Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ab780b70 by Utkarsh Gupta at 2026-07-13T02:01:42+05:30
lts: freetype not-affected in bullseye/bookworm (CVE-2026-50811)

- - - - -
de0e289a by Utkarsh Gupta at 2026-07-13T02:01:44+05:30
lts: gnupg2 not-affected/postponed in bullseye/bookworm

(CVE-2026-57062)

- - - - -
8838fb9c by Utkarsh Gupta at 2026-07-13T02:01:45+05:30
lts: gst-libav1.0 postponed in bullseye/bookworm (CVE-2026-12893)

- - - - -
26d6f3d6 by Utkarsh Gupta at 2026-07-13T02:01:47+05:30
lts: gzip postponed in bullseye/bookworm

(CVE-2026-41991, CVE-2026-41992)

- - - - -
5fd334fa by Utkarsh Gupta at 2026-07-13T02:01:48+05:30
lts: haproxy postponed in bullseye/bookworm

(CVE-2026-55203, CVE-2026-55204)

- - - - -
1f6976e7 by Utkarsh Gupta at 2026-07-13T02:01:50+05:30
lts: libhttp-date-perl postponed in bullseye/bookworm

(CVE-2026-14741)

- - - - -
d05acf85 by Utkarsh Gupta at 2026-07-13T02:01:51+05:30
lts: libidn postponed in bullseye/bookworm (CVE-2026-57053)

- - - - -
d421c210 by Utkarsh Gupta at 2026-07-13T02:01:53+05:30
lts: libxml2 postponed in bullseye/bookworm (CVE-2026-6653)

- - - - -
81a24224 by Utkarsh Gupta at 2026-07-13T02:01:55+05:30
lts: nghttp2 postponed in bullseye/bookworm (CVE-2026-58055)

- - - - -
5b224b3c by Utkarsh Gupta at 2026-07-13T02:01:56+05:30
lts: openssh postponed in bullseye/bookworm (8 CVEs)

- - - - -
8fc64418 by Utkarsh Gupta at 2026-07-13T02:01:58+05:30
lts: p11-kit postponed in bullseye/bookworm (CVE-2026-13757)

- - - - -
207bf6d4 by Utkarsh Gupta at 2026-07-13T02:01:59+05:30
lts: pam postponed in bullseye/bookworm (CVE-2026-54411)

- - - - -
db882698 by Utkarsh Gupta at 2026-07-13T02:02:01+05:30
lts: pillow postponed in bullseye/bookworm (4 CVEs)

- - - - -
a20e0052 by Utkarsh Gupta at 2026-07-13T02:02:02+05:30
lts: pulseaudio postponed in bullseye/bookworm (CVE-2026-14330)

- - - - -
4f358345 by Utkarsh Gupta at 2026-07-13T02:02:04+05:30
lts: pyjwt not-affected/postponed in bullseye/bookworm (5 CVEs)

- - - - -
e073aaed by Utkarsh Gupta at 2026-07-13T02:02:05+05:30
lts: python-django not-affected/postponed in bullseye/bookworm

(CVE-2026-48588, CVE-2026-53877, CVE-2026-53878)

- - - - -
89621927 by Utkarsh Gupta at 2026-07-13T02:02:07+05:30
lts: python-webob postponed in bullseye/bookworm (CVE-2026-44889)

- - - - -
888d638e by Utkarsh Gupta at 2026-07-13T02:02:08+05:30
lts: rpm postponed in bullseye/bookworm (CVE-2026-44605)

- - - - -
c2293c8d by Utkarsh Gupta at 2026-07-13T02:02:10+05:30
lts: rrdtool postponed in bullseye/bookworm (CVE-2026-43958)

- - - - -
bd5db2b6 by Utkarsh Gupta at 2026-07-13T02:02:11+05:30
lts: socat not-affected in bullseye/bookworm (CVE-2026-56123)

- - - - -
46c425b7 by Utkarsh Gupta at 2026-07-13T02:02:13+05:30
lts: sssd postponed in bullseye/bookworm

(CVE-2026-12610, CVE-2026-14474, CVE-2026-14476)

- - - - -
0f6de9a7 by Utkarsh Gupta at 2026-07-13T02:02:14+05:30
lts: wget postponed in bullseye/bookworm (4 CVEs)

- - - - -
f72b44ee by Utkarsh Gupta at 2026-07-13T02:02:16+05:30
lts: libdbi-perl postponed in bullseye/bookworm

(CVE-2026-14380, CVE-2026-14739, CVE-2026-14740)

- - - - -
d6f1e3fd by Utkarsh Gupta at 2026-07-13T02:02:16+05:30
dla-needed: add libass

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1190,6 +1190,8 @@ CVE-2025-45422 (Incorrect access control in Proximus 
b-box v8c.725A allows authe
 CVE-2026-14741
        - libhttp-date-perl 6.08-1
        [trixie] - libhttp-date-perl <no-dsa> (Minor issue)
+       [bookworm] - libhttp-date-perl <postponed> (Minor issue)
+       [bullseye] - libhttp-date-perl <postponed> (Minor issue)
        NOTE: 
https://github.com/libwww-perl/HTTP-Date/commit/78c20952cdfbf11e03cf1199ad70f13298a84c5c
 (v6.08)
 CVE-2026-9253 (The WP Cost Estimation & Payment Forms Builder (E&P Forms) 
plugin for  ...)
        NOT-FOR-US: WordPress plugin
@@ -2475,14 +2477,20 @@ CVE-2026-6101 (The AMP for WP \u2013 Accelerated Mobile 
Pages plugin for WordPre
 CVE-2026-60002 (ssh in OpenSSH before 10.4 can have a use-after-free when a 
server cha ...)
        - openssh 1:10.4p1-1
        [trixie] - openssh <no-dsa> (Minor issue)
+       [bookworm] - openssh <postponed> (Minor issue)
+       [bullseye] - openssh <postponed> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.4p1
 CVE-2026-60001 (sshd in OpenSSH before 10.4 does not always honor the minimum 
authenti ...)
        - openssh 1:10.4p1-1
        [trixie] - openssh <no-dsa> (Minor issue)
+       [bookworm] - openssh <postponed> (Minor issue)
+       [bullseye] - openssh <postponed> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.4p1
 CVE-2026-60000 (sshd in OpenSSH before 10.4 allows remote attackers to cause a 
denial  ...)
        - openssh 1:10.4p1-1
        [trixie] - openssh <no-dsa> (Minor issue)
+       [bookworm] - openssh <postponed> (Minor issue)
+       [bullseye] - openssh <postponed> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.4p1
 CVE-2026-5799 (Authorization bypass through User-Controlled key vulnerability 
in Idvl ...)
        NOT-FOR-US: Idvlabs Ontime
@@ -2491,22 +2499,32 @@ CVE-2026-5730 (Authorization bypass through 
User-Controlled key vulnerability in
 CVE-2026-59999 (In sshd in OpenSSH before 10.4, DisableForwarding=yes was 
supposed to  ...)
        - openssh 1:10.4p1-1
        [trixie] - openssh <no-dsa> (Minor issue)
+       [bookworm] - openssh <postponed> (Minor issue)
+       [bullseye] - openssh <postponed> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.4p1
 CVE-2026-59998 (sshd in OpenSSH before 10.4 has an undocumented 
security-relevant beha ...)
        - openssh 1:10.4p1-1
        [trixie] - openssh <no-dsa> (Minor issue)
+       [bookworm] - openssh <postponed> (Minor issue)
+       [bullseye] - openssh <postponed> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.4p1
 CVE-2026-59997 (internal-sftp in sshd in OpenSSH before 10.4 recognizes only 
the first ...)
        - openssh 1:10.4p1-1
        [trixie] - openssh <no-dsa> (Minor issue)
+       [bookworm] - openssh <postponed> (Minor issue)
+       [bullseye] - openssh <postponed> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.4p1
 CVE-2026-59996 (scp in OpenSSH before 10.4 may place a file in the parent 
directory of ...)
        - openssh 1:10.4p1-1
        [trixie] - openssh <no-dsa> (Minor issue)
+       [bookworm] - openssh <postponed> (Minor issue)
+       [bullseye] - openssh <postponed> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.4p1
 CVE-2026-59995 (sftp in OpenSSH before 10.4 does not properly constrain the 
location o ...)
        - openssh 1:10.4p1-1
        [trixie] - openssh <no-dsa> (Minor issue)
+       [bookworm] - openssh <postponed> (Minor issue)
+       [bullseye] - openssh <postponed> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.4p1
 CVE-2026-59800 (9Router before 0.4.44 contains an OS command injection 
vulnerability i ...)
        NOT-FOR-US: 9Router
@@ -2534,18 +2552,26 @@ CVE-2026-58473 (Cognee before 1.2.0 contains an 
improper access control vulnerab
 CVE-2026-58472 (GNU Wget through 1.25.0, fixed in commit dd692d9, contains a 
heap buff ...)
        - wget <unfixed> (bug #1141689)
        [trixie] - wget <no-dsa> (Minor issue)
+       [bookworm] - wget <postponed> (Minor issue)
+       [bullseye] - wget <postponed> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/gnuwget/wget/-/commit/dd692d9cea5335b181d877ae917fe6e75587a812
 CVE-2026-58471 (GNU Wget through 1.25.0, fixed in commit c2640fe, contains a 
heap buff ...)
        - wget <unfixed> (bug #1141689)
        [trixie] - wget <no-dsa> (Minor issue)
+       [bookworm] - wget <postponed> (Minor issue)
+       [bullseye] - wget <postponed> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/gnuwget/wget/-/commit/c2640fe5171c59f87c58dc9fcb195b2d18b010ee
 CVE-2026-58470 (GNU Wget through 1.25.0, fixed in commit 43d3ba9, contains an 
integer  ...)
        - wget <unfixed> (bug #1141689)
        [trixie] - wget <no-dsa> (Minor issue)
+       [bookworm] - wget <postponed> (Minor issue)
+       [bullseye] - wget <postponed> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/gnuwget/wget/-/commit/43d3ba9336bc94937e6fae2365c6ffd30c34ffcf
 CVE-2026-58469 (GNU Wget through 1.25.0, fixed in commit 37a40fc, contains a 
heap buff ...)
        - wget <unfixed> (bug #1141689)
        [trixie] - wget <no-dsa> (Minor issue)
+       [bookworm] - wget <postponed> (Minor issue)
+       [bullseye] - wget <postponed> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/gnuwget/wget/-/commit/37a40fcb450153f69537c7cbc2a7a4fb0b6f7826
 CVE-2026-58468 (NocoBase through 2.1.20 contains a server-side request forgery 
vulnera ...)
        NOT-FOR-US: NocoBase
@@ -2656,6 +2682,8 @@ CVE-2026-51937 (An issue in Oneblog V2.3.9 allows a 
remote attacker to obtain se
 CVE-2026-50811 (An out-of-bounds read vulnerability exists in FreeType 2.14.3 
and vers ...)
        - freetype <unfixed> (bug #1141704)
        [trixie] - freetype <no-dsa> (Minor issue)
+       [bookworm] - freetype <not-affected> (TT_Get_Var_Design OOB read 
introduced in 2.14.0; shipped code uses safe coords[i]=0)
+       [bullseye] - freetype <not-affected> (TT_Get_Var_Design OOB read 
introduced in 2.14.0; shipped code uses safe coords[i]=0)
        NOTE: https://gitlab.freedesktop.org/freetype/freetype/-/work_items/1436
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/freetype/freetype/-/commit/5a280ecde6f324de0d226261036e736e0cb49a71
 CVE-2026-50810 (A NULL pointer dereference in smooth_parse_stream_index() in 
src/media ...)
@@ -2763,6 +2791,8 @@ CVE-2026-14482 (The 
\u591a\u8bf4\u793e\u4f1a\u5316\u8bc4\u8bba\u6846 plugin for
 CVE-2026-14476 (A path traversal flaw was found in SSSD's AD GPO provider. The 
ad_gpo_ ...)
        - sssd <unfixed> (bug #1141769)
        [trixie] - sssd <no-dsa> (Minor issue)
+       [bookworm] - sssd <postponed> (Minor issue)
+       [bullseye] - sssd <postponed> (Minor issue)
        NOTE: https://github.com/SSSD/sssd/pull/8896
        NOTE: Fixed by: 
https://github.com/SSSD/sssd/commit/ba207eab76ff5253662a763b9b6e9ea42f03d31b 
(master)
        NOTE: Fixed by: 
https://github.com/SSSD/sssd/commit/3c1a31ab668b1ed7b97eb72d915a4187e549d86c 
(sssd-2-12 branch)
@@ -2771,6 +2801,8 @@ CVE-2026-14476 (A path traversal flaw was found in SSSD's 
AD GPO provider. The a
 CVE-2026-14474 (A flaw was found in SSSD's LDAP sudo provider. When the 
ldap_sudo_sear ...)
        - sssd <unfixed> (bug #1141769)
        [trixie] - sssd <no-dsa> (Minor issue)
+       [bookworm] - sssd <postponed> (Minor issue)
+       [bullseye] - sssd <postponed> (Minor issue)
        NOTE: https://github.com/SSSD/sssd/pull/8897
        NOTE: Fixed by: 
https://github.com/SSSD/sssd/commit/aa74f8b06b974796dfc4760f2363ab78fbb8cc56 
(sssd-2-12 branch)
        NOTE: Fixed by: 
https://github.com/SSSD/sssd/commit/0dd9e45e7cde18a3b7c2975b587d48a82eb5d830 
(sssd-2-10 branch)
@@ -2851,17 +2883,23 @@ CVE-2026-14895 (String::Util versions before 1.36 for 
Perl are susceptible to a
 CVE-2026-14380 (DBI versions before 1.650 for Perl are vulnerable to code 
injection vi ...)
        - libdbi-perl 1.650-1 (bug #1141667)
        [trixie] - libdbi-perl <no-dsa> (Minor issue)
+       [bookworm] - libdbi-perl <postponed> (Minor issue)
+       [bullseye] - libdbi-perl <postponed> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625527/
        NOTE: 
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-ch8w-hxc2-v557
        NOTE: Fixed by: 
https://github.com/perl5-dbi/dbi/commit/b73d5d9901767fc1d16b6661ef08fbed4532e259
 (1.650)
 CVE-2026-14739 (DBI versions before 1.650 for Perl have a heap overflow when 
preparsin ...)
        - libdbi-perl 1.650-1 (bug #1141667)
        [trixie] - libdbi-perl <no-dsa> (Minor issue)
+       [bookworm] - libdbi-perl <postponed> (Minor issue)
+       [bullseye] - libdbi-perl <postponed> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625530/
        NOTE: Fixed by: 
https://github.com/perl5-dbi/dbi/commit/2b77c88b655e9539a592c71a61fb965fc0075395
 (1.650)
 CVE-2026-14740 (DBI versions before 1.650 for Perl read one byte out-of-bounds 
in prep ...)
        - libdbi-perl 1.650-1 (bug #1141667)
        [trixie] - libdbi-perl <no-dsa> (Minor issue)
+       [bookworm] - libdbi-perl <postponed> (Minor issue)
+       [bullseye] - libdbi-perl <postponed> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41625532/
        NOTE: 
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-35f4-f8m9-w8xg
        NOTE: Fixed by: 
https://github.com/perl5-dbi/dbi/commit/fc16f9e8b3dd5c65caf1867781ab2bfe2fadcc01
 (1.650)
@@ -3000,16 +3038,22 @@ CVE-2026-7017 (HTTP::Tiny versions before 0.095 for 
Perl forward credential head
 CVE-2026-53878 (An issue was discovered in Django 6.0 before 6.0.7 and 5.2 
before 5.2. ...)
        - python-django 3:5.2.16-1 (bug #1141629)
        [trixie] - python-django <no-dsa> (Minor issue)
+       [bookworm] - python-django <not-affected> (DomainNameValidator 
introduced in Django 5.1)
+       [bullseye] - python-django <not-affected> (DomainNameValidator 
introduced in Django 5.1)
        NOTE: 
https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
        NOTE: Fixed by: 
https://github.com/django/django/commit/d5d60ed0323cddaa0ce0237a26a3d49ac21ee05e
 (5.2.16)
 CVE-2026-53877 (An issue was discovered in Django 6.0 before 6.0.7 and 5.2 
before 5.2. ...)
        - python-django 3:5.2.16-1 (bug #1141629)
        [trixie] - python-django <no-dsa> (Minor issue)
+       [bookworm] - python-django <postponed> (Minor issue)
+       [bullseye] - python-django <postponed> (Minor issue)
        NOTE: 
https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
        NOTE: Fixed by: 
https://github.com/django/django/commit/6c66eb8cec52b303af85c2c6e4dd00aa37654dbc
 (5.2.16)
 CVE-2026-48588 (An issue was discovered in Django 6.0 before 6.0.7 and 5.2 
before 5.2. ...)
        - python-django 3:5.2.16-1 (bug #1141629)
        [trixie] - python-django <no-dsa> (Minor issue)
+       [bookworm] - python-django <postponed> (Minor issue)
+       [bullseye] - python-django <postponed> (Minor issue)
        NOTE: 
https://www.djangoproject.com/weblog/2026/jul/07/security-releases/
        NOTE: Fixed by: 
https://github.com/django/django/commit/721685aa7799cc9327bd202cd1f70bd012ca95a7
 (5.2.16)
 CVE-2026-XXXX [InspIRCd Security Advisory 2026-01]
@@ -3419,11 +3463,15 @@ CVE-2026-55798 (Pillow is a Python imaging library. 
Prior to 12.3.0, WindowsView
 CVE-2026-55380 (Pillow is a Python imaging library. Prior to 12.3.0, 
PIL/GdImageFile.p ...)
        - pillow <unfixed>
        [trixie] - pillow <no-dsa> (Minor issue)
+       [bookworm] - pillow <postponed> (Minor issue)
+       [bullseye] - pillow <postponed> (Minor issue)
        NOTE: 
https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm
        NOTE: Fixed by: 
https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675
 (12.3.0)
 CVE-2026-55379 (Pillow is a Python imaging library. Prior to 12.3.0, 
PIL/BdfFontFile.p ...)
        - pillow <unfixed>
        [trixie] - pillow <no-dsa> (Minor issue)
+       [bookworm] - pillow <postponed> (Minor issue)
+       [bullseye] - pillow <postponed> (Minor issue)
        NOTE: 
https://github.com/python-pillow/Pillow/security/advisories/GHSA-45hq-cxwh-f6vc
        NOTE: Fixed by: 
https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
 (12.3.0)
 CVE-2026-54893 (URL path injection in the Microsoft Graph adapter of Swoosh. 
Swoosh.Ad ...)
@@ -3436,11 +3484,15 @@ CVE-2026-54291 (pgjdbc is an open source postgresql 
JDBC Driver. In releases 42.
 CVE-2026-54060 (Pillow is a Python imaging library. Prior to 12.3.0, 
PIL/FontFile.py F ...)
        - pillow <unfixed>
        [trixie] - pillow <no-dsa> (Minor issue)
+       [bookworm] - pillow <postponed> (Minor issue)
+       [bullseye] - pillow <postponed> (Minor issue)
        NOTE: 
https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2
        NOTE: Fixed by: 
https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
 (12.3.0)
 CVE-2026-54059 (Pillow is a Python imaging library. Prior to 12.3.0, 
PIL/PcfFontFile.p ...)
        - pillow <unfixed>
        [trixie] - pillow <no-dsa> (Minor issue)
+       [bookworm] - pillow <postponed> (Minor issue)
+       [bullseye] - pillow <postponed> (Minor issue)
        NOTE: 
https://github.com/python-pillow/Pillow/security/advisories/GHSA-8v84-f9pq-wr9x
        NOTE: Fixed by: 
https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
 (12.3.0)
 CVE-2026-53913 (Improper Authentication, Missing Authentication for Critical 
Function, ...)
@@ -4290,6 +4342,8 @@ CVE-2025-71342 (picklescan before 0.0.30 fails to detect 
malicious pickle files
 CVE-2026-12893 [gstreamer1-libav: gstreamer1-libav: NULL pointer dereference 
in gstavdemux.c error handler]
        - gst-libav1.0 1.28.4-1
        [trixie] - gst-libav1.0 <no-dsa> (Minor issue)
+       [bookworm] - gst-libav1.0 <postponed> (Minor issue)
+       [bullseye] - gst-libav1.0 <postponed> (Minor issue)
        NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0038.html
        NOTE: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/11802
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f904dfda677a0c148de8c391f3dbb11490c7e026
 (1.29.2)
@@ -5816,6 +5870,8 @@ CVE-2026-14358 (Improper neutralization of input during 
web page generation ('cr
 CVE-2026-14330 (Multiple unbounded alloca() calls in the PulseAudio protocol 
server.)
        - pulseaudio <unfixed> (bug #1141309)
        [trixie] - pulseaudio <no-dsa> (Minor issue)
+       [bookworm] - pulseaudio <postponed> (Minor issue)
+       [bullseye] - pulseaudio <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2495907
 CVE-2026-14324 (RAOP module accepts unbounded Content-Length values and does 
not check ...)
        - pipewire 1.6.8-1 (bug #1141308)
@@ -8337,6 +8393,8 @@ CVE-2026-13149 (brace-expansion through 5.0.6 is 
vulnerable to denial of service
 CVE-2026-12610 (A flaw was found in sssd. When authenticating with a YubiKey, 
the SSSD ...)
        - sssd <unfixed> (bug #1141323)
        [trixie] - sssd <no-dsa> (Minor issue)
+       [bookworm] - sssd <postponed> (Minor issue)
+       [bullseye] - sssd <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490288
        NOTE: https://github.com/SSSD/sssd/issues/8796
        NOTE: 
https://github.com/SSSD/sssd/commit/fa7a55949a30fed064a28ea6f0c801fc5e8c5ba7 
(master)
@@ -8454,6 +8512,8 @@ CVE-2026-57964
 CVE-2026-44605
        - rpm <unfixed>
        [trixie] - rpm <no-dsa> (Minor issue)
+       [bookworm] - rpm <postponed> (Minor issue)
+       [bullseye] - rpm <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2482481
 CVE-2026-13606
        - graphicsmagick <unfixed> (bug #1141493)
@@ -8828,10 +8888,14 @@ CVE-2026-46406 (Claude Code is an agentic coding tool.  
From 2.1.59 until 2.1.12
 CVE-2026-41992 (GNU gzip contains a global buffer overflow vulnerability in 
the LZH de ...)
        - gzip <unfixed> (bug #1141443)
        [trixie] - gzip <no-dsa> (Minor issue)
+       [bookworm] - gzip <postponed> (Minor issue)
+       [bullseye] - gzip <postponed> (Minor issue)
        NOTE: 
https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=63dbf6b3b9e6e781df1a6a64e609b10e23969681
 CVE-2026-41991 (GNU gzip contains a vulnerability in the gzexe utility related 
to inse ...)
        - gzip <unfixed> (bug #1141442)
        [trixie] - gzip <no-dsa> (Minor issue)
+       [bookworm] - gzip <postponed> (Minor issue)
+       [bullseye] - gzip <postponed> (Minor issue)
        NOTE: 
https://cgit.git.savannah.gnu.org/cgit/gzip.git/commit/?id=4e6f8b24ab823146ab8776f0b7fe486ab34d4269
 CVE-2026-41052 (Improper privilege handling could be used by users withProject 
Owner r ...)
        NOT-FOR-US: Rancher
@@ -8854,6 +8918,8 @@ CVE-2026-22078 (Because O+ Connect's IPC service does not 
authenticate clients,
 CVE-2026-13757 (A flaw was found in p11-kit. The RPC message attribute parsing 
functio ...)
        - p11-kit 0.26.4-1 (bug #1141184)
        [trixie] - p11-kit <no-dsa> (Minor issue)
+       [bookworm] - p11-kit <postponed> (Minor issue)
+       [bullseye] - p11-kit <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2494556
        NOTE: https://github.com/p11-glue/p11-kit/issues/767
        NOTE: https://github.com/p11-glue/p11-kit/pull/768
@@ -9199,6 +9265,8 @@ CVE-2026-58056 (RustDesk gates incoming control messages 
on per-capability flags
 CVE-2026-58055 (nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 
Upgrade re ...)
        - nghttp2 <unfixed> (bug #1140917)
        [trixie] - nghttp2 <no-dsa> (Minor issue)
+       [bookworm] - nghttp2 <postponed> (Minor issue)
+       [bullseye] - nghttp2 <postponed> (Minor issue)
        NOTE: 
https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc
        NOTE: 
https://github.com/nghttp2/nghttp2/commit/ab28105c4a0197da24f8bfc414bc116055249e1e
 CVE-2026-58054 (MyBB 1.8.40 does not restrict which usergroup a limited Admin 
Control  ...)
@@ -10802,6 +10870,8 @@ CVE-2026-56129 (Generic IO & Memory Access driver for 
PCs provided by TOSHIBA CO
 CVE-2026-56123 (socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based 
buffer ove ...)
        - socat 1.8.1.3-1
        [trixie] - socat <no-dsa> (Minor issue)
+       [bookworm] - socat <not-affected> (SOCKS5 client (xio-socks5.c) 
introduced in 1.8.0.0)
+       [bullseye] - socat <not-affected> (SOCKS5 client (xio-socks5.c) 
introduced in 1.8.0.0)
 CVE-2026-56122 (Winstone Servlet Engine through 0.9.10 contains a path 
traversal vulne ...)
        NOT-FOR-US: Winstone Servlet Container
 CVE-2026-56091 (When using Apache Shiro with the shiro-guice module in a web 
servlet c ...)
@@ -14255,6 +14325,8 @@ CVE-2026-55099
 CVE-2026-57062 (CMS (Cryptographic Message Syntax) parsing in gpgsm in GnuPG 
through 2 ...)
        - gnupg2 2.4.9-5
        [trixie] - gnupg2 <no-dsa> (Minor issue)
+       [bookworm] - gnupg2 <postponed> (Minor issue)
+       [bullseye] - gnupg2 <not-affected> (gpgsm GCM CMS-decrypt path not 
present; introduced after 2.2.27)
        NOTE: https://blog.calif.io/p/how-to-format-a-ciphertext
        NOTE: Fixed by: 
https://github.com/gpg/gnupg/commit/4c7e68cf3d335328821bdbb70db309a60d0e4fd4
 CVE-2026-56815 (pwnlift before d7a9544, in a privileged deployment, contains a 
symlink ...)
@@ -14855,6 +14927,8 @@ CVE-2026-45034 (PhpSpreadsheet is a pure PHP library 
for reading and writing spr
 CVE-2026-44889 (WebOb provides objects for HTTP requests and responses. Prior 
to 1.8.1 ...)
        - python-webob 1:1.8.10-1
        [trixie] - python-webob 1:1.8.10-0+deb13u1
+       [bookworm] - python-webob <postponed> (Minor issue)
+       [bullseye] - python-webob <postponed> (Minor issue)
        NOTE: 
https://github.com/Pylons/webob/security/advisories/GHSA-fh3h-vg37-cc95
 CVE-2026-44727 (Jupyter Server is the backend for Jupyter web applications. 
Prior to 2 ...)
        - jupyter-server 2.20.0-1
@@ -15293,6 +15367,8 @@ CVE-2026-11373 (Net::Statsite::Client versions through 
1.1.0 for Perl allow metr
 CVE-2026-6653 (Use After Free in libxml2's xmlParseInternalSubset from GNOME 
libxml2  ...)
        - libxml2 2.14.5+dfsg-0.1
        [trixie] - libxml2 <no-dsa> (Minor issue)
+       [bookworm] - libxml2 <postponed> (Minor issue; UAF present via 
CVE-2021-3541 backport, fix only in 2.11.0)
+       [bullseye] - libxml2 <postponed> (Minor issue; UAF present via 
CVE-2021-3541 backport, fix only in 2.11.0)
        NOTE: https://www.openwall.com/lists/oss-security/2026/06/22/3
        NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1058
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libxml2/-/commit/463bbeeca1805b5c4828f50d0fefc4eebaf620df
 (v2.11.0)
@@ -16286,11 +16362,15 @@ CVE-2026-55204 (HAProxy through  3.4.0, fixed in 
commit 9a6d1fe, contains a null
        [experimental] - haproxy 3.4.1-1
        - haproxy 3.2.20-1 (bug #1140430)
        [trixie] - haproxy <no-dsa> (Minor issue)
+       [bookworm] - haproxy <postponed> (Minor issue)
+       [bullseye] - haproxy <postponed> (Minor issue)
        NOTE: 
https://github.com/haproxy/haproxy/commit/9a6d1fe3f00d86ab4ea6ea6ea0a5d48fc058a513
 CVE-2026-55203 (HAProxy through 3.4.0, fixed in commit 5985276, contains an 
integer ov ...)
        [experimental] - haproxy 3.4.1-1
        - haproxy 3.2.20-1 (bug #1140430)
        [trixie] - haproxy <no-dsa> (Minor issue)
+       [bookworm] - haproxy <postponed> (Minor issue)
+       [bullseye] - haproxy <postponed> (Minor issue)
        NOTE: 
https://github.com/haproxy/haproxy/commit/5985276735777634d8c85f1d73bb7764aab0d6dd
 CVE-2026-54419 (claudiopizzillo PIAF-HMS (PBX-In-A-Flash Hotel Management 
System; no r ...)
        NOT-FOR-US: PBX-In-A-Flash Hotel Management System
@@ -18716,6 +18796,8 @@ CVE-2024-22447 (Dell Peripheral Manager, versions prior 
to 1.7.3, contain an unc
 CVE-2026-57053 (GNU libidn before 1.44 is prone to out-of-bounds reads 
ofuninitialized ...)
        - libidn 1.44-1
        [trixie] - libidn <no-dsa> (Minor issue)
+       [bookworm] - libidn <postponed> (Minor issue)
+       [bullseye] - libidn <postponed> (Minor issue)
        NOTE: 
https://lists.gnu.org/archive/html/help-libidn/2026-06/msg00001.html
        NOTE: 
https://lists.gnu.org/archive/html/help-libidn/2026-05/msg00000.html
 CVE-2026-46448 (In OpenStack Nova before 33.0.2, the server create API does 
not strip  ...)
@@ -19629,6 +19711,8 @@ CVE-2026-54412 (LiamBindle MQTT-C through version 1.1.6 
contains a heap-based ou
 CVE-2026-54411 (Linux-PAM through 1.7.2 contains an observable timing 
discrepancy (CWE ...)
        - pam <unfixed> (bug #1140190)
        [trixie] - pam <postponed> (Minor issue, revisit when fixed upstream)
+       [bookworm] - pam <postponed> (Minor issue)
+       [bullseye] - pam <postponed> (Minor issue)
        NOTE: https://github.com/linux-pam/linux-pam/issues/992
        NOTE: https://github.com/linux-pam/linux-pam/pull/991
 CVE-2026-54410 (nanoMODBUS through v1.23.0 contains an off-by-one buffer 
overflow in t ...)
@@ -28618,6 +28702,8 @@ CVE-2026-44211 (Cline is an autonomous coding agent as 
an SDK, IDE extension, or
 CVE-2026-43958 (A flaw was found in rrdcached, a component of rrdtool. A local 
attacke ...)
        - rrdtool <unfixed> (bug #1140106)
        [trixie] - rrdtool <no-dsa> (Minor issue)
+       [bookworm] - rrdtool <postponed> (Minor issue)
+       [bullseye] - rrdtool <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460932
        NOTE: Fixed by: 
https://github.com/oetiker/rrdtool-1.x/commit/4218ec7127ba6c7ea1c20d7c8ea6e2b3f83df73a
 (v1.10.0)
 CVE-2026-43625 (CodexBar prior to 0.32.0 contains a session cookie leakage 
vulnerabili ...)
@@ -30933,26 +31019,36 @@ CVE-2026-48735 (pypdf is a free and open-source 
pure-python PDF library. Prior t
 CVE-2026-48526 (PyJWT is a JSON Web Token implementation in Python. Prior to 
2.13.0, w ...)
        - pyjwt 2.13.0-1 (bug #1138191)
        [trixie] - pyjwt <no-dsa> (Minor issue)
+       [bookworm] - pyjwt <postponed> (Minor issue)
+       [bullseye] - pyjwt <postponed> (Minor issue)
        NOTE: 
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-xgmm-8j9v-c9wx
        NOTE: 
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
 (2.13.0)
 CVE-2026-48525 (PyJWT is a JSON Web Token implementation in Python. From 2.8.0 
to 2.12 ...)
        - pyjwt 2.13.0-1 (bug #1138191)
        [trixie] - pyjwt <no-dsa> (Minor issue)
+       [bookworm] - pyjwt <postponed> (Minor issue)
+       [bullseye] - pyjwt <not-affected> (RFC 7797 (b64=false) support not 
present)
        NOTE: 
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-w7vc-732c-9m39
        NOTE: 
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
 (2.13.0)
 CVE-2026-48524 (PyJWT is a JSON Web Token implementation in Python. Prior to 
2.13.0, P ...)
        - pyjwt 2.13.0-1 (bug #1138191)
        [trixie] - pyjwt <no-dsa> (Minor issue)
+       [bookworm] - pyjwt <postponed> (Minor issue)
+       [bullseye] - pyjwt <not-affected> (PyJWKClient not present)
        NOTE: 
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-fhv5-28vv-h8m8
        NOTE: 
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
 (2.13.0)
 CVE-2026-48523 (PyJWT is a JSON Web Token implementation in Python. From 2.9.0 
to 2.12 ...)
        - pyjwt 2.13.0-1 (bug #1138191)
        [trixie] - pyjwt <no-dsa> (Minor issue)
+       [bookworm] - pyjwt <not-affected> (PyJWK algorithm binding introduced 
in 2.9.0)
+       [bullseye] - pyjwt <not-affected> (PyJWK algorithm binding introduced 
in 2.9.0)
        NOTE: 
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-jq35-7prp-9v3f
        NOTE: 
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
 (2.13.0)
 CVE-2026-48522 (PyJWT is a JSON Web Token implementation in Python. Prior to 
2.13.0, P ...)
        - pyjwt 2.13.0-1 (bug #1138191)
        [trixie] - pyjwt <no-dsa> (Minor issue)
+       [bookworm] - pyjwt <postponed> (Minor issue)
+       [bullseye] - pyjwt <not-affected> (PyJWKClient not present)
        NOTE: 
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-993g-76c3-p5m4
        NOTE: 
https://github.com/jpadilla/pyjwt/commit/95791b1759b8aa4f2203575d344d5c78564cdc81
 (2.13.0)
 CVE-2026-48156 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.12 ...)


=====================================
data/dla-needed.txt
=====================================
@@ -328,6 +328,10 @@ knot-resolver/bullseye
 ldap-account-manager/bullseye
   NOTE: 20260418: Added by Front-Desk (rouca)
 --
+libass
+  NOTE: 20260712: Added by Front-Desk (utkarsh)
+  NOTE: 20260712: TEMP-0000000-AA08BC (GHSA-pjjp-65r7-ppgm): OOB read+write in 
wrap_lines_measure from untrusted subtitles; secteam fixed stable via point 
release. Affected in bullseye (0.15.0) and bookworm (0.17.1). 
(utkarsh/front-desk)
+--
 libcaca/bullseye
   NOTE: 20260519: Added by Front-Desk (Beuc)
   NOTE: 20260519: Fix unstable first. (Beuc/front-desk)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/38ed1d8117293fed0861b93ea13f6b0e099a1ae1...d6f1e3fd6468126429268c77746c2ab520f343c9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/38ed1d8117293fed0861b93ea13f6b0e099a1ae1...d6f1e3fd6468126429268c77746c2ab520f343c9
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to