Debian 11033 Published by

Debian issued security patches for a wide range of packages including Chromium, Thunderbird, Icinga 2, OpenJDK 21, NSS, WordPress, Caddy, libyaml-syck-perl, and libinput to address dozens of new CVEs. The updates mitigate risks ranging from arbitrary code execution and denial of service to privilege escalation and information disclosure, with Chromium resolving 57 vulnerabilities and Thunderbird fixing over 30 flaws across multiple Debian versions. Users should upgrade to the recommended versions immediately, keeping in mind that Icinga 2 and Caddy require manual intervention for specific configuration changes related to logrotate files and header handling. Legacy systems remain protected as well, with extended support advisories releasing fixes for libinput on Debian 9, 10, and 11 to patch local privilege escalation and code execution flaws.

[DLA 4728-1] chromium security update
[DLA 4727-1] thunderbird security update
[DSA 6426-1] icinga2 security update
[DSA 6425-1] openjdk-21 security update
[DLA 4729-1] nss security update
[DSA 6427-1] wordpress security update
[DSA 6429-1] caddy security update
[DLA 4730-1] libyaml-syck-perl security update
[DSA 6428-1] libyaml-syck-perl security update
ELA-1799-1 libinput security update (by )
ELA-1798-1 libinput security update (by )




[SECURITY] [DLA 4728-1] chromium security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4728-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
August 10, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : chromium
Version : 151.0.7922.108-1~deb12u1
CVE ID : CVE-2026-19137 CVE-2026-19138 CVE-2026-19139 CVE-2026-19140
CVE-2026-19141 CVE-2026-19142 CVE-2026-19143 CVE-2026-19144
CVE-2026-19145 CVE-2026-19146 CVE-2026-19147 CVE-2026-19148
CVE-2026-19149 CVE-2026-19150 CVE-2026-19151 CVE-2026-19152
CVE-2026-19153 CVE-2026-19154 CVE-2026-19155 CVE-2026-19156
CVE-2026-19157 CVE-2026-19158 CVE-2026-19159 CVE-2026-19160
CVE-2026-19161 CVE-2026-19162 CVE-2026-19163 CVE-2026-19164
CVE-2026-19165 CVE-2026-19166 CVE-2026-19167 CVE-2026-19168
CVE-2026-19169 CVE-2026-19170 CVE-2026-19171 CVE-2026-19172
CVE-2026-19173 CVE-2026-19174 CVE-2026-19175 CVE-2026-19176
CVE-2026-19177

Security issues were discovered in Chromium which could result
in the execution of arbitrary code, denial of service, or information
disclosure.

For Debian 12 bookworm, these problems have been fixed in version
151.0.7922.108-1~deb12u1.

We recommend that you upgrade your chromium packages.

For the detailed security status of chromium please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/chromium

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DLA 4727-1] thunderbird security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4727-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Emilio Pozuelo Monfort
August 10, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : thunderbird
Version : 1:140.13.0esr-2~deb11u1 1:140.13.0esr-2~deb12u1
CVE ID : CVE-2026-14899 CVE-2026-15718 CVE-2026-15719 CVE-2026-16349
CVE-2026-16350 CVE-2026-16351 CVE-2026-16352 CVE-2026-16353
CVE-2026-16354 CVE-2026-16355 CVE-2026-16356 CVE-2026-16357
CVE-2026-16358 CVE-2026-16359 CVE-2026-16360 CVE-2026-16361
CVE-2026-16362 CVE-2026-16363 CVE-2026-16368 CVE-2026-16369
CVE-2026-16371 CVE-2026-16374 CVE-2026-16375 CVE-2026-16377
CVE-2026-16379 CVE-2026-16381 CVE-2026-16383 CVE-2026-16387
CVE-2026-16390 CVE-2026-16391 CVE-2026-16396 CVE-2026-16405
CVE-2026-16412 CVE-2026-57962 CVE-2026-57963

Multiple security issues were discovered in Thunderbird, which could
result in the execution of arbitrary code.

For Debian 11 bullseye, these problems have been fixed in version
1:140.13.0esr-2~deb11u1.

For Debian 12 bookworm, these problems have been fixed in version
1:140.13.0esr-2~deb12u1.

We recommend that you upgrade your thunderbird packages.

For the detailed security status of thunderbird please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/thunderbird

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DSA 6426-1] icinga2 security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6426-1 security@debian.org
https://www.debian.org/security/ Sebastiaan Couwenberg
August 10, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : icinga2
CVE ID : CVE-2025-61907 CVE-2025-61908 CVE-2025-61909
CVE-2026-61550 CVE-2026-61551 CVE-2026-61552

Multiple vulnerabilities were discovered in Icinga 2, a monitoring and
alerting system, which may result in denial of service, information
disclosure, privilege escalation or the compromise of a monitoring node.

The fix for CVE-2025-61909 changes /etc/logrotate.d/icinga2, which is a
configuration file. If it was modified locally, dpkg will not replace it
and the fix will not take effect. After the upgrade, please make sure the
postrotate section is updated.

For the stable distribution (trixie), these problems have been fixed in
version 2.14.6-1+deb13u1.

We recommend that you upgrade your icinga2 packages.

For the detailed security status of icinga2 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/icinga2

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6425-1] openjdk-21 security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6425-1 security@debian.org
https://www.debian.org/security/ Moritz Muehlenhoff
August 10, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : openjdk-21
CVE ID : CVE-2026-41254 CVE-2026-46917 CVE-2026-46968 CVE-2026-47010
CVE-2026-47021 CVE-2026-47027 CVE-2026-47059 CVE-2026-47063
CVE-2026-60147

Several vulnerabilities have been discovered in the OpenJDK Java runtime,
which may result in incorrect validation of certificates or signed Jar
files, denial of service or information disclosure.

For the stable distribution (trixie), these problems have been fixed in
version 21.0.12+8-1~deb13u1.

We recommend that you upgrade your openjdk-21 packages.

For the detailed security status of openjdk-21 please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/openjdk-21

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4729-1] nss security update


-------------------------------------------------------------------------
Debian LTS Advisory DLA-4729-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Jochen Sprickerhof
August 10, 2026 https://wiki.debian.org/LTS
-------------------------------------------------------------------------

Package : nss
Version : 3.61-1+deb11u7 2:3.87.1-1+deb12u4
CVE ID : CVE-2026-16389

Tomoya Nakanishi discovered a flaw in nss, the Mozilla Network Security
Service library, which may result in execution of arbitrary code if a
specially crafted certificate is processed.

For Debian 11 bullseye, this problem has been fixed in version
3.61-1+deb11u7.

For Debian 12 bookworm, this problem has been fixed in version
2:3.87.1-1+deb12u4.

We recommend that you upgrade your nss packages.

For the detailed security status of nss please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/nss

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS



[SECURITY] [DSA 6427-1] wordpress security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6427-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 10, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : wordpress
CVE ID : CVE-2026-64638
Debian Bug : 1143843

Several vulnerabilities were discovered in wordpress, a web blogging
tool, which could result in cross-site scripting, server-side request
forgery, privilege escalation or remote code execution.

For the stable distribution (trixie), these problems have been fixed in
version 6.8.7+dfsg1-0+deb13u1.

We recommend that you upgrade your wordpress packages.

For the detailed security status of wordpress please refer to its
security tracker page at:
https://security-tracker.debian.org/tracker/wordpress

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DSA 6429-1] caddy security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6429-1 security@debian.org
https://www.debian.org/security/ Aron Xu
August 11, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : caddy
CVE ID : CVE-2026-27585 CVE-2026-27587 CVE-2026-27588 CVE-2026-27589
CVE-2026-27590 CVE-2026-45692 CVE-2026-52845 CVE-2026-52846

Multiple security issues were discovered in Caddy, a web server with
automatic HTTPS, which may result in the bypass of path- or host-based
access controls, the execution of an unintended file by a FastCGI
backend, the injection of identity headers trusted by applications
running behind Caddy, unauthorised reconfiguration of the server through
its admin API, or cross-site scripting.

The fix for CVE-2026-52845 follows upstream in dropping every request
header whose name contains an underscore, for all servers and without an
opt-out. Deployments which pass such headers through Caddy, for instance
X_Api_Key or gRPC custom metadata keys containing underscores, need to
switch to the hyphenated spelling.

For the stable distribution (trixie), these problems have been fixed in
version 2.6.2-12+deb13u1.

We recommend that you upgrade your caddy packages.

For the detailed security status of caddy please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/caddy

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


[SECURITY] [DLA 4730-1] libyaml-syck-perl security update



- -------------------------------------------------------------------------
Debian LTS Advisory DLA-4730-1 debian-lts@lists.debian.org
https://www.debian.org/lts/security/ Salvatore Bonaccorso
August 10, 2026 https://wiki.debian.org/LTS
- -------------------------------------------------------------------------

Package : libyaml-syck-perl
Version : 1.34-1+deb11u2 1.34-2+deb12u3
CVE ID : CVE-2026-5089 CVE-2026-13713 CVE-2026-57075 CVE-2026-57076
CVE-2026-57077
Debian Bug : 1142267

Several vulnerabilities were discovered in libyaml-syck-perl, a Perl
module providing a fast, lightweight YAML loader and dumper, which could
result in denial of service and potentially arbitrary code execution.

For Debian 11 bullseye, these problems have been fixed in version
1.34-1+deb11u2.

For Debian 12 bookworm, these problems have been fixed in version
1.34-2+deb12u3.

We recommend that you upgrade your libyaml-syck-perl packages.

For the detailed security status of libyaml-syck-perl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libyaml-syck-perl

Further information about Debian LTS security advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://wiki.debian.org/LTS

[SECURITY] [DSA 6428-1] libyaml-syck-perl security update



- -------------------------------------------------------------------------
Debian Security Advisory DSA-6428-1 security@debian.org
https://www.debian.org/security/ Salvatore Bonaccorso
August 10, 2026 https://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package : libyaml-syck-perl
CVE ID : CVE-2026-5089 CVE-2026-13713 CVE-2026-57075 CVE-2026-57076
CVE-2026-57077
Debian Bug : 1142267

Several vulnerabilities were discovered in libyaml-syck-perl, a Perl
module providing a fast, lightweight YAML loader and dumper, which could
result in denial of service and potentially arbitrary code execution.

For the stable distribution (trixie), these problems have been fixed in
version 1.34-2+deb13u3.

We recommend that you upgrade your libyaml-syck-perl packages.

For the detailed security status of libyaml-syck-perl please refer to
its security tracker page at:
https://security-tracker.debian.org/tracker/libyaml-syck-perl

Further information about Debian Security Advisories, how to apply
these updates to your system and frequently asked questions can be
found at: https://www.debian.org/security/


ELA-1799-1 libinput security update (by )


Package : libinput

Version : 1.6.3-1+deb9u1 (stretch)

Related CVEs :
CVE-2026-50292

A vulnerability was found in libinput, an input device management
and event handling library.
CVE-2026-50292
A udev helper provided by libinput performed insufficient sanitising of
device properties, which can result in local privilege escalation in
some setups. Reported by Csome.


ELA-1799-1 libinput security update (by )



ELA-1798-1 libinput security update (by )


Package : libinput

Version : 1.12.6-2+deb10u2 (buster)

Related CVEs :
CVE-2022-1215
CVE-2026-50292

Two vulnerabilities were found in libinput, an input device management
and event handling library.
CVE-2022-1215
libinput did not properly handled evdev devices, which may potentially be
exploited by malicious local users in specific setup to execute arbitrary
code. Reported by Albin Eldstål-Ahrens and Lukas Lamster.

CVE-2026-50292
A udev helper provided by libinput performed insufficient sanitising of
device properties, which can result in local privilege escalation in
some setups. Reported by Csome.


ELA-1798-1 libinput security update (by )