Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
81c3d2f0 by Utkarsh Gupta at 2026-07-13T06:55:35+05:30
lts: graphicsmagick postponed in bullseye/bookworm
(CVE-2026-13606)
- - - - -
4ad63756 by Utkarsh Gupta at 2026-07-13T06:55:42+05:30
lts: libmojolicious-perl postponed in bullseye/bookworm
(CVE-2026-14803)
- - - - -
6da707aa by Utkarsh Gupta at 2026-07-13T06:55:49+05:30
lts: httpcomponents-core not-affected/postponed in bullseye/bookworm
(CVE-2026-54399, CVE-2026-54428)
- - - - -
dba29f4d by Utkarsh Gupta at 2026-07-13T06:55:58+05:30
lts: node-ajv not-affected in bullseye/bookworm (CVE-2026-13676)
- - - - -
bb610d84 by Utkarsh Gupta at 2026-07-13T06:55:58+05:30
lts: node-form-data postponed in bullseye/bookworm (CVE-2026-12143)
- - - - -
12793a90 by Utkarsh Gupta at 2026-07-13T06:55:58+05:30
lts: node-brace-expansion postponed in bullseye/bookworm
(CVE-2026-13149)
- - - - -
78b7a304 by Utkarsh Gupta at 2026-07-13T06:56:04+05:30
lts: nut postponed in bullseye/bookworm (CVE-2026-54161)
- - - - -
d13bac9f by Utkarsh Gupta at 2026-07-13T06:56:04+05:30
lts: openslide ignored in bullseye/bookworm (CVE-2026-54604)
- - - - -
2efb1600 by Utkarsh Gupta at 2026-07-13T06:56:05+05:30
lts: gpsd postponed in bullseye/bookworm (CVE-2026-58459)
- - - - -
2f00100e by Utkarsh Gupta at 2026-07-13T06:56:05+05:30
lts: jansi not-affected/postponed in bullseye/bookworm
(CVE-2026-8484)
- - - - -
1ba112f4 by Utkarsh Gupta at 2026-07-13T06:56:11+05:30
lts: jansi-native postponed in bullseye/bookworm (CVE-2026-8484)
- - - - -
2bb000d6 by Utkarsh Gupta at 2026-07-13T06:56:12+05:30
lts: nsd not-affected/postponed in bullseye/bookworm (CVE-2026-12490)
- - - - -
2fb33ac9 by Utkarsh Gupta at 2026-07-13T06:56:12+05:30
lts: pipewire not-affected/postponed in bullseye/bookworm
(CVE-2026-14324)
- - - - -
ea7f8b14 by Utkarsh Gupta at 2026-07-13T06:56:17+05:30
lts: python-kafka postponed in bullseye/bookworm
(CVE-2026-10142, CVE-2026-10143)
- - - - -
d840e11b by Utkarsh Gupta at 2026-07-13T06:56:22+05:30
lts: ruby-faraday postponed in bullseye/bookworm (CVE-2026-54297)
- - - - -
e7b59426 by Utkarsh Gupta at 2026-07-13T06:56:23+05:30
lts: ruby-json not-affected in bullseye/bookworm (CVE-2026-54696)
- - - - -
0d83135f by Utkarsh Gupta at 2026-07-13T06:56:23+05:30
lts: ruby-nokogiri not-affected/postponed in bullseye/bookworm (8 CVEs)
- - - - -
5e33ba7b by Utkarsh Gupta at 2026-07-13T06:56:23+05:30
lts: ujson postponed in bullseye/bookworm (CVE-2026-54911)
- - - - -
f49f5ae3 by Utkarsh Gupta at 2026-07-13T06:56:23+05:30
lts: etcd not-affected in bullseye/bookworm (CVE-2026-59818)
- - - - -
fb9b4465 by Utkarsh Gupta at 2026-07-13T07:17:39+05:30
lts: php-horde-vfs postponed in bullseye (CVE-2026-60102)
- - - - -
c01edb23 by Utkarsh Gupta at 2026-07-13T07:17:39+05:30
dla-needed: extend ffmpeg to bookworm (CVE-2026-8461)
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1312,6 +1312,8 @@ CVE-2026-59148 (Mockoon provides way to design and run
mock APIs. Prior to 9.7.0
NOT-FOR-US: Mockoon
CVE-2026-58459 (gpsd through release-3.27.5, fixed at commit 4c06658, contains
a comma ...)
- gpsd <unfixed> (bug #1141962)
+ [bookworm] - gpsd <postponed> (Minor issue; command injection confined
to the gpsprof diagnostic client via device-controlled subtype, local +
user-interaction)
+ [bullseye] - gpsd <postponed> (Minor issue; command injection confined
to the gpsprof diagnostic client via device-controlled subtype, local +
user-interaction)
NOTE: https://gitlab.com/gpsd/gpsd/-/work_items/404#note_3534119267
NOTE:
https://github.com/ntpsec/gpsd/commit/5581ba196d826a984fbfaf792b7d58535f9911ce
NOTE:
https://github.com/ntpsec/gpsd/commit/1a6bb7bcbdf58aa940132e630870af061dc88537
@@ -1641,6 +1643,8 @@ CVE-2026-59819 (LiteLLM is a proxy server (AI Gateway) to
call LLM APIs in OpenA
NOT-FOR-US: LiteLLM
CVE-2026-59818 (etcd is a distributed key-value store for the data of a
distributed sy ...)
- etcd <unfixed> (bug #1141963)
+ [bookworm] - etcd <not-affected> (Split HTTP/gRPC listener onlyGRPC CRL
path introduced in 3.5.0; absent in 3.4.x)
+ [bullseye] - etcd <not-affected> (Split HTTP/gRPC listener onlyGRPC CRL
path introduced in 3.5.0; absent in 3.3.x)
NOTE:
https://github.com/etcd-io/etcd/security/advisories/GHSA-3wh4-j44w-pg92
NOTE: https://github.com/etcd-io/etcd/pull/22007
NOTE: https://github.com/etcd-io/etcd/pull/22021
@@ -2027,6 +2031,7 @@ CVE-2026-60124 (An authorization bypass in MISP\u2019s
EventsController::importM
CVE-2026-60102 (Horde Virtual File System (VFS) API before 3.0.1 contains an
OS comman ...)
- php-horde-vfs <unfixed>
[bookworm] - php-horde-vfs <end-of-life> (EOL in bookworm LTS)
+ [bullseye] - php-horde-vfs <postponed> (Minor issue; requires
authentication and the non-default Horde_Vfs_Smb/smbclient backend)
NOTE: https://github.com/horde/Vfs/pull/10
NOTE:
https://github.com/horde/Vfs/commit/41f74b4acfc144e09013d04dd121e0a5da808361
(v3.0.1)
CVE-2026-60092 (AVideo (Meet plugin) through commit
e8d6119f3cb1b849149906efeb0a41fc02 ...)
@@ -3709,6 +3714,8 @@ CVE-2026-59511 (Insertion of Sensitive Information Into
Sent Data vulnerability
CVE-2026-14803 (Mojo::JSON versions before 9.47 for Perl allow memory
exhaustion via u ...)
- libmojolicious-perl 9.47+dfsg-1 (bug #1141586)
[trixie] - libmojolicious-perl <no-dsa> (Minor issue)
+ [bookworm] - libmojolicious-perl <postponed> (Minor issue)
+ [bullseye] - libmojolicious-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41564627/
NOTE: Fixed by:
https://github.com/mojolicious/mojo/commit/cc38b0554275c4d84f6b8b49bcbbc1bec2068fe1
(v9.47)
CVE-2026-14799 (A security flaw has been discovered in CodeAstro Ecommerce
Website 1.0 ...)
@@ -4104,6 +4111,8 @@ CVE-2026-49297 (Apache Airflow's Google provider
operators `GCSToSFTPOperator` a
CVE-2026-54161
- nut <unfixed>
[trixie] - nut <no-dsa> (Minor issue)
+ [bookworm] - nut <postponed> (Minor issue)
+ [bullseye] - nut <postponed> (Minor issue)
NOTE:
https://github.com/networkupstools/nut/security/advisories/GHSA-mjgp-j4gm-6qg5
NOTE: Fixed by: https://github.com/networkupstools/nut/pull/3499
CVE-2026-58597 (Insufficient ui warning of dangerous operations in Microsoft
Edge (Chr ...)
@@ -5695,6 +5704,8 @@ CVE-2026-54428 (Allocation of resources without limits or
throttling in the HTTP
[trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
- httpcomponents-core <unfixed>
[trixie] - httpcomponents-core <no-dsa> (Minor issue)
+ [bookworm] - httpcomponents-core <not-affected> (HTTP/2 HPACK not
implemented in httpcomponents-core 4.x (v5-only feature))
+ [bullseye] - httpcomponents-core <not-affected> (HTTP/2 HPACK not
implemented in httpcomponents-core 4.x (v5-only feature))
NOTE: https://www.openwall.com/lists/oss-security/2026/07/01/3
NOTE: v4 possibly not affected, needs further validation once fix is
identified
CVE-2026-54399 (Uncontrolled Resource Consumption vulnerability in the
HTTP/1.1 messag ...)
@@ -5702,6 +5713,8 @@ CVE-2026-54399 (Uncontrolled Resource Consumption
vulnerability in the HTTP/1.1
[trixie] - httpcomponents-core5 <no-dsa> (Minor issue)
- httpcomponents-core <unfixed>
[trixie] - httpcomponents-core <no-dsa> (Minor issue)
+ [bookworm] - httpcomponents-core <postponed> (Minor issue)
+ [bullseye] - httpcomponents-core <postponed> (Minor issue)
NOTE: https://lists.apache.org/thread/zmxh1pl2zohov5ntdh4lt85gfrlchgpy
NOTE: v4 possibly not affected, needs further validation once fix is
identified
CVE-2026-53909 (MCO does not correctly validate types of uploaded files. File
upload v ...)
@@ -5876,6 +5889,8 @@ CVE-2026-14330 (Multiple unbounded alloca() calls in the
PulseAudio protocol ser
CVE-2026-14324 (RAOP module accepts unbounded Content-Length values and does
not check ...)
- pipewire 1.6.8-1 (bug #1141308)
[trixie] - pipewire <no-dsa> (Minor issue)
+ [bookworm] - pipewire <postponed> (Minor issue)
+ [bullseye] - pipewire <not-affected> (RAOP module not present in 0.3.19)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2495903
NOTE: https://gitlab.freedesktop.org/pipewire/pipewire/-/work_items/5352
NOTE: Fixed by:
https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/87ee525b0124755ccab99d873ddf85d9d4969f73
(master)
@@ -6331,6 +6346,8 @@ CVE-2026-54896 (Oj (Optimized JSON) is a JSON parser and
Object marshaller packa
CVE-2026-54696 (Ruby JSON is a JSON implementation for Ruby. Versions 2.9.0
through 2. ...)
- ruby-json 2.19.9+dfsg-1
[trixie] - ruby-json <no-dsa> (Minor issue)
+ [bookworm] - ruby-json <not-affected> (Vulnerable code introduced in
2.9.0)
+ [bullseye] - ruby-json <not-affected> (Vulnerable code introduced in
2.9.0)
NOTE:
https://github.com/ruby/json/security/advisories/GHSA-x2f5-4prf-w687
NOTE: Fixed by:
https://github.com/ruby/json/commit/fd6a65bd08e5f3a429c03919ebfd8dd19158f095
(v2.19.9)
CVE-2026-54673 (electron-updater allows for automatic updates for Electron
apps. Prior ...)
@@ -8389,6 +8406,8 @@ CVE-2026-13316 (A flaw has been found in foreman when
HTTP parameters are modifi
CVE-2026-13149 (brace-expansion through 5.0.6 is vulnerable to denial of
service. The ...)
- node-brace-expansion <unfixed> (bug #1141325)
[trixie] - node-brace-expansion <no-dsa> (Minor issue)
+ [bookworm] - node-brace-expansion <postponed> (Minor issue)
+ [bullseye] - node-brace-expansion <postponed> (Minor issue)
NOTE:
https://github.com/juliangruber/brace-expansion/commit/c7e33ec13ac1a684c116720843ce24e208611754
CVE-2026-12610 (A flaw was found in sssd. When authenticating with a YubiKey,
the SSSD ...)
- sssd <unfixed> (bug #1141323)
@@ -8518,6 +8537,8 @@ CVE-2026-44605
CVE-2026-13606
- graphicsmagick <unfixed> (bug #1141493)
[trixie] - graphicsmagick <no-dsa> (Minor issue)
+ [bookworm] - graphicsmagick <postponed> (Minor issue)
+ [bullseye] - graphicsmagick <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2494107
CVE-2026-9576 (The Fluent Booking WordPress plugin before 2.1.2 does not
verify owne ...)
NOT-FOR-US: WordPress plugin
@@ -8943,6 +8964,8 @@ CVE-2026-13742 (Honeywell IQ MultiAccess, all versions
prior to and including ve
CVE-2026-13676 (fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to
canonicalize U ...)
- node-ajv <unfixed>
[trixie] - node-ajv <no-dsa> (Minor issue)
+ [bookworm] - node-ajv <not-affected> (fast-uri not embedded; ajv <8
uses uri-js)
+ [bullseye] - node-ajv <not-affected> (fast-uri not embedded; ajv <8
uses uri-js)
NOTE:
https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6
NOTE: Embedded fast-uri used and provided as node-fast-uri, starting
with forky
CVE-2026-13595 (A flaw was found in the libblkid library of util-linux. During
nested ...)
@@ -10787,36 +10810,52 @@ CVE-2026-57451 (Vim is an open source, command line
text editor. Prior to 9.2.06
CVE-2026-57438 (Nokogiri is an open source XML and HTML library for the Ruby
programmi ...)
- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+ [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+ [bullseye] - ruby-nokogiri <postponed> (Minor issue)
NOTE:
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wfpw-mmfh-qq69
CVE-2026-57437 (Nokogiri is an open source XML and HTML library for the Ruby
programmi ...)
- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+ [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+ [bullseye] - ruby-nokogiri <postponed> (Minor issue)
NOTE:
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-p67v-3w7g-wjg7
CVE-2026-57436 (Nokogiri is an open source XML and HTML library for the Ruby
programmi ...)
- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+ [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+ [bullseye] - ruby-nokogiri <postponed> (Minor issue)
NOTE:
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wjv4-x9w8-wm3h
CVE-2026-57435 (Nokogiri is an open source XML and HTML library for the Ruby
programmi ...)
- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+ [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+ [bullseye] - ruby-nokogiri <postponed> (Minor issue)
NOTE:
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-phwj-rprq-35pp
CVE-2026-57434 (Nokogiri is an open source XML and HTML library for the Ruby
programmi ...)
- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+ [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+ [bullseye] - ruby-nokogiri <postponed> (Minor issue)
NOTE:
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-9cv2-cfxc-v4v2
CVE-2026-57429 (Contributor Broken Access Control in Slim SEO <= 4.6.2
versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57236 (Nokogiri is an open source XML and HTML library for the Ruby
programmi ...)
- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+ [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+ [bullseye] - ruby-nokogiri <postponed> (Minor issue)
NOTE:
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5v8h-3h3q-446p
CVE-2026-57235 (Nokogiri is an open source XML and HTML library for the Ruby
programmi ...)
- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+ [bookworm] - ruby-nokogiri <postponed> (Minor issue)
+ [bullseye] - ruby-nokogiri <postponed> (Minor issue)
NOTE:
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5prr-v3j2-97mh
CVE-2026-57234 (Nokogiri is an open source XML and HTML library for the Ruby
programmi ...)
- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
+ [bookworm] - ruby-nokogiri <not-affected> (JRuby-only; Debian
builds/uses the CRuby implementation)
+ [bullseye] - ruby-nokogiri <not-affected> (JRuby-only; Debian
builds/uses the CRuby implementation)
NOTE:
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-8678-w3jw-xfc2
CVE-2026-56790 (CANBoat through 6.22, fixed in commit a5a22b7, contains an
off-by-one ...)
- canboat <itp> (bug #921311)
@@ -12369,6 +12408,8 @@ CVE-2026-12635 (GitLab has remediated an issue in
GitLab CE/EE affecting all ver
CVE-2026-12490 (When a provide-xfr is given with a tls-auth-name, a secondary
requesti ...)
- nsd 4.14.3-1
[trixie] - nsd <no-dsa> (Minor issue)
+ [bookworm] - nsd <postponed> (Minor issue)
+ [bullseye] - nsd <not-affected> (Vulnerable code introduced later)
NOTE: https://www.nlnetlabs.nl/downloads/nsd/CVE-2026-12490.txt
CVE-2026-12246 (NSD version 4.14.0 introduced a bug where a specially crafted
APL RR, ...)
- nsd 4.14.3-1
@@ -12583,6 +12624,8 @@ CVE-2026-54686 (Warp is an agentic development
environment. From 0.2021.04.25.23
CVE-2026-54297 (Faraday is an HTTP client library abstraction layer that
provides a co ...)
- ruby-faraday 2.14.3-1
[trixie] - ruby-faraday <no-dsa> (Minor issue)
+ [bookworm] - ruby-faraday <postponed> (Minor issue)
+ [bullseye] - ruby-faraday <postponed> (Minor issue)
NOTE:
https://github.com/lostisland/faraday/security/advisories/GHSA-98m9-hrrm-r99r
CVE-2026-53950 (@tryghost/activitypub is Ghost\u2019s social/federation client
app. Pr ...)
NOT-FOR-US: tryghost/activitypub
@@ -14823,6 +14866,8 @@ CVE-2026-55409 (Filament is a collection of full-stack
components for accelerate
CVE-2026-54911 (UltraJSON is a fast JSON encoder and decoder written in pure C
with bi ...)
- ujson 5.13.0-1 (bug #1140630)
[trixie] - ujson <no-dsa> (Minor issue)
+ [bookworm] - ujson <postponed> (Minor issue)
+ [bullseye] - ujson <postponed> (Minor issue)
NOTE:
https://github.com/ultrajson/ultrajson/security/advisories/GHSA-3j69-69wj-xqx2
NOTE:
https://github.com/ultrajson/ultrajson/commit/169eaf36b1116fece5034ee79a7a0ef3f6deedcf
(5.13.0)
CVE-2026-54651 (pypdf is a free and open-source pure-python PDF library. Prior
to 6.13 ...)
@@ -15590,6 +15635,8 @@ CVE-2026-54604
[experimental] - openslide 4.0.1+dfsg-1~0exp2
- openslide <unfixed>
[trixie] - openslide <ignored> (Minor issue; only an exploitable issue
with behaviour change of libtiff in 4.7.1)
+ [bookworm] - openslide <ignored> (Minor issue; only exploitable with
the libtiff 4.7.1 behaviour change)
+ [bullseye] - openslide <ignored> (Minor issue; only exploitable with
the libtiff 4.7.1 behaviour change)
NOTE:
https://github.com/openslide/openslide/security/advisories/GHSA-f734-jv98-5677
CVE-2026-5366 (Prefect version 3.6.23 is vulnerable to remote code execution
due to i ...)
NOT-FOR-US: Prefect
@@ -18317,10 +18364,14 @@ CVE-2026-9307 (A sensitive information disclosure
security issue exists within t
CVE-2026-8484 (A heap buffer overflow vulnerability exists in the Jansi JNI
"ioctl()" ...)
- jansi <unfixed>
[trixie] - jansi <no-dsa> (Minor issue)
+ [bookworm] - jansi <postponed> (Minor issue)
+ [bullseye] - jansi <not-affected> (jansi 1.x ships no native code; the
vulnerable JNI ioctl is in jansi-native)
- jansi1 <unfixed>
[trixie] - jansi1 <no-dsa> (Minor issue)
- jansi-native <unfixed>
[trixie] - jansi-native <no-dsa> (Minor issue)
+ [bookworm] - jansi-native <postponed> (Minor issue)
+ [bullseye] - jansi-native <postponed> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/06/CVE-2026-8484/
TODO: double-check source packages, as there is not much details from
cert.pl post
CVE-2026-8444 (The WP Review Slider Pro plugin for WordPress is vulnerable to
SQL Inj ...)
@@ -20445,6 +20496,8 @@ CVE-2026-1836 (The system stores the username and
password from the login form a
CVE-2026-12143 (form-data is a library for creating readable
multipart/form-data strea ...)
- node-form-data 4.0.6+~2.1.0-1 (bug #1139959)
[trixie] - node-form-data <no-dsa> (Minor issue)
+ [bookworm] - node-form-data <postponed> (Minor issue)
+ [bullseye] - node-form-data <postponed> (Minor issue)
NOTE:
https://github.com/form-data/form-data/security/advisories/GHSA-hmw2-7cc7-3qxx
CVE-2026-12066 (A security flaw has been discovered in PbootCMS up to 3.2.12.
This vul ...)
NOT-FOR-US: PbootCMS
@@ -21181,6 +21234,8 @@ CVE-2026-10733 (GitLab has remediated an issue in
GitLab CE/EE affecting all ver
CVE-2026-10142 (kafka-python prior to 2.3.2 contains a denial-of-service
vulnerability ...)
- python-kafka 2.0.2-12 (bug #1139878)
[trixie] - python-kafka <no-dsa> (Minor issue)
+ [bookworm] - python-kafka <postponed> (Minor issue)
+ [bullseye] - python-kafka <postponed> (Minor issue)
NOTE: https://github.com/dpkp/kafka-python/pull/3019
NOTE: https://github.com/dpkp/kafka-python/pull/3026
NOTE: Fixed by:
https://github.com/dpkp/kafka-python/commit/6e4831444f972d169cdd11f5c8d50333cea3f19b
(3.0.0)
@@ -21247,6 +21302,8 @@ CVE-2022-48575 (A person with access to a Mac may be
able to bypass Login Window
CVE-2026-10143 (kafka-python prior to 2.3.2 contains a denial-of-service
vulnerability ...)
- python-kafka 2.0.2-12 (bug #1139822)
[trixie] - python-kafka <no-dsa> (Minor issue)
+ [bookworm] - python-kafka <postponed> (Minor issue)
+ [bullseye] - python-kafka <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2487722
NOTE: https://github.com/dpkp/kafka-python/pull/3019
NOTE: https://github.com/dpkp/kafka-python/pull/3026
=====================================
data/dla-needed.txt
=====================================
@@ -171,13 +171,15 @@ expat
NOTE: 20260518: Upcoming DSA + many postponed CVE.
NOTE: 20260518: CVE-2026-41080 fix requires for python's CVE-2026-7210.
--
-ffmpeg/bullseye
+ffmpeg
NOTE: 20260710: Added by Front-Desk (utkarsh)
NOTE: 20260710: CVE-2026-12706: heap UAF in RASC decoder. Fixed in
bookworm/trixie/sid
NOTE: 20260710: (DSA-6276-1/DSA-6268-1, upstream n5.1.9/n7.1.4).
NOTE: 20260710: Backport upstream 0db9de2219a4 (5.1 branch) onto 4.3.9;
4.3/4.1 branches
NOTE: 20260710: EOL upstream. Consider batching open CVE-2026-8461 (fixed
n5.1.10) +
NOTE: 20260710: postponed minors; watch CVE-2026-58049 (RASC, public PoC,
unfixed upstream).
+ NOTE: 20260712: CVE-2026-8461 (MagicYUV OOB write, DSA-6361-1, fixed
n5.1.10) affects
+ NOTE: 20260712: bullseye (4.3.7) and bookworm (5.1.9); bookworm added to
scope. (utkarsh/front-desk)
--
firebird3.0
NOTE: 20260418: Added by Front-Desk (rouca)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d6f1e3fd6468126429268c77746c2ab520f343c9...c01edb230a4a051605ffccbb81a600d5df306769
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d6f1e3fd6468126429268c77746c2ab520f343c9...c01edb230a4a051605ffccbb81a600d5df306769
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits