Thorsten Alteholz pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
853cce79 by Thorsten Alteholz at 2026-02-05T16:19:07+01:00
mark CVE-2026-24001 as postponed for Bullseye

- - - - -
afa5991a by Thorsten Alteholz at 2026-02-05T16:19:08+01:00
add phpunit

- - - - -
58b766f3 by Thorsten Alteholz at 2026-02-05T16:19:10+01:00
mark CVE-2025-8194 as postponed for Bullseye

- - - - -
a9d8d624 by Thorsten Alteholz at 2026-02-05T16:19:12+01:00
mark CVE-2026-1703 as postponed for Bullseye

- - - - -
d49be00d by Thorsten Alteholz at 2026-02-05T16:19:14+01:00
mark CVE-2026-25541 as not-affected in Bullseye and add NOTE about introduced 
commit

- - - - -


2 changed files:

- data/CVE/list
- data/dla-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -805,9 +805,11 @@ CVE-2026-25541 (Bytes is a utility library for working 
with bytes. From version
        - rust-bytes 1.11.1-1
        [trixie] - rust-bytes <no-dsa> (Minor issue)
        [bookworm] - rust-bytes <no-dsa> (Minor issue)
+       [bullseye] - rust-bytes <not-affected> (Vulnerable code was introduced 
in v1.2.1)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0007.html
        NOTE: https://github.com/advisories/GHSA-434x-w66g-qw3r
        NOTE: Fixed by: 
https://github.com/tokio-rs/bytes/commit/d0293b0e35838123c51ca5dfdf468ecafee4398f
 (v1.11.1)
+       NOTE: Introduced by: 
https://github.com/tokio-rs/bytes/commit/d6e1999d978a688625441348a81504ccab669aed
 (v1.2.1)
 CVE-2026-1801 (A flaw was found in libsoup, an HTTP client/server library. 
This HTTP  ...)
        - libsoup3 3.6.5-8
        [trixie] - libsoup3 <no-dsa> (Minor issue)
@@ -1530,6 +1532,7 @@ CVE-2026-1703 (When pip is installing and extracting a 
maliciously crafted wheel
        - python-pip 26.0+dfsg-1 (bug #1126875)
        [trixie] - python-pip <no-dsa> (Minor issue)
        [bookworm] - python-pip <no-dsa> (Minor issue)
+       [bullseye] - python-pip <postponed> (Minor issue)
        NOTE: https://github.com/pypa/pip/pull/13777
        NOTE: Fixed by: 
https://github.com/pypa/pip/commit/4c651b70d60ed91b13663bcda9b3ed41748d0124 
(26.0)
        NOTE: 
https://mail.python.org/archives/list/[email protected]/thread/WIEA34D4TABF2UNQJAOMXKCICSPBE2DJ/
@@ -4845,6 +4848,7 @@ CVE-2026-24001 (jsdiff is a JavaScript text differencing 
implementation. Prior t
        - node-diff <unfixed> (bug #1126272)
        [trixie] - node-diff <no-dsa> (Minor issue)
        [bookworm] - node-diff <no-dsa> (Minor issue)
+       [bullseye] - node-diff <postponed> (Minor issue)
        NOTE: 
https://github.com/kpdecker/jsdiff/security/advisories/GHSA-73rr-hh4g-fpgx
        NOTE: https://github.com/kpdecker/jsdiff/issues/653
        NOTE: https://github.com/kpdecker/jsdiff/pull/649
@@ -70098,6 +70102,7 @@ CVE-2025-8194 (There is a defect in the CPython 
\u201ctarfile\u201d module affec
        - pypy3 <unfixed> (bug #1126758)
        [trixie] - pypy3 <no-dsa> (Minor issue)
        [bookworm] - pypy3 <no-dsa> (Minor issue)
+       [bullseye] - pypy3 <postponed> (Minor issue)
        NOTE: https://github.com/python/cpython/issues/130577
        NOTE: https://github.com/python/cpython/pull/137027
        NOTE: 
https://mail.python.org/archives/list/[email protected]/thread/ZULLF3IZ726XP5EY7XJ7YIN3K5MDYR2D/


=====================================
data/dla-needed.txt
=====================================
@@ -323,6 +323,9 @@ php-laravel-framework
   NOTE: 20251027: tests is required to prevent regressions, but I could not 
get the upstream
   NOTE: 20251027: test suite to work. It is not exercised as part of Debian 
packages build. (paride)
 --
+phpunit
+  NOTE: 20260205: Added by Front-Desk (ta)
+--
 python-aiohttp (dleidert)
   NOTE: 20260106: Added by Front-Desk (lamby)
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6051fd7faaa16a6277f7173c75d2974b00102187...d49be00d7ed927c177ef77388c70b3f75c84038e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/6051fd7faaa16a6277f7173c75d2974b00102187...d49be00d7ed927c177ef77388c70b3f75c84038e
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to