Hi Team,

I am writing to follow up on the security report submitted regarding 121 
unresolved CVEs affecting chromium, tiff, and cups packages in Debian Trixie.
Given the "grave" severity and the large volume of critical and high-severity 
vulnerabilities-particularly the 44 critical vulnerabilities impacting the 
current chromium version (151.0.7922.173-1~deb13u1)-our container production 
pipeline remains significantly exposed.

Could you please provide an update on:

  *   The current status or timeline for backporting Chromium upstream version 
152.0.7977.64/.65 (or newer) into the trixie-security repository?
  *   Whether security updates for tiff (targeting CVE-2026-52490) and cups 
(targeting CVE-2026-34980) are currently being staged or reviewed for the 
Trixie release?

We appreciate the security team's hard work in maintaining the distribution and 
thank you in advance for your guidance.

Regards,
Joshua Aldwin L. Samonte
Software Prod & Plat Eng Specialist
Advanced Technology Centers in the Philippines
*: [email protected]<mailto:[email protected]>

From: Samonte, Joshua
Sent: Monday, August 31, 2026 7:17 PM
To: '[email protected]' <[email protected]>; 
'[email protected]' <[email protected]>; 
'[email protected]' <[email protected]>; 
'[email protected]' <[email protected]>
Cc: Prabhu V, Divya <[email protected]>; Gaurao Jain, Sonal 
<[email protected]>; Cajita, Jian Jaico 
<[email protected]>; Chandrasekharan, Abhilash 
<[email protected]>; Prasad, Ayush <[email protected]>
Subject: chromium, tiff, cups: 121 unresolved CVEs in Debian Trixie (45 
Critical, 76 High)

Package: chromium, tiff, cups
Version: chromium 151.0.7922.173-1~deb13u1 / tiff 4.7.0-3+deb13u3 / cups 
2.4.10-3+deb13u2
Severity: grave
Tags: security

Hi Team,

I am reporting 121 unresolved CVEs affecting the chromium, chromium-common, 
chromium-sandbox, libtiff6, libtiff-dev, libtiffxx6, and libcups2t64 packages 
on Debian Trixie (Debian 13), identified via a container image security scan 
(Prisma).

-- CVE Details --

Critical (chromium 151.0.7922.173-1~deb13u1):
- CVE-2026-79152
- CVE-2026-79090
- CVE-2026-79290
- CVE-2026-79282
- CVE-2026-79275
- CVE-2026-79257
- CVE-2026-79235
- CVE-2026-79232
- CVE-2026-79200
- CVE-2026-79189
- CVE-2026-79188
- CVE-2026-79150
- CVE-2026-79149
- CVE-2026-79140
- CVE-2026-79138
- CVE-2026-79131
- CVE-2026-79130
- CVE-2026-79129
- CVE-2026-79128
- CVE-2026-79111
- CVE-2026-79091
- CVE-2026-79078
- CVE-2026-79064
- CVE-2026-79056
- CVE-2026-79052
- CVE-2026-79047
- CVE-2026-79043
- CVE-2026-79026
- CVE-2026-79019
- CVE-2026-79012
- CVE-2026-78989
- CVE-2026-78985
- CVE-2026-78964
- CVE-2026-78951
- CVE-2026-78948
- CVE-2026-78945
- CVE-2026-78939
- CVE-2026-78937
- CVE-2026-78935
- CVE-2026-78909
- CVE-2026-78904
- CVE-2026-78900
- CVE-2026-79148
- CVE-2026-79058

Critical (tiff 4.7.0-3+deb13u3):
- CVE-2026-52490

High (chromium 151.0.7922.173-1~deb13u1):
- CVE-2026-79266
- CVE-2026-79244
- CVE-2026-79240
- CVE-2026-79236
- CVE-2026-79231
- CVE-2026-79230
- CVE-2026-79227
- CVE-2026-79226
- CVE-2026-79223
- CVE-2026-79219
- CVE-2026-79215
- CVE-2026-79209
- CVE-2026-79202
- CVE-2026-79198
- CVE-2026-79197
- CVE-2026-79195
- CVE-2026-79187
- CVE-2026-79183
- CVE-2026-79182
- CVE-2026-79142
- CVE-2026-79127
- CVE-2026-79119
- CVE-2026-79097
- CVE-2026-79073
- CVE-2026-79069
- CVE-2026-79048
- CVE-2026-79045
- CVE-2026-79033
- CVE-2026-78990
- CVE-2026-78978
- CVE-2026-78963
- CVE-2026-78956
- CVE-2026-78950
- CVE-2026-78944
- CVE-2026-78938
- CVE-2026-78910
- CVE-2026-78905
- CVE-2026-78899
- CVE-2026-78891
- CVE-2026-79292
- CVE-2026-79256
- CVE-2026-79247
- CVE-2026-79224
- CVE-2026-79218
- CVE-2026-79210
- CVE-2026-79175
- CVE-2026-79155
- CVE-2026-79132
- CVE-2026-79121
- CVE-2026-79109
- CVE-2026-79071
- CVE-2026-79054
- CVE-2026-79008
- CVE-2026-78999
- CVE-2026-78983
- CVE-2026-78952
- CVE-2026-78934
- CVE-2026-78911
- CVE-2026-79263
- CVE-2026-79194
- CVE-2026-79072
- CVE-2026-79057
- CVE-2026-79039
- CVE-2026-79027
- CVE-2026-79020
- CVE-2026-78913
- CVE-2026-79245
- CVE-2026-79216
- CVE-2026-79139
- CVE-2026-79083
- CVE-2026-78915
- CVE-2026-78906
- CVE-2026-78901
- CVE-2026-79286
- CVE-2026-78892

High (cups 2.4.10-3+deb13u2):
- CVE-2026-34980

Base Image: debian:trixie
Affected Packages: chromium, chromium-common, chromium-sandbox, libtiff6, 
libtiff-dev, libtiffxx6, libcups2t64
Installation Method: apt-get install chromium (pulls in 
libtiff6/libtiff-dev/libtiffxx6 via libgdk-pixbuf-2.0-dev, and libcups2t64 via 
libgtk-3-0t64)
Scan Tool: Prisma (container image layer scan)

Notes:
- All chromium CVEs above are fixed upstream in Google Chrome 
152.0.7977.64/.65, but Debian's trixie and trixie-security repositories are 
still on 151.0.7922.173-1~deb13u1.
- CVE-2026-52490 (tiff): the vulnerable code (tiffcrop.c, 
process_command_opts()) ships in libtiff-tools, which we have already removed. 
libtiff6/libtiff-dev/libtiffxx6 remain flagged by source-package version 
despite not containing the vulnerable tool. Fixed upstream (v4.7.2rc2) and in 
Debian unstable (4.7.2-1), but trixie/trixie-security are still on 
4.7.0-3+deb13u3.
- CVE-2026-34980 (cups): we have already removed the cupsd daemon package, 
which this CVE requires to be network-exposed to be exploitable. libcups2t64 
(client library) cannot be removed without cascading into removal of chromium 
itself. Fixed upstream (cups v2.4.17), but trixie/trixie-security are still on 
2.4.10-3+deb13u2.

Please advise on the availability of patched versions of the above packages in 
Debian Trixie's apt repository, and the expected timeline for patch inclusion 
if not yet available.

Regards,
Joshua Aldwin L. Samonte
Software Prod & Plat Eng Specialist
Advanced Technology Centers in the Philippines
*: [email protected]<mailto:[email protected]>


________________________________

This message is for the designated recipient only and may contain privileged, 
proprietary, or otherwise confidential information. If you have received it in 
error, please notify the sender immediately and delete the original. Any other 
use of the e-mail by you is prohibited. Where allowed by local law, electronic 
communications with Accenture and its affiliates, including e-mail and instant 
messaging (including content), may be scanned by our systems for the purposes 
of information security, AI-powered support capabilities, and assessment of 
internal compliance with Accenture policy. Your privacy is important to us. 
Accenture uses your personal data only in compliance with data protection laws. 
For further information on how Accenture processes your personal data, please 
see our privacy statement at https://www.accenture.com/us-en/privacy-policy.
______________________________________________________________________________________

www.accenture.com

Reply via email to