Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
be76a6d0 by Moritz Muehlenhoff at 2026-08-19T17:41:35+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -23639,6 +23639,7 @@ CVE-2026-7260 (Circular symbolic links in phar archives
could lead to unbounded
NOTE: Fixed by:
https://github.com/php/php-src/commit/16af1694dd4e0d0e4a24f90740651d3053edffa3
(php-8.4.24)
CVE-2026-71190 (In OpenStack Swift through 2.38.0, the proxy server Accept
header pars ...)
- swift 2.37.1-6 (bug #1142973)
+ [trixie] - swift <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-031.html
NOTE: https://bugs.launchpad.net/swift/+bug/2158771
CVE-2026-71192 (In OpenStack Swift through 2.38.0, the S3API middleware does
not sanit ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -34,7 +34,7 @@ containerd
--
cups
--
-designate
+designate (jmm)
--
dulwich
--
@@ -97,6 +97,10 @@ node-dompurify
--
openexr
--
+openjdk-21 (jmm)
+--
+openjdk-25 (jmm)
+--
pacemaker
--
pdfminer (carnil)
@@ -142,6 +146,8 @@ runc
rust-wasmtime
for CVE-2026-34987 CVE-2026-34971, rest would also be fine to ignore
--
+sabnzbdplus (jmm)
+--
shaarli
--
sogo
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be76a6d0e9f41c8b1b250bbbf3fac6d2aaca2da4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be76a6d0e9f41c8b1b250bbbf3fac6d2aaca2da4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits