#1146312 chromium, tiff, cups: 121 unresolved CVEs in Debian Trixie (45 Critical, 76 High)

#1146312#5
Date:
2026-08-31 11:17:01 UTC
From:
To:
Hi Team,

I am reporting 121 unresolved CVEs affecting the chromium, chromium-common, chromium-sandbox, libtiff6, libtiff-dev, libtiffxx6, and libcups2t64 packages on Debian Trixie (Debian 13), identified via a container image security scan (Prisma).

#1146312#14
Date:
2026-09-02 09:58:18 UTC
From:
To:
Hi Team,

I am writing to follow up on the security report submitted regarding 121 unresolved CVEs affecting chromium, tiff, and cups packages in Debian Trixie.
Given the "grave" severity and the large volume of critical and high-severity vulnerabilities-particularly the 44 critical vulnerabilities impacting the current chromium version (151.0.7922.173-1~deb13u1)-our container production pipeline remains significantly exposed.

Could you please provide an update on:

  *   The current status or timeline for backporting Chromium upstream version 152.0.7977.64/.65 (or newer) into the trixie-security repository?
  *   Whether security updates for tiff (targeting CVE-2026-52490) and cups (targeting CVE-2026-34980) are currently being staged or reviewed for the Trixie release?

We appreciate the security team's hard work in maintaining the distribution and thank you in advance for your guidance.

Regards,
Joshua Aldwin L. Samonte
Software Prod & Plat Eng Specialist
Advanced Technology Centers in the Philippines
*: joshua.a.samonte@accenture.com<mailto:joshua.a.samonte@accenture.com>