Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d9332741 by Moritz Muehlenhoff at 2026-08-08T17:23:46+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -476,6 +476,7 @@ CVE-2026-71502 (CTI-Transmute contains a stored cross-site 
scripting vulnerabili
        NOT-FOR-US: CTI-Transmute
 CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. 
Prior t ...)
        - node-re2 1.26.1+~cs1.7.0-1 (bug #1143901)
+       [trixie] - node-re2 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/uhop/node-re2/security/advisories/GHSA-j4r3-hg7j-8chg
        NOTE: https://github.com/uhop/node-re2/issues/272
        NOTE: Fixed by: 
https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4
 (1.26.1)
@@ -524,6 +525,7 @@ CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite 
Checkpoint are the Post
        NOT-FOR-US: LangGraph Checkpoint
 CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js. 
Prior t ...)
        - node-re2 1.26.1+~cs1.7.0-1 (bug #1143901)
+       [trixie] - node-re2 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/uhop/node-re2/security/advisories/GHSA-8hcv-x26h-mcgp
 CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load 
balancer. From 3 ...)
        - traefik <itp> (bug #983289)
@@ -3077,12 +3079,15 @@ CVE-2026-48121 (@langchain/langgraph-checkpoint-mongodb 
provides a LangGraph.js
        NOT-FOR-US: langchain/langgraph-checkpoint-mongodb
 CVE-2026-47781 (PDM is a Python package and dependency manager. In versions up 
to and  ...)
        - pdm 2.27.0-1
+       [trixie] - pdm <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf
 CVE-2026-47764 (pdm is a Python package and dependency manager supporting the 
latest P ...)
        - pdm 2.27.0-1
+       [trixie] - pdm <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pdm-project/pdm/security/advisories/GHSA-78v8-vpjp-cjqh
 CVE-2026-47763 (pdm is a Python package and dependency manager supporting the 
latest P ...)
        - pdm 2.27.0-1
+       [trixie] - pdm <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pdm-project/pdm/security/advisories/GHSA-ghq2-5c67-fprm
 CVE-2026-47623 (NVIDIA Dynamo for Linux contains a vulnerability where an 
attacker cou ...)
        NOT-FOR-US: NVIDIA
@@ -3315,6 +3320,7 @@ CVE-2026-69192 (ip-address is a library for parsing and 
manipulating IPv4 and IP
        NOTE: Fixed by: 
https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e
 (v10.3.1)
 CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication 
for ever ...)
        - node-socket.io-parser <unfixed> (bug #1143598)
+       [trixie] - node-socket.io-parser <no-dsa> (Minor issue)
        [bookworm] - node-socket.io-parser <postponed> (minor issue; DoS)
        [bullseye] - node-socket.io-parser <postponed> (minor issue; DoS)
        NOTE: 
https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
@@ -3596,6 +3602,7 @@ CVE-2026-8793 (PaperCut NG/MF does not properly restrict 
excessive authenticatio
        NOT-FOR-US: PaperCut
 CVE-2026-69153 (PostCSS takes a CSS file and provides an API to analyze and 
modify its ...)
        - node-postcss 8.5.23+~cs10.2.23-1
+       [trixie] - node-postcss <no-dsa> (Minor issue)
        NOTE: 
https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
        NOTE: Fixed by: 
https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8
 (8.5.23)
 CVE-2026-69152 (The brace-expansion library generates arbitrary strings 
containing a c ...)
@@ -3612,6 +3619,7 @@ CVE-2026-69149 (Angular is a development platform for 
building mobile and deskto
        - angular.js <unfixed>
 CVE-2026-69097 (GitPython before 3.1.53 fails to properly escape section names 
in git  ...)
        - python-git <unfixed> (bug #1143602)
+       [trixie] - python-git <no-dsa> (Minor issue)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2
 CVE-2026-69096 (OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 
snapshots co ...)
        NOT-FOR-US: OpenWrt luci-app-dockerman
@@ -4932,6 +4940,7 @@ CVE-2026-18358 (A flaw was found in gnome-remote-desktop 
as shipped in Red Hat E
        TODO: does not affect an upstream version, but need to check if still 
only Red Hat specific, check details RH bug
 CVE-2026-18321 (Buffer overflow in NTPsec's Zyfer refclock allows local 
attacker to cr ...)
        - ntpsec <unfixed>
+       [trixie] - ntpsec <no-dsa> (Minor issue)
        [bookworm] - ntpsec <postponed> (minor issue; DoS)
        [bullseye] - ntpsec <postponed> (minor issue; DoS)
        NOTE: https://gitlab.com/NTPsec/ntpsec/-/work_items/890
@@ -8631,6 +8640,7 @@ CVE-2026-16462 (In PROCON-WEB SCADA the endpoint 
'GetGridData' is not properly s
        NOT-FOR-US: PROCON-WEB SCADA
 CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when 
invoked with t ...)
        - sg3-utils <unfixed> (bug #1143004)
+       [trixie] - sg3-utils <no-dsa> (Minor issue)
        [bookworm] - sg3-utils <postponed> (Minor issue)
        [bullseye] - sg3-utils <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502845
@@ -20636,6 +20646,7 @@ CVE-2026-9585 (An unauthenticated reflected cross-site 
scripting (XSS) vulnerabi
        NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9537 (Mojo::JWT versions before 1.02 for Perl verify HMAC signatures 
with a  ...)
        - libmojo-jwt-perl 1.02-1
+       [trixie] - libmojo-jwt-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41907805/
        NOTE: Fixed by: 
https://github.com/jberger/Mojo-JWT/commit/b8aefb846613e44b5b12bc170898ffd5b05094a2
 (1.02)
 CVE-2026-9202 (IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated 
attackers ...)
@@ -26171,6 +26182,7 @@ CVE-2026-15104 (The BetterDocs \u2013 AI Documentation, 
Knowledge Base, Docs, Wi
        NOT-FOR-US: WordPress plugin
 CVE-2026-15028 (A flaw was found in libarchive. This vulnerability allows a 
remote att ...)
        - libarchive 3.8.9-1 (bug #1142833)
+       [trixie] - libarchive <no-dsa> (Minor issue)
        NOTE: https://github.com/libarchive/libarchive/issues/3251
        NOTE: https://github.com/libarchive/libarchive/pull/3253
        NOTE: Fixed by: 
https://github.com/libarchive/libarchive/commit/f93abd161ec37326c566f4f0efcd44fe7a66dd95
@@ -27065,6 +27077,7 @@ CVE-2026-55470 (HAPI FHIR is a complete implementation 
of the HL7 FHIR standard
        NOT-FOR-US: HAPI FHIR
 CVE-2026-55404 (yt-dlp and youtube-dl are command-line audio/video 
downloaders. Prior  ...)
        - yt-dlp 2026.07.04-1
+       [trixie] - yt-dlp <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32
        NOTE: Fixed by: 
https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789
 (2026.07.04)
 CVE-2026-55206 (py7zr is a Python-based library and utility to support 7zip 
archive co ...)
@@ -27818,14 +27831,17 @@ CVE-2026-3144 (IBM API Connect 12.1.0.0 through 
12.1.0.3 uses default credential
        NOT-FOR-US: IBM
 CVE-2026-29009 (U-Boot before 2026.07-rc2 contains a buffer overflow 
vulnerability in  ...)
        - u-boot <unfixed> (bug #1142070)
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
        NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
 CVE-2026-29008 (U-Boot through 2026.04-rc3 contains an integer underflow 
vulnerability ...)
        - u-boot <unfixed> (bug #1142070)
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
        NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
 CVE-2026-29007 (U-Boot through 2026.04-rc3 contains an out-of-bounds read 
vulnerabilit ...)
        - u-boot <unfixed> (bug #1142070)
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
        NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
 CVE-2026-24700 (An OS command injection vulnerability exists in the 
start_lltd() funct ...)
@@ -63109,13 +63125,14 @@ CVE-2026-39531 (Improper Neutralization of Special 
Elements used in an SQL Comma
 CVE-2026-39461 (libcasper(3) communicates with helper processes via UNIX 
domain socket ...)
        NOT-FOR-US: FreeBSD
 CVE-2026-36189 (Buffer Overflow vulnerability in Uncrustify Project Affected 
v.Uncrust ...)
-       - uncrustify <unfixed> (bug #1142851)
+       - uncrustify <unfixed> (bug #1142851; unimportant)
        NOTE: https://github.com/uncrustify/uncrustify/issues/4636
        NOTE: https://github.com/uncrustify/uncrustify/pull/4641
        NOTE: https://github.com/uncrustify/uncrustify/pull/4650
        NOTE: tokenizer related code moved to subfolder in:
        NOTE: 
https://github.com/uncrustify/uncrustify/commit/35f4eb550fd0cb419d0d48575c51b1d19def18fa
 (uncrustify-0.79.0)
        NOTE: Fixed by: 
https://github.com/uncrustify/uncrustify/commit/04e7614fd25d283508d6d68d85006d9b420c0f1a
 (uncrustify-0.83.0)
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-34930 (An origin validation vulnerability in the Apex One/SEP agent 
could all ...)
        NOT-FOR-US: Trend Micro
 CVE-2026-34929 (An origin validation vulnerability in the Apex One/SEP agent 
could all ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -85,9 +85,9 @@ node-dompurify
 --
 openexr
 --
-openjdk-17
+openjdk-21 (jmm)
 --
-openjdk-21
+openjdk-25 (jmm)
 --
 pacemaker
 --
@@ -135,12 +135,16 @@ rust-wasmtime
 --
 shaarli
 --
+srt
+--
 starlette
 --
 tomcat10
 --
 tomcat11
 --
+unbound
+--
 util-linux (carnil)
   Maintainer is preparing updates
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9332741d0696bebfc1256dbdf55f5f26289bbee

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9332741d0696bebfc1256dbdf55f5f26289bbee
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to