Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a25bff00 by Moritz Muehlenhoff at 2026-09-29T08:49:28+02:00
trixie triage
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -3830,13 +3830,11 @@ CVE-2026-XXXX [GHSA-443p-7392-h4v2]
NOTE:
https://github.com/lxc/incus/security/advisories/GHSA-443p-7392-h4v2
CVE-2026-85526 [GHSA-h85r-gjgx-g2rv]
- incus 7.0.1-5
- [trixie] - incus 6.0.4-2+deb13u11
- lxd <removed>
[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv
CVE-2026-85185 [GHSA-27q7-qwhm-c34p]
- incus 7.0.1-5
- [trixie] - incus 6.0.4-2+deb13u11
- lxd <removed>
[bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
NOTE:
https://github.com/canonical/lxd/security/advisories/GHSA-27q7-qwhm-c34p
@@ -17979,6 +17977,7 @@ CVE-2026-91993 (Jpom through 2.11.12 fails to validate
workspace ownership when
NOT-FOR-US: Jpom
CVE-2026-91992 (Tornado before 6.5.7 contains a credential leak vulnerability
in CurlA ...)
- python-tornado <unfixed> (bug #1148323)
+ [trixie] - python-tornado <no-dsa> (Minor issue)
NOTE:
https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f
CVE-2026-91991 (Tornado before 6.5.8 contains an incomplete fix for cookie
attribute i ...)
- python-tornado <unfixed> (bug #1148323)
@@ -17987,6 +17986,7 @@ CVE-2026-91991 (Tornado before 6.5.8 contains an
incomplete fix for cookie attri
NOTE: CVE exists because of an incomplete fix for CVE-2026-35536
CVE-2026-91990 (Tornado before 6.5.8 contains a memory amplification
vulnerability in ...)
- python-tornado <unfixed> (bug #1148323)
+ [trixie] - python-tornado <no-dsa> (Minor issue)
NOTE:
https://github.com/tornadoweb/tornado/security/advisories/GHSA-8423-8fgw-73vq
CVE-2026-91989 (atomic-agents-stack before 1.1.0 contains a path traversal
vulnerabili ...)
NOT-FOR-US: atomic-agents-stack
=====================================
data/DSA/list
=====================================
@@ -1697,7 +1697,7 @@
[bookworm] - lxd 5.0.2-5+deb12u1
[trixie] - lxd 5.0.2+git20231211.1364ae4-9+deb13u1
[17 Oct 2025] DSA-6027-1 incus - security update
- {CVE-2025-54286 CVE-2025-54287 CVE-2025-54288 CVE-2025-54289
CVE-2025-54290 CVE-2025-54291 CVE-2025-54293}
+ {CVE-2025-54286 CVE-2025-54287 CVE-2025-54288 CVE-2025-54289
CVE-2025-54290 CVE-2025-54291 CVE-2025-54293 CVE-2026-85526 CVE-2026-85185}
[trixie] - incus 6.0.4-2+deb13u1
[16 Oct 2025] DSA-6026-1 chromium - security update
{CVE-2025-11756}
=====================================
data/dsa-needed.txt
=====================================
@@ -185,6 +185,8 @@ vips
weechat
Upstream recommends to use branch from
https://github.com/weechat/weechat/commits/4.6/, cf #1142597
--
+wireshark
+--
xz-utils
--
zlib (carnil)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a25bff001e6fbe3a6af2d555e213d92bb21d0604
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a25bff001e6fbe3a6af2d555e213d92bb21d0604
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits