Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
aa961736 by Salvatore Bonaccorso at 2026-09-12T17:37:45+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1783,7 +1783,7 @@ CVE-2026-8303 (Incorrect privilege assignment 
vulnerability in TUBITAK BILGEM So
 CVE-2026-8301 (Improper neutralization of special elements used in an OS 
command ('OS ...)
        NOT-FOR-US: Pardus Boot Repair
 CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access 
to the  ...)
-       - multipath-tools <unfixed>
+       - multipath-tools <unfixed> (bug #1147523)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470013
        NOTE: 
https://github.com/opensvc/multipath-tools/security/advisories/GHSA-hmcm-9cq4-r2xm
 CVE-2026-89298 (A flaw was found in the Dynamic Client Registration service of 
Keycloa ...)
@@ -1909,11 +1909,11 @@ CVE-2026-87910 (When tarfile extracts a link on a 
system that doesn't support li
        NOTE: https://github.com/python/cpython/pull/157266
        NOTE: 
https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2
 (main)
 CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In 
versions b ...)
-       - node-morgan <unfixed>
+       - node-morgan <unfixed> (bug #1147520)
        NOTE: 
https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
        NOTE: Fixed by: 
https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee
 (1.12.1)
 CVE-2026-87776 (compression is a Node.js and Express compression middleware. 
In versio ...)
-       - node-compression <unfixed>
+       - node-compression <unfixed> (bug #1147519)
        NOTE: 
https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95
        NOTE: Fixed by: 
https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff
 (v1.8.2)
 CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal 
vulnerabi ...)
@@ -1939,7 +1939,7 @@ CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a 
hard-coded credential for
 CVE-2026-84390 (A inclusion of sensitive information in source code 
vulnerability in F ...)
        NOT-FOR-US: Fortinet
 CVE-2026-82617 (The two built-in name-finder patterns exposed by 
opennlp.tools.namefin ...)
-       - apache-opennlp <unfixed>
+       - apache-opennlp <unfixed> (bug #1147511)
        NOTE: https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3
 CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier 
allow an au ...)
        NOT-FOR-US: NextGen Connect (Mirth Connect)
@@ -1978,7 +1978,7 @@ CVE-2026-79393 (A heap-based buffer overflow 
vulnerability in the WS-Addressing
 CVE-2026-79362 (Certain Woltlab products are affected by RCE via Cache 
Poisoning. WCF  ...)
        NOT-FOR-US: Woltlab
 CVE-2026-78807 (An issue in wpa_supplicant all versions before v.2.12 allows a 
local a ...)
-       - wpa <unfixed>
+       - wpa <unfixed> (bug #1147510)
        NOTE: 
https://w1.fi/security/2026-2/missing-network-context-validation-for-pmksa-caching.txt
        NOTE: Fixed by: 
https://git.w1.fi/cgit/hostap/commit/?id=de5e73a03c34d83568afb3183b2b28c8d7641a30
 CVE-2026-78224 (The XSLT Transformer Step builds a bare TransformerFactory 
without the ...)
@@ -2021,7 +2021,7 @@ CVE-2026-6640 (The Media Library Assistant plugin for 
WordPress is vulnerable to
 CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3  rendered 
remote  ...)
        NOT-FOR-US: Concrete CMS
 CVE-2026-68497 (jackson-databind binds a JSON string to a 
javax.xml.datatype.Duration  ...)
-       - jackson-databind <unfixed>
+       - jackson-databind <unfixed> (bug #1147507)
        NOTE: 
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7
        NOTE: https://github.com/FasterXML/jackson-databind/pull/6127
        NOTE: Fixed by: 
https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd
 (jackson-databind-2.18.10)
@@ -2151,7 +2151,7 @@ CVE-2026-89094 (Forgejo before 16.0.4 allows remote code 
execution via a crafted
 CVE-2026-89089 (A SQL injection vulnerability exists in the 
JasperReports-based report ...)
        NOT-FOR-US: OpenNMS
 CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
-       - ocaml-cstruct <unfixed>
+       - ocaml-cstruct <unfixed> (bug #1147522)
        NOTE: https://osv.dev/vulnerability/OSEC-2026-20
        NOTE: https://github.com/mirage/ocaml-cstruct/pull/324 (v6.3.0)
 CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to 
validate ...)
@@ -2818,7 +2818,7 @@ CVE-2026-85228 (An integer overflow in the tensor buffer 
validation component in
 CVE-2026-85217 (A maliciously crafted add-in, when installed and executed in 
Autodesk  ...)
        NOT-FOR-US: Autodesk
 CVE-2026-84828 (A flaw was found in PCS (Pacemaker Configuration System). A 
local atta ...)
-       - pcs <unfixed>
+       - pcs <unfixed> (bug #1147515)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527320
        NOTE: Introduced with: 
https://github.com/ClusterLabs/pcs/commit/9178b78d11baa70e700a5c0d9fc1c17f27d452fa
 (0.10.8)
        NOTE: Fixed by: 
https://github.com/ClusterLabs/pcs/commit/b41eaf3c6e2ecfc575c42442fb02b8ef05b4dd6a
@@ -3048,7 +3048,7 @@ CVE-2026-87011 (Open WebUI is an extensible, 
feature-rich, and user-friendly sel
 CVE-2026-85645 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop 
Contact For ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-84939 (Path traversal vulnerability in Apache FreeMarker template 
loading mec ...)
-       - libfreemarker-java <unfixed>
+       - libfreemarker-java <unfixed> (bug #1147516)
        NOTE: https://lists.apache.org/thread/hrd7o2ylwkkswdyhyzllgqt0f80kyd5y
 CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with 
unrestricted u ...)
        NOT-FOR-US: BurgerEditor
@@ -3242,10 +3242,10 @@ CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail 
to validate closed state
        NOTE: Fixed by: 
https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e
 (v1.5.7-14)
        NOTE: Fixed by: 
https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555
 (v1.5.7-14)
 CVE-2026-87876 (Two case-insensitive comparisons on request-derived usernames 
outside  ...)
-       - cups <unfixed>
+       - cups <unfixed> (bug #1147521)
        NOTE: 
https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2
 CVE-2026-87875 (The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c 
lacks a sour ...)
-       - cups <unfixed>
+       - cups <unfixed> (bug #1147521)
        NOTE: 
https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq
 CVE-2026-87874 (A flaw was found in the memcached cache plugin of the 
community.genera ...)
        - ansible <unfixed>
@@ -3424,7 +3424,7 @@ CVE-2026-85102 (Improper certificate trust validation 
during VPN negotiation in
        NOT-FOR-US: Check Point
 CVE-2026-83530 (A user could provide an expression whose string length is 
longer than  ...)
        - golang-cel-cel-go 0.32.0+ds-1
-       - golang-github-google-cel-go <unfixed>
+       - golang-github-google-cel-go <unfixed> (bug #1147513)
        NOTE: https://github.com/cel-expr/cel-go/pull/1302
        NOTE: Fixed by: 
https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a
 (v0.29.0)
 CVE-2026-82563 (An attacker could impersonate the camera and place themselves 
in a man ...)
@@ -5052,7 +5052,7 @@ CVE-2026-87050
 CVE-2026-87049
        NOT-FOR-US: operator-foundry
 CVE-2026-86564 (A flaw was found in DPDK lib/vhost. Missing length validation 
before r ...)
-       - dpdk <unfixed>
+       - dpdk <unfixed> (bug #1147518)
        [trixie] - dpdk <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2529682
 CVE-2026-85630 (HTML::FormHandler versions before 0.410002 for Perl render 
field attri ...)
@@ -5835,7 +5835,7 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python 
bindings enabled. A remo
        NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/397
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/libxml2/-/commit/f41e1865781f74d1cadfe2fbdfeefed946026f12
 (v2.15.3)
 CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts 
user-supplied ZIP a ...)
-       - gnome-tweaks <unfixed>
+       - gnome-tweaks <unfixed> (bug #1147509)
        [trixie] - gnome-tweaks <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gnome-tweaks/-/issues/542
 CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability 
in the s ...)
@@ -8363,7 +8363,7 @@ CVE-2026-86231 (A security flaw has been discovered in 
mwiede jsch up to 2.28.5.
 CVE-2026-86228 (A security vulnerability has been detected in JeecgBoot up to 
3.9.3. T ...)
        NOT-FOR-US: JeecgBoot
 CVE-2026-86227 (A weakness has been identified in valkey-io valkey up to 
9.0.5/9.1.1.  ...)
-       - valkey <unfixed>
+       - valkey <unfixed> (bug #1147517)
        NOTE: https://github.com/valkey-io/valkey/issues/4222
        NOTE: https://github.com/valkey-io/valkey/pull/4229
        NOTE: Fixed by: 
https://github.com/valkey-io/valkey/commit/4691888e7fab3df128f0bde5750c9fde2ae552fa
 (unstable)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aa961736ae34cc770f97999966ccc1b31399f99b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aa961736ae34cc770f97999966ccc1b31399f99b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to