Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b920d348 by security tracker role at 2026-08-12T07:13:35+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,130 +1,386 @@
+CVE-2026-9318 (tablib prior to 3.10.0 contains a stored cross-site scripting 
vulnerab ...)
+       TODO: check
+CVE-2026-73250 (Notepad++ is a free and open-source source code editor. Prior 
to 8.9.7 ...)
+       TODO: check
+CVE-2026-73249 (calibre is an e-book manager. Prior to 9.12.0, the calibre 
Content Ser ...)
+       TODO: check
+CVE-2026-73248 (calibre is an e-book manager. Prior to 9.12.0, calibre 
processes attac ...)
+       TODO: check
+CVE-2026-73247 (Kestra is an open-source, event-driven orchestration platform. 
Prior t ...)
+       TODO: check
+CVE-2026-73246 (Kestra is an open-source, event-driven orchestration platform. 
Prior t ...)
+       TODO: check
+CVE-2026-73245 (Kestra is an open-source, event-driven orchestration platform. 
Prior t ...)
+       TODO: check
+CVE-2026-73244 (kkFileView is a universal file online preview project based on 
Spring  ...)
+       TODO: check
+CVE-2026-73243 (kkFileView is a universal file online preview project based on 
Spring  ...)
+       TODO: check
+CVE-2026-73242 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
+       TODO: check
+CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
+       TODO: check
+CVE-2026-73235 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
+       TODO: check
+CVE-2026-73234 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
+       TODO: check
+CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric 
modeler. ...)
+       TODO: check
+CVE-2026-73232 (ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf 
allows a ...)
+       TODO: check
+CVE-2026-73231 (Faker generates massive amounts of fake data in the browser 
and Node.j ...)
+       TODO: check
+CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security 
tools.  ...)
+       TODO: check
+CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for 
building  ...)
+       TODO: check
+CVE-2026-73122 (A flaw was found in the multicloud-operators-channel component 
of Red  ...)
+       TODO: check
+CVE-2026-73036 (Bash-it 3.2.0 contains a terminal escape sequence injection 
vulnerabil ...)
+       TODO: check
+CVE-2026-73034 (DB-GPT v0.8.1 contains an unauthenticated path traversal 
vulnerability ...)
+       TODO: check
+CVE-2026-73032 (PapersGPT for Zotero 0.6.1 contains a remote code execution 
vulnerabil ...)
+       TODO: check
+CVE-2026-73031 (telegram-search contains a stored cross-site scripting 
vulnerability t ...)
+       TODO: check
+CVE-2026-72526 (A flaw was found in the multicloud-integrations component. The 
Applica ...)
+       TODO: check
+CVE-2026-71845 (A flaw was found in insights-client. The setDefault() function 
logs th ...)
+       TODO: check
+CVE-2026-71475 (A flaw was found in insights-client. A compromised managed 
cluster, re ...)
+       TODO: check
+CVE-2026-71474 (A flaw was found in insights-client. When the application 
receives a n ...)
+       TODO: check
+CVE-2026-71468 (A flaw was found in acm-search-v2-api-rhel9. When the 
`getFederationCo ...)
+       TODO: check
+CVE-2026-71467 (A flaw was found in search-v2-api. The authentication 
middleware in th ...)
+       TODO: check
+CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache 
HttpCompone ...)
+       TODO: check
+CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of 
Red Hat Ad ...)
+       TODO: check
+CVE-2026-70339 (Access of resource using incompatible type ('type confusion') 
in Micro ...)
+       TODO: check
+CVE-2026-6484 (In an UEFI, Lack of verified boot to certain FV may cause 
arbitrary co ...)
+       TODO: check
+CVE-2026-68067 (The login endpoint on the Mira cloud API accepts any 
format-valid stri ...)
+       TODO: check
+CVE-2026-67568 (The distributed Mira Android APK v4.5.15.4 allows an attacker 
read/wri ...)
+       TODO: check
+CVE-2026-67558 (The Mira Android companion app v4.5.15.4 identifies the paired 
Mira ho ...)
+       TODO: check
+CVE-2026-66878 (A flaw was found in multicloud-operators-subscription. A 
privileged us ...)
+       TODO: check
+CVE-2026-66875 (In the Mira hormone monitor device firmware v1.7.1.47 build 
01070147,  ...)
+       TODO: check
+CVE-2026-66832 (When the Mira Android app opens in-app WebView content (e.g., 
shop red ...)
+       TODO: check
+CVE-2026-66659 (Improper Neutralization of Special Elements used in an SQL 
Command ('S ...)
+       TODO: check
+CVE-2026-66340 (The Mira cloud authentication endpoints do not enforce 
per-account rat ...)
+       TODO: check
+CVE-2026-66154 (An insufficient certificate validation in a privileged 
communication w ...)
+       TODO: check
+CVE-2026-66150 (Improper Control of Generation of Code ('Code Injection') 
Vulnerabilit ...)
+       TODO: check
+CVE-2026-66149 (Improper Control of Generation of Code ('Code Injection') 
Vulnerabilit ...)
+       TODO: check
+CVE-2026-66148 (An authenticated command injection vulnerability was 
identified in GMS ...)
+       TODO: check
+CVE-2026-66147 (An unauthenticated command injection vulnerability was 
identified in t ...)
+       TODO: check
+CVE-2026-66146 (Multiple Cross-Site Scripting (XSS) vulnerabilities were 
identified in ...)
+       TODO: check
+CVE-2026-66145 (An unauthenticated remote code execution vulnerability was 
identified  ...)
+       TODO: check
+CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write 
from any ...)
+       TODO: check
+CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS 
terminates ...)
+       TODO: check
+CVE-2026-64954 (Velociraptor allows scheduling new collections via VQL queries 
in note ...)
+       TODO: check
+CVE-2026-64934 (The Mira cloud API accepts the firmware version reported by 
the compan ...)
+       TODO: check
+CVE-2026-64927 (A flaw was found in the multicloud-operators-channel 
component. This v ...)
+       TODO: check
+CVE-2026-63177 (Malcolm is a network traffic analysis tool suite. Prior to 
version 26. ...)
+       TODO: check
+CVE-2026-63134 (Malcolm is a network traffic analysis tool suite. Prior to 
version 26. ...)
+       TODO: check
+CVE-2026-63133 (Malcolm is a network traffic analysis tool suite. Prior to 
version 26. ...)
+       TODO: check
+CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 
SSH bac ...)
+       TODO: check
+CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The 
file-upload comp ...)
+       TODO: check
+CVE-2026-48813 (Flawfinder is a a static analysis tool for finding 
vulnerabilities in  ...)
+       TODO: check
+CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO 
realtime c ...)
+       TODO: check
+CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 
allow a lo ...)
+       TODO: check
+CVE-2026-48763 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 
expose a d ...)
+       TODO: check
+CVE-2026-48762 (TypeBot is a chatbot builder tool. Prior to version 3.16.0, 
the OpenAI ...)
+       TODO: check
+CVE-2026-45618 (LiquidJS is a Shopify/GitHub Pages compatible template engine. 
Prior t ...)
+       TODO: check
+CVE-2026-29036 (cJSON versions 1.5.0 through 1.7.19 contain an 
incorrectly-resolved na ...)
+       TODO: check
+CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer 
overflow v ...)
+       TODO: check
+CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API 
(`snowflake.co ...)
+       TODO: check
+CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung 
Open Sour ...)
+       TODO: check
+CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung 
Open Source ...)
+       TODO: check
+CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass 
(insecure direc ...)
+       TODO: check
+CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command 
is gated  ...)
+       TODO: check
+CVE-2026-19217 (The Royal Addons for Elementor  WordPress plugin before 
1.7.1065 does  ...)
+       TODO: check
+CVE-2026-19091 (The GeoDirectory \u2013 WP Business Directory Plugin and 
Classified Li ...)
+       TODO: check
+CVE-2026-19073 (The Order Sync with Zendesk for WooCommerce WordPress plugin 
before 2. ...)
+       TODO: check
+CVE-2026-19052 (The ProSolution WP Client WordPress plugin before 2.0.9 does 
not perfo ...)
+       TODO: check
+CVE-2026-19050 (The ProSolution WP Client WordPress plugin before 2.0.9 does 
not valid ...)
+       TODO: check
+CVE-2026-18962 (The WP Photo Album Plus WordPress plugin before 9.2.09.002 
does not ch ...)
+       TODO: check
+CVE-2026-18961 (The Social Login, Passkeys, Magic Link & Email OTP \u2013 
Passwordless ...)
+       TODO: check
+CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not 
have auth ...)
+       TODO: check
+CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts 
several undi ...)
+       TODO: check
+CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly 
restrict ac ...)
+       TODO: check
+CVE-2026-18710 (A MongoDB driver component could write sensitive configuration 
informa ...)
+       TODO: check
+CVE-2026-18634 (An insecure handling of serialized objects vulnerability was 
found in  ...)
+       TODO: check
+CVE-2026-18474 (The WP Directory Kit WordPress plugin before 1.5.6 does not 
sanitise a ...)
+       TODO: check
+CVE-2026-18391 (The WooCommerce Subscriptions WordPress plugin before 9.1.0 
does not v ...)
+       TODO: check
+CVE-2026-18366 (The Events Manager  WordPress plugin before 7.4.1 does not 
properly sc ...)
+       TODO: check
+CVE-2026-18230 (The WP Directory Kit WordPress plugin before 1.5.6 does not 
sanitise a ...)
+       TODO: check
+CVE-2026-18057 (The Events Manager  WordPress plugin before 7.4.1 does not 
sanitise an ...)
+       TODO: check
+CVE-2026-18049 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 
does not pe ...)
+       TODO: check
+CVE-2026-18048 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 
does not va ...)
+       TODO: check
+CVE-2026-18046 (The Cookie Consent  WordPress plugin before 0.0.10 does not 
correctly  ...)
+       TODO: check
+CVE-2026-18035 (The User Access Manager WordPress plugin before 2.3.15 does 
not apply  ...)
+       TODO: check
+CVE-2026-17013 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 
does not sa ...)
+       TODO: check
+CVE-2026-16977 (The Form Maker by 10Web  WordPress plugin before 1.15.45 does 
not prop ...)
+       TODO: check
+CVE-2026-16737 (The WP Travel Engine  WordPress plugin before 6.8.5 does not 
perform a ...)
+       TODO: check
+CVE-2026-16538 (The Wallet for WooCommerce WordPress plugin before 1.6.10 does 
not ver ...)
+       TODO: check
+CVE-2026-16294 (The PowerPress Podcasting plugin by Blubrry WordPress plugin 
before 11 ...)
+       TODO: check
+CVE-2026-16253 (The Total Upkeep  WordPress plugin before 1.17.3 does not 
adequately p ...)
+       TODO: check
+CVE-2026-16230 (The Formidable Digital Signatures plugin for WordPress is 
vulnerable t ...)
+       TODO: check
+CVE-2026-16066 (The Welcart e-Commerce WordPress plugin before 2.11.34 does 
not saniti ...)
+       TODO: check
+CVE-2026-16051 (The wpmudev-updates WordPress plugin before 5.0.1 does not 
verify the  ...)
+       TODO: check
+CVE-2026-15606 (The Frontend Admin by DynamiApps plugin for WordPress is 
vulnerable to ...)
+       TODO: check
+CVE-2026-15388 (The Cookie Consent  WordPress plugin before 0.0.10 does not 
correctly  ...)
+       TODO: check
+CVE-2026-15249 (The Patterns Kit WordPress plugin through 1.0.3 does not 
escape a link ...)
+       TODO: check
+CVE-2026-15039 (The giftware WordPress plugin before 4.2.10 does not validate 
the type ...)
+       TODO: check
+CVE-2026-14925 (The Import WP  WordPress plugin before 2.14.23 does not 
perform any au ...)
+       TODO: check
+CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS 
command in ...)
+       TODO: check
+CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not 
check the c ...)
+       TODO: check
+CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not 
verify orde ...)
+       TODO: check
+CVE-2026-14857 (The WP Crowdfunding WordPress plugin before 2.2.1 does not 
verify owne ...)
+       TODO: check
+CVE-2026-13613 (The KiviCare  WordPress plugin before 4.5.2 does not properly 
sanitise ...)
+       TODO: check
+CVE-2026-13612 (The KiviCare  WordPress plugin before 4.5.2 does not verify 
that the r ...)
+       TODO: check
+CVE-2026-13457 (The InstaWP Connect \u2013 1-click WP Staging & Migration 
plugin for W ...)
+       TODO: check
+CVE-2026-13177 (The Eventin  WordPress plugin before 4.1.20 does not properly 
restrict ...)
+       TODO: check
+CVE-2026-13171 (The Eventin  WordPress plugin before 4.1.20 does not perform 
an author ...)
+       TODO: check
+CVE-2026-13168 (The Eventin  WordPress plugin before 4.1.20 does not properly 
restrict ...)
+       TODO: check
+CVE-2026-12976 (The LearnPress  WordPress plugin before 4.4.4 does not verify 
that a u ...)
+       TODO: check
+CVE-2026-12235 (The Linkable Loadable Extensions (llext) subsystem mis-handles 
PLT/REL ...)
+       TODO: check
+CVE-2026-12234 (The userspace syscall verifiers z_vrfy_zsock_sendmsg() and 
z_vrfy_zsoc ...)
+       TODO: check
+CVE-2026-12233 (The PSA Protected Storage credential backend 
(subsys/net/lib/tls_crede ...)
+       TODO: check
+CVE-2026-12232 (The Intel ALH digital-audio-interface driver function 
dai_alh_get_prop ...)
+       TODO: check
+CVE-2025-15687 (A security flaw has been discovered in Open5GS up to 2.7.6. 
Impacted i ...)
+       TODO: check
+CVE-2025-15686 (A vulnerability has been found in Open5GS up to 2.7.6. 
Affected by thi ...)
+       TODO: check
+CVE-2025-15685 (A flaw has been found in Open5GS up to 2.7.1. Affected by this 
vulnera ...)
+       TODO: check
+CVE-2025-15684 (A vulnerability was detected in Open5GS up to 2.7.6. Affected 
is the f ...)
+       TODO: check
+CVE-2024-14044 (A vulnerability was identified in Open5GS up to 2.7.1. This 
issue affe ...)
+       TODO: check
+CVE-2024-14043 (A vulnerability was determined in Open5GS up to 2.7.1. This 
vulnerabil ...)
+       TODO: check
+CVE-2024-14042 (A vulnerability was found in Open5GS up to 2.7.1. This affects 
the fun ...)
+       TODO: check
 CVE-2026-19496
        NOT-FOR-US: Red Hat sources-api-go
-CVE-2026-73283
+CVE-2026-73283 (In sshd in OpenSSH before 10.5, the restrict keyword (in 
authorized_ke ...)
        - openssh <unfixed> (bug #1144192)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
        NOTE: https://www.openssh.org/releasenotes.html#10.5
-CVE-2026-73282
+CVE-2026-73282 (In ssh in OpenSSH before 10.5, a use-after-free for realloc 
data can o ...)
        - openssh <unfixed> (bug #1144192)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
        NOTE: https://www.openssh.org/releasenotes.html#10.5
-CVE-2026-73281
+CVE-2026-73281 (In ssh-agent in OpenSSH before 10.5, some operations can occur 
remotel ...)
        - openssh <unfixed> (bug #1144192)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
        NOTE: https://www.openssh.org/releasenotes.html#10.5
-CVE-2026-68443 [hwmon: (gigabyte_waterforce) Stop device IO before calling 
hid_hw_stop]
+CVE-2026-68443 (In the Linux kernel, the following vulnerability has been 
resolved:  h ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/ff0c5c53d08274e200b48a4d53aa078265e873cb (7.2-rc5)
-CVE-2026-68442 [btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent 
maps]
+CVE-2026-68442 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/5eff4d5b17fa1950e80bfd1ba43dc0699e61a644 (7.2-rc5)
-CVE-2026-68440 [net: txgbe: fix heap overflow when reading module EEPROM]
+CVE-2026-68440 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 7.1.6-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/6a905a71fd43ce8b45f05044b11491337f232c9d (7.2-rc5)
-CVE-2026-68439 [wifi: mt76: mt7925: fix possible NULL-pointer deref in 
mt7925_mcu_bss_he_tlv()]
+CVE-2026-68439 (In the Linux kernel, the following vulnerability has been 
resolved:  w ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/8d1b6738c1ab48c086b17e7994034aca94258931 (7.2-rc5)
-CVE-2026-68438 [smp: Make CSD lock acquisition atomic for debug mode]
+CVE-2026-68438 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
        - linux 7.1.6-1
        [trixie] - linux <not-affected> (Vulnerable code not present)
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/35551efb155e3b83445a6c3f66cb498d5efc182c (7.2-rc5)
-CVE-2026-68437 [drm/imagination: Fit paired fragment job in the correct CCCB]
+CVE-2026-68437 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/4baf9e70cb756d78dd56419f8baee2978a72d0c3 (7.2-rc1)
-CVE-2026-68429 [drm/dp_mst: Handle torn-down topology gracefully in 
drm_dp_mst_topology_queue_probe()]
+CVE-2026-68429 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        [bookworm] - linux <not-affected> (Vulnerable code not present)
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/613059875958e7b217b250ed14c3b189f9488421 (7.2-rc2)
-CVE-2026-68450 [btrfs: free mapping node on duplicate reloc root insert]
+CVE-2026-68450 (In the Linux kernel, the following vulnerability has been 
resolved:  b ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/6a8269b6459ed870a8156c106a0f597383907872 (7.2-rc5)
-CVE-2026-68449 [ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion 
bit-scanning]
+CVE-2026-68449 (In the Linux kernel, the following vulnerability has been 
resolved:  a ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        NOTE: 
https://git.kernel.org/linus/c2130f6553f4a5cbdc259de069600117a995f197 (7.2-rc4)
-CVE-2026-68448 [ovl: check access to copy_file_range source with src mounter 
creds]
+CVE-2026-68448 (In the Linux kernel, the following vulnerability has been 
resolved:  o ...)
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/a1e0eb8f55cfe09bb31a202a388babc411292656 (7.2-rc5)
-CVE-2026-68447 [drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO 
size]
+CVE-2026-68447 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/426ffae6ecc7ec77d32bf8be065c21a1b881b084 (7.2-rc2)
-CVE-2026-68446 [drm/vmwgfx: Validate vmw_surface_metadata::array_size]
+CVE-2026-68446 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        NOTE: 
https://git.kernel.org/linus/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991 (7.2-rc5)
-CVE-2026-68445 [drm/vc4: Prevent shader BO mappings from becoming writable]
+CVE-2026-68445 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        NOTE: 
https://git.kernel.org/linus/0c9e6367639548307d3f578f6943ce72c9d39087 (7.2-rc5)
-CVE-2026-68444 [firmware: arm_ffa: Fix NULL dereference in 
ffa_partition_info_get()]
+CVE-2026-68444 (In the Linux kernel, the following vulnerability has been 
resolved:  f ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8 (7.2-rc4)
-CVE-2026-68441 [net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains]
+CVE-2026-68441 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/ec48b3be2c8595dd290be883dbd4fb8b2f9f5d5e (7.2-rc5)
-CVE-2026-68436 [drm/amd/display: use kvzalloc to allocate struct dc]
+CVE-2026-68436 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.6-1
        NOTE: 
https://git.kernel.org/linus/75050390151a14802be433c3856ddcb483cecd24 (7.2-rc2)
-CVE-2026-68435 [LoongArch: Fix address space mismatch in kexec command line 
lookup]
+CVE-2026-68435 (In the Linux kernel, the following vulnerability has been 
resolved:  L ...)
        - linux 7.1.6-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/485ed44db5694d8d2e5027f63ad608e705286f30 (7.2-rc5)
-CVE-2026-68434 [serial: 8250_mid: Fix NULL function pointer dereference on 
DNV/ICX-D/SNR platforms]
+CVE-2026-68434 (In the Linux kernel, the following vulnerability has been 
resolved:  s ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        NOTE: 
https://git.kernel.org/linus/7fb13fd7e9a59a37cd911efff83abe19e3ee029d (7.2-rc5)
-CVE-2026-68433 [libceph: bound get_version reply decode to front len]
+CVE-2026-68433 (In the Linux kernel, the following vulnerability has been 
resolved:  l ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        NOTE: 
https://git.kernel.org/linus/d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0 (7.2-rc5)
-CVE-2026-68432 [vxlan: require CAP_NET_ADMIN in the device netns for 
changelink]
+CVE-2026-68432 (In the Linux kernel, the following vulnerability has been 
resolved:  v ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        NOTE: 
https://git.kernel.org/linus/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e (7.2-rc5)
-CVE-2026-68431 [ksmbd: validate minimum PDU size for transform requests]
+CVE-2026-68431 (In the Linux kernel, the following vulnerability has been 
resolved:  k ...)
        - linux 7.1.6-1
        [bullseye] - linux <not-affected> (Vulnerable code not present)
        NOTE: 
https://git.kernel.org/linus/cfc0b8e5080aec87700774e8568765eaa4b7b92b (7.2-rc5)
-CVE-2026-68430 [drm/amdgpu/gfx8: drop unecessary BUG_ON()]
+CVE-2026-68430 (In the Linux kernel, the following vulnerability has been 
resolved:  d ...)
        - linux 7.1.6-1
        [trixie] - linux 6.12.101-1
        NOTE: 
https://git.kernel.org/linus/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5 (7.2-rc2)
-CVE-2026-19556
+CVE-2026-19556 (Use after free in V8 in Google Chrome prior to 151.0.7922.137 
allowed  ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19557
+CVE-2026-19557 (Use after free in TabStrip in Google Chrome on Mac prior to 
151.0.7922 ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19558
+CVE-2026-19558 (Use after free in Extensions in Google Chrome prior to 
151.0.7922.137  ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19559
+CVE-2026-19559 (Use after free in HTML in Google Chrome prior to 
151.0.7922.137 allowe ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19560
+CVE-2026-19560 (Use after free in Blink in Google Chrome prior to 
151.0.7922.137 allow ...)
        - chromium <unfixed>
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9214 (Insufficient input validation vulnerability in the NETGEAR 
R7000 model ...)
@@ -766,7 +1022,7 @@ CVE-2026-65678 (Use after free in Windows Win32K allows an 
authorized attacker t
        NOT-FOR-US: Microsoft
 CVE-2026-65675 (No cwe for this issue in Visual Studio Code CoPilot Chat 
Extension all ...)
        NOT-FOR-US: Microsoft
-CVE-2026-65673 (CVET-EOP)
+CVE-2026-65673 (Entra Connect Elevation of Privilege Vulnerability)
        NOT-FOR-US: Microsoft
 CVE-2026-65672 (Heap-based buffer overflow in Windows Remote Access API allows 
an auth ...)
        NOT-FOR-US: Microsoft
@@ -10738,7 +10994,7 @@ CVE-2026-62268
        NOTE: Fixed by: 
https://github.com/borgbackup/borg/commit/3e9ed6d1ad6d3531b39c07b8ef3ecf41fce4437f
 (1.4.5)
        NOTE: Fixed by: 
https://github.com/borgbackup/borg/commit/141888f2fabcd57a300547c2aa63212cb213924d
 (1.4.5)
 CVE-2026-9672
-       {DSA-6409-1}
+       {DSA-6409-1 DLA-4731-1}
        - libgd2 2.3.3-14 (bug #1143152)
        - php8.4 8.4.24-1 (unimportant)
        [trixie] - php8.4 8.4.24-1~deb13u1
@@ -10758,14 +11014,14 @@ CVE-2026-17544 (Attacker-provided inputs to bccomp() 
could lead to an out-of-bou
        NOTE: Fixed by: 
https://github.com/php/php-src/commit/fa18dab73f9340448c0d5c0a1d75d3fec844b358 
(php-8.4.24)
        NOTE: Introduced with: 
https://github.com/php/php-src/commit/063c3c852236ecbe45ab23c0fb271b6292ce82c3 
(php-8.4.3RC1)
 CVE-2026-17543 (Improper escaping of backslashes in attacker-provided 
parameters would ...)
-       {DSA-6406-1}
+       {DSA-6406-1 DLA-4733-1 DLA-4732-1}
        - php8.4 8.4.24-1 (bug #1143153)
        - php8.2 <removed>
        - php7.4 <removed>
        NOTE: 
https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4
        NOTE: Fixed by: 
https://github.com/php/php-src/commit/53ac7025451c6481d44cf1835bb8385299a6a3a3 
(php-8.4.24)
 CVE-2026-7260 (Circular symbolic links in phar archives could lead to 
unbounded recur ...)
-       {DSA-6406-1}
+       {DSA-6406-1 DLA-4733-1 DLA-4732-1}
        - php8.4 8.4.24-1 (bug #1143153)
        - php8.2 <removed>
        - php7.4 <removed>
@@ -21169,7 +21425,7 @@ CVE-2026-10675 (In Zephyr's Bluetooth Mesh PB-ADV 
provisioning bearer (subsys/bl
 CVE-2026-10674 (The NXP LPUART serial driver 
(drivers/serial/uart_mcux_lpuart.c), when ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-47010 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6425-1 DLA-4703-1 DLA-4702-1}
+       {DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1
        - openjdk-21 21.0.12+8-1
@@ -21178,7 +21434,7 @@ CVE-2026-47010 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-8 8u502-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-46917 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6425-1 DLA-4703-1 DLA-4702-1}
+       {DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1
        - openjdk-21 21.0.12+8-1
@@ -21186,7 +21442,7 @@ CVE-2026-46917 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-11 11.0.32+9-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-47021 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6425-1 DLA-4703-1 DLA-4702-1}
+       {DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1
        - openjdk-21 21.0.12+8-1
@@ -21195,7 +21451,7 @@ CVE-2026-47021 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-8 8u502-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-47027 (Vulnerability in Oracle Java SE (component: Libraries).  
Supported ver ...)
-       {DSA-6425-1 DLA-4703-1 DLA-4702-1}
+       {DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1
        - openjdk-21 21.0.12+8-1
@@ -21204,7 +21460,7 @@ CVE-2026-47027 (Vulnerability in Oracle Java SE 
(component: Libraries).  Support
        - openjdk-8 8u502-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-47059 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6425-1 DLA-4703-1 DLA-4702-1}
+       {DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1
        - openjdk-21 21.0.12+8-1
@@ -21213,7 +21469,7 @@ CVE-2026-47059 (Vulnerability in the Oracle Java SE, 
Oracle GraalVM for JDK, Ora
        - openjdk-8 8u502-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-46968 (Vulnerability in Oracle Java SE (component: JSSE).  Supported 
versions ...)
-       {DSA-6425-1 DLA-4703-1 DLA-4702-1}
+       {DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1
        - openjdk-21 21.0.12+8-1
@@ -21222,7 +21478,7 @@ CVE-2026-46968 (Vulnerability in Oracle Java SE 
(component: JSSE).  Supported ve
        - openjdk-8 8u502-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-60147 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6425-1 DLA-4703-1 DLA-4702-1}
+       {DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1
        - openjdk-21 21.0.12+8-1
@@ -21236,7 +21492,7 @@ CVE-2026-47058 (Vulnerability in Oracle Java SE 
(component: Scripting).  Support
        - openjdk-8 8u502-ga-1
        NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-47063 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, 
Oracle Gr ...)
-       {DSA-6425-1 DLA-4703-1 DLA-4702-1}
+       {DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1
        - openjdk-21 21.0.12+8-1
@@ -89599,7 +89855,7 @@ CVE-2026-5250
 CVE-2026-4801 (The Page Builder Gutenberg Blocks \u2013 CoBlocks plugin for 
WordPress ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-41254 (Little CMS (lcms2) through 2.18 has an integer overflow in 
CubeSize in ...)
-       {DSA-6425-1 DSA-6262-1 DLA-4703-1 DLA-4702-1 DLA-4568-1}
+       {DSA-6431-1 DSA-6425-1 DSA-6262-1 DLA-4703-1 DLA-4702-1 DLA-4568-1}
        - lcms2 2.17-1.1 (bug #1134335)
        - openjdk-26 26.0.2+10-1
        - openjdk-25 25.0.4+7-1



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b920d3485ea26b00db6199cd701471222faf9c75

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b920d3485ea26b00db6199cd701471222faf9c75
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to