Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9eff77de by Moritz Muehlenhoff at 2026-08-08T23:42:59+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -9577,6 +9577,7 @@ CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) in 
the email module in Rosk
 CVE-2026-58662 (Improper Validation of Specified Quantity in Input, 
Out-of-bounds Read ...)
        [experimental] - thrift 0.24.0-1
        - thrift <unfixed>
+       [trixie] - thrift <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/13mzvylr3r3nktxrh5k1h30ng1t1sw1d
 CVE-2026-58389 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
        [experimental] - thrift 0.24.0-1
@@ -9594,6 +9595,7 @@ CVE-2026-58227 (The Erlang/OTP ssl application does not 
detect cycles when recon
 CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib 
bindings.  Th ...)
        [experimental] - thrift 0.24.0-1
        - thrift <unfixed>
+       [trixie] - thrift <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/z2myopbovxngfvchdz8hddots9p5ffbt
 CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary 
crafted ...)
        NOT-FOR-US: proCertum SmartSign
@@ -9606,6 +9608,7 @@ CVE-2026-56537 (HCL Connections is vulnerable to 
information disclosure which co
 CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++ 
bindings ...)
        [experimental] - thrift 0.24.0-1
        - thrift <unfixed>
+       [trixie] - thrift <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/xjs36m6kjxpmrmzwck636msg3nvoqnmx
 CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings.  
This is ...)
        [experimental] - thrift 0.24.0-1
@@ -9615,6 +9618,7 @@ CVE-2026-55970 (Buffer Over-read vulnerability in Apache 
Thrift C++ bindings.  T
 CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift 
C++, c_g ...)
        [experimental] - thrift 0.24.0-1
        - thrift <unfixed>
+       [trixie] - thrift <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo
 CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources 
Without Li ...)
        [experimental] - thrift 0.24.0-1
@@ -9693,6 +9697,7 @@ CVE-2026-48145 (Improper Validation of Certificate with 
Host Mismatch vulnerabil
 CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch 
vulnerability in ...)
        [experimental] - thrift 0.24.0-1
        - thrift <unfixed>
+       [trixie] - thrift <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/2xoltfxgzf5jyhcwq6y07spts5cn6ppj
 CVE-2026-48052 (Papra is a minimalistic document management and archiving 
platform. Pr ...)
        NOT-FOR-US: Papra
@@ -9709,6 +9714,7 @@ CVE-2026-47078 (Relative Path Traversal vulnerability in 
Erlang OTP (stdlib zip
        NOTE: Fixed by: 
https://github.com/erlang/otp/commit/8a933c9c7835b06776d31d17b79b7336627d887a 
(OTP-29.0.4, OTP-28.5.0.4, OTP-27.3.4.15)
 CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and 
modify its ...)
        - node-postcss 8.5.12+~cs9.3.32-1
+       [trixie] - node-postcss <no-dsa> (Minor issue)
        NOTE: 
https://github.com/postcss/postcss/security/advisories/GHSA-6g55-p6wh-862q
        NOTE: 
https://github.com/postcss/postcss/commit/aaec7b78b3ce2792585b4b300ef1bd5dd5b3e8ad
 (8.5.12)
        NOTE: 
https://github.com/postcss/postcss/commit/c64b7488d2731dfa16213739b42c34faf5a9eba3
 (8.5.12)
@@ -9952,6 +9958,7 @@ CVE-2026-47701
        NOT-FOR-US: OpenTelemetry Operator
 CVE-2026-16566
        - ansible <unfixed>
+       [trixie] - ansible <no-dsa> (Minor issue)
        [bookworm] - ansible <not-affected> (Vulnerable code not present)
        [bullseye] - ansible <not-affected> (Vulnerable code not present)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506113
@@ -11641,10 +11648,12 @@ CVE-2026-66038 (FFmpeg through 8.1.2, fixed in commit 
8670835, contains an infor
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c
 CVE-2026-66037 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an 
uncontrolle ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5
 CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap 
out-of- ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c
 CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized 
attacker ...)
@@ -12124,7 +12133,10 @@ CVE-2026-16743 (A flaw was found in accountsservice. 
The systemd-homed code path
        NOTE: 
https://gitlab.freedesktop.org/accountsservice/accountsservice/-/merge_requests/182
 (26.26.9)
 CVE-2026-16730 (A flaw was found in dbus-broker. When the process 
file-descriptor limi ...)
        - dbus-broker <unfixed> (bug #1142850)
+       [trixie] - dbus-broker <no-dsa> (Minor issue)
        NOTE: https://github.com/bus1/dbus-broker/issues/435
+       NOTE: 
https://github.com/bus1/dbus-broker/commit/c4a3c886366f7bd566ec9a55b3855ade8290fa17
+       NOTE: 
https://github.com/bus1/dbus-broker/commit/aaa9fd6bbc2d5d7bfeca039f9c457b7f88a50dde
 CVE-2026-16519 (A DLL hijacking vulnerability exists in the GeoVision GV-IP 
Device Uti ...)
        NOT-FOR-US: GeoVision
 CVE-2026-15821 (The SureDash \u2013 Community, Courses & Member Dashboard 
plugin for W ...)
@@ -12189,18 +12201,22 @@ CVE-2026-66138 (In OpenStack Ironic Python Agent 
through 11.6.0, aproject-scoped
        NOTE: https://bugs.launchpad.net/ironic-python-agent/+bug/2160050
 CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds 
write vulne ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527
 CVE-2026-65705 (FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds 
write vulne ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c
 CVE-2026-65704 (FFmpeg through 8.1.2 contains an out-of-bounds write 
vulnerability tha ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7
 CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds 
write vulne ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773
        NOTE: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
 CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal 
vulnerability  ...)
@@ -13452,6 +13468,7 @@ CVE-2026-16544 (A flaw was found in AWX. The websocket 
event consumer performs R
        NOT-FOR-US: Ansible Tower
 CVE-2026-16473 (A flaw was found in the sbc library (BlueZ SBC codec). An 
off-by-one e ...)
        - sbc <unfixed> (bug #1142848)
+       [trixie] - sbc <no-dsa> (Minor issue)
        [bookworm] - sbc <postponed> (Minor issue)
        [bullseye] - sbc <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2503650
@@ -16545,6 +16562,7 @@ CVE-2026-1372 (The Tutor LMS Elementor Addons plugin 
for WordPress is vulnerable
        NOT-FOR-US: WordPress plugin
 CVE-2026-16493 (A flaw was found in ansible-core. The 
_extract_collection_from_git() f ...)
        - ansible-core <unfixed>
+       [trixie] - ansible-core <no-dsa> (Minor issue)
        - ansible 5.4.0-1
        [bullseye] - ansible <postponed> (Needs only work when CVE-2026-11332 
is fixed as well)
        NOTE: ansible-core was split off from src:ansible with 4.6.0-1 in 
experimental/5.4.0-1 in sid
@@ -17693,6 +17711,7 @@ CVE-2026-64187 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: 
https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4)
 CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure 
session ids  ...)
        - libdancer2-perl <unfixed> (bug #1142718)
+       [trixie] - libdancer2-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41975698/
 CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy 
Terms Word ...)
        NOT-FOR-US: WordPress plugin
@@ -21952,10 +21971,11 @@ CVE-2026-62389
 CVE-2026-62378 (RustFS Console is a web management console for the RustFS 
distributed  ...)
        NOT-FOR-US: RustFS
 CVE-2026-62294 (Flameshot is powerful yet simple to use screenshot software. 
Prior to  ...)
-       - flameshot 14.0.0-1
+       - flameshot 14.0.0-1 (unimportant)
        NOTE: 
https://github.com/flameshot-org/flameshot/security/advisories/GHSA-fqqf-4rj8-c392
        NOTE: https://github.com/flameshot-org/flameshot/pull/4716
        NOTE: Fixed by: 
https://github.com/flameshot-org/flameshot/commit/936716b8d8b7052be461c3d5e2f88492b6eb3b96
 (v14.0.0)
+       NOTE: Neutralised by kernel tmp hardening
 CVE-2026-62287
        REJECTED
 CVE-2026-62248
@@ -22375,6 +22395,7 @@ CVE-2026-15804 (The HCM developed by MetaGuru has a SQL 
Injection vulnerability.
        NOT-FOR-US: MetaGuru
 CVE-2026-15779 (A flaw was found in samba's pam_winbind. When mkhomedir is 
enabled, pa ...)
        - samba <unfixed>
+       [trixie] - samba <no-dsa> (Minor issue)
        [bookworm] - samba <postponed> (Minor issue; pam_winbind mkhomedir 
chowns a pre-existing home dir, and mkhomedir is not enabled by default in 
Debian; can be fixed in next update)
        [bullseye] - samba <postponed> (Minor issue; pam_winbind mkhomedir 
chowns a pre-existing home dir, and mkhomedir is not enabled by default in 
Debian; can be fixed in next update)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499991
@@ -24738,10 +24759,12 @@ CVE-2025-15665 (The Ultimate Before After Image 
Slider & Gallery  WordPress plug
        NOT-FOR-US: WordPress plugin
 CVE-2026-58102 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a 
heap out-o ...)
        - libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
+       [trixie] - libcrypt-openssl-x509-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792355/
        NOTE: Fixed by: 
https://github.com/dsully/perl-crypt-openssl-x509/commit/757289bfce095455c104d4adfe9312e7b339620f
 (2.1.3)
 CVE-2026-58101 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow 
denial of se ...)
        - libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
+       [trixie] - libcrypt-openssl-x509-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792358/
        NOTE: Fixed by: 
https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2
 (2.1.3)
 CVE-2026-63090 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based 
buffer overf ...)
@@ -26270,6 +26293,7 @@ CVE-2026-15373 (A vulnerability was detected in Eleveo 
Call Recording Software 9
        NOT-FOR-US: Eleveo Call Recording Software
 CVE-2026-15146 (GNU Wget does not validate the IP address provided by an FTP 
PASV resp ...)
        - wget 1.25.0-3 (bug #1142284)
+       [trixie] - wget <no-dsa> (Minor issue)
        [bookworm] - wget <postponed> (Minor issue)
        [bullseye] - wget <postponed> (Minor issue)
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b
@@ -26472,6 +26496,7 @@ CVE-2026-39243 (decompress before 4.2.2 allows 
arbitrary hardlink creation durin
        NOT-FOR-US: Node decompress module
 CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function 
of Arti ...)
        - jbig2dec <unfixed> (bug #1142282)
+       [trixie] - jbig2dec <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b
 CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended 
Endpoints ...)
        NOT-FOR-US: Juniper



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9eff77de9ac4997c483051d676d749cf88897f7b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9eff77de9ac4997c483051d676d749cf88897f7b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to