 
component, when processing WS
 CVE-2026-28385 (In Canonical LXD versions 4.12 through 6.9, a Server-Side 
Request Forg ...)
        - lxd <removed>
        [trixie] - lxd <postponed> (Fix along in future DSA)
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-3gq2-x4qg-p4g6
        NOTE: https://github.com/canonical/lxd/pull/18462
 CVE-2026-24547 (Unauthenticated Broken Access Control in SiteGround Email 
Marketing <= ...)
@@ -10121,6 +10139,7 @@ CVE-2026-8797 (An access control deficiency 
vulnerability exists in ExpressUpdat
 CVE-2026-8720 (wc_Blake2bHmacFinal and wc_Blake2sHmacFinal discard the message 
when t ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10447 (v5.9.2-stable)
 CVE-2026-8661 (Server-Side Cross-Site Scripting and Server-Side Request 
Forgery vulne ...)
        NOT-FOR-US: Rapid7
@@ -10129,58 +10148,72 @@ CVE-2026-8380 (The Frontend File Manager Plugin 
WordPress plugin through 23.6 do
 CVE-2026-7532 (iPAddress name constraints bypass when WOLFSSL_IP_ALT_NAME is 
not defi ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10354 (v5.9.2-stable)
 CVE-2026-7531 (Use-after-free in PQC hybrid key-share handling. This is an 
incomplete ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10327 (v5.9.2-stable)
 CVE-2026-7511 (PKCS7_verify signer confusion allows forged signatures, where 
the sign ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
 CVE-2026-6731 (X.509 name constraint bypass via the Subject Common Name when 
treated  ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10223 (v5.9.2-stable)
 CVE-2026-6681 (The PKCS#7 decode path ignores the caller-supplied output 
buffer size  ...)
        - wolfssl 5.9.2-1
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
 CVE-2026-6679 (A heap buffer overflow could occur in the DTLS 1.3 ACK 
serialization p ...)
        - wolfssl 5.9.2-1
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
 CVE-2026-6678 (Integer underflow in wc_PKCS7_DecryptOri when handling crafted 
Other R ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
 CVE-2026-6450 (A CRL critical extension bypass exists in ParseCRL_Extensions 
where cr ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10239 (v5.9.2-stable)
 CVE-2026-6412 (Certificate policy and RFC 8446 compliance concerns regarding 
the cont ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10222 (v5.9.2-stable)
 CVE-2026-6331 (HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a 
zero-le ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
 CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext comparison only compares half 
of the  ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
 CVE-2026-6329 (PKCS#12 MAC verification uses an attacker-controlled comparison 
length ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
 CVE-2026-6325 (Out-of-bounds write in SetSuitesHashSigAlgo when processing an 
oversiz ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10204 (v5.9.2-stable)
 CVE-2026-6092 (When HAVE_ENCRYPT_THEN_MAC is configured, the implementation 
could fal ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10167 (v5.9.2-stable)
 CVE-2026-57522 (Bitwarden Server before 2026.5.0 contains a JSON injection 
vulnerabili ...)
        - bitwarden <itp> (bug #956836)
@@ -10193,18 +10226,22 @@ CVE-2026-56445 (The qrscp application's C-STORE 
handler uses a specific instance
 CVE-2026-55964 (Chain intermediate CA:TRUE without keyCertSign accepted as a 
signing C ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
 CVE-2026-55962 (TLS 1.3 post-handshake authentication (PHA) issue where a 
server could ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
 CVE-2026-55960 (Un-negotiated Raw Public Key (RFC 7250) accepted in place of 
an X.509  ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
 CVE-2026-55958 (Out-of-bounds write in the Renesas TSIP TLS 1.3 transcript 
buffer. In  ...)
        - wolfssl 5.9.2-1 (bug #1140815)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10705 (v5.9.2-stable)
 CVE-2026-54479 (The WebSocket backend uses charging station identifiers to 
uniquely as ...)
        NOT-FOR-US: Evoke
@@ -10368,18 +10405,21 @@ CVE-2026-48750
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-73hr-m85f-64v9
        NOTE: https://github.com/canonical/lxd/pull/18590
 CVE-2026-48751
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-48q5-w887-33wv
        NOTE: https://github.com/canonical/lxd/pull/18604
 CVE-2026-48752
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-vxp5-584q-c479
        NOTE: 
https://github.com/lxc/incus/commit/cbefa31ae0da8fd96361178aed3a3c631e098fef 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18590
@@ -10387,6 +10427,7 @@ CVE-2026-48755
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-v6mj-8pf4-hhw4
        NOTE: 
https://github.com/lxc/incus/commit/873a032a461df6b09b7586435b592873863a4e88 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18597
@@ -10394,6 +10435,7 @@ CVE-2026-48769
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-f6m5-xw2g-xc4x
        NOTE: 
https://github.com/lxc/incus/commit/46d6ef232186df5535c49ca9f3597cab381f9b86 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18594
@@ -10401,6 +10443,7 @@ CVE-2026-55621
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-64f3-v33m-w89f
        NOTE: 
https://github.com/lxc/incus/commit/2e01078366e2653712719dec82318e51c6d21b28 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18603
@@ -10408,6 +10451,7 @@ CVE-2026-55622
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-c9f5-j9c3-mhrg
        NOTE: 
https://github.com/lxc/incus/commit/1e3ffc53a10950e55de62ac1e0d612be597b84eb 
(v7.2.0)
        NOTE: https://github.com/canonical/lxd/pull/18603
@@ -10415,6 +10459,7 @@ CVE-2026-48749
        {DSA-6373-1 DSA-6370-1}
        - incus 7.0.0-5
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-2q3f-q5pq-g8wv
        NOTE: https://github.com/canonical/lxd/pull/18590
 CVE-2026-XXXX [ZSA-2026-12]
@@ -10454,14 +10499,17 @@ CVE-2026-6432 (Improper bounds validation in 
EmberZNet SDK versions 9.0.2 and ea
 CVE-2026-6291 (Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When 
decrypti ...)
        - wolfssl 5.9.2-1 (bug #1140765)
        [trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
 CVE-2026-6094 (Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when 
parsing craf ...)
        - wolfssl 5.9.2-1 (bug #1140765)
        [trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10128 (v5.9.2-stable)
 CVE-2026-6091 (Partial-chain certificate verification may accept chains that 
terminat ...)
        - wolfssl 5.9.2-1 (bug #1140765)
        [trixie] - wolfssl <no-dsa> (Can be fixed in point release)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10170 (v5.9.2-stable)
 CVE-2026-57700 (Unrestricted Upload of File with Dangerous Type vulnerability 
in Daan. ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -10628,10 +10676,12 @@ CVE-2026-56005 (Subscriber Cross Site Scripting (XSS) 
in WP Activity Log <= 5.6.
 CVE-2026-55967 (AES-GCM encryption/decryption with extremely large cumulative 
single m ...)
        - wolfssl 5.9.2-1 (bug #1140765)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10709 (v5.9.2-stable)
 CVE-2026-55961 (wolfSSL_PKCS7_verify() returning success for a degenerate 
(certs-only) ...)
        - wolfssl 5.9.2-1 (bug #1140765)
        [trixie] - wolfssl <no-dsa> (Minor issue)
+       [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
 CVE-2026-55895 (Vim is an open source, command line text editor. Prior to 
9.2.0663, a  ...)
        - vim 2:9.2.0782-1 (bug #1140775)
@@ -16219,11 +16269,13 @@ CVE-2026-9692 (Mojolicious::Sessions::Storable 
versions through 0.05 for Perl ge
 CVE-2026-XXXX [RUSTSEC-2026-0183]
        - rust-git2 <unfixed>
        [trixie] - rust-git2 <no-dsa> (Minor issue)
+       [bookworm] - rust-git2 <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0183.html
        NOTE: https://github.com/rust-lang/git2-rs/pull/1250
 CVE-2026-XXXX [RUSTSEC-2026-0184]
        - rust-git2 <unfixed>
        [trixie] - rust-git2 <no-dsa> (Minor issue)
+       [bookworm] - rust-git2 <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0184.html
