Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
eee6a607 by Moritz Muehlenhoff at 2026-08-11T14:15:07+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -58,6 +58,7 @@ CVE-2026-73033 (Sucuri Security WordPress plugin through 
version 2.7.3 contains
        NOT-FOR-US: WordPress plugin
 CVE-2026-73030 (unearth through 0.18.2, fixed in commit 6c78164, contains a 
path trave ...)
        - unearth <unfixed>
+       [trixie] - unearth <no-dsa> (Minor issue)
        NOTE: https://github.com/frostming/unearth/issues/180
        NOTE: https://github.com/frostming/unearth/pull/181
        NOTE: Fixed by: 
https://github.com/frostming/unearth/commit/6c78164e7bfa28b8b3d6f247b87e560692e3c8ba
@@ -508,15 +509,18 @@ CVE-2026-72564 (An improper authorization vulnerability 
in fosrl/pangolin throug
        NOT-FOR-US: fosrl/pangolin
 CVE-2026-71969 (OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a 
buffer u ...)
        - optee-os <unfixed>
+       [trixie] - optee-os <no-dsa> (Minor issue)
        NOTE: https://github.com/OP-TEE/optee_os/pull/7898
        NOTE: https://github.com/OP-TEE/optee_os/pull/7808
        NOTE: Fixed by: 
https://github.com/OP-TEE/optee_os/commit/7b8b494e0a324cefec8ed386b7de413b44f1aaf3
 CVE-2026-71968 (OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a 
use-afte ...)
        - optee-os <unfixed>
+       [trixie] - optee-os <no-dsa> (Minor issue)
        NOTE: https://github.com/OP-TEE/optee_os/pull/7900
        NOTE: Fixed by: 
https://github.com/OP-TEE/optee_os/commit/8794043c4065c26a2b8b1313794ba5ba5f06d296
 CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a 
null poi ...)
        - optee-os <unfixed>
+       [trixie] - optee-os <no-dsa> (Minor issue)
        NOTE: https://github.com/OP-TEE/optee_os/pull/7899
        NOTE: Fixed by: 
https://github.com/OP-TEE/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833
 CVE-2026-71964 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an 
arbitrary file  ...)
@@ -6795,9 +6799,11 @@ CVE-2026-18574 (An authentication bypass vulnerability 
in Check Point Security M
        NOT-FOR-US: Check Point Security Management Server
 CVE-2026-18508 (A flaw was found in GNU tar. When extracting an archive with 
the --one ...)
        - tar <unfixed> (bug #1143836)
+       [trixie] - tar <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509843
 CVE-2026-18477 (A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU 
tar's increm ...)
        - tar <unfixed> (bug #1143836)
+       [trixie] - tar <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509735
 CVE-2026-18248 (@fastify/aws-lambda version 6.4.0 decorates each Fastify 
request with  ...)
        NOT-FOR-US: fastify/aws-lambda
@@ -20110,12 +20116,12 @@ CVE-2026-63731 (HyperDX before 2.31.0 contains a 
server-side request forgery vul
 CVE-2026-63730 (HyperDX before 2.31.0 contains a server-side request forgery 
vulnerabi ...)
        NOT-FOR-US: HyperDX
 CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) shipped with TeX Live 
and embedd ...)
-       - texlive-bin 2026.20260303.78225+ds-2
-       [trixie] - texlive-bin <no-dsa> (Minor issue)
-       - texstudio 4.9.6+ds-1
-       - okular <unfixed>
+       - texlive-bin 2026.20260303.78225+ds-2 (unimportant)
+       - texstudio 4.9.6+ds-1 (unimportant)
+       - okular <unfixed> (unimportant)
        NOTE: Fixed by: 
https://github.com/TeX-Live/texlive-source/commit/002dcd3eac30db5c352f53d4181737961cc7ee9a
 (svn78081)
        NOTE: 
https://fatihhcelik.github.io/posts/evince-synctex-heap-use-after-free/
+       NOTE: Crash in CLI/GUI tool, no security impact
 CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection 
vulnerability t ...)
        NOT-FOR-US: Gitleaks
 CVE-2026-62414 (Joomla Extension - joomlack.fr - Improper access control in 
Page Build ...)
@@ -26758,14 +26764,17 @@ CVE-2026-49978 (DOMPurify is a DOM-only cross-site 
scripting sanitizer for HTML,
        NOTE: Fixed by: 
https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff
 (3.4.7)
 CVE-2026-49855 (Tornado is a Python web framework and asynchronous networking 
library. ...)
        - python-tornado <unfixed> (bug #1142277)
+       [trixie] - python-tornado <no-dsa> (Minor issue)
        NOTE: 
https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56
        NOTE: Fixed by: 
https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff
 (v6.5.6)
 CVE-2026-49854 (Tornado is a Python web framework and asynchronous networking 
library. ...)
        - python-tornado <unfixed> (bug #1142277)
+       [trixie] - python-tornado <no-dsa> (Minor issue)
        NOTE: 
https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9
        NOTE: Fixed by: 
https://github.com/tornadoweb/tornado/commit/96dc88c2a05705287856b2cd6b4b4034f9a6aaac
 (v6.5.6)
 CVE-2026-49853 (Tornado is a Python web framework and asynchronous networking 
library. ...)
        - python-tornado <unfixed> (bug #1142277)
+       [trixie] - python-tornado <no-dsa> (Minor issue)
        NOTE: 
https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf
 CVE-2026-49808 (Concurrent execution using shared resource with improper 
synchronizati ...)
        NOT-FOR-US: Microsoft
@@ -28675,6 +28684,9 @@ CVE-2026-57219 (RabbitMQ is a messaging and streaming 
broker. Prior to 3.13.15,
        NOTE: 
https://github.com/rabbitmq/rabbitmq-server/commit/98b1daf740237c85941e8addcbea6e74f4a2743c
 (v4.2.6)
 CVE-2026-57218 (RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, 
RabbitMQ ...)
        - rabbitmq-server 4.3.0-2
+       [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, 
only affects 4.2.x)
+       [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not 
present, only affects 4.2.x)
+       [bullseye] - rabbitmq-server <not-affected> (Vulnerable code not 
present, only affects 4.2.x)
        NOTE: 
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7
        NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/16092
        NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/16097
@@ -28703,6 +28715,9 @@ CVE-2026-57215 (RabbitMQ is a messaging and streaming 
broker. Prior to 3.13.15,
        NOTE: 
https://github.com/rabbitmq/rabbitmq-server/commit/c84f3c880e0f22b49c01237cf8f86e176eeadc72
 (v4.2.6)
 CVE-2026-57214 (RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, 
the Rabb ...)
        - rabbitmq-server 4.3.0-2
+       [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, 
only affects 4.2.x)
+       [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not 
present, only affects 4.2.x)
+       [bullseye] - rabbitmq-server <not-affected> (Vulnerable code not 
present, only affects 4.2.x)
        NOTE: 
https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6jfq-prw2-7rwp
        NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/15606
        NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/15608
@@ -283025,6 +283040,7 @@ CVE-2024-43698 (Kieback & Peter's DDC4000 seriesuses 
weak credentials, which may
        NOT-FOR-US: Kieback & Peter's DDC4000 series
 CVE-2024-42643 (Integer Overflow in fast_ping.c in SmartDNS Release46 allows 
remote at ...)
        - smartdns <unfixed> (bug #1086146)
+       [trixie] - smartdns <no-dsa> (Minor issue)
        [bookworm] - smartdns <postponed> (minor issue; DoS)
        [bullseye] - smartdns <postponed> (minor issue; DoS)
        NOTE: https://github.com/pymumu/smartdns/issues/1779


=====================================
data/dsa-needed.txt
=====================================
@@ -121,6 +121,8 @@ python-httplib2 (carnil)
 python-msgpack
   Problems with autopkgtests, maintainer pinged and waiting for feedback
 --
+rabbitmq-server
+--
 redis
 --
 roundcube
@@ -146,10 +148,14 @@ rust-wasmtime
 --
 shaarli
 --
+spip
+--
 srt
 --
 starlette
 --
+swift
+--
 tomcat10
 --
 tomcat11
@@ -168,6 +174,8 @@ vim
 --
 vips
 --
+weechat
+--
 xorg-server
 --
 xrdp



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eee6a607a64cbb8b950d07362c59e532d8bd0cd3

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eee6a607a64cbb8b950d07362c59e532d8bd0cd3
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to