Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7ca99966 by Moritz Muehlenhoff at 2026-09-14T18:41:28+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,8 +1,10 @@
 CVE-2026-XXXX [GHSA-484h-v688-jq5j: Source URL scheme bypasses sandboxed mode 
protections across multiple source subtypes]
        - flatpak-builder <unfixed> (bug #1147701)
+       [trixie] - flatpak-builder <no-dsa> (Minor issue)
        NOTE: 
https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-484h-v688-jq5j
 CVE-2026-86320
        - flatpak-builder <unfixed> (bug #1147700)
+       [trixie] - flatpak-builder <no-dsa> (Minor issue)
        NOTE: 
https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
 CVE-2026-90691 (A security vulnerability has been detected in 0x4m4 HexStrike 
AI up to ...)
        NOT-FOR-US: 0x4m4 HexStrike AI
@@ -326,6 +328,7 @@ CVE-2023-32778 (An issue was discovered in ILIAS 6.23, 7 
before 7.22, and 8.1. A
 CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in 
the bundle ...)
        - mkvtoolnix 101.0-2 (bug #1147621)
        - ogmrip <unfixed>
+       [trixie] - ogmrip <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0
        NOTE: Fixed by: 
https://codeberg.org/mbunkus/mkvtoolnix/commit/13fd81db3ae2b79d41536a9663719df11780797e
 CVE-2026-90782 (S2OPC through 1.7.3 contains a null pointer dereference in 
msg_subscri ...)
@@ -3321,16 +3324,19 @@ CVE-2026-88047 (Tesseract is an open source OCR engine. 
In version 5.5.3 and ear
        NOTE: Fixed by: 
https://github.com/tesseract-ocr/tesseract/commit/1bda5079b1c8a7e25f523486837426903d29ce84
 CVE-2026-88046 (rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1147404)
+       [trixie] - rclone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-38xv-hf3p-h7mq
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/57842c5ee4e1407eda06a414a36510cce2db4252
 (v1.75.1)
 CVE-2026-88045 (rclone is a command-line program to sync files and directories 
to and  ...)
-       - rclone <unfixed> (bug #1147404)
+       - rclone <not-affected> (Only affects 1.75.0)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-2p48-j3qc-rx9f
        NOTE: https://github.com/rclone/rclone/issues/9616
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/7c1dfd99f3e6a22fcefd8686cc478226a15e63a1
 (v1.75.1)
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/ab1f458013aaf6356e4bdeca61f7cb9139f8eb86
 (v1.75.1)
 CVE-2026-88044 (rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1147404)
+       [trixie] - rclone <not-affected> (Vulnerable code not present, affects 
1.70 and later)
+       [bookworm] - rclone <not-affected> (Vulnerable code not present, 
affects 1.70 and later)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-p569-5gjg-9cmj
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/739403963abf6f58003c2becd5f7c4ad0d644153
 (v1.75.1)
 CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP 
cookies, use ...)
@@ -3369,6 +3375,7 @@ CVE-2026-88031 (Improper neutralization of special 
elements in data query logic
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-go-driver/commit/806e132f9501a2665d05ebaba3b6f0d787ceaa96
 (v1.17.10)
 CVE-2026-88030 (Improper neutralization of special elements in data query 
logic in the ...)
        - ruby-mongo <unfixed> (bug #1147409)
+       [trixie] - ruby-mongo <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/RUBY-3941
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d
 (v2.26.0)
 CVE-2026-88029 (Improper neutralization of special elements in data query 
logic in the ...)
@@ -3398,25 +3405,31 @@ CVE-2026-88018 (rclone is a command-line program to 
sync files and directories t
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/90595f34f27f569be6b27c57fe5ab65057d323bd
 (1.75.1)
 CVE-2026-88017 (rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1147404)
+       [trixie] - rclone <not-affected> (Vulnerable code not present, only 
affects 1.64 and later)
+       [bookworm] - rclone <not-affected> (Vulnerable code not present, only 
affects 1.64 and later)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-c476-6w5q-jw77
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/c6af0b57c2b4af848bc968c2b407354476184b99
 (v1.75.1)
 CVE-2026-88016 (rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1147404)
+       [trixie] - rclone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/17b0c03338a857bcb0a68d2d4c82ddbdec3f7893
 (v1.75.1)
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/a7ab39d3d1958afa1446982c1dc4e4a73a887e3e
 (v1.75.1)
 CVE-2026-88015 (rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1147404)
+       [trixie] - rclone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9
 (v1.75.1)
 CVE-2026-88014 (rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1147404)
+       [trixie] - rclone <not-affected> (Vulnerable code not present, only 
affects 1.72 and later)
+       [bookworm] - rclone <not-affected> (Vulnerable code not present, only 
affects 1.72 and later)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-66hp-wgxq-6f5q
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/5dae3adbf571a6cd9ba501eb47397a7e871e1ae0
 (v1.75.1)
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/6507e13d5a83789f500af96d7188c302c9d74d98
 (v1.75.1)
-       TODO: check, said to affect only 1.72.0 onwards
 CVE-2026-88013 (rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1147404)
+       [trixie] - rclone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-486v-q2wf-fp2r
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/22859b7e696cea3c563c6ba04c6b7f91f74456b4
 (v1.75.1)
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/79fbc0842f74e02cb84f0e3e7261d169983c8831
 (v1.75.1)
@@ -4079,6 +4092,7 @@ CVE-2026-85102 (Improper certificate trust validation 
during VPN negotiation in
 CVE-2026-83530 (A user could provide an expression whose string length is 
longer than  ...)
        - golang-cel-cel-go 0.32.0+ds-1
        - golang-github-google-cel-go <unfixed> (bug #1147513)
+       [trixie] - golang-github-google-cel-go <no-dsa> (Minor issue)
        NOTE: https://github.com/cel-expr/cel-go/pull/1302
        NOTE: Fixed by: 
https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a
 (v0.29.0)
 CVE-2026-82563 (An attacker could impersonate the camera and place themselves 
in a man ...)
@@ -16598,6 +16612,7 @@ CVE-2026-58106 (CVE-2025-40843 
https://github.com/advisories/GHSA-5xf2-f6ch-6p8r
        NOT-FOR-US: Ericsson
 CVE-2026-56854 (The source-address critical option in the Permissions returned 
by an a ...)
        - golang-go.crypto 1:0.55.0-1
+       [trixie] - golang-go.crypto <no-dsa> (Minor issue)
        [bookworm] - golang-go.crypto <postponed> (Limited support)
        NOTE: https://github.com/golang/go/issues/80213
        NOTE: Fixed by: 
https://github.com/golang/crypto/commit/e557b08ec2b4f5dd00f38356919fc7b051dd88f8
 (v0.55.0)
@@ -17971,7 +17986,7 @@ CVE-2026-10036 (SpeechBrain before 1.1.1 contains an 
arbitrary code execution vu
        NOT-FOR-US: SpeechBrain
 CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially 
crafted JPEG  ...)
        - gdk-pixbuf <unfixed> (bug #1145988)
-       [trixie] - gdk-pixbuf <no-dsa> (Minor issue)
+       [trixie] - gdk-pixbuf <postponed> (Minor issue, revisit when/if a fix 
is available for the C-based legacy implementation)
        [bookworm] - gdk-pixbuf <postponed> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
        NOTE: Introduced with: 
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/4af78023ce7d3b5e3cec422a59bb4f48fa4f5886
 (2.43.4)
@@ -59135,7 +59150,7 @@ CVE-2026-24537 (Unauthenticated Cross Site Request 
Forgery (CSRF) in WP Accessib
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially 
crafted ICO f ...)
        - gdk-pixbuf <unfixed> (bug #1143155)
-       [trixie] - gdk-pixbuf <no-dsa> (Minor issue)
+       [trixie] - gdk-pixbuf <postponed> (Minor issue, revisit when/if a fix 
is available for the C-based legacy implementation)
        [bookworm] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in 
the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the 
rendered image; unfixed upstream)
        [bullseye] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in 
the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the 
rendered image; unfixed upstream)
        NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302
@@ -66757,6 +66772,7 @@ CVE-2026-54242 (Statamic is a Laravel and Git powered 
content management system
        NOT-FOR-US: Statamic CMS
 CVE-2026-54171 (Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 
1.5.0, Excon ...)
        - ruby-excon 1.5.0-1
+       [trixie] - ruby-excon <no-dsa> (Minor issue)
        NOTE: 
https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r
        NOTE: https://github.com/excon/excon/pull/901
        NOTE: Fixed by: 
https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 
(v1.5.0)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ca999664c3a49ebb26538987bde091b805651b2

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ca999664c3a49ebb26538987bde091b805651b2
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to