Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
46c1b148 by Moritz Muehlenhoff at 2026-08-31T17:13:27+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -283,102 +283,123 @@ CVE-2026-40463 (WaveSuite is affected by an 
insufficient role-based access contr
        NOT-FOR-US: Nokia
 CVE-2026-18054
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/1f24066fc88d33455ee54a20f29994d9e69997ba
 (v11.1.0-rc3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/5fbd2fe1cc54259d045d00d4966aa2db1ba990d6
 (v11.0.4)
 CVE-2026-15264
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/a113e0c53fb50d78529fd5ea79e3b8313a7ddcaa
 (v11.1.0-rc3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/7cd760867bdf753ac8d41c9567a1d36eb6d7aee8
 (v11.0.4)
 CVE-2026-17516
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4085
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/95687639e647ec917226e6d3a6713a2b373e1ffe
 (v11.1.0-rc3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/3ecb483c4c727d382b856c70f47ff54a68ce2bf5
 (v11.0.4)
 CVE-2026-65928
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3846
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/370882d0869567e5f21b95229a763171e319d0db
 (v11.1.0-rc3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/e00b9c9193de00f5782cb919d91eb80d255017fe
 (v11.0.4)
 CVE-2026-65929
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3844
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/0c43f801c0d7a31ef05bc22914cca0b0e28210a8
 (v11.1.0-rc3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/ffe6640f445cf27513627e9295fa3de23b000261
 (v11.0.4)
 CVE-2026-50624
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3917
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/0be94d8d9c28e6b7235b34133d057090fe93be6c
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/88a0e5e45b41d407cf9adf1f2cf6f20f394a578d
 (v11.0.4)
 CVE-2026-66022
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4073
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/df12999cc81339ffb252875608919c72ccc37bcd
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/5b105521527ec01dc7cf2f3834ddef935ab127f0
 (v11.0.4)
 CVE-2026-61402
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/733a98a552e4bd68932de1f58bd6ea39b57b261c
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/6680c5612401c1eaa49eba134d14d374fefeb9d4
 (v11.0.4)
 CVE-2026-63110
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/b9d248dfaca5e31377ea4f7204aae788a050bafd
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/82520d7759557062a5fae2211e3c79bbd5f01ed3
 (v11.0.4)
 CVE-2026-63323
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3938
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/5cc182ba39a3ca8ec9ba0576de9696be76dc087d
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/a7f027cff81c8047707d574f0e4ec57e66c63452
 (v11.0.4)
 CVE-2026-61476
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3875
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/f404bf0e6504e0412a00ea64708f17d2a5e3f869
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/a4abe1f1fa6f465b64fb400bea14c72bd5e32ac9
 (v11.0.4)
 CVE-2026-63320
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3626
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/772488562053c1299fc3667a49b3ff1858f83979
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/c159357f8c38cc4c64bacaebe8eeaf68af2a4b69
 (v11.0.4)
 CVE-2026-63321
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/a6e0519ea8ed6fc84fab9bf9ca82c7a55780f880
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/52c7bb369b23dfcafb6e6d90665c777797b55e88
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/f348425fddae38e0c1d6823501890acfb2a3bfb1
 (v11.0.4)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/9a06bb17256c0a38f0b53025bf804d2e2035f93f
 (v11.0.4)
 CVE-2026-63322
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3607
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/4727cc883b7e81d2c30b9801af54482d65b84292
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/95b9a1bf26fef7c44f4925f78ade7fa824ed5e76
 (v11.0.4)
 CVE-2026-63109
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3989
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/861372428b05f74a1cf9a8af22a863aa7b46c7ce
 (v11.1.0-rc1)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/37cec1fe0e4e14385a19e3c13012e8b06387758a
 (v11.0.4)
 CVE-2026-16288
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4039
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/bd9b3c50f458ce24fee084916cf0eba58bd9a33b
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/26d21226515b89a9039b168fd0511f1945fe8b72
 (v11.0.4)
 CVE-2026-61404
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/acba2d78176d8235b81fd886b37642ae6c464982
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/d91e0141c52b0f39c8d0cb4b0f1cbb0d9aee6550
 (v11.0.4)
 CVE-2026-61405
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3890
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/8e0ddb4a6ebd1c3d2dfd067f82b6d92de5b23e30
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/a7d7f39ddb6abf4cec8e6eed94599065855137bd
 (v11.0.4)
 CVE-2026-61406
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3899
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/647ba95eda5a21518f84c6593ed97e0447f38a90
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/550725189217c23b31de47d917135303981c1f7c
 (v11.0.4)
 CVE-2026-58582
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3615
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/ff5a9eb13c862ed274ea0d0682a6573411e31543
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/db51779dc442cab2d95d64795b0cec64da4d47b2
 (v11.0.4)
 CVE-2026-58581
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3614
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/702216619e2a1afd5039520114f4d245d7011f09
 (v11.1.0-rc2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/e0397dbe1a295e037f16f154aaaa3cff3341fc3d
 (v11.0.4)
@@ -1065,6 +1086,7 @@ CVE-2026-82247 (gitoxide's gix-url crate (<= 0.32.0, 
fixed in 0.37.1) uses a han
        - rust-gix-url 0.37.1-1
        [trixie] - rust-gix-url <no-dsa> (Minor issue)
        - rust-gix-transport 0.58.1-1
+       [trixie] - rust-gix-transport <no-dsa> (Minor issue)
        NOTE: 
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-jrcm-326h-gpp8
 CVE-2026-82246 (Budibase Server before 3.41.3 contains a server-side request 
forgery v ...)
        NOT-FOR-US: Budibase
@@ -6330,6 +6352,7 @@ CVE-2026-15310 (When decompressing crafted zip files 
using the bzip/LZMA/Zstanda
        - python3.15 <unfixed>
        - python3.14 <unfixed>
        - python3.13 <unfixed>
+       [trixie] - python3.13 <no-dsa> (Minor issue)
        - python3.11 <removed>
        - python3.9 <removed>
        NOTE: 
https://mail.python.org/archives/list/[email protected]/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/
@@ -6812,6 +6835,7 @@ CVE-2026-78378 (Ransomlook contains a Redis glob pattern 
injection vulnerability
        NOT-FOR-US: RansomLook
 CVE-2026-78376 (A flaw was found in WebKitGTK. Processing malicious web 
content can ca ...)
        - webkit2gtk <unfixed>
+       [trixie] - webkit2gtk <postponed> (Fix along with future DSA)
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        [bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
        - wpewebkit <unfixed>


=====================================
data/dsa-needed.txt
=====================================
@@ -26,7 +26,7 @@ bouncycastle
 cacti
   probably best to move to 1.2.31
 --
-chromum (dilinger)
+chromium (dilinger)
 --
 containerd
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/46c1b14867605cfc40e1c32f6280965bca350248

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/46c1b14867605cfc40e1c32f6280965bca350248
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to