Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
81c3d2f0 by Utkarsh Gupta at 2026-07-13T06:55:35+05:30
lts: graphicsmagick postponed in bullseye/bookworm

(CVE-2026-13606)

- - - - -
4ad63756 by Utkarsh Gupta at 2026-07-13T06:55:42+05:30
lts: libmojolicious-perl postponed in bullseye/bookworm

(CVE-2026-14803)

- - - - -
6da707aa by Utkarsh Gupta at 2026-07-13T06:55:49+05:30
lts: httpcomponents-core not-affected/postponed in bullseye/bookworm

(CVE-2026-54399, CVE-2026-54428)

- - - - -
dba29f4d by Utkarsh Gupta at 2026-07-13T06:55:58+05:30
lts: node-ajv not-affected in bullseye/bookworm (CVE-2026-13676)

- - - - -
bb610d84 by Utkarsh Gupta at 2026-07-13T06:55:58+05:30
lts: node-form-data postponed in bullseye/bookworm (CVE-2026-12143)

- - - - -
12793a90 by Utkarsh Gupta at 2026-07-13T06:55:58+05:30
lts: node-brace-expansion postponed in bullseye/bookworm

(CVE-2026-13149)

- - - - -
78b7a304 by Utkarsh Gupta at 2026-07-13T06:56:04+05:30
lts: nut postponed in bullseye/bookworm (CVE-2026-54161)

- - - - -
d13bac9f by Utkarsh Gupta at 2026-07-13T06:56:04+05:30
lts: openslide ignored in bullseye/bookworm (CVE-2026-54604)

- - - - -
2efb1600 by Utkarsh Gupta at 2026-07-13T06:56:05+05:30
lts: gpsd postponed in bullseye/bookworm (CVE-2026-58459)

- - - - -
2f00100e by Utkarsh Gupta at 2026-07-13T06:56:05+05:30
lts: jansi not-affected/postponed in bullseye/bookworm

(CVE-2026-8484)

- - - - -
1ba112f4 by Utkarsh Gupta at 2026-07-13T06:56:11+05:30
lts: jansi-native postponed in bullseye/bookworm (CVE-2026-8484)

- - - - -
2bb000d6 by Utkarsh Gupta at 2026-07-13T06:56:12+05:30
lts: nsd not-affected/postponed in bullseye/bookworm (CVE-2026-12490)

- - - - -
2fb33ac9 by Utkarsh Gupta at 2026-07-13T06:56:12+05:30
lts: pipewire not-affected/postponed in bullseye/bookworm

(CVE-2026-14324)

- - - - -
ea7f8b14 by Utkarsh Gupta at 2026-07-13T06:56:17+05:30
lts: python-kafka postponed in bullseye/bookworm

(CVE-2026-10142, CVE-2026-10143)

- - - - -
d840e11b by Utkarsh Gupta at 2026-07-13T06:56:22+05:30
lts: ruby-faraday postponed in bullseye/bookworm (CVE-2026-54297)

- - - - -
e7b59426 by Utkarsh Gupta at 2026-07-13T06:56:23+05:30
lts: ruby-json not-affected in bullseye/bookworm (CVE-2026-54696)

- - - - -
0d83135f by Utkarsh Gupta at 2026-07-13T06:56:23+05:30
lts: ruby-nokogiri not-affected/postponed in bullseye/bookworm (8 CVEs)

- - - - -
5e33ba7b by Utkarsh Gupta at 2026-07-13T06:56:23+05:30
lts: ujson postponed in bullseye/bookworm (CVE-2026-54911)

- - - - -
f49f5ae3 by Utkarsh Gupta at 2026-07-13T06:56:23+05:30
lts: etcd not-affected in bullseye/bookworm (CVE-2026-59818)

- - - - -
fb9b4465 by Utkarsh Gupta at 2026-07-13T07:17:39+05:30
lts: php-horde-vfs postponed in bullseye (CVE-2026-60102)

- - - - -
c01edb23 by Utkarsh Gupta at 2026-07-13T07:17:39+05:30
dla-needed: extend ffmpeg to bookworm (CVE-2026-8461)

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1312,6 +1312,8 @@ CVE-2026-59148 (Mockoon provides way to design and run 
mock APIs. Prior to 9.7.0
        NOT-FOR-US: Mockoon
 CVE-2026-58459 (gpsd through release-3.27.5, fixed at commit 4c06658, contains 
a comma ...)
        - gpsd <unfixed> (bug #1141962)
+       [bookworm] - gpsd <postponed> (Minor issue; command injection confined 
to the gpsprof diagnostic client via device-controlled subtype, local + 
user-interaction)
+       [bullseye] - gpsd <postponed> (Minor issue; command injection confined 
to the gpsprof diagnostic client via device-controlled subtype, local + 
user-interaction)
        NOTE: https://gitlab.com/gpsd/gpsd/-/work_items/404#note_3534119267
        NOTE: 
https://github.com/ntpsec/gpsd/commit/5581ba196d826a984fbfaf792b7d58535f9911ce
        NOTE: 
https://github.com/ntpsec/gpsd/commit/1a6bb7bcbdf58aa940132e630870af061dc88537
@@ -1641,6 +1643,8 @@ CVE-2026-59819 (LiteLLM is a proxy server (AI Gateway) to 
call LLM APIs in OpenA
        NOT-FOR-US: LiteLLM
 CVE-2026-59818 (etcd is a distributed key-value store for the data of a 
distributed sy ...)
        - etcd <unfixed> (bug #1141963)
+       [bookworm] - etcd <not-affected> (Split HTTP/gRPC listener onlyGRPC CRL 
path introduced in 3.5.0; absent in 3.4.x)
+       [bullseye] - etcd <not-affected> (Split HTTP/gRPC listener onlyGRPC CRL 
path introduced in 3.5.0; absent in 3.3.x)
        NOTE: 
https://github.com/etcd-io/etcd/security/advisories/GHSA-3wh4-j44w-pg92
        NOTE: https://github.com/etcd-io/etcd/pull/22007
        NOTE: https://github.com/etcd-io/etcd/pull/22021
@@ -2027,6 +2031,7 @@ CVE-2026-60124 (An authorization bypass in MISP\u2019s 
EventsController::importM
 CVE-2026-60102 (Horde Virtual File System (VFS) API before 3.0.1 contains an 
OS comman ...)
        - php-horde-vfs <unfixed>
        [bookworm] - php-horde-vfs <end-of-life> (EOL in bookworm LTS)
+       [bullseye] - php-horde-vfs <postponed> (Minor issue; requires 
authentication and the non-default Horde_Vfs_Smb/smbclient backend)
        NOTE: https://github.com/horde/Vfs/pull/10
        NOTE: 
https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361 
(v3.0.1)
 CVE-2026-60092 (AVideo (Meet plugin) through commit 
e8d6119f3cb1b849149906efeb0a41fc02 ...)
@@ -3709,6 +3714,8 @@ CVE-2026-59511 (Insertion of Sensitive Information Into 
Sent Data vulnerability
 CVE-2026-14803 (Mojo::JSON versions before 9.47 for Perl allow memory 
exhaustion via u ...)
        - libmojolicious-perl 9.47+dfsg-1 (bug #1141586)
        [trixie] - libmojolicious-perl <no-dsa> (Minor issue)
+       [bookworm] - libmojolicious-perl <postponed> (Minor issue)
+       [bullseye] - libmojolicious-perl <postponed> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41564627/
        NOTE: Fixed by: 
https://github.com/mojolicious/mojo/commit/cc38b0554275c4d84f6b8b49bcbbc1bec2068fe1
 (v9.47)
 CVE-2026-14799 (A security flaw has been discovered in CodeAstro Ecommerce 
Website 1.0 ...)
@@ -4104,6 +4111,8 @@ CVE-2026-49297 (Apache Airflow's Google provider 
operators `GCSToSFTPOperator` a
 CVE-2026-54161
        - nut <unfixed>
        [trixie] - nut <no-dsa> (Minor issue)
+       [bookworm] - nut <postponed> (Minor issue)
+       [bullseye] - nut <postponed> (Minor issue)
        NOTE: 
https://github.com/networkupstools/nut/security/advisories/GHSA-mjgp-j4gm-6qg5
        NOTE: Fixed by: https://github.com/networkupstools/nut/pull/3499
 CVE-2026-58597 (Insufficient ui warning of dangerous operations in Microsoft 
Edge (Chr ...)
@@ -5695,6 +5704,8 @@ CVE-2026-54428 (Allocation of resources without limits or 
throttling in the HTTP
        [trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
        - httpcomponents-core <unfixed>
        [trixie] - httpcomponents-core <no-dsa> (Minor issue)
+       [bookworm] - httpcomponents-core <not-affected> (HTTP/2 HPACK not 
implemented in httpcomponents-core 4.x (v5-only feature))
+       [bullseye] - httpcomponents-core <not-affected> (HTTP/2 HPACK not 
implemented in httpcomponents-core 4.x (v5-only feature))
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/01/3
        NOTE: v4 possibly not affected, needs further validation once fix is 
identified
 CVE-2026-54399 (Uncontrolled Resource Consumption vulnerability in the 
HTTP/1.1 messag ...)
@@ -5702,6 +5713,8 @@ CVE-2026-54399 (Uncontrolled Resource Consumption 
vulnerability in the HTTP/1.1
        [trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
        - httpcomponents-core <unfixed>
        [trixie] - httpcomponents-core <no-dsa> (Minor issue)
+       [bookworm] - httpcomponents-core <postponed> (Minor issue)
+       [bullseye] - httpcomponents-core <postponed> (Minor issue)
        NOTE: https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy
        NOTE: v4 possibly not affected, needs further validation once fix is 
identified
 CVE-2026-53909 (MCO does not correctly validate types of uploaded files. File 
upload v ...)
@@ -5876,6 +5889,8 @@ CVE-2026-14330 (Multiple unbounded alloca() calls in the 
PulseAudio protocol ser
 CVE-2026-14324 (RAOP module accepts unbounded Content-Length values and does 
not check ...)
        - pipewire 1.6.8-1 (bug #1141308)
        [trixie] - pipewire <no-dsa> (Minor issue)
+       [bookworm] - pipewire <postponed> (Minor issue)
+       [bullseye] - pipewire <not-affected> (RAOP module not present in 0.3.19)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2495903
        NOTE: https://gitlab.freedesktop.org/pipewire/pipewire/-/work_items/5352
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/87ee525b0124755ccab99d873ddf85d9d4969f73
 (master)
@@ -6331,6 +6346,8 @@ CVE-2026-54896 (Oj (Optimized JSON) is a JSON parser and 
Object marshaller packa
 CVE-2026-54696 (Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0 
through 2. ...)
        - ruby-json 2.19.9+dfsg-1
        [trixie] - ruby-json <no-dsa> (Minor issue)
+       [bookworm] - ruby-json <not-affected> (Vulnerable code introduced in 
2.9.0)
+       [bullseye] - ruby-json <not-affected> (Vulnerable code introduced in 
2.9.0)
        NOTE: 
https://github.com/ruby/json/security/advisories/GHSA-x2f5-4prf-w687
        NOTE: Fixed by: 
https://github.com/ruby/json/commit/fd6a65bd08e5f3a429c03919ebfd8dd19158f095 
(v2.19.9)
 CVE-2026-54673 (electron-updater allows for automatic updates for Electron 
apps. Prior ...)
@@ -8389,6 +8406,8 @@ CVE-2026-13316 (A flaw has been found in foreman when 
HTTP parameters are modifi
 CVE-2026-13149 (brace-expansion through 5.0.6 is vulnerable to denial of 
service. The  ...)
        - node-brace-expansion <unfixed> (bug #1141325)
        [trixie] - node-brace-expansion <no-dsa> (Minor issue)
+       [bookworm] - node-brace-expansion <postponed> (Minor issue)
+       [bullseye] - node-brace-expansion <postponed> (Minor issue)
        NOTE: 
https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754
 CVE-2026-12610 (A flaw was found in sssd. When authenticating with a YubiKey, 
the SSSD ...)
        - sssd <unfixed> (bug #1141323)
@@ -8518,6 +8537,8 @@ CVE-2026-44605
 CVE-2026-13606
        - graphicsmagick <unfixed> (bug #1141493)
        [trixie] - graphicsmagick <no-dsa> (Minor issue)
+       [bookworm] - graphicsmagick <postponed> (Minor issue)
+       [bullseye] - graphicsmagick <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2494107
 CVE-2026-9576 (The Fluent Booking  WordPress plugin before 2.1.2 does not 
verify owne ...)
        NOT-FOR-US: WordPress plugin
@@ -8943,6 +8964,8 @@ CVE-2026-13742 (Honeywell IQ MultiAccess, all versions 
prior to and including ve
 CVE-2026-13676 (fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to 
canonicalize U ...)
        - node-ajv <unfixed>
        [trixie] - node-ajv <no-dsa> (Minor issue)
+       [bookworm] - node-ajv <not-affected> (fast-uri not embedded; ajv <8 
uses uri-js)
+       [bullseye] - node-ajv <not-affected> (fast-uri not embedded; ajv <8 
uses uri-js)
        NOTE: 
https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6
        NOTE: Embedded fast-uri used and provided as node-fast-uri, starting 
with forky
 CVE-2026-13595 (A flaw was found in the libblkid library of util-linux. During 
nested  ...)
@@ -10787,36 +10810,52 @@ CVE-2026-57451 (Vim is an open source, command line 
text editor. Prior to 9.2.06
 CVE-2026-57438 (Nokogiri is an open source XML and HTML library for the Ruby 
programmi ...)
        - ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
        [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+       [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+       [bullseye] - ruby-nokogiri <postponed> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wfpw-mmfh-qq69
 CVE-2026-57437 (Nokogiri is an open source XML and HTML library for the Ruby 
programmi ...)
        - ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
        [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+       [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+       [bullseye] - ruby-nokogiri <postponed> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-p67v-3w7g-wjg7
 CVE-2026-57436 (Nokogiri is an open source XML and HTML library for the Ruby 
programmi ...)
        - ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
        [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+       [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+       [bullseye] - ruby-nokogiri <postponed> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wjv4-x9w8-wm3h
 CVE-2026-57435 (Nokogiri is an open source XML and HTML library for the Ruby 
programmi ...)
        - ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
        [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+       [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+       [bullseye] - ruby-nokogiri <postponed> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-phwj-rprq-35pp
 CVE-2026-57434 (Nokogiri is an open source XML and HTML library for the Ruby 
programmi ...)
        - ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
        [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+       [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+       [bullseye] - ruby-nokogiri <postponed> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-9cv2-cfxc-v4v2
 CVE-2026-57429 (Contributor Broken Access Control in Slim SEO <= 4.6.2 
versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57236 (Nokogiri is an open source XML and HTML library for the Ruby 
programmi ...)
        - ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
        [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+       [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+       [bullseye] - ruby-nokogiri <postponed> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5v8h-3h3q-446p
 CVE-2026-57235 (Nokogiri is an open source XML and HTML library for the Ruby 
programmi ...)
        - ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
        [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+       [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+       [bullseye] - ruby-nokogiri <postponed> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5prr-v3j2-97mh
 CVE-2026-57234 (Nokogiri is an open source XML and HTML library for the Ruby 
programmi ...)
        - ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
        [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+       [bookworm] - ruby-nokogiri <not-affected> (JRuby-only; Debian 
builds/uses the CRuby implementation)
+       [bullseye] - ruby-nokogiri <not-affected> (JRuby-only; Debian 
builds/uses the CRuby implementation)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-8678-w3jw-xfc2
 CVE-2026-56790 (CANBoat through 6.22, fixed in commit a5a22b7, contains an 
off-by-one  ...)
        - canboat <itp> (bug #921311)
@@ -12369,6 +12408,8 @@ CVE-2026-12635 (GitLab has remediated an issue in 
GitLab CE/EE affecting all ver
 CVE-2026-12490 (When a provide-xfr is given with a tls-auth-name, a secondary 
requesti ...)
        - nsd 4.14.3-1
        [trixie] - nsd <no-dsa> (Minor issue)
+       [bookworm] - nsd <postponed> (Minor issue)
+       [bullseye] - nsd <not-affected> (Vulnerable code introduced later)
        NOTE: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt
 CVE-2026-12246 (NSD version 4.14.0 introduced a bug where a specially crafted 
APL RR,  ...)
        - nsd 4.14.3-1
@@ -12583,6 +12624,8 @@ CVE-2026-54686 (Warp is an agentic development 
environment. From 0.2021.04.25.23
 CVE-2026-54297 (Faraday is an HTTP client library abstraction layer that 
provides a co ...)
        - ruby-faraday 2.14.3-1
        [trixie] - ruby-faraday <no-dsa> (Minor issue)
+       [bookworm] - ruby-faraday <postponed> (Minor issue)
+       [bullseye] - ruby-faraday <postponed> (Minor issue)
        NOTE: 
https://github.com/lostisland/faraday/security/advisories/GHSA-98m9-hrrm-r99r
