Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
288a1044 by Moritz Muehlenhoff at 2026-09-04T19:49:16+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -343,12 +343,15 @@ CVE-2026-81738
- openvpn <not-affected> (Only affects OpenVPN on Windows)
CVE-2026-71198
- glance 2:32.0.0-4 (bug #1146594)
+ [trixie] - glance <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-71197
- glance 2:32.0.0-4 (bug #1146594)
+ [trixie] - glance <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-71196
- glance 2:32.0.0-4 (bug #1146594)
+ [trixie] - glance <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users
having acc ...)
NOT-FOR-US: Hitachi Energy
@@ -564,6 +567,7 @@ CVE-2026-84970 (A numeric truncation weakness exists in the
JSON parsing compone
NOTE: https://jira.mongodb.org/browse/CXX-3547
CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers
of the ...)
- mongo-c-driver 2.5.2-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6410
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/4229afa3bb4d0842edd5ee8da0f5143bd563e0bd
(2.5.2)
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6
(1.30.9)
@@ -578,14 +582,17 @@ CVE-2026-84966 (An incorrect numeric type conversion in
the BSON document buildi
NOTE: https://jira.mongodb.org/browse/CXX-3548
CVE-2026-84965 (An integer wraparound in an allocation size calculation in the
BSON li ...)
- mongo-c-driver 2.5.2-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6405
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/8a4c4416a171b66a3eb0b136f844c62ca9e36025
(2.5.2)
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/aba72444f8e8950b8a57636b1ad72a5a853f8264
(1.30.9)
CVE-2026-84964 (A double free in the OpenSSL-based TLS certificate revocation
checking ...)
- mongo-c-driver 2.5.2-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6409
CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component
of the M ...)
- mongo-c-driver 2.5.2-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6407
CVE-2026-84962 (An unauthorized user with key vault write access may cause an
authoriz ...)
- libmongocrypt 1.20.2-1
@@ -1732,6 +1739,7 @@ CVE-2026-84309 (pypdf is a free and open-source
pure-python PDF library. Prior t
CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to
3.0.57 and ...)
- php-phpseclib4 4.0.1-1
- php-phpseclib3 3.0.57-1
+ [trixie] - php-phpseclib3 <no-dsa> (Minor issue)
- php-phpseclib <not-affected> (Vulnerable code not present)
- phpseclib <not-affected> (Vulnerable code not present)
NOTE:
https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6
@@ -2212,6 +2220,7 @@ CVE-2026-73553
- envoyproxy <itp> (bug #987544)
CVE-2026-16658
- ansible <unfixed> (bug #1146701)
+ [trixie] - ansible <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506209
CVE-2026-84353 (Use after free in Shared Tab Groups in Google Chrome on on
Android pri ...)
{DSA-6482-1}
@@ -2317,6 +2326,7 @@ CVE-2026-8712 (Wyoming before 1.10.2 contains a
server-side request forgery vuln
NOT-FOR-US: Wyoming
CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python.
Prior to 0. ...)
- sqlparse <unfixed> (bug #1146628)
+ [trixie] - sqlparse <no-dsa> (Minor issue)
NOTE:
https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
NOTE: Fixed by:
https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b
(0.6.0)
CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to
1.83.1, in ...)
@@ -5077,6 +5087,7 @@ CVE-2026-76581 (The WPMU DEV Dashboard plugin for
WordPress is vulnerable to Aut
NOT-FOR-US: WordPress plugin
CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard
library al ...)
- elixir-lang <unfixed> (bug #1146626)
+ [trixie] - elixir-lang <no-dsa> (Minor issue)
[bookworm] - elixir-lang <not-affected> (Vulnerable code introduced
later)
NOTE:
https://github.com/elixir-lang/elixir/security/advisories/GHSA-jf5q-v438-665c
NOTE: https://cna.erlef.org/cves/CVE-2026-75758.html
=====================================
data/dsa-needed.txt
=====================================
@@ -152,6 +152,8 @@ sabnzbdplus
--
shaarli
--
+slurm-wlm
+--
sogo
Regression update for #1144734, new batch of issues from 5.12.10 release
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/288a1044518efa98669ea5ba257da697ca7caec7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/288a1044518efa98669ea5ba257da697ca7caec7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits