Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
1e877666 by Moritz Muehlenhoff at 2026-09-25T12:21:00+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -100,6 +100,7 @@ CVE-2026-97224 (A vulnerability was detected in Excalidraw 
up to 0.18.1. The imp
        NOT-FOR-US: Excalidraw
 CVE-2026-97185 (A flaw was found in GIMP. When processing a specially crafted 
GIMPress ...)
        - gimp <unfixed>
+       [trixie] - gimp <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16788
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3016
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/3b5e12f8eb2734f954559fbdaf27d03765cea2e5
@@ -154,9 +155,11 @@ CVE-2026-95985 (The file write tool in Amazon Kiro IDE 
versions before 1.0.242 m
        NOT-FOR-US: Amazon
 CVE-2026-95521 (A command injection flaw was found in rpm. Installing or 
rebuilding a  ...)
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537812
 CVE-2026-95519 (A flaw was found in rpm. An attacker can supply a crafted 
manifest fil ...)
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470977
 CVE-2026-94613 (authentik is an open-source identity provider. Prior to 
2026.2.7, 2026 ...)
        NOT-FOR-US: authentik
@@ -174,24 +177,31 @@ CVE-2026-94416 (An authorization bypass was found in the 
Ansible Automation Plat
        NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-94282
        - libxi <unfixed>
+       [trixie] - libxi <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-94281 (An out-of-bounds read in libXi's XListInputDevices() class 
parsing in  ...)
        - libxi <unfixed>
+       [trixie] - libxi <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93545 (An out-of-bounds read in libXi's XListInputDevices() in libXi 
before 1 ...)
        - libxi <unfixed>
+       [trixie] - libxi <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93544 (An out-of-bounds read in libXi's XI2 XIQueryDevice reply 
parsing in li ...)
        - libxi <unfixed>
+       [trixie] - libxi <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93543 (An out-of-bounds read in libXi's XI2 class parser in libXi 
before 1.8. ...)
        - libxi <unfixed>
+       [trixie] - libxi <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93542 (An out-of-bounds read in libXi's XI2 class parsing via 
size_classes()  ...)
        - libxi <unfixed>
+       [trixie] - libxi <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93541 (An out-of-bounds read in libXi's XQueryDeviceState() in libXi 
before 1 ...)
        - libxi <unfixed>
+       [trixie] - libxi <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93425 (Dokploy is a free, self-hostable Platform as a Service (PaaS). 
Prior t ...)
        NOT-FOR-US: Dokploy
@@ -252,6 +262,7 @@ CVE-2026-88383 (libical 4.0.6 contains an incompatible 
function pointer in icalp
        NOTE: Fixed by: 
https://github.com/libical/libical/commit/1fc946aaa91e5995dee593092723ba67d7113846
 (4.0 branch)
 CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled 
memory a ...)
        - hiredis <unfixed>
+       [trixie] - hiredis <no-dsa> (Minor issue)
        NOTE: https://github.com/redis/hiredis/issues/1357
 CVE-2026-88378 (QuickJS commit 04be24600 contains a heap out-of-bounds write 
condition ...)
        - quickjs-ng <unfixed>
@@ -268,6 +279,7 @@ CVE-2026-88373 (libde265 commit 4d45a6b contains a NULL 
pointer dereference vuln
        NOTE: Fixed by: 
https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea
 (v1.1.2)
 CVE-2026-88372 (libsndfile 1.2.2 contains an integer overflow vulnerability in 
mat4_re ...)
        - libsndfile <unfixed>
+       [trixie] - libsndfile <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/libsndfile/libsndfile/issues/1151
 CVE-2026-88371 (ZBar commit 2ea2ca58 contains an undefined-behavior 
vulnerability in t ...)
        - zbar <unfixed>
@@ -1460,9 +1472,11 @@ CVE-2026-96676 (A vulnerability was identified in Fast 
FAC1900R 20190827_2.0.2.
        NOT-FOR-US: Fast FAC1900R
 CVE-2026-96675 (alsa-lib through 1.2.16.1 contains a denial of service 
vulnerability i ...)
        - alsa-lib <unfixed> (bug #1148900)
+       [trixie] - alsa-lib <no-dsa> (Minor issue)
        NOTE: https://github.com/alsa-project/alsa-lib/pull/527
 CVE-2026-96674 (alsa-lib through 1.2.16.1 computes combined topology element 
size usin ...)
        - alsa-lib <unfixed> (bug #1148896)
+       [trixie] - alsa-lib <no-dsa> (Minor issue)
        NOTE: https://github.com/alsa-project/alsa-lib/pull/527
 CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection 
vulnerability in the ...)
        NOT-FOR-US: Photoview
@@ -1541,6 +1555,7 @@ CVE-2026-96513 (A security flaw has been discovered in 
Neethuharii CafeManagemen
        NOT-FOR-US: Neethuharii CafeManagement
 CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or 
NOTAFTER ...)
        - sudo <unfixed> (bug #1148890)
+       [trixie] - sudo <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539327
        NOTE: Fixed by: 
https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c
 CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for 
a PIN b ...)
@@ -1846,9 +1861,9 @@ CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) 
password hashes as plaintext
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
        TODO: check
 CVE-2026-88835 (BusyBox dpkg read_package_field() steps past a NUL terminator 
on malfo ...)
-       - busybox <unfixed>
+       - busybox <unfixed> (unimportant)
        NOTE: ttps://bugzilla.redhat.com/show_bug.cgi?id=2531349
-       TODO: check
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-88832 (BusyBox romfs volume ID parsing uses unbounded strlen on 
attacker-cont ...)
        - busybox <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531345
@@ -2907,10 +2922,12 @@ CVE-2026-88344 (An out-of-bounds read vulnerability 
exists in the schema lexer o
        NOT-FOR-US: Dvidelabs flatcc
 CVE-2026-88341 (A reachable assertion vulnerability exists in YARA 4.5.8 when 
loading  ...)
        - yara <unfixed> (bug #1148825)
+       [trixie] - yara <no-dsa> (Minor issue)
        NOTE: https://github.com/VirusTotal/yara/issues/2238
        NOTE: Fixed by: 
https://github.com/NOUIY/yara/commit/0cdff36723cd260243bb2b330bda555693354760
 CVE-2026-88340 (An invalid pointer release vulnerability exists in YARA 4.5.8 
during d ...)
        - yara <unfixed> (bug #1148825)
+       [trixie] - yara <no-dsa> (Minor issue)
        NOTE: https://github.com/VirusTotal/yara/issues/2239
        NOTE: https://github.com/VirusTotal/yara/pull/2244
 CVE-2026-88339 (A NULL pointer dereference vulnerability exists in the 
gf_sg_vrml_fiel ...)
@@ -5384,6 +5401,7 @@ CVE-2026-77820 (The WPComplete plugin for WordPress is 
vulnerable to Stored Cros
        NOT-FOR-US: WordPress plugin
 CVE-2026-77528 (Autobahn Python is a WebSocket and WAMP implementation for 
Python that ...)
        - python-autobahn <unfixed>
+       [trixie] - python-autobahn <no-dsa> (Minor issue)
        NOTE: 
https://github.com/crossbario/autobahn-python/security/advisories/GHSA-hxp9-w8x3-p566
        NOTE: https://github.com/crossbario/autobahn-python/pull/1916
        NOTE: Fixed by: 
https://github.com/crossbario/autobahn-python/commit/77d323a30b09b1828ad8be2ce6344e056970e613
 (v26.7.1)
@@ -12121,6 +12139,7 @@ CVE-2026-76104 (Dell ObjectScale, versions prior to 
4.4.0.0, contains an Incorre
        NOT-FOR-US: Dell / EMC
 CVE-2026-75516 (The RabbitMQ Java client library allows Java and JVM-based 
application ...)
        - rabbitmq-java-client <unfixed>
+       [trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-jh4v-gfqj-7rhx
        NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2015
        NOTE: Fixed by: 
https://github.com/rabbitmq/rabbitmq-java-client/commit/6d7c2bfe89796ca34d3531098fb59dd657fea39e
 (main)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e87766645b05ac36954c68cea5e65b7b4142a2e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e87766645b05ac36954c68cea5e65b7b4142a2e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to