Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
83f0fe21 by Moritz Muehlenhoff at 2026-02-06T22:26:56+01:00
bugnums
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -226,7 +226,7 @@ CVE-2026-25727 (time provides date and time handling in
Rust. From 0.3.6 to befo
NOTE: https://github.com/advisories/GHSA-r6v5-fh4h-64xc
NOTE:
https://github.com/time-rs/time/commit/f6206b050fd54817d8872834b4d61f605570e89b
(v0.3.47)
CVE-2026-XXXX [RUSTSEC-2026-0008]
- - rust-git2 <unfixed>
+ - rust-git2 <unfixed> (bug #1127315)
[trixie] - rust-git2 <no-dsa> (Minor issue)
[bookworm] - rust-git2 <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0008.html
@@ -273,14 +273,14 @@ CVE-2026-1998 (A flaw has been found in micropython up to
1.27.0. This vulnerabi
NOTE:
https://github.com/dpgeorge/micropython/commit/570744d06c5ba9dba59b4c3f432ca4f0abd396b6
NOTE: No security impact
CVE-2026-1991 (A vulnerability was detected in libuvc up to 0.0.7. Affected is
the fu ...)
- - libuvc <unfixed>
+ - libuvc <unfixed> (bug #1127316)
[trixie] - libuvc <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - libuvc <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://github.com/libuvc/libuvc/issues/300
CVE-2026-1990 (A security vulnerability has been detected in oatpp up to
1.3.1. This ...)
NOT-FOR-US: oatpp
CVE-2026-1979 (A flaw has been found in mruby up to 3.4.0. This affects the
function ...)
- - mruby <unfixed>
+ - mruby <unfixed> (bug #1127317)
[trixie] - mruby <no-dsa> (Minor issue)
[bookworm] - mruby <no-dsa> (Minor issue)
NOTE: https://github.com/mruby/mruby/issues/6701
@@ -546,7 +546,7 @@ CVE-2026-25578 (Navidrome is an open source web-based music
collection server an
CVE-2026-25575 (NavigaTUM is a website and API to search for rooms, buildings
and othe ...)
NOT-FOR-US: NavigaTUM
CVE-2026-25547 (@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of
brace-e ...)
- - node-brace-expansion <unfixed>
+ - node-brace-expansion <unfixed> (bug #1127313)
NOTE:
https://github.com/isaacs/brace-expansion/security/advisories/GHSA-7h2j-956f-4vf2
NOTE: Fixed by:
https://github.com/isaacs/brace-expansion/commit/59d12f1e23accdec8c395ca824cf942c1fdea860
CVE-2026-25546 (Godot MCP is a Model Context Protocol (MCP) server for
interacting wit ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f0fe21fc6e2ea45b0daeac58ed6e66782548f7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f0fe21fc6e2ea45b0daeac58ed6e66782548f7
You're receiving this email because of your account on salsa.debian.org.
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits