Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8adb2750 by Moritz Muehlenhoff at 2026-10-04T23:32:28+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -2262,7 +2262,7 @@ CVE-2026-12241 (The Advanced Woo Labels \u2013 Product
Labels & Badges for WooCo
CVE-2026-103641 (A flaw was found in GEGL. The Radiance HDR loader reads past
the end o ...)
- gegl <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2544420
- TODO: check status upstream
+ NOTE:
https://gitlab.gnome.org/GNOME/gegl/-/commit/75214d1e6893d5a6b418a62ae6953a121c371a32
CVE-2026-103592 (simple-php-router through 5.4.1.7 contains an IP restriction
bypass vu ...)
NOT-FOR-US: simple-php-router
CVE-2026-103591 (DeepWiki-Open through commit d92819a contains an
unauthenticated arbit ...)
@@ -2307,15 +2307,18 @@ CVE-2026-103532 (A vulnerability has been found in
immich-app Immich up to 2.7.5
NOT-FOR-US: immich-app Immich
CVE-2026-103531 (A flaw has been found in OpenSC up to 0.27.1. The impacted
element is ...)
- opensc <unfixed> (bug #1149970)
+ [trixie] - opensc <no-dsa> (Minor issue)
NOTE: https://github.com/OpenSC/OpenSC/pull/3812
NOTE: Fixed by:
https://github.com/OpenSC/OpenSC/commit/ad730304052937c32b4eb489a06835ac6123632c
CVE-2026-103530 (A vulnerability was detected in decolua 9Router up to 0.5.55.
The affe ...)
NOT-FOR-US: decolua 9Router
CVE-2026-103387 (A weakness has been identified in garycourt uri-js up to
4.4.1. This a ...)
- node-uri-js <unfixed> (bug #1149972)
+ [trixie] - node-uri-js <no-dsa> (Minor issue)
NOTE: https://github.com/garycourt/uri-js/issues/103
CVE-2026-103001 (PyJWT is a Python implementation of JSON Web Token standards.
From 2.1 ...)
- pyjwt 2.14.0-1
+ [trixie] - pyjwt <not-affected> (Vulnerable code not present)
[bookworm] - pyjwt <not-affected> (Vulnerable code introduced in 2.11.0)
NOTE:
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q
NOTE: https://github.com/jpadilla/pyjwt/issues/679
=====================================
data/dsa-needed.txt
=====================================
@@ -158,7 +158,7 @@ runc
rust-wasmtime
for CVE-2026-34987 CVE-2026-34971, rest would also be fine to ignore
--
-sabnzbdplus
+sabnzbdplus (jmm)
Maintainer is proposing an update for review in
https://bugs.debian.org/1147154#17
--
shaarli
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8adb275017fd6e9c8efa590fdd10fac8d1e5062a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8adb275017fd6e9c8efa590fdd10fac8d1e5062a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits