Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
46c1b148 by Moritz Muehlenhoff at 2026-08-31T17:13:27+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -283,102 +283,123 @@ CVE-2026-40463 (WaveSuite is affected by an
insufficient role-based access contr
NOT-FOR-US: Nokia
CVE-2026-18054
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/1f24066fc88d33455ee54a20f29994d9e69997ba
(v11.1.0-rc3)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/5fbd2fe1cc54259d045d00d4966aa2db1ba990d6
(v11.0.4)
CVE-2026-15264
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/a113e0c53fb50d78529fd5ea79e3b8313a7ddcaa
(v11.1.0-rc3)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/7cd760867bdf753ac8d41c9567a1d36eb6d7aee8
(v11.0.4)
CVE-2026-17516
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4085
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/95687639e647ec917226e6d3a6713a2b373e1ffe
(v11.1.0-rc3)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/3ecb483c4c727d382b856c70f47ff54a68ce2bf5
(v11.0.4)
CVE-2026-65928
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3846
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/370882d0869567e5f21b95229a763171e319d0db
(v11.1.0-rc3)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/e00b9c9193de00f5782cb919d91eb80d255017fe
(v11.0.4)
CVE-2026-65929
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3844
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/0c43f801c0d7a31ef05bc22914cca0b0e28210a8
(v11.1.0-rc3)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/ffe6640f445cf27513627e9295fa3de23b000261
(v11.0.4)
CVE-2026-50624
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3917
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/0be94d8d9c28e6b7235b34133d057090fe93be6c
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/88a0e5e45b41d407cf9adf1f2cf6f20f394a578d
(v11.0.4)
CVE-2026-66022
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4073
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/df12999cc81339ffb252875608919c72ccc37bcd
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/5b105521527ec01dc7cf2f3834ddef935ab127f0
(v11.0.4)
CVE-2026-61402
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/733a98a552e4bd68932de1f58bd6ea39b57b261c
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/6680c5612401c1eaa49eba134d14d374fefeb9d4
(v11.0.4)
CVE-2026-63110
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/b9d248dfaca5e31377ea4f7204aae788a050bafd
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/82520d7759557062a5fae2211e3c79bbd5f01ed3
(v11.0.4)
CVE-2026-63323
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3938
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/5cc182ba39a3ca8ec9ba0576de9696be76dc087d
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/a7f027cff81c8047707d574f0e4ec57e66c63452
(v11.0.4)
CVE-2026-61476
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3875
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/f404bf0e6504e0412a00ea64708f17d2a5e3f869
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/a4abe1f1fa6f465b64fb400bea14c72bd5e32ac9
(v11.0.4)
CVE-2026-63320
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3626
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/772488562053c1299fc3667a49b3ff1858f83979
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/c159357f8c38cc4c64bacaebe8eeaf68af2a4b69
(v11.0.4)
CVE-2026-63321
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/a6e0519ea8ed6fc84fab9bf9ca82c7a55780f880
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/52c7bb369b23dfcafb6e6d90665c777797b55e88
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/f348425fddae38e0c1d6823501890acfb2a3bfb1
(v11.0.4)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/9a06bb17256c0a38f0b53025bf804d2e2035f93f
(v11.0.4)
CVE-2026-63322
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3607
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/4727cc883b7e81d2c30b9801af54482d65b84292
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/95b9a1bf26fef7c44f4925f78ade7fa824ed5e76
(v11.0.4)
CVE-2026-63109
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3989
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/861372428b05f74a1cf9a8af22a863aa7b46c7ce
(v11.1.0-rc1)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/37cec1fe0e4e14385a19e3c13012e8b06387758a
(v11.0.4)
CVE-2026-16288
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4039
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/bd9b3c50f458ce24fee084916cf0eba58bd9a33b
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/26d21226515b89a9039b168fd0511f1945fe8b72
(v11.0.4)
CVE-2026-61404
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/acba2d78176d8235b81fd886b37642ae6c464982
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/d91e0141c52b0f39c8d0cb4b0f1cbb0d9aee6550
(v11.0.4)
CVE-2026-61405
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3890
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/8e0ddb4a6ebd1c3d2dfd067f82b6d92de5b23e30
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/a7d7f39ddb6abf4cec8e6eed94599065855137bd
(v11.0.4)
CVE-2026-61406
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3899
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/647ba95eda5a21518f84c6593ed97e0447f38a90
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/550725189217c23b31de47d917135303981c1f7c
(v11.0.4)
CVE-2026-58582
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3615
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/ff5a9eb13c862ed274ea0d0682a6573411e31543
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/db51779dc442cab2d95d64795b0cec64da4d47b2
(v11.0.4)
CVE-2026-58581
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3614
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/702216619e2a1afd5039520114f4d245d7011f09
(v11.1.0-rc2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/e0397dbe1a295e037f16f154aaaa3cff3341fc3d
(v11.0.4)
@@ -1065,6 +1086,7 @@ CVE-2026-82247 (gitoxide's gix-url crate (<= 0.32.0,
fixed in 0.37.1) uses a han
- rust-gix-url 0.37.1-1
[trixie] - rust-gix-url <no-dsa> (Minor issue)
- rust-gix-transport 0.58.1-1
+ [trixie] - rust-gix-transport <no-dsa> (Minor issue)
NOTE:
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-jrcm-326h-gpp8
CVE-2026-82246 (Budibase Server before 3.41.3 contains a server-side request
forgery v ...)
NOT-FOR-US: Budibase
@@ -6330,6 +6352,7 @@ CVE-2026-15310 (When decompressing crafted zip files
using the bzip/LZMA/Zstanda
- python3.15 <unfixed>
- python3.14 <unfixed>
- python3.13 <unfixed>
+ [trixie] - python3.13 <no-dsa> (Minor issue)
- python3.11 <removed>
- python3.9 <removed>
NOTE:
https://mail.python.org/archives/list/[email protected]/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/
@@ -6812,6 +6835,7 @@ CVE-2026-78378 (Ransomlook contains a Redis glob pattern
injection vulnerability
NOT-FOR-US: RansomLook
CVE-2026-78376 (A flaw was found in WebKitGTK. Processing malicious web
content can ca ...)
- webkit2gtk <unfixed>
+ [trixie] - webkit2gtk <postponed> (Fix along with future DSA)
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
- wpewebkit <unfixed>
=====================================
data/dsa-needed.txt
=====================================
@@ -26,7 +26,7 @@ bouncycastle
cacti
probably best to move to 1.2.31
--
-chromum (dilinger)
+chromium (dilinger)
--
containerd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/46c1b14867605cfc40e1c32f6280965bca350248
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/46c1b14867605cfc40e1c32f6280965bca350248
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits