Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6ca2d4ca by Moritz Muehlenhoff at 2026-06-26T10:47:36+02:00
NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -142,9 +142,9 @@ CVE-2026-2299 (The Mattermost Google Drive plugin before
version 1.1.0 fails to
CVE-2026-22879 (vtk vtk-dicom vtkDICOMItem::NewDataElement heap-based buffer
overflow ...)
TODO: check
CVE-2026-13322 (A flaw was found in KubeVirt's downward metrics virtio-serial
server. ...)
- TODO: check
+ NOT-FOR-US: KubeVirt
CVE-2026-13318 (A server-side request forgery (SSRF) flaw was found in
KubeVirt's virt ...)
- TODO: check
+ NOT-FOR-US: KubeVirt
CVE-2026-13283 (Use after free in AdFilter in Google Chrome on Android prior
to 149.0. ...)
TODO: check
CVE-2026-13282 (Use after free in Payments in Google Chrome on Android prior
to 149.0. ...)
@@ -154,21 +154,21 @@ CVE-2026-13281 (Integer overflow in Mojo in Google Chrome
prior to 149.0.7827.20
CVE-2026-13226 (The Groundhogg \u2014 CRM, Newsletters, and Marketing
Automation plugi ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13218 (A flaw was found in KubeVirt's virt-handler network cache
handling. Th ...)
- TODO: check
+ NOT-FOR-US: KubeVirt
CVE-2026-13083 (A flaw was found in the Pen Drive report generator.
Cluster-sourced da ...)
- TODO: check
+ NOT-FOR-US: Red Hat Pen Drive
CVE-2026-12993 (A flaw was found in Apicurio Registry. The
DocumentBuilderAccessor cor ...)
- TODO: check
+ NOT-FOR-US: Apicurio Registry
CVE-2026-12992 (A flaw was found in Apicurio Registry. The WSDLReaderAccessor
creates ...)
- TODO: check
+ NOT-FOR-US: Apicurio Registry
CVE-2026-12975 (A flaw was found in Apicurio Registry. The
ContentTypeUtil.isParsableX ...)
- TODO: check
+ NOT-FOR-US: Apicurio Registry
CVE-2026-12473 (Two data sources (DICOMWebProxy and DICOMJSON) shipped in the
default ...)
TODO: check
CVE-2026-12340 (Out-of-bounds heap read during SM2/SM3 certificate signature
verificat ...)
TODO: check
CVE-2026-11800 (A flaw was found in Keycloak. This JWT algorithm confusion
vulnerabili ...)
- TODO: check
+ - keycloak <itp> (bug #1088287)
CVE-2026-11703 (Missing SNI/ALPN binding on stateful (session-ID) resumption,
which pr ...)
TODO: check
CVE-2026-11310 (X.509 trust-chain bypass in the OpenSSL compatibility
certificate veri ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6ca2d4ca06cc5e388d7ff4ba32692087db201c1e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6ca2d4ca06cc5e388d7ff4ba32692087db201c1e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits