Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6d4052dd by Moritz Muehlenhoff at 2026-08-10T14:22:40+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,6 +9,7 @@ CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read
and resultant in
NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
CVE-2026-19389 (Multiple integer overflow and underflow vulnerabilities were
found in ...)
- gst-plugins-ugly1.0 1.28.6-1
+ [trixie] - gst-plugins-ugly1.0 <no-dsa> (Minor issue)
NOTE:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12233
NOTE:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12243
NOTE: Fixed by:
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a598edfef83878f714ea53925ae802f49c3b31a6
(1.28.6)
@@ -1037,6 +1038,7 @@ CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and
detects violations of a
NOT-FOR-US: PHP_CodeSniffer
CVE-2026-67422 (pymdown-extensions is a collection of extensions for the
Python Markdo ...)
- pymdown-extensions 11.0.1-1
+ [trixie] - pymdown-extensions <no-dsa> (Minor issue)
NOTE:
https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-gm37-52c6-37mw
NOTE: Fixed by:
https://github.com/facelessuser/pymdown-extensions/commit/c68498598d7b13011bb4571350b6e3612a4ce44b
(11.0.1)
CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows
an auth ...)
@@ -1083,6 +1085,7 @@ CVE-2026-62830 (Missing authorization in Azure SRE Agent
allows an authorized at
NOT-FOR-US: Microsoft
CVE-2026-61632 (PyMdown Extensions is a set of extensions for the
Python-Markdown mark ...)
- pymdown-extensions 11.0.1-1
+ [trixie] - pymdown-extensions <no-dsa> (Minor issue)
NOTE:
https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-9xwg-3r6f-jcx2
CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in
os/net/app-layer/mqtt ...)
NOT-FOR-US: Contiki-NG
@@ -1257,6 +1260,7 @@ CVE-2026-19054 (A vulnerability was detected in Lspace-io
lspace-server up to 79
NOT-FOR-US: Lspace-io lspace-server
CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser
reads web ad ...)
- epiphany-browser <unfixed> (bug #1143966)
+ [trixie] - epiphany-browser <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897
NOTE:
https://gitlab.gnome.org/GNOME/epiphany/-/commit/13dd600719d7aac532ed6c84ea0d12dd372d4ac4
CVE-2026-18367 (A privilege escalation vulnerability allows local users to
execute arb ...)
@@ -1381,6 +1385,7 @@ CVE-2024-39024 (In Packetfence 13.2.0, the WebGui
interface setting allows authe
TODO: check
CVE-2026-18938 (A flaw was found in p11-kit. A local attacker, or one with
equivalent ...)
- p11-kit <unfixed>
+ [trixie] - p11-kit <no-dsa> (Minor issue)
NOTE: https://github.com/p11-glue/p11-kit/pull/777
NOTE: Fixed by:
https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc
(0.26.5)
CVE-2026-64638 (WordPress is vulnerable to a pre-auth reflected XSS
vulnerability on t ...)
@@ -5059,6 +5064,7 @@ CVE-2026-54909 (pion/stun is a Go implementation of STUN.
Prior to 3.1.3, XORMap
NOTE: Fixed by:
https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423
(v3.1.3)
CVE-2026-54787 (sigstore-go is a Go library for Sigstore signing and
verification. Pri ...)
- sigstore-go 1.2.1-1
+ [trixie] - sigstore-go <no-dsa> (Minor issue)
NOTE:
https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm
NOTE: https://github.com/sigstore/sigstore-go/pull/642
NOTE:
https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f
(v1.2.1)
@@ -10261,9 +10267,11 @@ CVE-2025-50455 (SQL injection vulnerability exists in
the order_by parameter of
CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
- unzip <unfixed> (bug #1142906)
CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
- - unzip <unfixed> (bug #1142905)
+ - unzip <unfixed> (bug #1142905; unimportant)
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-XXXX [heap OOB read in EF_IZUNIX3 extra field handler]
- - unzip <unfixed> (bug #1142904)
+ - unzip <unfixed> (bug #1142904; unimportant)
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin
before 5.7.3 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control
vulnerabilit ...)
@@ -10360,6 +10368,7 @@ CVE-2026-49478
NOTE: Fixed by:
https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1
(v1.8.6)
CVE-2026-48702
- rekor 1.5.2-1
+ [trixie] - rekor <no-dsa> (Minor issue)
NOTE: https://github.com/sigstore/rekor/pull/2831
NOTE: Fixed by:
https://github.com/sigstore/rekor/commit/759b98e2a7c39ea9779b6a51299c5f0f987f8802
(v1.5.2)
CVE-2026-50540 (Kata Containers is an open source project focusing on a
standard imple ...)
@@ -12615,6 +12624,7 @@ CVE-2026-6454 (The Firelight Lightbox plugin for
WordPress is vulnerable to Stor
NOT-FOR-US: WordPress plugin
CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass
via an EXT ...)
- zaqar 22.0.0-3 (bug #1142858)
+ [trixie] - zaqar <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/7
NOTE: https://launchpad.net/bugs/2161254
CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0,
aproject-scoped user ...)
@@ -12893,6 +12903,7 @@ CVE-2026-65919 (Meshery before 1.0.57 contains an
unauthenticated arbitrary file
NOT-FOR-US: Meshery
CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2,
contains ...)
- pytorch-vision <unfixed> (bug #1142689)
+ [trixie] - pytorch-vision <no-dsa> (Minor issue)
NOTE: https://github.com/pytorch/vision/issues/9551
NOTE: https://github.com/pytorch/vision/pull/9520
NOTE: Fixed by:
https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed
@@ -13218,6 +13229,7 @@ CVE-2026-64799 (Joomla Extension - regularlabs.com -
SSRF via remote image downl
NOT-FOR-US: Joomla
CVE-2026-64611 (A flaw was found in libcupsfilters. The
cfIEEE1284NormalizeMakeModel() ...)
- libcupsfilters <unfixed> (bug #1142686)
+ [trixie] - libcupsfilters <no-dsa> (Minor issue)
[bookworm] - libcupsfilters <postponed> (Minor issue)
[bullseye] - libcupsfilters <postponed> (Minor issue)
NOTE:
https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4
@@ -21824,6 +21836,7 @@ CVE-2026-46341 (The Apify MCP server enables AI agents
to extract data from webs
NOT-FOR-US: Apify MCP server
CVE-2026-46338 (PyMdown Extensions is a set of extensions for the
Python-Markdown mark ...)
- pymdown-extensions 11.0.1-1
+ [trixie] - pymdown-extensions <no-dsa> (Minor issue)
NOTE:
https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-62q4-447f-wv8h
NOTE: Fixed by:
https://github.com/facelessuser/pymdown-extensions/commit/63b7835776d703d6c339cf2110d9888f676efc0c
(10.21.3)
CVE-2026-46336 (Manyfold is an open source, self-hosted web application for
managing a ...)
@@ -23010,14 +23023,17 @@ CVE-2026-59888 (jackson-databind contains the
general-purpose data-binding funct
NOTE: Fixed by:
https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d
(jackson-databind-2.18.8)
CVE-2026-59886 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4,
the univ ...)
- pyasn1 0.6.4-1 (bug #1142388)
+ [trixie] - pyasn1 <no-dsa> (Minor issue)
NOTE:
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r
NOTE: Fixed by:
https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886
(v0.6.4)
CVE-2026-59885 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4,
the BER, ...)
- pyasn1 0.6.4-1 (bug #1142388)
+ [trixie] - pyasn1 <no-dsa> (Minor issue)
NOTE:
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj
NOTE: Fixed by:
https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9
(v0.6.4)
CVE-2026-59884 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4,
the BER ...)
- pyasn1 0.6.4-1 (bug #1142388)
+ [trixie] - pyasn1 <no-dsa> (Minor issue)
NOTE:
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j
NOTE: Fixed by:
https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5
(v0.6.4)
CVE-2026-59841 (A improper restriction of communication channel to intended
endpoints ...)
@@ -24248,10 +24264,12 @@ CVE-2026-49783 (Improperly implemented security check
for standard in Windows Se
NOT-FOR-US: Microsoft
CVE-2026-49477 (Soup Sieve is a CSS selector library designed to be used with
Beautifu ...)
- soupsieve 2.8.4-1
+ [trixie] - soupsieve <no-dsa> (Minor issue)
NOTE:
https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37
NOTE: Fixed by:
https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3
(2.8.4)
CVE-2026-49476 (Soup Sieve is a CSS selector library designed to be used with
Beautifu ...)
- soupsieve 2.8.4-1
+ [trixie] - soupsieve <no-dsa> (Minor issue)
NOTE:
https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x
NOTE: Fixed by:
https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39
(2.8.4)
CVE-2026-49459 (DOMPurify is a DOM-only cross-site scripting sanitizer for
HTML, MathM ...)
@@ -41403,9 +41421,11 @@ CVE-2026-56221 (Cap-go before 12.128.2 contains
multiple SQL injection vulnerabi
NOT-FOR-US: Cap-go
CVE-2026-55655 (A flaw was found in OpenSSH. A local unprivileged attacker on
a Linux ...)
- openssh <unfixed> (bug #1143936)
+ [trixie] - openssh <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462250
CVE-2026-55654 (A flaw was found in OpenSSH. This vulnerability, a heap
out-of-bounds ...)
- openssh <unfixed> (bug #1143924)
+ [trixie] - openssh <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462493
CVE-2026-55653 (A flaw was found in OpenSSH. A malicious SSH server can
exploit a doub ...)
- openssh <not-affected> (Only an issue with FIPS patch which is not in
Debian/upstream)
=====================================
data/dsa-needed.txt
=====================================
@@ -49,6 +49,10 @@ firebird4.0
--
gimp
--
+gst-plugins-bad1.0
+--
+ironic
+--
jackson-databind
--
jetty9
@@ -144,6 +148,8 @@ tomcat11
unbound
Michael Tokarev is working on rebasing to 1.25.2 (possibly 1.26.0)
--
+unzip
+--
util-linux (carnil)
Maintainer is preparing updates
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d4052ddcfd70277a9a16cadf6d41420c341e5c9
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d4052ddcfd70277a9a16cadf6d41420c341e5c9
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits