Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4d7627ae by Moritz Muehlenhoff at 2026-09-03T15:56:37+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -33,9 +33,11 @@ CVE-2026-84839 (A vulnerability was determined in tsi-coop 
tsi-dpdp-cms up to 0.
        NOT-FOR-US: tsi-coop tsi-dpdp-cms
 CVE-2026-84838 (A flaw was found in rpmuncompress. This command injection 
vulnerabilit ...)
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462222
 CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command 
injection v ...)
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478408
 CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst 
allows Expl ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -631,6 +633,7 @@ CVE-2026-84367 (joi is a schema description language and 
data validator for Java
        NOT-FOR-US: Node joi
 CVE-2026-84366 (Scrapy is a high-level web crawling and scraping framework for 
Python. ...)
        - python-scrapy 2.17.0-1
+       [trixie] - python-scrapy <no-dsa> (Minor issue)
        NOTE: 
https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx
        NOTE: Fixed by: 
https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b
 (2.17.0)
 CVE-2026-84365 (Hono is a Web application framework that provides support for 
any Java ...)
@@ -647,6 +650,7 @@ CVE-2026-84361 (Composer is a dependency Manager for the 
PHP language. From 1.0
        NOTE: Fixed by: 
https://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af
 (2.2.30)
 CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.16 ...)
        - pypdf <unfixed>
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
        NOTE: https://github.com/py-pdf/pypdf/pull/3964
@@ -1052,16 +1056,19 @@ CVE-2026-80229
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb 
(rc-8_22_0-3)
 CVE-2026-19931
        - curl 8.22.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-19931.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59 
(curl-7_64_1)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f 
(rc-8_22_0-2)
 CVE-2026-18924
        - curl 8.22.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-18924.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/ea7134ac874a66107e54ff93657ac565cf2ec4aa 
(curl-7_44_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43 
(rc-8_22_0-1)
 CVE-2026-13608
        - curl 8.22.0~rc2-1
+       [trixie] - curl <no-dsa> (Minor issue)
        NOTE: https://curl.se/docs/CVE-2026-13608.html
        NOTE: Introduced with: 
https://github.com/curl/curl/commit/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 
(curl-7_82_0)
        NOTE: Fixed by: 
https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519 
(rc-8_22_0-1)
@@ -1071,11 +1078,13 @@ CVE-2026-84373 (Vitest is a testing framework powered 
by Vite. From 2.1.0 until
        NOT-FOR-US: Vitest
 CVE-2026-84311 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.16 ...)
        - pypdf <unfixed> (bug #1146476)
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527050
        TODO: check upstream references
 CVE-2026-84310 (pypdf is a free and open-source pure-python PDF library. Prior 
to 6.16 ...)
        - pypdf <unfixed> (bug #1146476)
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527049
        TODO: check upstream references
@@ -1919,6 +1928,7 @@ CVE-2026-83743 (A weakness has been identified in 
invoiceninja Invoice Ninja up
        NOT-FOR-US: invoiceninja Invoice Ninja
 CVE-2026-83596 (A flaw was found in WebKitGTK. Processing malicious web 
content can ca ...)
        - webkit2gtk <unfixed>
+       [trixie] - webkit2gtk <postponed> (Fix along with future DSA)
        [bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
        - wpewebkit <unfixed>
        [trixie] - wpewebkit <ignored> (wpewebkit not covered by security 
support in Trixie)


=====================================
data/dsa-needed.txt
=====================================
@@ -138,7 +138,7 @@ ruby3.3
 --
 ruby-oj
 --
-ruby-rack
+ruby-rack (jmm)
 --
 ruby-rack-session
 --
@@ -154,6 +154,8 @@ shaarli
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --
+spip
+--
 thunderbird (jmm)
 --
 tomcat10



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d7627ae8cabebc680ef290a62f96b6cde6532b7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d7627ae8cabebc680ef290a62f96b6cde6532b7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to