Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
b2bc88ba by Moritz Muehlenhoff at 2026-08-14T12:43:00+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -441,6 +441,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable 
of forging up to two
        - golang-1.26 <unfixed> (bug #1144341)
        - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-1.15 <removed>
        NOTE: https://github.com/golang/go/issues/80744
@@ -452,6 +453,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving 
arbitrary module cont
        - golang-1.26 <unfixed> (bug #1144341)
        - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-1.15 <removed>
        NOTE: https://github.com/golang/go/issues/80745
@@ -463,6 +465,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the 
depth counter causing
        - golang-1.26 <unfixed> (bug #1144341)
        - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-1.15 <removed>
        NOTE: https://github.com/golang/go/issues/80481
@@ -474,6 +477,7 @@ CVE-2026-56853 (When a server is configured to support 
unencrypted HTTP/2, it re
        - golang-1.26 <unfixed> (bug #1144341)
        - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-1.15 <removed>
        NOTE: https://github.com/golang/go/issues/80205
@@ -485,6 +489,7 @@ CVE-2026-56860 (Previously, resolving relative paths 
containing parent directory
        - golang-1.26 <unfixed> (bug #1144341)
        - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-1.15 <removed>
        NOTE: https://github.com/golang/go/issues/80494
@@ -496,6 +501,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are 
always considered as
        - golang-1.26 <unfixed> (bug #1144341)
        - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-1.15 <removed>
        NOTE: https://github.com/golang/go/issues/80528
@@ -507,6 +513,7 @@ CVE-2026-56858 (Previously, pathological inputs could close 
an unescaped '/' ear
        - golang-1.26 <unfixed> (bug #1144341)
        - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-1.15 <removed>
        NOTE: https://github.com/golang/go/issues/80435
@@ -518,6 +525,7 @@ CVE-2026-33818 (Enforce a recursion limit in Unmarshal to 
prevent stack exhausti
        - golang-1.26 <unfixed> (bug #1144341)
        - golang-1.25 <unfixed> (bug #1144342)
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-1.15 <removed>
        NOTE: https://github.com/golang/go/issues/80405
@@ -1468,15 +1476,18 @@ CVE-2026-73519 (WolfStack before 25.9.2 contains a 
hard-coded cluster-authentica
        NOT-FOR-US: WolfStack
 CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior 
to 0.144 ...)
        - golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
+       [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
        NOTE: Fixed by: 
https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da
 (v0.144.0)
 CVE-2026-73500 (etcd is a distributed key-value store for the data of a 
distributed sy ...)
        - etcd <unfixed> (bug #1144346)
+       [trixie] - etcd <no-dsa> (Minor issue)
        NOTE: 
https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
        NOTE: https://github.com/etcd-io/etcd/pull/22130
        NOTE: Fixed by: 
https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057 
(v3.5.33)
 CVE-2026-73499 (etcd is a distributed key-value store for the data of a 
distributed sy ...)
        - etcd <unfixed> (bug #1144346)
+       [trixie] - etcd <no-dsa> (Minor issue)
        NOTE: 
https://github.com/etcd-io/etcd/security/advisories/GHSA-xg4h-6gfc-h4m8
        NOTE: Fixed by: 
https://github.com/etcd-io/etcd/commit/e863b001bbf3367003a543aa3099db9892134cd7 
(v3.5.33)
 CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for 
Atlassian p ...)
@@ -2497,12 +2508,14 @@ CVE-2026-73243 (kkFileView is a universal file online 
preview project based on S
        NOT-FOR-US: kkFileView
 CVE-2026-73242 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.30.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
        NOTE: https://github.com/FreeRDP/FreeRDP/pull/13065
        NOTE: Fixed by: 
https://github.com/FreeRDP/FreeRDP/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc
 (3.30.0)
 CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop 
Protocol. Prior ...)
        - freerdp3 3.30.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6x
        NOTE: https://github.com/FreeRDP/FreeRDP/pull/13065
@@ -2657,6 +2670,7 @@ CVE-2026-19579 (Snipe-IT before 8.6.0 contains an 
authorization bypass (insecure
        - snipe-it <itp> (bug #1005172)
 CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command 
is gated  ...)
        - freeipa <unfixed>
+       [trixie] - freeipa <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2514019
 CVE-2026-19217 (The Royal Addons for Elementor  WordPress plugin before 
1.7.1065 does  ...)
        NOT-FOR-US: WordPress plugin
@@ -3154,10 +3168,12 @@ CVE-2026-72712 (Nmap versions up to and including 7.99 
contains a denial of serv
        NOTE: Crash in CLI tool, no security impact
 CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a 
root us ...)
        - mrtg <unfixed>
+       [trixie] - mrtg <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460973
        NOTE: Fixed by: 
https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269
 CVE-2026-72693 (`openvt -u` is intended to identify the owner of the current 
VT and th ...)
        - kbd <unfixed>
+       [trixie] - kbd <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462115
        NOTE: Fixed by: 
https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698 
(v2.10.0)
 CVE-2026-72610 (A stored SQL injection vulnerability in Koha through 24.11.17, 
25.05.1 ...)
@@ -5004,6 +5020,7 @@ CVE-2026-66760 (SAP Approuter does not correctly validate 
client certificates in
        NOT-FOR-US: SAP
 CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a 
process  ...)
        - libvirt 12.6.0-1
+       [trixie] - libvirt <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513065
        NOTE: Fixed by: 
https://gitlab.com/libvirt/libvirt/-/commit/801160fd414ca2cc402bc01ead09b7ed4c3b8f5b
 (v12.6.0-rc2)
 CVE-2026-5304 (An ACAP configuration file lacks input validation, which could 
potenti ...)
@@ -5445,6 +5462,7 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- 
provided by Nishishi Factory
        NOT-FOR-US: Nishishi Factory
 CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or 
convert op ...)
        - libvirt 12.6.0-1
+       [trixie] - libvirt <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513066
        NOTE: Fixed by: 
https://gitlab.com/libvirt/libvirt/-/commit/69335a484768d550854da1133d5490074695e825
 (v12.6.0-rc2)
 CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL 
injection  ...)
@@ -10725,6 +10743,7 @@ CVE-2026-18322 (The Smart Popup by Supsystic plugin for 
WordPress is vulnerable
        NOT-FOR-US: WordPress plugin
 CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with 
network access ...)
        - isc-dhcp <removed>
+       [trixie] - isc-dhcp <ignored> (ISC DHCP not covered by security support 
in Trixie)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2508081
 CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate 
Listings WordPr ...)
        NOT-FOR-US: WordPress plugin



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bc88ba0050ac79720c6c33a8992e6f77fd9502

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bc88ba0050ac79720c6c33a8992e6f77fd9502
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to