Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
03b5fd0d by Moritz Muehlenhoff at 2026-09-26T23:03:03+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -756,9 +756,10 @@ CVE-2026-97324 (A vulnerability was identified in 
YunaiV/zhijiantianya ruoyi-vue
 CVE-2026-97228 (Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer 
from a Grap ...)
        NOT-FOR-US: Rapid7 Bulk Export MCP
 CVE-2026-97222 (A heap use-after-free flaw was found in Gnumeric. When a user 
opens a  ...)
-       - gnumeric <unfixed>
+       - gnumeric <unfixed> (unimportant)
        NOTE: https://gitlab.gnome.org/GNOME/gnumeric/-/issues/897
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gnumeric/-/commit/bc1dee29525933994181fb2307d6ad584de6040d
+       NOTE: Crash in GUI tool, no security impact
 CVE-2026-97064 (X-SpringBoot through 6.0 ships with a hardcoded static master 
login ve ...)
        NOT-FOR-US: X-SpringBoot
 CVE-2026-97063 (X-SpringBoot through 6.0 returns login verification codes in 
HTTP resp ...)
@@ -901,6 +902,7 @@ CVE-2026-88387 (LibRaw 0.22.0 contains an incorrect numeric 
conversion vulnerabi
        NOTE: Fixed by: 
https://github.com/LibRaw/LibRaw/commit/b41cbbd61951783e0440590dae55411a16185bdf
 (master)
 CVE-2026-88386 (libsndfile 1.2.2 contains a misaligned memory access issue in 
psf_binh ...)
        - libsndfile <unfixed> (bug #1149062)
+       [trixie] - libsndfile <no-dsa> (Minor issue)
        NOTE: https://github.com/libsndfile/libsndfile/issues/1150
        NOTE: Fixed by: 
https://github.com/libsndfile/libsndfile/commit/474e4d328b1e6240b93ec6ed14efb7c6a44bee57
 CVE-2026-87722 (Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in 
regex search ...)
@@ -2807,6 +2809,7 @@ CVE-2026-97061 (Black Candy through 3.2.1 fails to scope 
playlist search queries
        NOT-FOR-US: Black Candy
 CVE-2026-97059 (DCMTK through 3.7.0 contains a heap over-read vulnerability in 
Concate ...)
        - dcmtk <unfixed>
+       [trixie] - dcmtk <no-dsa> (Minor issue)
        NOTE: https://support.dcmtk.org/redmine/issues/1281
        NOTE: Fixed by: 
https://github.com/DCMTK/dcmtk/commit/18379d5b8d234977cc30644e9e70d76d89c87285
        NOTE: Fixed by: 
https://github.com/DCMTK/dcmtk/commit/c33790827a192a598d20463af701a8b819f46ec1
@@ -2836,6 +2839,7 @@ CVE-2026-96746 (An out-of-bounds write in the 
connection-monitoring logic of the
        NOTE: 
https://github.com/mongodb/mongo-c-driver/commit/59bcc756ad8f04af74b84b88ab747adfd2647b5b
 (1.30.12)
 CVE-2026-96745 (Deserialization of untrusted data in the command monitoring 
support of ...)
        - php-mongodb <unfixed> (bug #1148966)
+       [trixie] - php-mongodb <no-dsa> (Minor issue)
        NOTE: 
https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c
        NOTE: https://jira.mongodb.org/browse/PHPC-2743
        NOTE: https://github.com/mongodb/mongo-php-driver/pull/2115
@@ -2939,6 +2943,7 @@ CVE-2026-88390 (An out-of-bounds write vulnerability in 
jslGetTokenValueAsString
        NOT-FOR-US: Espruino
 CVE-2026-88385 (Mini-XML 4.0.5 contains a memory leak vulnerability in 
mxml_load_data( ...)
        - mxml 4.0.6-2
+       [trixie] - mxml <no-dsa> (Minor issue)
        NOTE: https://github.com/michaelrsweet/mxml/issues/356
        NOTE: Fixed by: 
https://github.com/michaelrsweet/mxml/commit/83ef80ae3c5413b73f501edb59ee74e31ce399d0
 (v4.0.6)
 CVE-2026-88384 (OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ 
attribut ...)
@@ -2947,11 +2952,12 @@ CVE-2026-88384 (OpenEXR 3.4.14 contains a NULL Pointer 
Dereference in the C++ at
        NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2615
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/e782bcc1ffe1cc9edfaa5dbad4f28e866eaf9bbb
 (v3.5.0-rc)
 CVE-2026-88383 (libical 4.0.6 contains an incompatible function pointer in 
icalparamet ...)
-       - libical3 <unfixed> (bug #1149060)
+       - libical3 <unfixed> (bug #1149060; unimportant)
        - libical <removed>
        NOTE: https://github.com/libical/libical/issues/1361
        NOTE: https://github.com/libical/libical/pull/1363
        NOTE: Fixed by: 
https://github.com/libical/libical/commit/1fc946aaa91e5995dee593092723ba67d7113846
 (4.0 branch)
+       NOTE: Negligible security impact
 CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled 
memory a ...)
        - hiredis <unfixed> (bug #1149059)
        [trixie] - hiredis <no-dsa> (Minor issue)
@@ -2975,8 +2981,9 @@ CVE-2026-88372 (libsndfile 1.2.2 contains an integer 
overflow vulnerability in m
        [trixie] - libsndfile <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/libsndfile/libsndfile/issues/1151
 CVE-2026-88371 (ZBar commit 2ea2ca58 contains an undefined-behavior 
vulnerability in t ...)
-       - zbar <unfixed> (bug #1149058)
+       - zbar <unfixed> (bug #1149058; unimportant)
        NOTE: https://github.com/mchehab/zbar/issues/336
+       NOTE: Negligible security impact
 CVE-2026-88370 (libconfini 1.16.4 contains a heap out-of-bounds write 
condition involv ...)
        NOT-FOR-US: libconfini
 CVE-2026-88369 (zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in 
example ...)
@@ -3005,6 +3012,7 @@ CVE-2026-88360 (libvips 8.19.0 contains a memory access 
vulnerability when proce
        NOTE: Not considered a security issue by upstream
 CVE-2026-88359 (libfyaml 0.9.6 contains a stack exhaustion vulnerability in 
fy_atom_it ...)
        - libfyaml <unfixed> (bug #1149055)
+       [trixie] - libfyaml <no-dsa> (Minor issue)
        NOTE: https://github.com/pantoniou/libfyaml/issues/315
        NOTE: Fixed by: 
https://github.com/pantoniou/libfyaml/commit/12d903a5c9163d15edf2ef9d7311bd0d1505d902
 (v1.0.0-beta1)
 CVE-2026-88358 (simdjson 4.6.1 contains a one-byte out-of-bounds read 
vulnerability in ...)
@@ -3309,6 +3317,7 @@ CVE-2025-32000 (HCL Sametime is vulnerable to 
insufficient input sanitization. T
        NOT-FOR-US: HCL
 CVE-2026-97404 (In OpenStack Zaqar before 22.0.2, WSGI transport mishandles 
the URL-Si ...)
        - zaqar 23.0.0~rc1-3 (bug #1148897)
+       [trixie] - zaqar <no-dsa> (Minor issue)
        NOTE: https://security.openstack.org/ossa/OSSA-2026-042.html
 CVE-2026-88816 [Fix FetchHashKeyName   on IV/NV]
        - libdbi-perl <unfixed> (bug #1149042)
@@ -5029,6 +5038,7 @@ CVE-2026-59990 (Jawn is an open source JSON parser. Prior 
to 1.7.0, Jawn parse m
        NOTE: Fixed by: 
https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214
 (v1.7.0)
 CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to 
version 4.2.0, ...)
        - python-hpack <unfixed> (bug #1148944)
+       [trixie] - python-hpack <no-dsa> (Minor issue)
        NOTE: 
https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
        NOTE: 
https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c
 (v4.2.0)
 CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in 
vanilla Java ...)
@@ -5546,6 +5556,7 @@ CVE-2026-XXXX [GHSA-83g2-gf92-5c4g]
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-83g2-gf92-5c4g
 CVE-2026-95516
        - zbar 0.23.93-10
+       [trixie] - zbar <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537756
 CVE-2026-96273 (Ghidra before 12.1.4 fails to validate the TYPE_COL byte in 
OptionsDB. ...)
        - ghidra <itp> (bug #923851)
@@ -5646,6 +5657,7 @@ CVE-2026-91024 (The Booking Manager  WordPress plugin 
before 2.1.21 does not san
        NOT-FOR-US: WordPress plugin
 CVE-2026-91018 (lwIP (Lightweight IP)has a double free vulnerability, which 
could cras ...)
        - lwip <unfixed> (bug #1148822)
+       [trixie] - lwip <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f873b6295933e4149a2132adf3e9a2d2a676a5ec
 CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 
6.6.1 do ...)
        NOT-FOR-US: WordPress plugin
@@ -5704,6 +5716,7 @@ CVE-2026-87979 (The Paymob for WooCommerce WordPress 
plugin before 4.1.14 does n
        NOT-FOR-US: WordPress plugin
 CVE-2026-87121 (lwIPTCP/IP Stack MQTTis vulnerable to an out-of-bounds write, 
which ma ...)
        - lwip <unfixed> (bug #1148822)
+       [trixie] - lwip <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=68b2c1191886578d40342846db6ab9a0099c2f40
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f89407ea711879c04d91c92b35d67be78bbaf0f1
 CVE-2026-87074 (The Forminator Forms  WordPress plugin before 1.57.2.1 does 
not bind i ...)
@@ -10250,6 +10263,7 @@ CVE-2026-61793 (Nuxt OG Image generates OG Images with 
Vue templates in Nuxt. Fr
        NOT-FOR-US: Nuxt OG Image
 CVE-2026-61700 (MariaDB Connector/J is used to connect applications developed 
in Java  ...)
        - mariadb-connector-java 2.7.15-1
+       [trixie] - mariadb-connector-java <no-dsa> (Minor issue)
        NOTE: https://jira.mariadb.org/browse/CONJ-1318
        NOTE: 
https://github.com/mariadb-corporation/mariadb-connector-j/security/advisories/GHSA-wxmm-q36w-r9xj
        NOTE: Fixed by: 
https://github.com/mariadb-corporation/mariadb-connector-j/commit/0205d8be947918566cd9ce5a9db149541bbc8dee
 (3.5.9)


=====================================
data/dsa-needed.txt
=====================================
@@ -23,7 +23,7 @@ amd64-microcode (carnil)
 bouncycastle
   possibly move to 1.85 for trixie
 --
-buildstream
+buildstream (jmm)
   Maintainer can provide an update for review
 --
 cacti
@@ -116,6 +116,9 @@ pacemaker
 pdfminer (carnil)
   Required followup for CVE-2025-64512 as original fix was incomplete.
 --
+pillow
+  more CVEs to come
+--
 podman
 --
 prometheus



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03b5fd0d6bd463ae6c9aa1a0258e410cc583416c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03b5fd0d6bd463ae6c9aa1a0258e410cc583416c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to