Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
288a1044 by Moritz Muehlenhoff at 2026-09-04T19:49:16+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -343,12 +343,15 @@ CVE-2026-81738
        - openvpn <not-affected> (Only affects OpenVPN on Windows)
 CVE-2026-71198
        - glance 2:32.0.0-4 (bug #1146594)
+       [trixie] - glance <no-dsa> (Minor issue)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-71197
        - glance 2:32.0.0-4 (bug #1146594)
+       [trixie] - glance <no-dsa> (Minor issue)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-71196
        - glance 2:32.0.0-4 (bug #1146594)
+       [trixie] - glance <no-dsa> (Minor issue)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users 
having acc ...)
        NOT-FOR-US: Hitachi Energy
@@ -564,6 +567,7 @@ CVE-2026-84970 (A numeric truncation weakness exists in the 
JSON parsing compone
        NOTE: https://jira.mongodb.org/browse/CXX-3547
 CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers 
of the  ...)
        - mongo-c-driver 2.5.2-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6410
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/4229afa3bb4d0842edd5ee8da0f5143bd563e0bd
 (2.5.2)
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6
 (1.30.9)
@@ -578,14 +582,17 @@ CVE-2026-84966 (An incorrect numeric type conversion in 
the BSON document buildi
        NOTE: https://jira.mongodb.org/browse/CXX-3548
 CVE-2026-84965 (An integer wraparound in an allocation size calculation in the 
BSON li ...)
        - mongo-c-driver 2.5.2-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6405
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/8a4c4416a171b66a3eb0b136f844c62ca9e36025
 (2.5.2)
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/aba72444f8e8950b8a57636b1ad72a5a853f8264
 (1.30.9)
 CVE-2026-84964 (A double free in the OpenSSL-based TLS certificate revocation 
checking ...)
        - mongo-c-driver 2.5.2-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6409
 CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component 
of the M ...)
        - mongo-c-driver 2.5.2-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6407
 CVE-2026-84962 (An unauthorized user with key vault write access may cause an 
authoriz ...)
        - libmongocrypt 1.20.2-1
@@ -1732,6 +1739,7 @@ CVE-2026-84309 (pypdf is a free and open-source 
pure-python PDF library. Prior t
 CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to 
3.0.57 and  ...)
        - php-phpseclib4 4.0.1-1
        - php-phpseclib3 3.0.57-1
+       [trixie] - php-phpseclib3 <no-dsa> (Minor issue)
        - php-phpseclib <not-affected> (Vulnerable code not present)
        - phpseclib <not-affected> (Vulnerable code not present)
        NOTE: 
https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6
@@ -2212,6 +2220,7 @@ CVE-2026-73553
        - envoyproxy <itp> (bug #987544)
 CVE-2026-16658
        - ansible <unfixed> (bug #1146701)
+       [trixie] - ansible <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506209
 CVE-2026-84353 (Use after free in Shared Tab Groups in Google Chrome on on 
Android pri ...)
        {DSA-6482-1}
@@ -2317,6 +2326,7 @@ CVE-2026-8712 (Wyoming before 1.10.2 contains a 
server-side request forgery vuln
        NOT-FOR-US: Wyoming
 CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. 
Prior to 0. ...)
        - sqlparse <unfixed> (bug #1146628)
+       [trixie] - sqlparse <no-dsa> (Minor issue)
        NOTE: 
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
        NOTE: Fixed by: 
https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b
 (0.6.0)
 CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 
1.83.1, in ...)
@@ -5077,6 +5087,7 @@ CVE-2026-76581 (The WPMU DEV Dashboard plugin for 
WordPress is vulnerable to Aut
        NOT-FOR-US: WordPress plugin
 CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard 
library al ...)
        - elixir-lang <unfixed> (bug #1146626)
+       [trixie] - elixir-lang <no-dsa> (Minor issue)
        [bookworm] - elixir-lang <not-affected> (Vulnerable code introduced 
later)
        NOTE: 
https://github.com/elixir-lang/elixir/security/advisories/GHSA-jf5q-v438-665c
        NOTE: https://cna.erlef.org/cves/CVE-2026-75758.html


=====================================
data/dsa-needed.txt
=====================================
@@ -152,6 +152,8 @@ sabnzbdplus
 --
 shaarli
 --
+slurm-wlm
+--
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/288a1044518efa98669ea5ba257da697ca7caec7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/288a1044518efa98669ea5ba257da697ca7caec7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to