Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
0843f80b by Salvatore Bonaccorso at 2026-08-20T18:59:21+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3641,7 +3641,7 @@ CVE-2026-75912 (CodeWhale versions before 0.8.64 contain 
an argument injection v
 CVE-2026-75911 (CodeWhale versions before 0.8.64 fail to properly validate the 
allow_s ...)
        NOT-FOR-US: CodeWhale
 CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in 
pat_smplo ...)
-       - libmodplug <unfixed>
+       - libmodplug <unfixed> (bug #1144933)
        NOTE: https://github.com/Konstanty/libmodplug/issues/103
 CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery 
vulnerabi ...)
        NOT-FOR-US: RAGFlow
@@ -5215,7 +5215,7 @@ CVE-2026-71567 (Inopenshift-metal3/fakefish there is a 
repeated pattern in some
 CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to 
scripts ...)
        NOT-FOR-US: FakeFish
 CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
-       - sqlparse <unfixed>
+       - sqlparse <unfixed> (bug #1144932)
        NOTE: 
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
        NOTE: Fixed by: 
https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87
 (0.6.0)
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial 
intellig ...)
@@ -5289,11 +5289,11 @@ CVE-2026-59902 (Netty is an asynchronous, event-driven 
network application frame
        NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
        NOTE: Fixed by: 
https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 
(netty-4.2.17.Final)
 CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
-       - sqlparse <unfixed>
+       - sqlparse <unfixed> (bug #1144932)
        NOTE: 
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x
        NOTE: Fixed by: 
https://github.com/andialbrecht/sqlparse/commit/53ff44b53e27cff78259acc1af015506fea60f63
 (0.6.0)
 CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
-       - sqlparse <unfixed>
+       - sqlparse <unfixed> (bug #1144932)
        NOTE: 
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
        NOTE: Fixed by: 
https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e
 (0.6.0)
 CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
@@ -5315,7 +5315,7 @@ CVE-2026-55704 (Discourse is an open-source discussion 
platform. Prior o 2026.1.
 CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
        NOT-FOR-US: Discourse
 CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
-       - sqlparse <unfixed>
+       - sqlparse <unfixed> (bug #1144932)
        NOTE: 
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f
        NOTE: Fixed by: 
https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f
 (0.6.0)
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 
2026.1.6, 20 ...)
@@ -5379,7 +5379,7 @@ CVE-2026-19999 (A security vulnerability has been 
detected in Open Asset Import
 CVE-2026-19998 (A weakness has been identified in code-projects Online 
Shopping System ...)
        NOT-FOR-US: code-projects
 CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent 
directory ...)
-       - node-extract-zip <unfixed>
+       - node-extract-zip <unfixed> (bug #1144934)
        NOTE: https://github.com/max-mapper/extract-zip/pull/160
 CVE-2026-18674 (On a Kong Mesh global control plane, resources received over 
the zone- ...)
        TODO: check
@@ -5566,14 +5566,14 @@ CVE-2026-66798
 CVE-2026-66797
        NOT-FOR-US: Red Hat cluster-backup-operator
 CVE-2026-18725
-       - open-iscsi <unfixed>
+       - open-iscsi <unfixed> (bug #1144935)
        [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462023
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
        NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
        NOTE: Fixed by: 
https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
 CVE-2026-18724
-       - open-iscsi <unfixed>
+       - open-iscsi <unfixed> (bug #1144935)
        [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2461994
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
@@ -12706,21 +12706,21 @@ CVE-2026-18749 (The type=track branch authorises on 
_is_my_case(t_attach.case) o
 CVE-2026-18744 (Any authenticated case participant can fetch any OTHER 
vendor's CaseSt ...)
        NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow 
vulnerability in  ...)
-       - open-iscsi <unfixed>
+       - open-iscsi <unfixed> (bug #1144935)
        [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2463029
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
        NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
        NOTE: Fixed by: 
https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
 CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This 
vulnerabilit ...)
-       - open-iscsi <unfixed>
+       - open-iscsi <unfixed> (bug #1144935)
        [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462956
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
        NOTE: https://github.com/open-iscsi/open-iscsi/pull/544
        NOTE: Fixed by: 
https://github.com/open-iscsi/open-iscsi/commit/0bdc1ab6718215e67a4acff1e711fc8c6693cff4
 CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a 
remote att ...)
-       - open-iscsi <unfixed>
+       - open-iscsi <unfixed> (bug #1144935)
        [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462331
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0843f80bfb570e23a8762052dde2f34e31d4b920

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0843f80bfb570e23a8762052dde2f34e31d4b920
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to