Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8115c3cb by Moritz Muehlenhoff at 2026-10-10T00:30:25+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1342,11 +1342,13 @@ CVE-2026-106596 (Missing Authorization vulnerability in
Visual Composer Visual C
NOT-FOR-US: WordPress plugin or theme
CVE-2026-106438 (An incorrect calculation in Decimal128 string parsing in the
MongoDB C ...)
- mongo-c-driver 2.5.6-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6419
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/54a7e9f372bd8e1953298b60393b07b042360a87
(2.5.6)
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/12930599bad296e8a42042677478279fd9e903f7
(1.30.13)
CVE-2026-106437 (The BSON buffer-reservation API in the MongoDB C Driver can
record a l ...)
- mongo-c-driver 2.5.6-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6423
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/6c593a59a9dce87e42298b85779ca02a9357dd74
(2.5.6)
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/b7f1f5742351741c068020196fd88f196551aad2
(1.30.13)
@@ -1375,6 +1377,7 @@ CVE-2026-106432 (The BSON encoder in the MongoDB PHP
Driver converts a string le
NOTE: Fixed by:
https://github.com/mongodb/mongo-php-driver/commit/79036dd7a4c946cfef2d0105f8102f26d685b260
(2.5.4, 2.1.11, 1.21.11)
CVE-2026-106431 (An off-by-one error in the BSON bulk document writer in the
MongoDB C ...)
- mongo-c-driver 2.5.6-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6418
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/bddaffdabdb449d8ee5e8b28f9a82afd03cd42aa
(2.5.6)
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/70d96b8f28974e02cc966a00953dc3d8c308b8ff
(1.30.13)
@@ -1392,6 +1395,7 @@ CVE-2026-106429 (An integer underflow in the KMS
endpoint-parsing logic of Mongo
NOTE: Fixed by:
https://github.com/mongodb/libmongocrypt/commit/03d09f07bb32f9387aec823444cd7bb6d41cddad
(1.20.5)
CVE-2026-106428 (An out-of-bounds read in SCRAM authentication response
parsing in the ...)
- mongo-c-driver 2.4.0-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6370
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/9655909e15c83149c0fc68e53f38e696bbd23569
(2.4.0)
NOTE: Fixed by:
https://github.com/mongodb/mongo-c-driver/commit/57054353fdf79383341de21540a2adab196eb6a4
(1.30.13)
@@ -1568,6 +1572,7 @@ CVE-2026-97032 (HTTP/2 servers could end up crashing due
to inadvertently modify
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-golang-x-net 1:0.60.0-1
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
@@ -1580,6 +1585,7 @@ CVE-2026-78659 (When "Trailer" headers are sent by a
client, the HTTP server int
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-golang-x-net 1:0.60.0-1
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
@@ -1592,6 +1598,7 @@ CVE-2026-97031 (Multiple ECH outer extension references
are not permitted under
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81855
@@ -1602,6 +1609,7 @@ CVE-2026-94444 (Previously, a user operating inside of a
malicious Go project th
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81833
@@ -1612,6 +1620,7 @@ CVE-2026-94447 (Previously, a user operating inside of a
malicious Go project th
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81834
@@ -1622,6 +1631,7 @@ CVE-2026-94448 (When a JavaScript template literal
contains consecutive expressi
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81821
@@ -1632,6 +1642,7 @@ CVE-2026-97030 (A trusted template author may have
previously written a valid te
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81823
@@ -1642,6 +1653,7 @@ CVE-2026-94440 (Parsing a multipart form can bypass
memory limits and read an ar
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81741
@@ -1652,6 +1664,7 @@ CVE-2026-56866 (When http.Transport sends an HTTP/1
CONNECT request with a non-e
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81740
@@ -1662,6 +1675,7 @@ CVE-2026-94439 (When an HTTP server handler sends a 2xx
response to an HTTP/1 CO
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81744
@@ -1672,6 +1686,7 @@ CVE-2026-78669 (A malicious HTTP/2 peer can cause
excessive CPU consumption in t
- golang-1.26 <unfixed>
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-golang-x-net 1:0.60.0-1
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
@@ -1684,6 +1699,7 @@ CVE-2026-78660 (Historically, we have been rather lax
about malformed framing-re
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-golang-x-net 1:0.60.0-1
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
@@ -1703,6 +1719,7 @@ CVE-2026-78667 (When parsing a Range header containing a
large number of small r
- golang-1.26 1.26.9-1
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
NOTE: https://github.com/golang/go/issues/81858
@@ -1713,6 +1730,7 @@ CVE-2026-78663 (The HTTP/2 server can refund
connection-level flow control twice
- golang-1.26 <unfixed>
- golang-1.25 <removed>
- golang-1.24 <removed>
+ [trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- golang-golang-x-net 1:0.60.0-1
NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
=====================================
data/dsa-needed.txt
=====================================
@@ -199,6 +199,8 @@ vips
weechat
Upstream recommends to use branch from
https://github.com/weechat/weechat/commits/4.6/, cf #1142597
--
+wordpress
+--
xorg-server (carnil)
--
zlib (carnil)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8115c3cbfce736a791981092cbc56fe2e8a88ee4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8115c3cbfce736a791981092cbc56fe2e8a88ee4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits