Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
dcfa620c by Utkarsh Gupta at 2026-07-22T03:56:14+05:30
lts: rsyslog postponed in bookworm/bullseye (CVE-2026-61548)
- - - - -
e1689d24 by Utkarsh Gupta at 2026-07-22T04:12:14+05:30
lts: hdf5 postponed in bookworm/bullseye (CVE-2026-26199)
- - - - -
ed71dc8d by Utkarsh Gupta at 2026-07-22T04:16:21+05:30
dla-needed: extend python-tornado to bullseye
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -814,6 +814,8 @@ CVE-2026-56452 (Path traversal in the sshd-scp component of
Apache MINA SSHD.Apa
CVE-2026-61548 [rsyslog mmpstrucdata stack overflow]
- rsyslog 8.2606.0-4
[trixie] - rsyslog <no-dsa> (Minor issue; can be fixed in a point
release)
+ [bookworm] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs
module loaded + oversized RFC5424 structured-data)
+ [bullseye] - rsyslog <postponed> (mmpstrucdata module, opt-in; needs
module loaded + oversized RFC5424 structured-data)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/20/1
NOTE:
https://github.com/rsyslog/rsyslog/security/advisories/GHSA-8qmr-c66f-g368
NOTE: Fixed in major cleanup and refactoring of mmpstrucdata:
@@ -1111,6 +1113,8 @@ CVE-2026-26483 (Mettle SendPortal 3.0.1 and earlier
contains a stored cross-site
CVE-2026-26199 (HDF5 is a high-performance library and a file format
specification tha ...)
- hdf5 <unfixed>
[trixie] - hdf5 <no-dsa> (Minor issue)
+ [bookworm] - hdf5 <postponed> (Minor issue; H5G_get_name buffer
underflow only when caller passes size=0 to H5Iget_name)
+ [bullseye] - hdf5 <postponed> (Minor issue; H5G_get_name buffer
underflow only when caller passes size=0 to H5Iget_name)
NOTE:
https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
TODO: isolate fixing commit
CVE-2026-26197 (HDF5 is a high-performance library and a file format
specification tha ...)
=====================================
data/dla-needed.txt
=====================================
@@ -655,9 +655,11 @@ python-msgpack
python-oslo.messaging/bullseye
NOTE: 20260612: Added by Front-Desk (rouca)
--
-python-tornado/bookworm
+python-tornado
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: See also
https://salsa.debian.org/lts-team/lts-updates-tasks/-/work_items/322
(Beuc/front-desk)
+ NOTE: 20260722: Extend to bullseye; CVE-2026-49853/49854/49855 in 6.1.0 too,
+ NOTE: 20260722: shared with bookworm; fix in 6.5.6 (utkarsh/front-desk)
--
qemu
NOTE: 20260520: Added by Front-Desk (Beuc)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4ed36ba85c92dcf239b24ea7978088f20ba6b8f5...ed71dc8d1e276c85073517681853bffe23860a06
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/4ed36ba85c92dcf239b24ea7978088f20ba6b8f5...ed71dc8d1e276c85073517681853bffe23860a06
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits