Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bd36d426 by Moritz Muehlenhoff at 2026-10-09T15:14:38+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -516,39 +516,48 @@ CVE-2026-107698 (FFmpeg before 7.1.4 and 8.0.x before 
8.0.2 contains a server-si
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b05562b9b399057b6537fae337d0eeabcff6ef5c
 (n5.1.9)
 CVE-2026-107697 (FFmpeg before 8.1.3 contains a protection mechanism failure 
in the HLS ...)
        - ffmpeg 7:9.0.2-1
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/23602df9cd1b485c45ba6f533d3b85569de3f323
 (master)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/01044d04536eec6e2f5f48ef404cf45d15feb461
 (n9.0)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/191715f0232cee64402c3e7733f28ff4061224b6
 (n8.1.3)
 CVE-2026-107696 (FFmpeg through 9.0.2 contains an infinite loop vulnerability 
in ff_rts ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24902
 CVE-2026-107695 (FFmpeg before 8.1.3 contains an infinite loop vulnerability 
in the HLS ...)
        - ffmpeg 7:9.0.2-1
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c364ab176f722bdabc886845e770c9eacbc1e3e5
 (master)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/0e6eef35517af086419c5157980e926a81070c2a
 (n9.0)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a4ddaba8bb7811b1a3afaad59fe6555e720d4754
 (n8.1.3)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23618
 CVE-2026-107678 (FFmpeg through 9.0.2 contains a stack exhaustion 
vulnerability in av_e ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24593
 CVE-2026-107677 (FFmpeg through 9.0.2 contains a denial of service 
vulnerability in the ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24592
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ed27bfcbbbc0872c0195eaf4dd2c0c93b9f1778e
 (master)
 CVE-2026-107676 (FFmpeg through 9.0.2 contains an uninitialized memory 
disclosure vulne ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24590
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2c2f6e96e31795ae95a8f8323a493ffbc493111f
 (master)
 CVE-2026-107675 (FFmpeg through 9.0.2 contains a missing host key verification 
vulnerab ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <ignored> (Minor issue and breaking change, won't be 
backported to release branches)
+       [bookworm] - ffmpeg <ignored> (Minor issue and breaking change, won't 
be backported to release branches)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24384
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2b822b7fb6ed195546bc9fd9bdb794e98222bdce
 (master)
 CVE-2026-107660 (FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper 
certific ...)
-       - ffmpeg 7:9.0.2-1
+       - ffmpeg 7:9.0.2-1 (unimportant)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24383
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/57a2e704b4a6eda5d061b45aacde6b19c026bfc0
 (master)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d377212904a19fc740d721cbda0ba58fa3805a29
 (n9.0.2)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/0cd2a70eacd510c2efed48b9fc177c7cb2bc549f
 (n8.1.3)
+       NOTE: mbedtls not enabled in Debian builds
 CVE-2026-107651 (A flaw was found in Eye of GNOME (eog). A heap-based buffer 
overflow e ...)
        - eog <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547986
@@ -2000,9 +2009,11 @@ CVE-2025-64391 (This vulnerability in Veeam Agent for 
Microsoft Windows allows a
        NOT-FOR-US: Veeam
 CVE-2026-92415 (\u2014 Use of Externally-Controlled Input to Select Classes or 
Code vu ...)
        - jackrabbit <unfixed> (bug #1150343)
+       [trixie] - jackrabbit <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/07/28
 CVE-2026-92414 (: Session Fixation / Session Reuse across Users vulnerability 
in Apach ...)
        - jackrabbit <unfixed> (bug #1150343)
+       [trixie] - jackrabbit <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/07/27
 CVE-2026-98374 (In the Linux kernel, the following vulnerability has been 
resolved:  t ...)
        - linux 7.2.9-1
@@ -21123,7 +21134,8 @@ CVE-2026-95619 (A flaw was found in libstdc++. An 
integer overflow can occur whe
        [trixie] - gcc-14 <no-dsa> (Minor issue)
        - gcc-12 <unfixed>
        [trixie] - gcc-12 <no-dsa> (Minor issue)
-       NOTE: 
https://github.com/gcc-mirror/gcc/commit/59d235ffa5a69231eb42e5290d52dc8c90d28b7a
+       NOTE: 
https://github.com/gcc-mirror/gcc/commit/59d235ffa5a69231eb42e5290d52dc8c90d28b7a
 (master)
+       NOTE: 
https://github.com/gcc-mirror/gcc/commit/200183d4ab5d57575f3dfebc6af3baf649910b9e
 (releases/gcc-14)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537811
 CVE-2026-95511
        REJECTED


=====================================
data/dsa-needed.txt
=====================================
@@ -100,7 +100,9 @@ modsecurity
 --
 modsecurity-apache
 --
-nagios4
+mutt (jmm)
+--
+nagios4 (jmm)
   Maintainer provided an update for review in 
<[email protected]>
 --
 nats-server



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd36d42621b5fad95773b4561704b2b23257167c

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd36d42621b5fad95773b4561704b2b23257167c
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to