        NOTE: https://github.com/rust-lang/git2-rs/pull/1254
 CVE-2026-50190
@@ -19496,6 +19548,7 @@ CVE-2026-11527 (Config::IniFiles versions before 
3.001000 for Perl allow OS comm
 CVE-2026-XXXX [RUSTSEC-2026-0178]
        - rust-tokio-postgres <unfixed> (bug #1140013)
        [trixie] - rust-tokio-postgres <no-dsa> (Minor issue)
+       [bookworm] - rust-tokio-postgres <postponed> (Limited support, minor 
issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0178.html
        NOTE: 
https://github.com/rust-postgres/rust-postgres/commit/7a00ffa9ad4d951ec0a4564b52f1780fa9d353c1
 (tokio-postgres-v0.7.18)
 CVE-2026-XXXX [RUSTSEC-2026-0176]
@@ -19829,16 +19882,19 @@ CVE-2026-XXXX [RUSTSEC-2026-0172]
 CVE-2026-XXXX [RUSTSEC-2026-0180]
        - rust-postgres-protocol 0.6.12-1 (bug #1139876)
        [trixie] - rust-postgres-protocol <no-dsa> (Minor issue)
+       [bookworm] - rust-postgres-protocol <postponed> (Limited support, minor 
issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0180.html
        NOTE: 
https://github.com/rust-postgres/rust-postgres/commit/a7cf84b5c46431cbca9d8ff50508c23f446efa7d
 (postgres-protocol-v0.6.12)
 CVE-2026-XXXX [RUSTSEC-2026-0179]
        - rust-postgres-protocol 0.6.12-1 (bug #1139876)
        [trixie] - rust-postgres-protocol <no-dsa> (Minor issue)
+       [bookworm] - rust-postgres-protocol <postponed> (Limited support, minor 
issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0179.html
        NOTE: 
https://github.com/rust-postgres/rust-postgres/commit/d40097a36a85068ea50a3afbf0ce154ba439e7f0
 (postgres-protocol-v0.6.12)
 CVE-2026-XXXX [RUSTSEC-2026-0177]
        - rust-pyo3 <unfixed> (bug #1139875)
        [trixie] - rust-pyo3 <no-dsa> (Minor issue)
+       [bookworm] - rust-pyo3 <postponed> (Limited support, minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0177.html
        NOTE: https://github.com/PyO3/pyo3/pull/6096
 CVE-2026-9641 (Crypt::PBKDF2 versions before 0.261630 for Perl have a weak 
default al ...)
@@ -28393,6 +28449,7 @@ CVE-2026-45131 (CloudPirates Open Source Helm Charts is 
a collection of Helm cha
 CVE-2026-44740 (Billy is an interface filesystem abstraction for Go. Prior to 
versions ...)
        - golang-github-go-git-go-billy <unfixed>
        [trixie] - golang-github-go-git-go-billy <no-dsa> (Minor issue)
+       [bookworm] - golang-github-go-git-go-billy <postponed> (Limited 
support, minor issue; DoS on malformed input)
        - golang-github-go-git-go-billy-v6 <unfixed>
        NOTE: 
https://github.com/go-git/go-billy/security/advisories/GHSA-m3xc-h892-ggx6
 CVE-2026-44211 (Cline is an autonomous coding agent as an SDK, IDE extension, 
or CLI a ...)
@@ -29250,6 +29307,7 @@ CVE-2026-44285 (FastGPT is an AI Agent building 
platform. Prior to 4.15.0-beta1,
 CVE-2026-42500 (Decoding a paletted BMP file with an out-of-range palette 
index result ...)
        - golang-golang-x-image 0.42.0-1 (bug #1138257)
        [trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-image <postponed> (Limited support, minor 
issue; BMP OOB read)
        [bullseye] - golang-golang-x-image <no-dsa> (Minor issue)
        NOTE: https://github.com/golang/go/issues/79576
        NOTE: https://go-review.googlesource.com/c/image/+/781500
@@ -29377,6 +29435,7 @@ CVE-2026-48501 (GitHub CLI (gh) is GitHub\u2019s 
official command line tool. Pri
        [trixie] - golang-github-cli-go-gh-v2 <no-dsa> (Minor issue)
        - golang-github-cli-go-gh <unfixed>
        [trixie] - golang-github-cli-go-gh <no-dsa> (Minor issue)
+       [bookworm] - golang-github-cli-go-gh <postponed> (Limited support, 
minor issue; token leak to sibling *.github.com hosts)
        NOTE: https://github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9
 CVE-2026-47745 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, 
the admi ...)
        NOT-FOR-US: Shopper
@@ -30402,6 +30461,7 @@ CVE-2026-45023 (AutoGPT is a workflow automation 
platform for creating, deployin
 CVE-2026-44973 (Billy is an interface filesystem abstraction for Go. Prior to 
5.9.0, m ...)
        - golang-github-go-git-go-billy <unfixed>
        [trixie] - golang-github-go-git-go-billy <no-dsa> (Minor issue)
+       [bookworm] - golang-github-go-git-go-billy <postponed> (Limited 
support, minor issue; path traversal)
        - golang-github-go-git-go-billy-v6 <unfixed>
        NOTE: 
https://github.com/go-git/go-billy/security/advisories/GHSA-qw64-3x98-g7q2
 CVE-2026-44885 (Portainer Community Edition is a lightweight service delivery 
platform ...)
@@ -32157,11 +32217,13 @@ CVE-2026-45571 (go-git is an extensible git 
implementation library written in pu
        - golang-github-go-git-go-git-v6 6.0.0~alpha4-1
        - golang-github-go-git-go-git 5.19.1-1
        [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+       [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, 
minor issue; path traversal)
        NOTE: 
https://github.com/go-git/go-git/security/advisories/GHSA-crhj-59gh-8x96
 CVE-2026-45570 (go-git is an extensible git implementation library written in 
pure Go. ...)
        - golang-github-go-git-go-git-v6 6.0.0~alpha4-1
        - golang-github-go-git-go-git 5.19.1-1
        [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+       [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, 
minor issue; SSH argument quoting)
        NOTE: 
https://github.com/go-git/go-git/security/advisories/GHSA-m7cr-m3pv-hgrp
 CVE-2026-45548 (Budibase is an open-source low-code platform. Prior to 3.34.8, 
the pro ...)
        NOT-FOR-US: Budibase
@@ -32189,6 +32251,7 @@ CVE-2026-45022 (go-git is an extensible git 
implementation library written in pu
        - golang-github-go-git-go-git-v6 6.0.0~alpha4-1
        - golang-github-go-git-go-git 5.19.1-1
        [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+       [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, 
minor issue; signature-verification bypass)
        NOTE: 
https://github.com/go-git/go-git/security/advisories/GHSA-389r-gv7p-r3rp
 CVE-2026-44988 (LibVNCClient is a library for easy implementation of a VNC 
client. In  ...)
        - libvncserver 0.9.15+dfsg-5 (bug #1138174)
@@ -35974,12 +36037,14 @@ CVE-2026-42626 (HP ENVY 5000 series printers 
VERBASPP1N003.2237A.00 do not prope
 CVE-2026-42506 (Parsing arbitrary HTML which is then rendered using Render can 
result  ...)
        - golang-golang-x-net 1:0.55.0-1
        [trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-net <postponed> (Limited support, minor 
issue; html.Render output)
        [bullseye] - golang-golang-x-net <postponed> (Limited support, minor 
issue)
        NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
        NOTE: https://github.com/golang/go/issues/79571
 CVE-2026-42502 (Parsing arbitrary HTML which is then rendered using Render can 
result  ...)
        - golang-golang-x-net 1:0.55.0-1
        [trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-net <postponed> (Limited support, minor 
issue; html.Render output)
        [bullseye] - golang-golang-x-net <postponed> (Limited support, minor 
issue)
        NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
        NOTE: https://github.com/golang/go/issues/79572
@@ -36008,6 +36073,7 @@ CVE-2026-39964 (TypeBot is a chatbot builder tool. In 
versions prior to 3.16.0,
 CVE-2026-39821 (The ToASCII and ToUnicode functions incorrectly accept 
Punycode-encode ...)
        - golang-golang-x-net 1:0.55.0-1
        [trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-net <postponed> (Limited support, minor 
issue; IDNA Punycode validation)
        [bullseye] - golang-golang-x-net <postponed> (Limited support, minor 
issue)
        NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
        NOTE: https://github.com/golang/go/issues/78760
@@ -36035,18 +36101,21 @@ CVE-2026-28444 (Typebot is a chatbot builder tool. In 
versions 3.15.2 and prior,
 CVE-2026-27136 (Parsing arbitrary HTML which is then rendered using Render can 
result  ...)
        - golang-golang-x-net 1:0.55.0-1
        [trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-net <postponed> (Limited support, minor 
issue; html.Render output)
        [bullseye] - golang-golang-x-net <postponed> (Limited support, minor 
issue)
        NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
        NOTE: https://github.com/golang/go/issues/79575
 CVE-2026-25681 (Parsing arbitrary HTML which is then rendered using Render can 
result  ...)
        - golang-golang-x-net 1:0.55.0-1
        [trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-net <postponed> (Limited support, minor 
issue; html.Render output)
        [bullseye] - golang-golang-x-net <postponed> (Limited support, minor 
issue)
        NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
        NOTE: https://github.com/golang/go/issues/79574
 CVE-2026-25680 (Parsing arbitrary HTML can consume excessive CPU time, 
possibly leadin ...)
        - golang-golang-x-net 1:0.55.0-1
        [trixie] - golang-golang-x-net <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-net <postponed> (Limited support, minor 
issue; html parse CPU DoS)
        [bullseye] - golang-golang-x-net <postponed> (Limited support, minor 
issue)
        NOTE: https://groups.google.com/g/golang-announce/c/iI-mYSI0lu8
        NOTE: https://github.com/golang/go/issues/79573
@@ -36202,18 +36271,21 @@ CVE-2026-47101 (LiteLLM prior to 1.83.14 allows an 
authenticated internal_user t
 CVE-2026-46598 (For certain crafted inputs, a 'ed25519.PrivateKey' was created 
by cast ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79596
 CVE-2026-46597 (An incorrectly placed cast from bytes to int allowed for 
server-side p ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79561
 CVE-2026-46595 (Previously, CVE-2024-45337 fixed an authorization bypass for 
misused s ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79570
@@ -36222,6 +36294,7 @@ CVE-2026-44409 (There is an an information disclosure 
vulnerability in ZTE MU525
 CVE-2026-42508 (Previously, a revoked 'SignatureKey' belonging to a CA was not 
correct ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79568
@@ -36230,54 +36303,63 @@ CVE-2026-3481 (The WP Blockade plugin for WordPress 
is vulnerable to Reflected C
 CVE-2026-39835 (SSH servers which use CertChecker as a public key callback 
without set ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79563
 CVE-2026-39834 (When writing data larger than 4GB in a single Write call on an 
SSH cha ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79567
 CVE-2026-39833 (The in-memory keyring returned by NewKeyring() silently 
accepted keys  ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79436
 CVE-2026-39832 (When adding a key to a remote agent constraint extensions such 
as rest ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79435
 CVE-2026-39831 (The Verify() method for FIDO/U2F security key types 
(sk-ecdsa-sha2-nis ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79566
 CVE-2026-39830 (A malicious SSH peer could send unsolicited global request 
responses t ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79564
 CVE-2026-39829 (The RSA and DSA public key parsers did not enforce size limits 
on key  ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79565
 CVE-2026-39828 (When an SSH server authentication callback returned 
PartialSuccessErro ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/79562
 CVE-2026-39827 (An authenticated SSH client that repeatedly opened channels 
which were ...)
        - golang-go.crypto 1:0.52.0-1 (bug #1137516)
        [trixie] - golang-go.crypto <no-dsa> (Minor issue)
+       [bookworm] - golang-go.crypto <postponed> (Limited support, minor issue)
        [bullseye] - golang-go.crypto <postponed> (Limited support, follow 
bookworm DSAs/point-releases)
        NOTE: https://www.openwall.com/lists/oss-security/2026/05/22/6
        NOTE: https://github.com/golang/go/issues/35127
@@ -43824,6 +43906,7 @@ CVE-2026-41506 (go-git is an extensible git 
implementation library written in pu
        - golang-github-go-git-go-git-v6 6.0.0~alpha4-1
        - golang-github-go-git-go-git 5.19.1-1 (bug #1136095)
        [trixie] - golang-github-go-git-go-git <no-dsa> (Minor issue)
+       [bookworm] - golang-github-go-git-go-git <postponed> (Limited support, 
minor issue; credential leak on cross-host redirect)
        NOTE: 
https://github.com/go-git/go-git/security/advisories/GHSA-3xc5-wrhm-f963
        NOTE: Fixed by: 
https://github.com/go-git/go-git/commit/bcd20a9c525826081262a06a9ed9c3167abfcd53
 (v5.18.0)
 CVE-2026-41497 (PraisonAI is a multi-agent teams system. Prior to version 
4.6.9, the f ...)
@@ -49618,18 +49701,21 @@ CVE-2026-41685 (Incus is a system container and 
virtual machine manager. Prior t
        {DSA-6247-1 DSA-6244-1}
        - incus 7.0.0-1 (bug #1135644)
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-98vh-x9cx-9cfp
        NOTE: https://github.com/lxc/incus/pull/3273
 CVE-2026-41684 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6247-1 DSA-6244-1}
        - incus 7.0.0-1 (bug #1135644)
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-x5r6-jr56-89pv
        NOTE: https://github.com/lxc/incus/pull/3273
 CVE-2026-41648 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
        {DSA-6247-1 DSA-6244-1}
        - incus 7.0.0-1 (bug #1135644)
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-67wx-r9xr-x75x
        NOTE: https://github.com/lxc/incus/pull/3273
 CVE-2026-41647 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
@@ -49641,6 +49727,7 @@ CVE-2026-40251 (Incus is a system container and virtual 
machine manager. In vers
        {DSA-6247-1 DSA-6244-1}
        - incus 7.0.0-1 (bug #1135644)
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-4m88-wxj4-9qj6
        NOTE: https://github.com/lxc/incus/pull/3273
 CVE-2026-40243 (Incus is a system container and virtual machine manager. In 
versions b ...)
@@ -49652,6 +49739,7 @@ CVE-2026-40197 (Incus is a system container and virtual 
machine manager. In vers
        {DSA-6247-1 DSA-6244-1}
        - incus 7.0.0-1 (bug #1135644)
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-r7w7-mmxr-47r9
        NOTE: https://github.com/lxc/incus/pull/3273
 CVE-2026-35527 (Incus is an open source container and virtual machine manager. 
In vers ...)
@@ -61860,6 +61948,7 @@ CVE-2026-34179 (In Canonical LXD versions 4.12 through 
6.7, the doCertificateUpd
        {DSA-6213-1 DSA-6212-1}
        - incus 6.0.6-3
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-c3h3-89qf-jqm5
        NOTE: https://github.com/canonical/lxd/pull/17936
        NOTE: 
https://github.com/canonical/lxd/commit/8c0c8dcc0f7b6ef59524bfeae198b6081248a88d
@@ -61878,6 +61967,7 @@ CVE-2026-34177 (Canonical LXD versions 4.12 through 6.7 
contain an incomplete de
        {DSA-6213-1}
        - incus 6.0.2-1
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-fm2x-c5qw-4h6f
        NOTE: https://github.com/canonical/lxd/pull/17909
        NOTE: 
https://github.com/canonical/lxd/commit/2f85d3ec0a6f9c9de8c003b81591ec173d489914
@@ -69340,6 +69430,7 @@ CVE-2026-33542 (Incus is a system container and virtual 
machine manager. Prior t
        {DSA-6188-1 DSA-6184-1}
        - incus 6.0.6-2
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/lxc/incus/pull/3092
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-p8mm-23gg-jc9r
 CVE-2026-33711 (Incus is a system container and virtual machine manager. Incus 
provide ...)
@@ -69358,6 +69449,7 @@ CVE-2026-33897 (Incus is a system container and virtual 
machine manager. Prior t
        {DSA-6188-1 DSA-6184-1}
        - incus 6.0.6-2
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: https://github.com/lxc/incus/pull/3092
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-83xr-5xxr-mh92
 CVE-2026-33898 (Incus is a system container and virtual machine manager. Prior 
to vers ...)
@@ -74344,9 +74436,11 @@ CVE-2026-33057 (Mesop is a Python-based UI framework 
that allows users to build
 CVE-2026-33056 (tar-rs is a tar archive reading/writing library for Rust. In 
versions  ...)
        - rustc 1.92.0+dfsg1-2
        [trixie] - rustc <no-dsa> (Minor issue)
+       [bookworm] - rustc <postponed> (Minor issue, parsing inconsistencies 
among tar libraries, requires recompiling rdeps)
        [bullseye] - rustc <postponed> (Minor issue, parsing inconsistencies 
among tar libraries, requires recompiling rdeps)
        - rust-tar 0.4.45-1 (bug #1131481)
        [trixie] - rust-tar <no-dsa> (Minor issue)
+       [bookworm] - rust-tar <postponed> (Minor issue, parsing inconsistencies 
among tar libraries, requires recompiling rdeps)
        [bullseye] - rust-tar <postponed> (Minor issue, parsing inconsistencies 
among tar libraries, requires recompiling rdeps)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0067.html
        NOTE: 
https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-j4xf-2g29-59ph
@@ -74354,9 +74448,11 @@ CVE-2026-33056 (tar-rs is a tar archive 
reading/writing library for Rust. In ver
 CVE-2026-33055 (tar-rs is a tar archive reading/writing library for Rust. 
Versions 0.4 ...)
        - rustc 1.92.0+dfsg1-2 (bug #1135225)
        [trixie] - rustc <no-dsa> (Minor issue)
+       [bookworm] - rustc <postponed> (Minor issue, path traversal, requires 
recompiling rdeps)
        [bullseye] - rustc <postponed> (Minor issue, path traversal, requires 
recompiling rdeps)
        - rust-tar 0.4.45-1 (bug #1131480)
        [trixie] - rust-tar <no-dsa> (Minor issue)
+       [bookworm] - rust-tar <postponed> (Minor issue, path traversal, 
requires recompiling rdeps)
        [bullseye] - rust-tar <postponed> (Minor issue, path traversal, 
requires recompiling rdeps)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0068.html
        NOTE: 
https://github.com/alexcrichton/tar-rs/security/advisories/GHSA-gchp-q4r4-x4ff
@@ -77695,6 +77791,7 @@ CVE-2026-28384 (An improper sanitization of the 
compression_algorithm parameter
        {DSA-6188-1 DSA-6184-1}
        - incus 6.0.6-1
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-4rmf-rcp8-2r9g
        NOTE: https://github.com/canonical/lxd/pull/17820
        NOTE: https://github.com/lxc/incus/pull/2972
@@ -99376,12 +99473,14 @@ CVE-2026-23954 (Incus is a system container and 
virtual machine manager. Version
        {DSA-6153-1 DSA-6109-1}
        - incus 6.0.5-8
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-7f67-crqm-jgh7
        NOTE: 
https://github.com/canonical/lxd/commit/9a80e47b358e56fb2c9f7abad61b1d0ac654b6fa
 (lxd-5.0.6)
 CVE-2026-23953 (Incus is a system container and virtual machine manager. In 
versions 6 ...)
        {DSA-6153-1 DSA-6109-1}
        - incus 6.0.5-8
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-x6jc-phwx-hp32
        NOTE: 
https://github.com/canonical/lxd/commit/6343c2cb0c2c5d4057821f05094671bff032ede8
 (lxd-5.0.6)
 CVE-2024-31884
@@ -128690,6 +128789,7 @@ CVE-2025-64507 (Incus is a system container and 
virtual machine manager. An issu
        - incus 6.0.5-4
        - lxd <removed>
        [trixie] - lxd 5.0.2+git20231211.1364ae4-9+deb13u2
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-56mx-8g9f-5crf
        NOTE: https://github.com/lxc/incus/issues/2641
        NOTE: Fixed by: https://github.com/lxc/incus/pull/2642
@@ -141458,6 +141558,7 @@ CVE-2025-54293 (Path Traversal in the log file 
retrieval function in Canonical L
        {DSA-6028-1 DSA-6027-1}
        - incus 6.0.5-1
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-472f-vmf2-pr3h
 CVE-2025-54292 (Path traversal in Canonical LXD LXD-UI versions before 6.5 and 
5.21.4  ...)
        NOT-FOR-US: Canonical LXD LXD-UI (not bundled in src:lxd or src:incus)
@@ -141487,16 +141588,19 @@ CVE-2025-54288 (Information Spoofing in devLXD 
Server in Canonical LXD versions
        {DSA-6028-1 DSA-6027-1}
        - incus 6.0.5-1
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-7232-97c6-j525
 CVE-2025-54287 (Template Injection in instance snapshot creation component in 
Canonica ...)
        {DSA-6028-1 DSA-6027-1}
        - incus 6.0.5-1
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-w2hg-2v4p-vmh6
 CVE-2025-54286 (Cross-Site Request Forgery (CSRF) in LXD-UI in Canonical LXD 
versions  ...)
        {DSA-6028-1 DSA-6027-1}
        - incus 6.0.5-1
        - lxd <removed>
+       [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-p8hw-rfjg-689h
 CVE-2025-54086 (CVE-2025-54086 is an excess permissions vulnerability in the 
Warehouse ...)
        NOT-FOR-US: Absolute Software



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e4fd8128c65e1a07bd26a91d0df6d8871cefbef8...ae5ec5623d3865db6e731e5c7c511a9b413ddb2b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/e4fd8128c65e1a07bd26a91d0df6d8871cefbef8...ae5ec5623d3865db6e731e5c7c511a9b413ddb2b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to