Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
ba5eacaa by Salvatore Bonaccorso at 2026-07-23T16:03:48+02:00
Process some NFUs

- - - - -
8bed17f3 by Salvatore Bonaccorso at 2026-07-23T16:04:09+02:00
Add new librest issue

- - - - -
620b387d by Salvatore Bonaccorso at 2026-07-23T16:04:22+02:00
Add new 389-ds-base issue

- - - - -
c38ad973 by Salvatore Bonaccorso at 2026-07-23T16:04:36+02:00
Add new systemd issue

- - - - -
66fd116a by Salvatore Bonaccorso at 2026-07-23T16:04:48+02:00
Add sbc issue, CVE-2026-16473

- - - - -
b07001e2 by Salvatore Bonaccorso at 2026-07-23T16:05:03+02:00
Add new duplicati issue, itp'ed

- - - - -
9a5ef793 by Salvatore Bonaccorso at 2026-07-23T16:05:16+02:00
Add new libarchive issue

- - - - -
a03cb112 by Salvatore Bonaccorso at 2026-07-23T16:05:30+02:00
Add new libsoup issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -72,25 +72,25 @@ CVE-2026-60366 (Vulnerability in the Oracle Platform 
Security for Java product o
 CVE-2026-59676 (A Time-of-check Time-of-use (TOCTOU) Race Condition 
vulnerability in s ...)
        TODO: check
 CVE-2026-38766 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
-       TODO: check
+       NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
 CVE-2026-38765 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
-       TODO: check
+       NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
 CVE-2026-38763 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 
allows a l ...)
-       TODO: check
+       NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
 CVE-2026-21723 (The alertmanager templates test endpoint 
(/api/alertmanager/grafana/co ...)
        NOT-FOR-US: Grafana Labs
 CVE-2026-16653 (A security flaw has been discovered in boazsegev facil.io up 
to 0.7.58 ...)
-       TODO: check
+       NOT-FOR-US: boazsegev facil.io
 CVE-2026-16632 (A flaw has been found in boazsegev facil.io up to 0.7.4. 
Affected is t ...)
-       TODO: check
+       NOT-FOR-US: boazsegev facil.io
 CVE-2026-16631 (A vulnerability was detected in publint up to 0.1.4. This 
impacts the  ...)
-       TODO: check
+       NOT-FOR-US: publint
 CVE-2026-16630 (A security vulnerability has been detected in syncfusion 
ej2-javascrip ...)
-       TODO: check
+       NOT-FOR-US: syncfusion ej2-javascript-ui-controls
 CVE-2026-16629 (A vulnerability was identified in danger danger-js up to 
13.0.7. Impac ...)
-       TODO: check
+       NOT-FOR-US: danger danger-js
 CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected 
by this  ...)
-       TODO: check
+       NOT-FOR-US: oclif
 CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to 
reject dot ...)
        TODO: check
 CVE-2026-14899 (The code to parse MIME headers for display when forwarding a 
message ( ...)
@@ -100,7 +100,7 @@ CVE-2026-14881 (When importing connections in Compass it is 
possible to override
 CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does 
not veri ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token 
signature v ...)
-       TODO: check
+       NOT-FOR-US: OIDC::Lite Perl module
 CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the 
server-side ...)
        TODO: check
 CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element 
accessors allows ...)
@@ -304,35 +304,40 @@ CVE-2026-40712 (Dell PowerProtect Data Manager, versions 
prior to 20.2.0.0, cont
 CVE-2026-3482 (IBM Sterling B2B Integrator and IBM Sterling File 
Gateway6.2.0.0 throu ...)
        NOT-FOR-US: IBM
 CVE-2026-2406 (Authorization bypass through User-Controlled key vulnerability 
in Univ ...)
-       TODO: check
+       NOT-FOR-US: Online Registration and Workflow Management System
 CVE-2026-2395 (Improper neutralization of special elements used in an SQL 
command ('S ...)
-       TODO: check
+       NOT-FOR-US: No Code Platform
 CVE-2026-22049 (ONTAP versions 9.16.1 and higher with WebAuthn multi-factor 
authentica ...)
        NOT-FOR-US: NetApp
 CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId 
creation, allo ...)
-       TODO: check
+       NOT-FOR-US: Cal.com OSS
 CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth 
authori ...)
-       TODO: check
+       - librest <unfixed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2504432
+       NOTE: https://gitlab.gnome.org/GNOME/librest/-/issues/25
 CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu 
Software O ...)
-       TODO: check
+       NOT-FOR-US: Fujitsu
 CVE-2026-16606 (A vulnerability in Fujitsu Software Linux openFT andFujitsu 
Software O ...)
-       TODO: check
+       NOT-FOR-US: Fujitsu
 CVE-2026-16560 (A heap-buffer-overflow flaw was found in Directory Server 
(389-ds-base ...)
-       TODO: check
+       - 389-ds-base <unfixed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506102
 CVE-2026-16552 (A flaw was found in systemd-tmpfiles. When processing a 
tmpfiles.d con ...)
-       TODO: check
+       - systemd <unfixed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506073
 CVE-2026-16551 (Denial-of-Service in Thinkst Applied Research OpenCanary 
(MongoDB modu ...)
-       TODO: check
+       NOT-FOR-US: Thinkst Applied Research OpenCanary (MongoDB module)
 CVE-2026-16544 (A flaw was found in AWX. The websocket event consumer performs 
RBAC au ...)
-       TODO: check
+       NOT-FOR-US: Ansible Tower
 CVE-2026-16473 (A flaw was found in the sbc library (BlueZ SBC codec). An 
off-by-one e ...)
-       TODO: check
+       - sbc <unfixed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2503650
 CVE-2026-16270 (Open Mercato does not validate regex rules. An attacker with 
privilege ...)
-       TODO: check
+       NOT-FOR-US: Open Mercato
 CVE-2026-16232 (An authentication bypass vulnerability in the Check Point 
SmartConsole ...)
-       TODO: check
+       NOT-FOR-US: Check Point
 CVE-2026-16157 (Duplicati v2.3.0.1 backup software gives Authenticated Users 
MODIFY pe ...)
-       TODO: check
+       - duplicati <itp> (bug #969188)
 CVE-2026-15787 (The Ultimate Addons for Elementor plugin for WordPress is 
vulnerable t ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14985 (The Analog Way Picturall Quad Compact Mark II version 3.5.8, 
contains  ...)
@@ -2904,31 +2909,35 @@ CVE-2026-42397 (Allocation of Resources Without Limits 
or Throttling (CWE-770) i
 CVE-2026-3821 (Supermicro (SMC) SMASH services contain an Arbitrary code 
execution is ...)
        NOT-FOR-US: Supermicro
 CVE-2026-35290 (Vulnerability in Oracle Application Testing Suite.   The 
supported ver ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-35287 (Vulnerability in Oracle Application Testing Suite.   The 
supported ver ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-34316 (Vulnerability in the Oracle Commerce Service Center product of 
Oracle  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-30633 (Directory traversal vulnerability in knowns-dev/knowns 0.11.4 
via craf ...)
-       TODO: check
+       NOT-FOR-US: knowns-dev/knowns
 CVE-2026-30632 (Directory traversal vulnerability in knowns-dev/knowns 0.11.4 
via craf ...)
-       TODO: check
+       NOT-FOR-US: knowns-dev/knowns
 CVE-2026-30631 (An issue was discovered in bytebot-ai in commit 
3d37894ce07ef8d8b40adc ...)
-       TODO: check
+       NOT-FOR-US: bytebot-ai
 CVE-2026-21954 (Vulnerability in the Oracle Retail Xstore Point of Service 
product of  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-21953 (Vulnerability in the Oracle Retail Xstore Point of Service 
product of  ...)
-       TODO: check
+       NOT-FOR-US: Oracle
 CVE-2026-16517 (A signed integer overflow vulnerability was found in 
libarchive's ZIP  ...)
-       TODO: check
+       - libarchive <unfixed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2505492
+       NOTE: https://github.com/libarchive/libarchive/issues/3225
+       NOTE: https://github.com/libarchive/libarchive/pull/3228
+       NOTE: Fixed by: 
https://github.com/libarchive/libarchive/commit/1c6e7b491f60fce335c20a9692f870d1f1ca39aa
 CVE-2026-16492 (A weakness has been identified in umijs umi up to 4.6.63. The 
affected ...)
-       TODO: check
+       NOT-FOR-US: umijs umi
 CVE-2026-16490 (A security flaw has been discovered in itsourcecode Hospital 
Managemen ...)
        NOT-FOR-US: itsourcecode System
 CVE-2026-16489 (A vulnerability was identified in jsforce up to 3.10.16. This 
issue af ...)
-       TODO: check
+       NOT-FOR-US: jsforce
 CVE-2026-16488 (A vulnerability was determined in QUSETIONS MiniCode-Python 
0.1.0. Thi ...)
-       TODO: check
+       NOT-FOR-US: QUSETIONS MiniCode-Python
 CVE-2026-16486 (A vulnerability was found in SourceCodester Class and Exam 
Timetabling ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-16485 (A vulnerability has been found in SourceCodester Class and 
Exam Timeta ...)
@@ -10810,15 +10819,30 @@ CVE-2026-15720 (InOpen5GS through version 2.7.7 a 
pre-authenticationheap out-of-
 CVE-2026-15715 (A vulnerability was identified in SourceCodester Class and 
Exam Timeta ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-15714 (An out-of-bounds read vulnerability was found in libsoup's 
multipart p ...)
-       TODO: check
+       - libsoup3 <unfixed>
+       - libsoup2.4 <removed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499942
+       NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/542
 CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol 
implementation. ...)
-       TODO: check
+       - libsoup3 <unfixed>
+       - libsoup2.4 <removed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499941
+       NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/541
 CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in 
libsoup's (ver ...)
-       TODO: check
+       - libsoup3 <unfixed>
+       - libsoup2.4 <removed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499939
+       NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540
 CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing 
impleme ...)
-       TODO: check
+       - libsoup3 <unfixed>
+       - libsoup2.4 <removed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499924
+       NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/515
 CVE-2026-15709 (A flaw was found in libsoup's WebSocket implementation when 
using the  ...)
-       TODO: check
+       - libsoup3 <unfixed>
+       - libsoup2.4 <removed>
+       NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499922
+       NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/511
 CVE-2026-15703 (A vulnerability was detected in SourceCodester Simple and Nice 
Shoppin ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-15702 (A security vulnerability has been detected in tamagui up to 
2.3.0. Thi ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ed7793a9745ce2ccfbf939d33f2c1d5eca7bfd5f...a03cb112b7789afadfa97e1dc924cf577de5e781

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ed7793a9745ce2ccfbf939d33f2c1d5eca7bfd5f...a03cb112b7789afadfa97e1dc924cf577de5e781
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to