Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
7a0a8ba4 by Moritz Muehlenhoff at 2026-09-15T13:29:35+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -876,11 +876,11 @@ CVE-2026-12758 (IBM Cloud Pak for Business Automation 
could allow a remote attac
 CVE-2026-12756 (IBM Business Automation Workflow containers and traditional is 
vulnera ...)
        NOT-FOR-US: IBM
 CVE-2026-82049 (In CPython 3.13 and earlier, the tarfilemodule's dataand tar 
extractio ...)
-       - python3.15 <unfixed>
-       - python3.14 <unfixed>
        - python3.13 <unfixed>
+       [trixie] - python3.13 <no-dsa> (Minor issue)
        - python3.11 <removed>
        - pypy3 <unfixed>
+       [trixie] - pypy3 <no-dsa> (Minor issue)
        NOTE: https://github.com/python/cpython/issues/157190
        NOTE: https://github.com/python/cpython/pull/157191
        NOTE: https://github.com/python/cpython/pull/157262 (3.15)
@@ -888,7 +888,7 @@ CVE-2026-82049 (In CPython 3.13 and earlier, the 
tarfilemodule's dataand tar ext
        NOTE: https://github.com/python/cpython/pull/157192 (3.13)
        NOTE: 
https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d
 (3.13 branch)
        NOTE: https://github.com/python/cpython/pull/157454 (3.12)
-       TODO: check, only impacts 3.13 and below, but pull requests are open as 
well for newer versions
+       NOTE: Fixed by changes in Python 3.14, some followup changes for 
3.15/3.16, but without security impact
 CVE-2026-9812 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x 
<= 11.7 ...)
        - mattermost-server <itp> (bug #823556)
 CVE-2026-91081 (Docs through 5.6.1 contains a server-side request forgery 
vulnerabilit ...)
@@ -916,9 +916,12 @@ CVE-2026-90955 (Affected versions of MISP\u2019s 
interactive CLI shell do not re
        - misp <itp> (bug #1144317)
 CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. 
When proc ...)
        - gimp <unfixed>
+       [trixie] - gimp <not-affected> (Vulnerable code not present)
+       [bookworm] - gimp <not-affected> (Vulnerable code not present)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16753
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2998
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/0ff8049449b00bdd906faad7fcea091de8aa00a5
+       NOTE: Introduced by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/680ebede22bf7f34f78e5342b4df207892559406
 (GIMP_3_2_2)
 CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an 
ICO fil ...)
        - gimp <unfixed>
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16742
@@ -1175,6 +1178,7 @@ CVE-2026-82232 (Improper neutralization of special 
elements used in an SQL comma
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a 
path trave ...)
        - pymupdf <unfixed>
+       [trixie] - pymupdf <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/pymupdf/PyMuPDF/commit/b2c8f3a859fed35c379a44df566f770dc3e18605
 CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a 
DOM-base ...)
        NOT-FOR-US: TripleLift


=====================================
data/dsa-needed.txt
=====================================
@@ -49,6 +49,8 @@ firebird4.0
 gegl (jmm)
   move to 0.4.72
 --
+gimp (jmm)
+--
 gst-plugins-good1.0
 --
 jackson-databind



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to