Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c26215d9 by Moritz Muehlenhoff at 2026-09-27T22:46:54+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1216,10 +1216,11 @@ CVE-2026-88389 (Espruino 2v29 (commit bffc6d0) contains 
a NULL pointer dereferen
 CVE-2026-88388 (Espruino 2v29 (commit bffc6d0) contains a stack-based buffer 
overflow  ...)
        NOT-FOR-US: Espruino
 CVE-2026-88387 (LibRaw 0.22.0 contains an incorrect numeric conversion 
vulnerability i ...)
-       - libraw <unfixed> (bug #1149063)
+       - libraw <unfixed> (bug #1149063; unimportant)
        NOTE: https://github.com/LibRaw/LibRaw/issues/844
        NOTE: https://github.com/LibRaw/LibRaw/pull/853
        NOTE: Fixed by: 
https://github.com/LibRaw/LibRaw/commit/b41cbbd61951783e0440590dae55411a16185bdf
 (master)
+       NOTE: Negligible security impact
 CVE-2026-88386 (libsndfile 1.2.2 contains a misaligned memory access issue in 
psf_binh ...)
        - libsndfile <unfixed> (bug #1149062)
        [trixie] - libsndfile <no-dsa> (Minor issue)
@@ -6700,6 +6701,7 @@ CVE-2026-95511
        REJECTED
 CVE-2026-95508 (A heap-based buffer overflow was found in the DHCPv6 and TFTP 
response ...)
        - libslirp 4.9.5-1 (bug #1148836)
+       [trixie] - libslirp <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537748
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/slirp/libslirp/-/commit/97f2dd0afea0db8b31135f768ecafe0775722a25
 (v4.9.5)
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/slirp/libslirp/-/commit/5815f119c334c26e6e7a14ac87eca12b69918627
 (v4.9.5)
@@ -6707,6 +6709,7 @@ CVE-2026-95508 (A heap-based buffer overflow was found in 
the DHCPv6 and TFTP re
        NOTE: is only for the DHCPv6 part
 CVE-2026-95507
        - libslirp 4.9.5-1 (bug #1148835)
+       [trixie] - libslirp <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537747
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/slirp/libslirp/-/commit/b4b2b07812fcadd2754281e5ae8d9fe2bfb3c96a
 (v4.9.5)
 CVE-2026-95503 (A flaw was found in the Kerberos federation provider of 
Keycloak, an o ...)
@@ -6785,6 +6788,7 @@ CVE-2026-90882 (The open-vsx.org deployment returned 
Access-Control-Allow-Origin
        NOT-FOR-US: open-vsx.org
 CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access 
provide ...)
        - sssd <unfixed> (bug #1148827)
+       [trixie] - sssd <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479483
 CVE-2026-8849 (Use After Free vulnerability in RTI Connext Professional 
(Security Plu ...)
        NOT-FOR-US: RTI Connext


=====================================
data/dsa-needed.txt
=====================================
@@ -76,6 +76,8 @@ kitty
 libheif (aron)
   Wait until new upstream release lands in sid
 --
+libwebsockets (jmm)
+--
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more 6.12.y versions



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c26215d9fbe27fa9e1a22b6ce8d3b9d514751c73

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c26215d9fbe27fa9e1a22b6ce8d3b9d514751c73
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to