Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
85cf948d by Moritz Muehlenhoff at 2026-10-04T23:01:58+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -355,6 +355,7 @@ CVE-2026-105090 (Formbricks before 5.4.4 and 6 before 6.0.1
allows stored XSS. T
NOT-FOR-US: Formbricks
CVE-2026-105083 (ImageMagick before 7.1.2-32 and 6.9.13-57 contains a policy
bypass vul ...)
- imagemagick <unfixed> (bug #1149969)
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE:
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-jjp4-3fwf-393j
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/1926ccf119141c26274c120d1899dffae19b0c71
(7.1.2-32)
NOTE: Fixed by:
https://github.com/ImageMagick/ImageMagick/commit/399d4bd3b081f44c7fef78153f65e8cdebed9f1a
(7.1.2-32)
@@ -529,6 +530,7 @@ CVE-2026-95662 (Cross-Site Scripting vulnerability in the
Repasat application. S
NOT-FOR-US: Repasat
CVE-2026-95512 (A flaw was found in FreeType, specifically within its CID font
loader. ...)
- freetype <unfixed> (bug #1149953)
+ [trixie] - freetype <no-dsa> (Minor issue)
[bookworm] - freetype <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462295
NOTE: Fixed by:
https://gitlab.freedesktop.org/freetype/freetype/-/commit/f3ca71c9900fe860849b3163a6e2c1e765b291d9
@@ -2114,12 +2116,14 @@ CVE-2026-93546 (Integer overflow in mod_dav_fs in
Apache HTTP Server through 2.4
CVE-2026-102505 (Imager versions before 1.037 for Perl overflow a heap buffer
fetching ...)
[experimental] - libimager-perl 1.037+dfsg-1
- libimager-perl <unfixed>
+ [trixie] - libimager-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43998313/
NOTE:
https://github.com/tonycoz/imager/security/advisories/GHSA-4rx6-cgv3-fmxp
NOTE: Fixed by:
https://github.com/tonycoz/imager/commit/aae49c6be065aa467e834105c816359394a634db
(v1.037)
CVE-2026-102504 (Imager versions before 1.037 for Perl exit the process
reading a raw i ...)
[experimental] - libimager-perl 1.037+dfsg-1
- libimager-perl <unfixed>
+ [trixie] - libimager-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43998314/
NOTE:
https://github.com/tonycoz/imager/security/advisories/GHSA-g549-r73g-x7x6
NOTE: Fixed by:
https://github.com/tonycoz/imager/commit/21b0df9eef1dffe1fdcd3706bfea9f1338031679
(v1.037)
@@ -6031,9 +6035,9 @@ CVE-2026-102474 (A flaw was found in dash. The printf
builtin reserves four byte
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543004
NOTE: Negligible security impact
CVE-2026-102473 (A flaw was found in dash. When built without libc fnmatch,
the interna ...)
- - dash <unfixed> (bug #1149887)
- [bookworm] - dash <postponed> (Minor issue)
+ - dash <unfixed> (bug #1149887; unimportant)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543005
+ NOTE: Negligible security impact
CVE-2026-102437 (OS Command Injection in internal/gitcmd (git diff
filter.clean/smudge ...)
NOT-FOR-US: DeepSeek-Reasonix
CVE-2026-102425 (Joomla Extension - balbooa.com - Unauthenticated RCE via
field shortco ...)
@@ -6902,6 +6906,7 @@ CVE-2026-102279 (Laravel is a web application framework.
Prior to 12.69.0 and 13
NOTE: Fixed by:
https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12
(v12.69.0)
CVE-2026-102278 (The brace-expansion library generates arbitrary strings
containing a c ...)
- node-brace-expansion 2.1.7+~1.1.2-1 (bug #1149649)
+ [trixie] - node-brace-expansion <no-dsa> (Minor issue)
NOTE:
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-qhr7-859c-m2p7
NOTE: Fixed by:
https://github.com/juliangruber/brace-expansion/commit/935d78f32f335b2ff76578e5c5e877d31ae9888c
(v5.0.11)
NOTE: Fxied by:
https://github.com/juliangruber/brace-expansion/commit/de84f144e9816f30e25fc8179e2e1249ab6df0db
(v3.0.8)
@@ -6909,6 +6914,7 @@ CVE-2026-102278 (The brace-expansion library generates
arbitrary strings contain
NOTE: Fixed by:
https://github.com/juliangruber/brace-expansion/commit/1efee7c397c191da6287a78ec19512476a966a7b
(v1.1.20)
CVE-2026-102277 (The brace-expansion library generates arbitrary strings
containing a c ...)
- node-brace-expansion 2.1.7+~1.1.2-1 (bug #1149649)
+ [trixie] - node-brace-expansion <no-dsa> (Minor issue)
NOTE:
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-q2hr-2g5m-vwhr
NOTE: Fixed by:
https://github.com/juliangruber/brace-expansion/commit/33a5ef17b8d800bbfa8c52b14c39043b6aac1a96
(v5.0.12)
NOTE: Fixed by:
https://github.com/juliangruber/brace-expansion/commit/c55e67d8d8b1c56a2474afff15c2891166b2d364
(v3.0.9)
@@ -6916,6 +6922,7 @@ CVE-2026-102277 (The brace-expansion library generates
arbitrary strings contain
NOTE: Fixed by:
https://github.com/juliangruber/brace-expansion/commit/ffdfa3e3806bed17c0874b8f1439b084de354a7e
(v1.1.21)
CVE-2026-102276 (The brace-expansion library generates arbitrary strings
containing a c ...)
- node-brace-expansion 2.1.7+~1.1.2-1 (bug #1149649)
+ [trixie] - node-brace-expansion <no-dsa> (Minor issue)
NOTE:
https://github.com/juliangruber/brace-expansion/security/advisories/GHSA-6j4f-fj2g-mc7p
NOTE: Fixed by:
https://github.com/juliangruber/brace-expansion/commit/6735c94873ca570bcdd6a0690033bdd3126379d3
(v5.0.10)
NOTE: Fixed by:
https://github.com/juliangruber/brace-expansion/commit/316359e6019c39b3254c8ba8e25dc586a480652c
(v3.0.7)
@@ -14391,6 +14398,7 @@ CVE-2026-95924 (A vulnerability has been found in
SourceCodester Online Reviewer
NOT-FOR-US: SourceCodester
CVE-2026-95897 (A security vulnerability has been detected in Dask up to
2026.8.0. Thi ...)
- dask <unfixed>
+ [trixie] - dask <no-dsa> (Minor issue)
NOTE: https://github.com/dask/dask/issues/12578
CVE-2026-95868 (A weakness has been identified in AdithyaYelloju
Restaurant-Management ...)
NOT-FOR-US: AdithyaYelloju Restaurant-Management-System
=====================================
data/dsa-needed.txt
=====================================
@@ -150,7 +150,7 @@ rtpengine
--
ruby3.3
--
-ruby-jwt
+ruby-jwt (jmm)
Abhijith PA proposing a debdiff for review in <[email protected]>
--
runc
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/85cf948d86bff26ddef2cab950c7bacebdf4c7e3
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/85cf948d86bff26ddef2cab950c7bacebdf4c7e3
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits