Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c399f5a9 by Moritz Muehlenhoff at 2026-06-30T11:44:36+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,6 +3,7 @@ CVE-2026-57964
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493580
CVE-2026-44605
- rpm <unfixed>
+ [trixie] - rpm <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2482481
CVE-2026-13606
- graphicsmagick <unfixed>
@@ -228,6 +229,7 @@ CVE-2026-50229 (Improper Neutralization of Script-Related
HTML Tags in a Web Pag
NOTE:
https://github.com/apache/tomcat/commit/de5a950415fc67713f17fab63d0c7809e0fca80b
(9.0.119)
CVE-2026-13758 (CryptX versions before 0.088_001 for Perl compare AEAD
authentication ...)
- libcryptx-perl 0.089-1
+ [trixie] - libcryptx-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41398101/
NOTE: Fixed by:
https://github.com/DCIT/perl-CryptX/commit/7e56347d420aaf43b2ee1586f4a230492ccf1642
(v0.089)
CVE-2026-13593 (CSS::Minifier::XS versions before 0.14 for Perl have a memory
leak whe ...)
@@ -1489,6 +1491,7 @@ CVE-2026-57231 (Podman is a tool for managing OCI
containers and pods. From 1.8.
NOTE: Fixed by:
https://github.com/podman-container-tools/podman/commit/85832029d537c2c0df89e47d4a03d55ba099a848
(v5.8.4)
CVE-2026-56876 (extract-zip does not validate symlink targets when extracting
zip arch ...)
- node-extract-zip <unfixed>
+ [trixie] - node-extract-zip <no-dsa> (Minor issue)
NOTE:
https://github.com/ziad626/extract-zip-security-research/security/advisories/GHSA-x7jf-2287-qcpf
CVE-2026-56823 (AutoGPT is a workflow automation platform for creating,
deploying, and ...)
NOT-FOR-US: AutoGPT
@@ -2485,6 +2488,7 @@ CVE-2026-11999 (X.509 trust-chain bypass (path-depth
exhaustion) in the OpenSSL
TODO: check
CVE-2026-12844 (List::SomeUtils::XS versions before 0.59 for Perl have a heap
buffer o ...)
- liblist-someutils-xs-perl 0.59-1
+ [trixie] - liblist-someutils-xs-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41398142/
NOTE: Fixed by:
https://github.com/houseabsolute/List-SomeUtils-XS/commit/22549f78669b780d6aa338a2d2e49a3dedfffaa6
(v0.59)
CVE-2026-40211 (An attacker can send crafted DNS over HTTP/3 queries,
triggering an ex ...)
@@ -5777,9 +5781,9 @@ CVE-2025-71337 (Flowise before 3.0.10 (affected versions
3.0.7 and earlier) cont
CVE-2025-62180 (Pega Platform versions 8.3.0 through Infinity 25.1.2 are
affected by a ...)
NOT-FOR-US: Pega Platform
CVE-2025-61029 (An issue in the sqlo_untry component of openlink
virtuoso-opensource v ...)
- - virtuoso-opensource <undetermined>
+ - virtuoso-opensource 7.2.12+dfsg-0.2
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1228
- TODO: check, pinpoint commit, upstream issue say "This issue has been
fixed by recent commits to the develop/7 branch" and might be in v7.2.12
+ NOTE: Fixed by:
https://github.com/openlink/virtuoso-opensource/commit/9df21ea5c2100b90503ee83d828dae6a3d56444a
(v7.2.12)
CVE-2025-61028 (An issue in the time_t_to_dt component of openlink
virtuoso-opensource ...)
- virtuoso-opensource 7.2.12+dfsg-0.2
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1233
@@ -5793,25 +5797,25 @@ CVE-2025-61025 (An issue in the sslr_qst_get component
of openlink virtuoso-open
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1229
NOTE: Fixed by:
https://github.com/openlink/virtuoso-opensource/commit/d1774339a7ff48f924ac6bc486f541851166091b
(v7.2.12)
CVE-2025-61024 (An issue in the sqlo_try_in_loop component of openlink
virtuoso-openso ...)
- - virtuoso-opensource <undetermined>
+ - virtuoso-opensource 7.2.12+dfsg-0.2
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1227
- TODO: check, pinpoint commit, upstream issue say "This issue has been
fixed by recent commits to the develop/7 branch" and might be in v7.2.12
+ NOTE: Fixed by:
https://github.com/openlink/virtuoso-opensource/commit/9df21ea5c2100b90503ee83d828dae6a3d56444a
(v7.2.12)
CVE-2025-61023 (An issue in the st_compare component of openlink
virtuoso-opensource v ...)
- virtuoso-opensource 7.2.12+dfsg-0.2
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1230
NOTE: Fixed by:
https://github.com/openlink/virtuoso-opensource/commit/b27928d04343730b2cb6c23d1c23d52770347940
(v7.2.12)
CVE-2025-61022 (An issue in the sqlo_tb_col_preds component of openlink
virtuoso-opens ...)
- - virtuoso-opensource <undetermined>
+ - virtuoso-opensource 7.2.12+dfsg-0.2
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1226
- TODO: check, pinpoint commit, upstream issue say "This issue has been
fixed by recent commits to the develop/7 branch" and might be in v7.2.12
+ NOTE: Fixed by:
https://github.com/openlink/virtuoso-opensource/commit/9df21ea5c2100b90503ee83d828dae6a3d56444a
(v7.2.12)
CVE-2025-61021 (An issue in the sqlo_natural_join_cond component of openlink
virtuoso- ...)
- virtuoso-opensource 7.2.12+dfsg-0.2
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1223
NOTE: Fixed by:
https://github.com/openlink/virtuoso-opensource/commit/99e0c0a22691a08e69958875b1b30007baa82b8e
(v7.2.12)
CVE-2025-61020 (An issue in the sqlo_strip_in_join component of openlink
virtuoso-open ...)
- - virtuoso-opensource <undetermined>
+ - virtuoso-opensource 7.2.12+dfsg-0.2
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1225
- TODO: check, pinpoint commit, upstream issue say "This issue has been
fixed by recent commits to the develop/7 branch" and might be in v7.2.12
+ NOTE: Fixed by:
https://github.com/openlink/virtuoso-opensource/commit/9df21ea5c2100b90503ee83d828dae6a3d56444a
(v7.2.12)
CVE-2025-61019 (An issue in the sqlo_key_part_best component of openlink
virtuoso-open ...)
- virtuoso-opensource 7.2.12+dfsg-0.2
NOTE: https://github.com/openlink/virtuoso-opensource/issues/1222
@@ -6798,6 +6802,7 @@ CVE-2026-49344 (Mercator is an open source web
application that enables mapping
NOT-FOR-US: Mercator
CVE-2026-49342 (YARD is a documentation generation tool for the Ruby
programming langu ...)
- yard 0.9.44-1
+ [trixie] - yard <no-dsa> (Minor issue)
NOTE:
https://github.com/lsegal/yard/security/advisories/GHSA-pxcc-8665-phx8
NOTE:
https://github.com/lsegal/yard/commit/f78c19f0dd33a407085b4ed181bb60c0aa0078b4
(v0.9.44)
CVE-2026-49340 (gonic is a music streaming server / free-software subsonic
server API ...)
@@ -42370,7 +42375,7 @@ CVE-2026-38991 (Cockpit 2.13.5 and earlier is affected
by a misconfiguration wit
NOT-FOR-US: Cockpit-HQ/Cockpit
CVE-2026-37555 (An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec.
The AIFF ...)
- libsndfile <unfixed> (bug #1135346)
- [trixie] - libsndfile <postponed> (Minor issue, revisit when fixed
upstream)
+ [trixie] - libsndfile <no-dsa> (Minor issue)
[bookworm] - libsndfile <postponed> (Minor issue, revisit when fixed
upstream)
[bullseye] - libsndfile <postponed> (Minor issue; can be fixed in next
update)
NOTE: https://www.openwall.com/lists/oss-security/2026/04/30/7
=====================================
data/dsa-needed.txt
=====================================
@@ -93,6 +93,10 @@ rust-wasmtime
--
shaarli
--
+tomcat10
+--
+tomcat11
+--
util-linux (carnil)
Maintainer is preparing updates
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c399f5a968413d5cc771b1d841f3e2fdef94a928
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c399f5a968413d5cc771b1d841f3e2fdef94a928
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits