Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8d46a9e4 by Moritz Muehlenhoff at 2026-08-16T22:26:30+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -48,11 +48,13 @@ CVE-2024-13784 (The Contact Form, Survey, Quiz & Popup Form
Builder \u2013 ARFor
NOT-FOR-US: WordPress plugin
CVE-2026-72888 (Net::OAuth versions before 0.32 for Perl allow memory
exhaustion via u ...)
- libnet-oauth-perl 0.32-1 (bug #1144539)
+ [trixie] - libnet-oauth-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42733455/
NOTE:
https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-m2cv-cq5x-47ph
NOTE: Fixed by:
https://github.com/vurtdev/Net-OAuth/commit/ee713fc96263c70b3b9a5280612618b474576f8f
CVE-2026-72887 (Net::OAuth::Client versions before 0.32 for Perl allow the
service pro ...)
- libnet-oauth-perl 0.32-1 (bug #1144539)
+ [trixie] - libnet-oauth-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42733454/
NOTE:
https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-jh72-4qq2-8j6g
NOTE: Fixed by:
https://github.com/vurtdev/Net-OAuth/commit/fd505dac1988723ed96721657663f2e4ac731644
@@ -4948,12 +4950,15 @@ CVE-2026-72819 (Grav CMS before 2.0.13 contains a
remote code execution vulnerab
NOT-FOR-US: Grav CMS
CVE-2026-72817 (go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing
vulnera ...)
- golang-github-go-chi-chi 5.3.0-1
+ [trixie] - golang-github-go-chi-chi <no-dsa> (Minor issue)
NOTE:
https://github.com/go-chi/chi/security/advisories/GHSA-9g5q-2w5x-hmxf
CVE-2026-72816 (go-chi/chi through 5.2.1 contains an IP spoofing vulnerability
in the ...)
- golang-github-go-chi-chi 5.3.0-1
+ [trixie] - golang-github-go-chi-chi <no-dsa> (Minor issue)
NOTE:
https://github.com/go-chi/chi/security/advisories/GHSA-rjr7-jggh-pgcp
CVE-2026-72815 (go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP
spoofing v ...)
- golang-github-go-chi-chi 5.3.0-1
+ [trixie] - golang-github-go-chi-chi <no-dsa> (Minor issue)
NOTE:
https://github.com/go-chi/chi/security/advisories/GHSA-3fxj-6jh8-hvhx
CVE-2026-72814 (The actix-files crate (actix_files) before version 0.6.10
contains an ...)
- rust-actix-files <not-affected> (Fixed with initial upload to Debian)
@@ -5009,6 +5014,7 @@ CVE-2026-48528 (Metacat is data repository software that
helps researchers prese
NOT-FOR-US: Metacat
CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an
excessive amo ...)
- golang-golang-x-image <unfixed> (bug #1144496)
+ [trixie] - golang-golang-x-image <no-dsa> (Minor issue)
NOTE: https://github.com/golang/go/issues/80069
NOTE: Fixed by:
https://github.com/golang/image/commit/981eaa05a5065f5dd09c3139029c0d7dbda956d8
(v0.45.0)
CVE-2026-46439 (compliance-trestle is a tooling platform for managing
compliance as co ...)
@@ -5141,6 +5147,7 @@ CVE-2026-XXXX [RUSTSEC-2025-0167]
NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0167.html
CVE-2026-XXXX [RUSTSEC-2026-0213]
- rust-ammonia 4.1.4-1
+ [trixie] - rust-ammonia <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0213.html
CVE-2026-XXXX [RUSTSEC-2026-0223]
- rust-wasmtime <not-affected> (Only affects 46.0.0 and later)
@@ -5150,6 +5157,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0222]
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0222.html
CVE-2026-XXXX [RUSTSEC-2026-0244]
- rust-gettext-rs <unfixed> (bug #1144394)
+ [trixie] - rust-gettext-rs <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0244.html
NOTE: https://github.com/gettext-rs/gettext-rs/issues/64
CVE-2026-XXXX [RUSTSEC-2026-0218]
@@ -5158,6 +5166,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0218]
NOTE: https://github.com/rustsec/advisory-db/issues/3060
CVE-2026-XXXX [RUSTSEC-2026-0221]
- rust-event-listener 5.4.2+ds-1 (bug #1144395)
+ [trixie] - rust-event-listener <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0221.html
NOTE: https://github.com/smol-rs/event-listener/pull/163
CVE-2026-12876
@@ -5173,11 +5182,13 @@ CVE-2026-XXXX [RUSTSEC-2026-0257]
NOTE:
https://github.com/amodm/webbrowser-rs/commit/31d1b924885551c0e553909d27c738ca6958a0f3
(v1.2.2)
CVE-2026-XXXX [RUSTSEC-2026-0253]
- rust-lru <unfixed> (bug #1144397)
+ [trixie] - rust-lru <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0253.html
NOTE: https://github.com/jeromefroe/lru-rs/pull/238
NOTE:
https://github.com/jeromefroe/lru-rs/commit/2776ded569ee89a99c515bca8194f65639182c96
(0.18.2)
CVE-2026-XXXX [RUSTSEC-2026-0256]
- rust-circular-buffer <unfixed> (bug #1144398)
+ [trixie] - rust-circular-buffer <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0256.html
CVE-2026-XXXX [RUSTSEC-2026-0255]
- rust-sized-chunks <unfixed> (bug #1144399)
@@ -5231,10 +5242,11 @@ CVE-2026-73489 (Russh is a Rust SSH client & server
library. Prior to 0.62.4, an
NOTE:
https://github.com/Eugeny/russh/security/advisories/GHSA-cqjc-rmpq-xprq
NOTE: Fixed by:
https://github.com/Eugeny/russh/commit/8912512371820167a12a0a638bd666856ce458ad
(v0.62.4)
CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory
and file n ...)
- - gdu <unfixed> (bug #1144461)
+ - gdu <unfixed> (bug #1144461; unimportant)
NOTE: https://github.com/dundee/gdu/issues/615
NOTE: https://github.com/dundee/gdu/pull/616
NOTE: Fixed by:
https://github.com/dundee/gdu/commit/5d76fab735f190fd645896de90ac9982b6382aeb
+ NOTE: Not considered a security issue, needs to be correctly handled in
the terminal emulators
CVE-2026-73479 (dua-cli fails to filter terminal escape sequences when
printing marked ...)
NOT-FOR-US: dua-cli
CVE-2026-73428 (Trix is a what-you-see-is-what-you-get rich text editor for
everyday w ...)
@@ -7230,6 +7242,7 @@ CVE-2026-73296 (Microsoft UFO open-source framework for
intelligent automation a
NOT-FOR-US: Microsoft UFO
CVE-2026-73295 (Material for MkDocs is a powerful documentation framework
built on top ...)
- mkdocs-material <unfixed> (bug #1144348)
+ [trixie] - mkdocs-material <no-dsa> (Minor issue)
NOTE:
https://github.com/squidfunk/mkdocs-material/security/advisories/GHSA-xvg9-69gf-fjrf
NOTE: Fixed by:
https://github.com/squidfunk/mkdocs-material/commit/52fb6be8aafe326419f34dc94d3211e7bbfbfb25
(9.7.7)
CVE-2026-73294 (Semaphore UI is a web interface for managing DevOps tools.
Prior to 2. ...)
@@ -7612,6 +7625,7 @@ CVE-2026-XXXX [OSSN-0106: API ramdisk endpoints require
network-level access con
NOTE: https://bugs.launchpad.net/ironic/+bug/2162818
CVE-2026-XXXX [OSSN-0105: OpenStack Glance legacy Tasks import bypasses image
import URI filtering]
- glance 2:32.0.0-3 (bug #1144212)
+ [trixie] - glance <no-dsa> (Minor issue)
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0105
NOTE: https://bugs.launchpad.net/glance/+bug/2152110
CVE-2026-12061
=====================================
data/dsa-needed.txt
=====================================
@@ -76,6 +76,8 @@ linux (carnil)
Wait until more issues have piled up, though try to regulary rebase for point
releases to more 6.12.y versions
--
+lxd
+--
nats-server
maybe move to 2.12.2 if sufficiently backwards compatible
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d46a9e4f3d22671fb374944a2ba27d67414912d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8d46a9e4f3d22671fb374944a2ba27d67414912d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits