Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
da2bd0df by Moritz Muehlenhoff at 2026-08-10T17:05:08+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1825,6 +1825,7 @@ CVE-2026-12570 (A vulnerability in keras-team/keras 
versions <= 3.15.0 allows fo
        [bullseye] - keras <end-of-life> (EOL in bullseye LTS)
 CVE-2026-12372 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
nltk/nltk ...)
        - nltk <unfixed>
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513003
 CVE-2026-70395 (Improper Neutralization of Special Elements in Data Query 
Logic vulner ...)
        NOT-FOR-US: ash-project ash
@@ -5129,6 +5130,7 @@ CVE-2026-69098 (kotaemon through 0.12.0 contains an 
insecure deserialization vul
        NOT-FOR-US: kotaemon
 CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in 
the PAM ...)
        - sssd <unfixed> (bug #1143947)
+       [trixie] - sssd <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509760
 CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for 
CVE-2026-18401  ...)
        - jackson-core <not-affected> (Incomplete fix for CVE-2026-18401 not 
applied)
@@ -5461,6 +5463,7 @@ CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide 
a Parameter Context up
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() 
function  ...)
        - sssd <unfixed> (bug #1143600)
+       [trixie] - sssd <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509761
 CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows 
attackers  ...)
        NOT-FOR-US: NASA cFS
@@ -5794,8 +5797,8 @@ CVE-2026-68869
        REJECTED
 CVE-2026-68742 (A flaw was found in SSSD. The sss_nss_protocol_parse_addr() 
function i ...)
        - sssd <unfixed> (bug #1143600)
+       [trixie] - sssd <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509762
-       TODO: check upstream status
 CVE-2026-68587 (SiYuan versions before v3.7.3 contain an information 
disclosure vulner ...)
        NOT-FOR-US: SiYuan
 CVE-2026-68586 (SiYuan before v3.7.3 fails to apply publish-access filters to 
the getB ...)
@@ -9779,6 +9782,7 @@ CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to 
uncontrolled recursion lea
        NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
 CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in 
the custom ...)
        - node-postcss 8.5.15+~cs9.3.39-1
+       [trixie] - node-postcss <no-dsa> (Minor issue)
        - node-mocha 9.1.4+ds1+~cs28.2.8-1
        [bullseye] - node-mocha <postponed> (Minor issue, only test framework)
        NOTE: node-postcss bundles nanoid
@@ -9786,6 +9790,7 @@ CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains 
an infinite loop in the
        NOTE: Fixed by: 
https://github.com/ai/nanoid/commit/6de05d794f62eeac3f527c74c34c6af0c1d32e49 
(5.1.16)
 CVE-2026-67213 (nanoid (Nano ID) before 5.1.6 contains an infinite loop in the 
customA ...)
        - node-postcss 8.5.8+~cs9.3.30-1
+       [trixie] - node-postcss <no-dsa> (Minor issue)
        - node-mocha 9.1.4+ds1+~cs28.2.8-1
        [bullseye] - node-mocha <postponed> (Minor issue, only test framework)
        NOTE: node-postcss bundles nanoid
@@ -13785,6 +13790,7 @@ CVE-2026-66374 (Knot Resolver before 6.4.1 allows 
remote code execution via a he
        [bullseye] - knot-resolver <not-affected> (Vulnerable code not present, 
quic support added in 6.2)
        NOTE: https://openwall.com/lists/oss-security/2026/07/23/6
        NOTE: https://github.com/venglin/knot-doq
+       NOTE: 
https://lists.nic.cz/hyperkitty/list/[email protected]/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
 CVE-2026-9765 (Note: The CVE and blog post don't exist because we determined 
this is  ...)
        NOT-FOR-US: Grafana
 CVE-2026-8789 (The Easy Appointments plugin for WordPress is vulnerable to 
unauthoriz ...)
@@ -14135,6 +14141,7 @@ CVE-2026-64208 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: 
https://git.kernel.org/linus/2b50aceafe6606ea52ed42aadd1b4d44a188aade (7.1-rc5)
 CVE-2026-63317 (Arbitrary Class Instantiation via XML Feature Generator 
Descriptor and ...)
