Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
bf7a745b by Moritz Muehlenhoff at 2026-09-11T22:49:11+02:00
bugnums
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -5864,7 +5864,7 @@ CVE-2026-0054 (In isCallerAllowed of
WalletContextualLocationsService.kt, there
CVE-2026-0001 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel
Driver, Arm ...)
NOT-FOR-US: ARM
CVE-2026-18090 (A flaw was found in gdk-pixbuf. This vulnerability allows a
remote att ...)
- - gdk-pixbuf <unfixed>
+ - gdk-pixbuf <unfixed> (bug #1147444)
[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517751
CVE-2026-86544 (knowns versions before 0.30.0 contain an authorization bypass
vulnerab ...)
@@ -28408,7 +28408,7 @@ CVE-2026-17084 (The "stringprep" module didn't process
characters from RFC 3454
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- - pypy3 <unfixed>
+ - pypy3 <unfixed> (bug #1147445)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <postponed> (Minor issue)
NOTE:
https://mail.python.org/archives/list/[email protected]/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/
@@ -28428,7 +28428,7 @@ CVE-2026-15806 (The HTTPPasswordMgr class in the
urllib.request module, along wi
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- - pypy3 <unfixed>
+ - pypy3 <unfixed> (bug #1147448)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <postponed> (Minor issue)
NOTE:
https://mail.python.org/archives/list/[email protected]/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/
@@ -40744,7 +40744,7 @@ CVE-2026-18503 (Attacker-controlled CSV samples can
trigger super-linear regula
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- - pypy3 <unfixed>
+ - pypy3 <unfixed> (bug #1147450)
[trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <postponed> (Minor issue)
NOTE:
https://mail.python.org/archives/list/[email protected]/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/
@@ -43630,9 +43630,8 @@ CVE-2026-16637 (OPeNDAP Hyrax allows SSRF and
credential disclosure via unvalida
CVE-2026-16027 (Server-Side request forgery (SSRF) vulnerability in Revenue
Administra ...)
NOT-FOR-US: Turkie's E-Signature
CVE-2026-15816 (A flaw was found in dracut. The die() error-handling function
writes i ...)
- - dracut <unfixed>
+ - dracut <unfixed> (bug #1147447)
[trixie] - dracut <no-dsa> (Minor issue)
- NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2459963
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500889
CVE-2026-15570 (An improper restriction of URL schemes and destinations in the
SmartCe ...)
NOT-FOR-US: Telefunken TE24553B45V2DZ Smart TV
@@ -60212,7 +60211,7 @@ CVE-2026-1617 (Improper neutralization of special
elements used in an SQL comman
CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is
vulnerable to M ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16493 (A flaw was found in ansible-core. The
_extract_collection_from_git() f ...)
- - ansible-core <unfixed>
+ - ansible-core <unfixed> (bug #1147449)
[trixie] - ansible-core <no-dsa> (Minor issue)
[bookworm] - ansible-core <postponed> (Minor issue)
- ansible 5.4.0-1
@@ -60220,7 +60219,6 @@ CVE-2026-16493 (A flaw was found in ansible-core. The
_extract_collection_from_g
NOTE: ansible-core was split off from src:ansible with 4.6.0-1 in
experimental/5.4.0-1 in sid
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2503724
NOTE: Issue exists due to an incomplete fix for CVE-2026-11332
- TODO: check upstream details
CVE-2026-16461 (A stack-based buffer overflow was found in rpcbind's rpcinfo
utility. ...)
- rpcbind <unfixed> (bug #1142716)
[trixie] - rpcbind <no-dsa> (Minor issue)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf7a745be48ac81122c6f57e648fb8916894fe5d
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf7a745be48ac81122c6f57e648fb8916894fe5d
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits