Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
2a34e31f by Moritz Muehlenhoff at 2026-08-12T13:35:47+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1924,21 +1924,21 @@ CVE-2026-20770 (Protection mechanism failure for some 
Cluster Management Toolkit
 CVE-2026-20769 (Improper conditions check for the Intel(R) NPU Driver for all 
versions ...)
        TODO: check
 CVE-2026-20765 (Incorrect comparison for some Intel(R) TDX Guest software 
before versi ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20763 (Incorrect calculation for some Intel(R) TDX Guest software 
before vers ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20755 (Protection mechanism failure for some LLM Scaler software 
within Ring  ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20752 (Improper authentication for some Intel(R) PROSet/Wireless WiFi 
Softwar ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20749 (Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi 
Software wit ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20747 (Improper conditions check for some Intel(R) PROSet/Wireless 
WiFi Softw ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20745 (Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi 
Software fo ...)
        NOT-FOR-US: Intel
 CVE-2026-20741 (Improper access control for some Intel(R) PROSet/Wireless WiFi 
Softwar ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20739 (Improper conditions check for some Intel(R) PROSet/Wireless 
WiFi Softw ...)
        NOT-FOR-US: Intel
 CVE-2026-20737 (Exposure of sensitive information to an unauthorized actor for 
some In ...)
@@ -1948,13 +1948,13 @@ CVE-2026-20734 (Improper initialization in some 
firmware for some Intel(R) Activ
 CVE-2026-20731 (Improper buffer restrictions for the Intel(R) NPU Driver for 
all versi ...)
        TODO: check
 CVE-2026-20728 (Protection mechanism failure for some Intel Extension for 
TensorFlow s ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20727 (Null pointer dereference for some Intel(R) PROSet/Wireless 
WiFi Softwa ...)
        NOT-FOR-US: Intel
 CVE-2026-20715 (Improper input validation in some firmware for some Intel(R) 
Active Ma ...)
        TODO: check
 CVE-2026-20712 (Incomplete cleanup in some UEFI firmware for some Intel(R) 
reference p ...)
-       TODO: check
+       NOT-FOR-US: Intel
 CVE-2026-20708 (Insertion of sensitive information into log file in the 
subsystem for  ...)
        TODO: check
 CVE-2026-20705 (Insecure storage of sensitive information in the Intel(R) TDX 
module f ...)
@@ -1968,17 +1968,17 @@ CVE-2026-19546 (A flaw was found in DBI. This is a fix 
for a partial fix for CVE
 CVE-2026-19539 (Authorization Bypass Through User-Controlled Key in the ticket 
managem ...)
        TODO: check
 CVE-2026-19519 (A flaw was found in claircore's RPM package scanner. Crafted 
RPM heade ...)
-       TODO: check
+       NOT-FOR-US: claircore
 CVE-2026-19434 (Cross-site Scripting in the finding renderer in maalfer 
Pentestify bef ...)
-       TODO: check
+       NOT-FOR-US: Pentestify
 CVE-2026-19418 (The referrer enforcement introduced with 
TYPO3-CORE-SA-2020-006 (CVE-2 ...)
        NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-19078 (A flaw was found in the oauth-server component. This open 
redirect vul ...)
-       TODO: check
+       NOT-FOR-US: Red Hat OpenShift Container Platform 4
 CVE-2026-18972 (An authenticated attacker can spoof another GUI user's 
identity by sen ...)
-       TODO: check
+       NOT-FOR-US: Velociraptor
 CVE-2026-18860 (Velociraptor allows multi-tenant deployments named "Orgs".  By 
default ...)
-       TODO: check
+       NOT-FOR-US: Velociraptor
 CVE-2026-18712 (An issue in MongoDB Server's Queryable Encryption maintenance 
operatio ...)
        - mongodb <removed>
 CVE-2026-18711 (An issue in MongoDB Server's query execution engine could 
allow an aut ...)
@@ -2028,7 +2028,7 @@ CVE-2026-18688 (An issue in MongoDB Server's aggregation 
framework could allow a
 CVE-2026-18687 (MongoDB Server's handling of a Queryable Encryption 
maintenance operat ...)
        - mongodb <removed>
 CVE-2026-18640 (The NewNotebook API does not sufficiently sanitize its 
parameters allo ...)
-       TODO: check
+       NOT-FOR-US: Velociraptor
 CVE-2026-18639 (When Velociraptor is configured to use an OIDC IdP for 
authentication, ...)
        NOT-FOR-US: Velociraptor
 CVE-2026-18638 (Any authenticated Velociraptor user \u2014 including one 
holding only  ...)
@@ -2054,17 +2054,17 @@ CVE-2026-15567 (A flaw was found in Wildfly. A remote 
unauthenticated attacker c
 CVE-2026-15565 (A flaw was found in Undertow. A remote attacker can cause Out 
of Memor ...)
        TODO: check
 CVE-2026-15563 (A flaw was found in EAP's IIOP. The listener's NameService 
would accep ...)
-       TODO: check
+       NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15562 (A flaw was found in EAP's jboss-remoting. A remote 
unauthenticated att ...)
-       TODO: check
+       NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15561 (A flaw was found in EAP's undertow http/1.1 chunked-transfer 
decoder.  ...)
        TODO: check
 CVE-2026-15560 (when EAP runs with -secmgr, the openjdk-orb's JDKBridge 
honours attack ...)
-       TODO: check
+       NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15556 (A flaw was found in Picketlink's SP signature validation; a 
SAML respo ...)
-       TODO: check
+       NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15555 (A flaw was found in JBoss marshalling. The Infinispan session 
replicat ...)
-       TODO: check
+       NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15554 (the Undertow AJP listener honours forged ssl_cert and is_ssl 
AJP attri ...)
        TODO: check
 CVE-2026-15426 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and 
Marketing Auto ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a34e31f9f4bd6b75777bcb81befbb970a88c4a4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a34e31f9f4bd6b75777bcb81befbb970a88c4a4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to