        - apache-opennlp <unfixed> (bug #1142855)
+       [trixie] - apache-opennlp <no-dsa> (Minor issue)
        [bookworm] - apache-opennlp <postponed> (minor issue)
        [bullseye] - apache-opennlp <postponed> (minor issue)
        NOTE: https://lists.apache.org/thread/myr446n8t3gv8gq8wbpxm41olx16d8yj
@@ -14500,10 +14507,6 @@ CVE-2024-58354 (cal.com (calcom repository, later 
renamed cal.diy) is affected b
        NOT-FOR-US: Cal.com (calcom/cal.diy)
 CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is 
vulnerabl ...)
        NOT-FOR-US: Cal.com (calcom/cal.diy)
-CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
-       - knot-resolver 6.4.1-1
-       NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
-       NOTE: 
https://lists.nic.cz/hyperkitty/list/[email protected]/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
 CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious 
bootc cont ...)
        - ironic-python-agent 11.5.0-4 (bug #1142854)
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
@@ -15564,6 +15567,7 @@ CVE-2026-16624 (Cal.com OSS ships lacks authorization 
on webhook teamId creation
        NOT-FOR-US: Cal.com OSS
 CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth 
authori ...)
        - librest <unfixed> (bug #1142715)
+       [trixie] - librest <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2504432
        NOTE: https://gitlab.gnome.org/GNOME/librest/-/issues/25
 CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu 
Software O ...)
@@ -19469,6 +19473,7 @@ CVE-2026-64612 (A flaw was found in libcupsfilters and 
cups-filters. The PNG ima
        NOTE: 
https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 (2.2.0)
 CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of 
Service via de ...)
        - libnet-dns-perl 1.56-1 (bug #1142503)
+       [trixie] - libnet-dns-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41989541/
        NOTE: https://rt.cpan.org/Ticket/Display.html?id=179946
 CVE-2026-64193 (Net::DNS versions through 1.55 for Perl allow remote execution 
injecti ...)
@@ -19665,6 +19670,7 @@ CVE-2026-40187 (In egroupware version 26.0 and earlier, 
an authenticated adminis
        - egroupware <removed>
 CVE-2026-39879 (Due to a missing sanitization call in 
[`afsql_dd_run_query`](https://g ...)
        - syslog-ng <unfixed> (bug #1143061)
+       [trixie] - syslog-ng <no-dsa> (Minor issue)
        [bookworm] - syslog-ng <postponed> (Minor issue)
        [bullseye] - syslog-ng <postponed> (Minor issue)
        NOTE: 
https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-qwf9-6222-m24m
@@ -23043,6 +23049,7 @@ CVE-2026-45162 (Pimcore is an Open Source Data & 
Experience Management Platform.
        NOT-FOR-US: Pimcore
 CVE-2026-44722 (pyzipper is a replacement for Python's zipfile that can read 
and write ...)
        - python-pyzipper <unfixed> (bug #1142473)
+       [trixie] - python-pyzipper <no-dsa> (Minor issue)
        NOTE: 
https://github.com/danifus/pyzipper/security/advisories/GHSA-crqm-m339-7m2p
        NOTE: Fixed by; 
https://github.com/danifus/pyzipper/commit/93ce88e7dfd1635443197dab3fb8d477cff579ae
 (v0.4.0)
 CVE-2026-22104 (Improper access control in Hashtopolis server web-interface 
chunk acti ...)
@@ -26207,6 +26214,7 @@ CVE-2026-47767 (Symfony is a PHP framework for web and 
console applications and
        NOTE: 
https://github.com/symfony/symfony/commit/3228c3806ee511008bea19a95084d460b17e5d25
 (v5.4.52, v6.4.40, v7.4.12, v8.0.12)
 CVE-2026-47737 (Puma is a Ruby/Rack web server built for parallelism. From 
5.5.0 until ...)
        - puma 8.0.2-1
+       [trixie] - puma <no-dsa> (Minor issue)
        NOTE: 
https://github.com/puma/puma/security/advisories/GHSA-2vqw-3mp8-cgmx
        NOTE: https://github.com/puma/puma/pull/3944
        NOTE: https://github.com/puma/puma/pull/3947
@@ -26214,6 +26222,7 @@ CVE-2026-47737 (Puma is a Ruby/Rack web server built 
for parallelism. From 5.5.0
        NOTE: 
https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58 
(v7.2.1)
 CVE-2026-47736 (Puma is a Ruby/Rack web server built for parallelism. From 
5.5.0 until ...)
        - puma 8.0.2-1
+       [trixie] - puma <no-dsa> (Minor issue)
        NOTE: 
https://github.com/puma/puma/security/advisories/GHSA-qpgp-93vx-g8v8
        NOTE: 
https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f 
(v8.0.2)
        NOTE: 
https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58 
(v7.2.1)
@@ -26664,6 +26673,7 @@ CVE-2026-42491
        NOTE: https://xenbits.xen.org/xsa/advisory-498.html
 CVE-2026-15747 (Mojolicious versions from 4.59 before 9.48 for Perl expose a 
stable re ...)
        - libmojolicious-perl 9.48+dfsg-1
+       [trixie] - libmojolicious-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41816171/
        NOTE: Fixed by: 
https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27
 (v9.48)
 CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the 
table file  ...)
@@ -26987,12 +26997,10 @@ CVE-2026-61462 (mcp-gitlab contains a path traversal 
vulnerability in the job_id
 CVE-2026-60121 (Vitec Flamingo 4.12.2 contains an unauthenticated OS command 
injection ...)
        NOT-FOR-US: Vitec Flamingo
 CVE-2026-60103 (Blender 3.0.0 through 5.1.2 contains an out-of-bounds read 
vulnerabili ...)
-       - blender <unfixed> (bug #1143049)
-       [trixie] - blender <no-dsa> (Minor issue)
-       [bookworm] - blender <postponed> (Minor issue, OOB read)
-       [bullseye] - blender <postponed> (Minor issue, OOB read)
+       - blender <unfixed> (bug #1143049; unimportant)
        NOTE: https://projects.blender.org/blender/blender/pulls/161273
        NOTE: Fixed by: 
https://projects.blender.org/blender/blender/commit/968972a918b5ed2d534295b639c54449d7de11cd
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-59523 (Missing Authorization vulnerability in NSquared Simply 
Schedule Appoin ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59521 (Deserialization of Untrusted Data vulnerability in 
ShapedPlugin LLC Re ...)
@@ -27932,6 +27940,7 @@ CVE-2026-4661 (The WP CTA \u2013 Sticky CTA Builder, 
Generate Leads, Promote Sal
        NOT-FOR-US: WordPress plugin
 CVE-2026-49844 (Improper encoding of non-finite floating-point values during 
MapMessag ...)
        - apache-log4j2 <unfixed> (bug #1141960)
+       [trixie] - apache-log4j2 <no-dsa> (Minor issue)
        NOTE: https://logging.apache.org/security.html#CVE-2026-49844
        NOTE: https://github.com/apache/logging-log4j2/pull/4163
        NOTE: Fixed by: 
https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300
 (2.x branch)
@@ -264265,6 +264274,7 @@ CVE-2024-52046 (The ObjectSerializationDecoder in 
Apache MINA uses Java\u2019s n
        [bookworm] - mina <no-dsa> (Minor issue)
        [bullseye] - mina <postponed> (Minor issue; need specific conditions)
        - mina2 2.2.9-1 (bug #1091530)
+       [trixie] - mina2 <no-dsa> (Minor issue)
        [bookworm] - mina2 <no-dsa> (Minor issue)
        [bullseye] - mina2 <postponed> (Minor issue; need specific conditions)
        NOTE: https://lists.apache.org/thread/4wxktgjpggdbto15d515wdctohb0qmv8



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da2bd0df13d9e2cca7613b647069548ca9395084

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da2bd0df13d9e2cca7613b647069548ca9395084
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to