Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
62cda978 by Moritz Muehlenhoff at 2026-09-14T20:22:24+02:00
bugnums

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -689,7 +689,7 @@ CVE-2026-89268 (QloApps through 1.7.0 renders back-office 
list filter POST param
 CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce 
the sea ...)
        NOT-FOR-US: Starlette-Admin
 CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in 
start_decod ...)
-       - libstb <unfixed>
+       - libstb <unfixed> (bug #1147728)
        [trixie] - libstb <no-dsa> (Minor issue)
        NOTE: https://github.com/nothings/stb/issues/1928
        NOTE: https://github.com/nothings/stb/issues/1933
@@ -3737,7 +3737,7 @@ CVE-2026-81431 (The Registration Form for WooCommerce 
WordPress plugin before 1.
 CVE-2026-79522 (An out-of-bounds read in the gf_dm_get_chunk_data function 
(src/utils/ ...)
        - gpac <removed>
 CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function 
(stb_sprintf.h)  ...)
-       - libstb <unfixed>
+       - libstb <unfixed> (bug #1147725)
        [trixie] - libstb <postponed> (Minor issue, revisit when fixed upstream)
        NOTE: https://github.com/nothings/stb/issues/1963
 CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of 
nothings ...)
@@ -3924,7 +3924,7 @@ CVE-2026-87874 (A flaw was found in the memcached cache 
plugin of the community.
        [trixie] - ansible <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530995
 CVE-2026-87872 (A flaw was found in the OCAPI modules (ocapi_command, 
ocapi_info) of t ...)
-       - ansible <unfixed>
+       - ansible <unfixed> (bug #1147729)
        [trixie] - ansible <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530988 (private)
 CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The 
eval_acces ...)
@@ -54345,7 +54345,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed 
`Element.iterfind()` exhib
        [bullseye] - python3.9 <postponed> (Minor issue)
        - python2.7 <removed>
        [bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
-       - pypy3 <unfixed>
+       - pypy3 <unfixed> (bug #1147726)
        [trixie] - pypy3 <no-dsa> (Minor issue)
        [bookworm] - pypy3 <postponed> (Minor issue)
        [bullseye] - pypy3 <postponed> (Minor issue)
@@ -113412,7 +113412,7 @@ CVE-2026-8466 (Allocation of Resources Without Limits 
or Throttling vulnerabilit
 CVE-2026-8369 (Improper Input Validation in the NAT64 translator in The 
OpenThread Au ...)
        NOT-FOR-US: OpenThread
 CVE-2026-8367 (aria2c accepts a server certificate with incorrect Extended Key 
Usage  ...)
-       - aria2 <unfixed>
+       - aria2 <unfixed> (bug #1147724)
        [trixie] - aria2 <postponed> (Minor issue, revisit when fixed upstream)
        [bookworm] - aria2 <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - aria2 <postponed> (Minor issue, revisit when fixed 
upstream)
@@ -140133,7 +140133,7 @@ CVE-2026-5314 (A vulnerability was found in Nothings 
stb up to 1.26. Impacted is
        - libstb <unfixed> (unimportant)
        NOTE: truetype parser only supported for trusted font files
 CVE-2026-5313 (A vulnerability has been found in Nothings stb up to 2.30. This 
issue  ...)
-       - libstb <unfixed>
+       - libstb <unfixed> (bug #1147721)
        [trixie] - libstb <no-dsa> (Minor issue)
        [bookworm] - libstb <no-dsa> (Minor issue)
        NOTE: https://vuldb.com/submit/780462
@@ -140753,7 +140753,7 @@ CVE-2026-5195 (A flaw has been found in code-projects 
Student Membership System
 CVE-2026-5190 (Out-of-bounds write in the streaming decoder component in 
aws-c-event- ...)
        NOT-FOR-US: Amazon
 CVE-2026-5186 (A weakness has been identified in Nothings stb up to 2.30. This 
impact ...)
-       - libstb <unfixed>
+       - libstb <unfixed> (bug #1147722)
        [trixie] - libstb <no-dsa> (Minor issue)
        [bookworm] - libstb <no-dsa> (Minor issue)
        NOTE: https://vuldb.com/submit/780395



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62cda97809c76be5d131dcf37b2926a8ffed6fcd

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62cda97809c76be5d131dcf37b2926a8ffed6fcd
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to