ELA-1802-1 bind9 security update (by )
ELA-1801-1 jq security update (by )
ELA-1803-1 ca-certificates CA certificates update (by )
ELA-1802-1 bind9 security update (by )
ELA-1807-1 php7.0 security update (by )
ELA-1806-1 php7.3 security update (by )
ELA-1805-1 libgd2 security update (by )
ELA-1804-1 libconfig-inifiles-perl security update (by )
[DLA 4735-1] neutron security update
[DSA 6434-1] lemonldap-ng security update
[DSA 6432-1] flatpak security update
[DLA 4736-1] python-django security update
[DSA 6435-1] spip security update
ELA-1802-1 bind9 security update (by )
Package : bind9
Version : 1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1~deb9u1 (stretch)
Related CVEs :
CVE-2023-4408
CVE-2025-8677
CVE-2025-40778
CVE-2026-1519
CVE-2026-3039
CVE-2026-3592
CVE-2026-5946
CVE-2026-5950
CVE-2026-10723
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321
bind9 a popular name server was affected by multiple vulnerabilities.
CVE-2023-4408
The DNS message parsing code in `named` includes a section whose computational complexity is overly high.
It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw
CVE-2025-8677
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
CVE-2025-40778
BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
CVE-2026-1519
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU.
CVE-2026-3039
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption
when receiving and processing maliciously-constructed packets.
CVE-2026-3592
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack.
If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources.
CVE-2026-5946
Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (`IN`),
for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section.
CVE-2026-5950
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling,
enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger
specific retry conditions.
CVE-2026-10723
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge
authenticated NXDOMAIN responses.
CVE-2026-11622
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage.
CVE-2026-11721
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone
in which the RRSIG is contained. This causes named to produce a wildcard name for a zone that
is shorter than the attacker's zone, which can result in cache poisoning.
CVE-2026-13204
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG
for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.
CVE-2026-13321
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.
BIND was backported from Buster to address these vulnerabilities, this results in a major version upgrade.
Existing user configurations will likely remain valid thanks to strong forward upstream compatibility.
However, this upgrade breaks binary compatibility, and users of third‑party applications linked against
the BIND9 libraries may need to rebuild those applications.
For this reason, security fixes needed to update and rebuild isc-dhcp, libnss-lwres, milter-greylist and bind-dyndb-ldap packages for stretch.
To ensure strictly increasing versioning and a smooth upgrade path, libnss-lwres and milter‑greylist were also rebuilt for buster.ELA-1802-1 bind9 security update (by )
ELA-1801-1 jq security update (by )
Package : jq
Version : 1.5+dfsg-1.3+deb9u2 (stretch), 1.5+dfsg-2+deb10u2 (buster)
Related CVEs :
CVE-2026-32316
CVE-2026-33947
CVE-2026-33948
CVE-2026-39956
CVE-2026-39979
CVE-2026-40164
CVE-2026-41256
CVE-2026-41257
CVE-2026-43894
CVE-2026-43895
CVE-2026-43896
CVE-2026-47770
CVE-2026-49839
CVE-2026-54679
Multiple security issues were discovered in jq, a command-line JSON
processor, which could result in denial of service or potentially the
execution of arbitrary code when processing untrusted input.
This update additionally addresses two issues for which no CVE has been
assigned: GHSA-ggc9-rpv2-xgpm and GHSA-gvwx-xj9r-3frq.
Two changes in behaviour follow from the fixes above. An operation whose
result would exceed the internal string length limit, such as repeating
or escaping a very large string, now terminates with the error “String
too long” instead of returning a truncated result. A comparison or
containment check on a deeply nested value now reports an error rather
than recursing until the stack is exhausted. Filters relying on the
previous behaviour will report an error where they previously appeared
to succeed.ELA-1801-1 jq security update (by )
ELA-1803-1 ca-certificates CA certificates update (by )
Package : ca-certificates
Version : 20250419~deb12u1~deb11u1~deb10u1 (buster)
ca-certificates a package that contains the certificate authorities
shipped with Mozilla’s browser to allow SSL-based applications to check
for the authenticity of SSL connections, was updated
Mozilla certificate authority bundle was updated to version 2.74
Please note Freexian Debian can neither confirm nor deny whether the
certificate authorities whose certificates are included in this package
have in any way been audited for trustworthiness or RFC 3647 compliance.
Full responsibility to assess them belongs to the local system administrator.ELA-1803-1 ca-certificates CA certificates update (by )
ELA-1802-1 bind9 security update (by )
Package : bind9
Version : 1:9.11.37+git20260722.018aa2e+dfsg-0~deb10u1~deb9u1 (stretch)
Related CVEs :
CVE-2023-4408
CVE-2025-8677
CVE-2025-40778
CVE-2026-1519
CVE-2026-3039
CVE-2026-3592
CVE-2026-5946
CVE-2026-5950
CVE-2026-10723
CVE-2026-11622
CVE-2026-11721
CVE-2026-13204
CVE-2026-13321
bind9 a popular name (DNS) server was affected by multiple vulnerabilities.
CVE-2023-4408
The DNS message parsing code in `named` includes a section whose computational complexity is overly high.
It does not cause problems for typical DNS traffic, but crafted queries and responses may cause excessive CPU load on the affected `named` instance by exploiting this flaw
CVE-2025-8677
Querying for records within a specially crafted zone containing certain malformed DNSKEY records can lead to CPU exhaustion.
CVE-2025-40778
BIND is too lenient when accepting records from answers, allowing an attacker to inject forged data into the cache.
CVE-2026-1519
If a BIND resolver is performing DNSSEC validation and encounters a maliciously crafted zone, the resolver may consume excessive CPU.
CVE-2026-3039
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption
when receiving and processing maliciously-constructed packets.
CVE-2026-3592
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack.
If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resources.
CVE-2026-5946
Multiple flaws have been identified in named related to the handling of DNS messages whose CLASS is not Internet (`IN`),
for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes (`ANY` or `NONE`) in the question section.
CVE-2026-5950
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling,
enabling a remote unauthenticated attacker to cause severe resource exhaustion by sending queries that trigger
specific retry conditions.
CVE-2026-10723
BIND may accept incorrect child-zone NSEC3 records as valid, which could allow an attacker to forge
authenticated NXDOMAIN responses.
CVE-2026-11622
A DNSSEC validating resolver that is under a random subdomain attack against a DNSSEC-signed zone can suffer from runaway memory usage.
CVE-2026-11721
It is possible for an attacker's zone to respond to a query with an RRSIG that has a smaller number of labels than the zone
in which the RRSIG is contained. This causes named to produce a wildcard name for a zone that
is shorter than the attacker's zone, which can result in cache poisoning.
CVE-2026-13204
If a provably insecure domain is covered by both an NSEC and NSEC3 record at the parent, and there exist an RRSIG
for only one of these types, then BIND may exit unexpectedly with an assertion while validating this proof.
CVE-2026-13321
The BIND resolver accepts validly-signed NSEC records where the "Next Domain Name" field points outside the signer's zone.
BIND has been backported from buster to stretch in order to address these vulnerabilities, which entails
a major version upgrade. Existing user configurations are expected to remain valid thanks to strong upstream forward‑compatibility.
However, this upgrade breaks binary compatibility. Third‑party applications linked against the BIND9 libraries may therefore require rebuilding.
To deliver the security fixes, several archive packages needed updates. The packages isc‑dhcp,
libnss‑lwres, milter‑greylist, and bind‑dyndb‑ldap were rebuilt for stretch.
Additionally, to maintain strictly increasing version numbers and ensure a smooth upgrade path,
libnss‑lwres and milter‑greylist were also rebuilt for buster.ELA-1802-1 bind9 security update (by )
ELA-1807-1 php7.0 security update (by )
Package : php7.0
Version : 7.0.33-0+deb9u24 (stretch)
Related CVEs :
CVE-2026-7260
CVE-2026-17543
CVE-2026-7260
Symbolic links in phar archives are followed without any depth limit
or cycle detection. A crafted tar-based phar archive containing
circular symbolic links could therefore cause unbounded recursion,
exhausting the C stack and crashing the PHP process, resulting in
denial of service.
CVE-2026-17543
Improper escaping of backslashes in user-provided parameters allow
for trivial SQL injection via E'…' backslash breakout in the psql
extension.
In addition, this update fixes the following issues which, while
not directly affecting normal Stretch environments, might affect custom
builds.
CVE-2026-9672
Processing of malicious GIF files may lead to crash or arbitrary
code execution.
The package build uses the system libgd so is not directly affected.
A separate libgd2 ELA is available for the
system library.
CVE-2026-14355
Usage of AES-WRAP-PAD may result in denial of service via memory corruption.
Normal Stretch environments are not affected because AES
key-wrap-with-padding operation is not usable with Stretch’s OpenSSL
1.1.0 build.
ELA-1807-1 php7.0 security update (by )
ELA-1806-1 php7.3 security update (by )
Package : php7.3
Version : 7.3.31-1~deb10u14 (buster)
Related CVEs :
CVE-2026-7260
CVE-2026-17543
CVE-2026-7260
Symbolic links in phar archives are followed without any depth limit
or cycle detection. A crafted tar-based phar archive containing
circular symbolic links could therefore cause unbounded recursion,
exhausting the C stack and crashing the PHP process, resulting in
denial of service.
CVE-2026-17543
Improper escaping of backslashes in user-provided parameters allow
for trivial SQL injection via E'…' backslash breakout in the psql
extension.
In addition, this update fixes the following issues which, while
not directly affecting normal Buster environments, might affect custom
builds.
CVE-2026-9672
Processing of malicious GIF files may lead to crash or arbitrary
code execution.
The package build uses the system libgd so is not directly affected.
A separate libgd2 ELA is available for the
system library.
CVE-2026-14355
Usage of AES-WRAP-PAD may result in denial of service via memory corruption.
Normal Buster environments are not affected because AES
key-wrap-with-padding operation is not usable with Buster’s OpenSSL
1.1.1 build.
ELA-1806-1 php7.3 security update (by )
ELA-1805-1 libgd2 security update (by )
Package : libgd2
Version : 2.2.4-2+deb9u7 (stretch), 2.2.5-5.2+deb10u2 (buster)
Related CVEs :
CVE-2026-9672
A vulnerability was discovered in libgd2, a library for programmatic
graphics creation and manipulation, which may result in denial of
service or potentially the execution of arbitrary code if a malformed
GIF file is processed.ELA-1805-1 libgd2 security update (by )
ELA-1804-1 libconfig-inifiles-perl security update (by )
Package : libconfig-inifiles-perl
Version : 2.94-1+deb9u1 (stretch), 3.000001-1+deb10u1 (buster)
Related CVEs :
CVE-2026-11527
A flaw was discovered in libconfig-inifiles-perl, a Perl module to read
.ini-style configuration files, which may result in the execution of
arbitrary shell commands or file overwrite when processing specially
crafted file names.ELA-1804-1 libconfig-inifiles-perl security update (by )
[SECURITY] [DLA 4735-1] neutron security update
-------------------------------------------------------------------------
Debian LTS Advisory DLA-4735-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Santiago Ruano Rinc
August 12, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------
Package : neutron
Version : 2:21.0.0-7+deb12u1
CVE ID : CVE-2026-55707
Debian Bug : 1142937 1143170
Multiple vulnerabilities were discovered in Neutron, the OpenStack virtual
network service. These vulnerabilities were reported by Tim Shephard from
roiai.ca.
CVE-2026-55707
A project member can onboard subnets from another project's shared network into
their own subnetpool, mutating the victim's persistent subnet state and
altering L3 routing, NAT, and address-scope behavior for victim routers. Only
deployments with shared or RBAC-shared networks and the subnetpool onboarding
extension enabled are affected.
Not assigned yet
A project member can read or modify another project's sub-resource by
substituting their own parent resource ID in URL used in APIs. For
conntrack helpers, deletion is also possible. The attack requires
knowing the victim's sub-resource UUID, which is a random UUIDv4 that
cannot be enumerated through the API.
For Debian 12 bookworm, this problem has been fixed in version
2:21.0.0-7+deb12u1.
We recommend that you upgrade your neutron packages.
For the detailed security status of neutron please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/neutron
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
[SECURITY] [DSA 6434-1] lemonldap-ng security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6434-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 12, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : lemonldap-ng
CVE ID : CVE-2026-12804 CVE-2026-19349
It was discovered that the Lemonldap::NG web SSO system insufficiently
enforced access when using the GitHub/Linkedin authentication backends.
For the stable distribution (trixie), these problems have been fixed in
version 2.21.2+ds-1+deb13u3.
We recommend that you upgrade your lemonldap-ng packages.
For the detailed security status of lemonldap-ng please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/lemonldap-ng
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
[SECURITY] [DSA 6432-1] flatpak security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6432-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 12, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : flatpak
CVE ID : not yet available
Multiple security vulnerabilities were discovered in Flatpak, an
application deployment framework for desktop apps, which could result in
local privilege escalation, sandbox escape or information disclosure.
For the stable distribution (trixie), this problem has been fixed in
version 1.16.6-1~deb13u2.
We recommend that you upgrade your flatpak packages.
For the detailed security status of flatpak please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/flatpak
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/
[SECURITY] [DLA 4736-1] python-django security update
- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4736-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Chris Lamb
August 12, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------
Package : python-django
Version : 2:2.2.28-1~deb11u13 3:3.2.25-0+deb12u4
CVE ID : CVE-2026-15337 CVE-2026-15920
Two issues were discovered in Django, the Python-based web
development framework.
CVE-2026-15337
Avoid a potential denial-of-service vulnerability in the
check_for_language() method in the django.utils.translation
module.
This method was subject to a potential denial-of-service (DoS)
attack when checking many distinct, very long language codes. To
mitigate this vulnerability, language codes longer than 500
characters are now rejected before the cached lookup.
CVE-2026-15920
Prevent a potential cross-site scripting (XSS) attack via
bogus URLField values in the Django admin.
The admin renders URLField values as clickable links on
'changelist' views and read-only fields. This link was hitherto
generated without validating the value as a safe URL, so a stored
value using a potentially dangerous scheme was rendered as a
link. URLField values shown via display_for_field are now
validated using the URLValidator class before a link is rendered
and displayed as plain text if validation fails.
For Debian 11 bullseye, these problems have been fixed in version
2:2.2.28-1~deb11u13.
For Debian 12 bookworm, these problems have been fixed in version
3:3.2.25-0+deb12u4.
We recommend that you upgrade your python-django packages.
For the detailed security status of python-django please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/python-django
Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS
[SECURITY] [DSA 6435-1] spip security update
- -------------------------------------------------------------------------
Debian Security Advisory DSA-6435-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 12, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------
Package : spip
CVE ID : CVE-2026-66738
Several vulnerabilities were discovered in SPIP, a website engine for
publishing, which could result in remote code execution, SQL injection
and server-side request forgery.
For the stable distribution (trixie), these problems have been fixed in
version 4.4.19+dfsg-0+deb13u1.
We recommend that you upgrade your spip packages.
For the detailed security status of spip please refer to its security
tracker page at:
https://security-tracker.debian.org/tracker/spip
Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/