Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a530d81e by Moritz Muehlenhoff at 2026-09-20T13:02:52+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -293,12 +293,15 @@ CVE-2026-91847 (The Online Scheduling and Appointment 
Booking System  WordPress
        NOT-FOR-US: WordPress plugin
 CVE-2026-91205 (A flaw was found in cockpit-files. A local unprivileged 
attacker can e ...)
        - cockpit-files <unfixed> (bug #1148476)
+       [trixie] - cockpit-files <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2466442
 CVE-2026-91203 (A flaw was found in cockpit-files. This vulnerability allows a 
local a ...)
        - cockpit-files <unfixed> (bug #1148475)
+       [trixie] - cockpit-files <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2465632
 CVE-2026-91202 (A flaw was found in cockpit-files. A low-privileged local user 
can exp ...)
        - cockpit-files <unfixed> (bug #1148474)
+       [trixie] - cockpit-files <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2465834
 CVE-2026-89334 (The Better Messages \u2013 Chat Rooms, Group Chat, Private 
Messages &  ...)
        NOT-FOR-US: WordPress plugin
@@ -9728,6 +9731,8 @@ CVE-2026-92073 (Privilege escalation in the Enterprise 
Policies component. This
 CVE-2026-92072 (Incorrect boundary conditions in the Safe Browsing component. 
This vul ...)
        - firefox 156.0-1
        - thunderbird 1:153.3.0esr-1
+       [trixie] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
+       [bookworm] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92072
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92072
 CVE-2026-92071 (Sandbox escape due to incorrect boundary conditions in the 
Widget: Win ...)
@@ -9738,11 +9743,15 @@ CVE-2026-92071 (Sandbox escape due to incorrect 
boundary conditions in the Widge
 CVE-2026-92070 (Information disclosure in the Networking component. This 
vulnerability ...)
        - firefox 156.0-1
        - thunderbird 1:153.3.0esr-1
+       [trixie] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
+       [bookworm] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92070
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92070
 CVE-2026-92069 (Spoofing issue in the DOM: Navigation component. This 
vulnerability wa ...)
        - firefox 156.0-1
        - thunderbird 1:153.3.0esr-1
+       [trixie] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
+       [bookworm] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92069
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92069
 CVE-2026-92068 (Site isolation issue in the Reader Mode component. This 
vulnerability  ...)
@@ -9753,6 +9762,8 @@ CVE-2026-92068 (Site isolation issue in the Reader Mode 
component. This vulnerab
 CVE-2026-92067 (Use-after-free in the Widget: Gtk component. This 
vulnerability was fi ...)
        - firefox 156.0-1
        - thunderbird 1:153.3.0esr-1
+       [trixie] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
+       [bookworm] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92067
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92067
 CVE-2026-92066 (Sandbox escape in the Profile Backup component. This 
vulnerability was ...)
@@ -9774,6 +9785,8 @@ CVE-2026-92063 (Denial-of-service in the Audio/Video 
component. This vulnerabili
 CVE-2026-92062 (Privilege escalation in the Session Restore component. This 
vulnerabil ...)
        - firefox 156.0-1
        - thunderbird 1:153.3.0esr-1
+       [trixie] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
+       [bookworm] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92062
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92062
 CVE-2026-92061 (Incorrect boundary conditions in the Security: Process 
Sandboxing comp ...)
@@ -9782,11 +9795,15 @@ CVE-2026-92061 (Incorrect boundary conditions in the 
Security: Process Sandboxin
 CVE-2026-92060 (Use-after-free in the Internationalization component. This 
vulnerabili ...)
        - firefox 156.0-1
        - thunderbird 1:153.3.0esr-1
+       [trixie] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
+       [bookworm] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92060
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92060
 CVE-2026-92059 (Incorrect boundary conditions in the DOM: Editor component. 
This vulne ...)
        - firefox 156.0-1
        - thunderbird 1:153.3.0esr-1
+       [trixie] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
+       [bookworm] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92059
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92059
 CVE-2026-92058 (Use-after-free in the Graphics component. This vulnerability 
was fixed ...)
@@ -11494,6 +11511,7 @@ CVE-2026-55091 (flat-to-nested converts a hierarchy 
from a flat representation t
        TODO: check
 CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior 
to 70.0 ...)
        - weasyprint <unfixed> (bug #1148178)
+       [trixie] - weasyprint <no-dsa> (Minor issue)
        NOTE: 
https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jf6q-chmf-3h3v
        NOTE: 
https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443
 (v70.0)
 CVE-2026-55072 (Pimcore is an Open Source Data & Experience Management 
Platform. Prior ...)
@@ -16023,9 +16041,11 @@ CVE-2026-23855 (Dell iDRAC9, 14G versions prior to 
7.00.00.184, 15G/16G versions
        NOT-FOR-US: Dell / EMC
 CVE-2026-22591 (eprosima Fast DDS is a C++ implementation of the DDS (Data 
Distributio ...)
        - fastdds <unfixed>
+       [trixie] - fastdds <no-dsa> (Minor issue)
        NOTE: 
https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7577-rf2r-j88m
 CVE-2026-22590 (eprosima Fast DDS is a C++ implementation of the DDS (Data 
Distributio ...)
        - fastdds <unfixed>
+       [trixie] - fastdds <no-dsa> (Minor issue)
        NOTE: 
https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7r7h-hwfj-q626
 CVE-2026-19778 (The WPMR Google Feed Manager for WooCommerce \u2013 Sell on 
Google Mer ...)
        NOT-FOR-US: WordPress plugin



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a530d81eebda9825abf88e1f78fb1130ce9681a5

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a530d81eebda9825abf88e1f78fb1130ce9681a5
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to