 CVE-2026-53950 (@tryghost/activitypub is Ghost\u2019s social/federation client 
app. Pr ...)
        NOT-FOR-US: tryghost/activitypub
@@ -14823,6 +14866,8 @@ CVE-2026-55409 (Filament is a collection of full-stack 
components for accelerate
 CVE-2026-54911 (UltraJSON is a fast JSON encoder and decoder written in pure C 
with bi ...)
        - ujson 5.13.0-1 (bug #1140630)
        [trixie] - ujson <no-dsa> (Minor issue)
+       [bookworm] - ujson <postponed> (Minor issue)
+       [bullseye] - ujson <postponed> (Minor issue)
        NOTE: 
https://github.com/ultrajson/ultrajson/security/advisories/GHSA-3j69-69wj-xqx2
        NOTE: 
https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf
 (5.13.0)
 CVE-2026-54651 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.13 ...)
@@ -15590,6 +15635,8 @@ CVE-2026-54604
        [experimental] - openslide 4.0.1+dfsg-1~0exp2
        - openslide <unfixed>
        [trixie] - openslide <ignored> (Minor issue; only an exploitable issue 
with behaviour change of libtiff in 4.7.1)
+       [bookworm] - openslide <ignored> (Minor issue; only exploitable with 
the libtiff 4.7.1 behaviour change)
+       [bullseye] - openslide <ignored> (Minor issue; only exploitable with 
the libtiff 4.7.1 behaviour change)
        NOTE: 
https://github.com/openslide/openslide/security/advisories/GHSA-f734-jv98-5677
 CVE-2026-5366 (Prefect version 3.6.23 is vulnerable to remote code execution 
due to i ...)
        NOT-FOR-US: Prefect
@@ -18317,10 +18364,14 @@ CVE-2026-9307 (A sensitive information disclosure 
security issue exists within t
 CVE-2026-8484 (A heap buffer overflow vulnerability exists in the Jansi JNI 
"ioctl()" ...)
        - jansi <unfixed>
        [trixie] - jansi <no-dsa> (Minor issue)
+       [bookworm] - jansi <postponed> (Minor issue)
+       [bullseye] - jansi <not-affected> (jansi 1.x ships no native code; the 
vulnerable JNI ioctl is in jansi-native)
        - jansi1 <unfixed>
        [trixie] - jansi1 <no-dsa> (Minor issue)
        - jansi-native <unfixed>
        [trixie] - jansi-native <no-dsa> (Minor issue)
+       [bookworm] - jansi-native <postponed> (Minor issue)
+       [bullseye] - jansi-native <postponed> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/06/CVE-2026-8484/
        TODO: double-check source packages, as there is not much details from 
cert.pl post
 CVE-2026-8444 (The WP Review Slider Pro plugin for WordPress is vulnerable to 
SQL Inj ...)
@@ -20445,6 +20496,8 @@ CVE-2026-1836 (The system stores the username and 
password from the login form a
 CVE-2026-12143 (form-data is a library for creating readable 
multipart/form-data strea ...)
        - node-form-data 4.0.6+~2.1.0-1 (bug #1139959)
        [trixie] - node-form-data <no-dsa> (Minor issue)
+       [bookworm] - node-form-data <postponed> (Minor issue)
+       [bullseye] - node-form-data <postponed> (Minor issue)
        NOTE: 
https://github.com/form-data/form-data/security/advisories/GHSA-hmw2-7cc7-3qxx
 CVE-2026-12066 (A security flaw has been discovered in PbootCMS up to 3.2.12. 
This vul ...)
        NOT-FOR-US: PbootCMS
@@ -21181,6 +21234,8 @@ CVE-2026-10733 (GitLab has remediated an issue in 
GitLab CE/EE affecting all ver
 CVE-2026-10142 (kafka-python prior to 2.3.2 contains a denial-of-service 
vulnerability ...)
        - python-kafka 2.0.2-12 (bug #1139878)
        [trixie] - python-kafka <no-dsa> (Minor issue)
+       [bookworm] - python-kafka <postponed> (Minor issue)
+       [bullseye] - python-kafka <postponed> (Minor issue)
        NOTE: https://github.com/dpkp/kafka-python/pull/3019
        NOTE: https://github.com/dpkp/kafka-python/pull/3026
        NOTE: Fixed by: 
https://github.com/dpkp/kafka-python/commit/6e4831444f972d169cdd11f5c8d50333cea3f19b
 (3.0.0)
@@ -21247,6 +21302,8 @@ CVE-2022-48575 (A person with access to a Mac may be 
able to bypass Login Window
 CVE-2026-10143 (kafka-python prior to 2.3.2 contains a denial-of-service 
vulnerability ...)
        - python-kafka 2.0.2-12 (bug #1139822)
        [trixie] - python-kafka <no-dsa> (Minor issue)
+       [bookworm] - python-kafka <postponed> (Minor issue)
+       [bullseye] - python-kafka <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2487722
        NOTE: https://github.com/dpkp/kafka-python/pull/3019
        NOTE: https://github.com/dpkp/kafka-python/pull/3026


=====================================
data/dla-needed.txt
=====================================
@@ -171,13 +171,15 @@ expat
   NOTE: 20260518: Upcoming DSA + many postponed CVE.
   NOTE: 20260518: CVE-2026-41080 fix requires for python's CVE-2026-7210.
 --
-ffmpeg/bullseye
+ffmpeg
   NOTE: 20260710: Added by Front-Desk (utkarsh)
   NOTE: 20260710: CVE-2026-12706: heap UAF in RASC decoder. Fixed in 
bookworm/trixie/sid
   NOTE: 20260710: (DSA-6276-1/DSA-6268-1, upstream n5.1.9/n7.1.4).
   NOTE: 20260710: Backport upstream 0db9de2219a4 (5.1 branch) onto 4.3.9; 
4.3/4.1 branches
   NOTE: 20260710: EOL upstream. Consider batching open CVE-2026-8461 (fixed 
n5.1.10) +
   NOTE: 20260710: postponed minors; watch CVE-2026-58049 (RASC, public PoC, 
unfixed upstream).
+  NOTE: 20260712: CVE-2026-8461 (MagicYUV OOB write, DSA-6361-1, fixed 
n5.1.10) affects
+  NOTE: 20260712: bullseye (4.3.7) and bookworm (5.1.9); bookworm added to 
scope. (utkarsh/front-desk)
 --
 firebird3.0
   NOTE: 20260418: Added by Front-Desk (rouca)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d6f1e3fd6468126429268c77746c2ab520f343c9...c01edb230a4a051605ffccbb81a600d5df306769

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d6f1e3fd6468126429268c77746c2ab520f343c9...c01edb230a4a051605ffccbb81a600d5df306769
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to