Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
83f0fe21 by Moritz Muehlenhoff at 2026-02-06T22:26:56+01:00
bugnums

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -226,7 +226,7 @@ CVE-2026-25727 (time provides date and time handling in 
Rust. From 0.3.6 to befo
        NOTE: https://github.com/advisories/GHSA-r6v5-fh4h-64xc
        NOTE: 
https://github.com/time-rs/time/commit/f6206b050fd54817d8872834b4d61f605570e89b 
(v0.3.47)
 CVE-2026-XXXX [RUSTSEC-2026-0008]
-       - rust-git2 <unfixed>
+       - rust-git2 <unfixed> (bug #1127315)
        [trixie] - rust-git2 <no-dsa> (Minor issue)
        [bookworm] - rust-git2 <no-dsa> (Minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0008.html
@@ -273,14 +273,14 @@ CVE-2026-1998 (A flaw has been found in micropython up to 
1.27.0. This vulnerabi
        NOTE: 
https://github.com/dpgeorge/micropython/commit/570744d06c5ba9dba59b4c3f432ca4f0abd396b6
        NOTE: No security impact
 CVE-2026-1991 (A vulnerability was detected in libuvc up to 0.0.7. Affected is 
the fu ...)
-       - libuvc <unfixed>
+       - libuvc <unfixed> (bug #1127316)
        [trixie] - libuvc <postponed> (Minor issue, revisit when fixed upstream)
        [bookworm] - libuvc <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/libuvc/libuvc/issues/300
 CVE-2026-1990 (A security vulnerability has been detected in oatpp up to 
1.3.1. This  ...)
        NOT-FOR-US: oatpp
 CVE-2026-1979 (A flaw has been found in mruby up to 3.4.0. This affects the 
function  ...)
-       - mruby <unfixed>
+       - mruby <unfixed> (bug #1127317)
        [trixie] - mruby <no-dsa> (Minor issue)
        [bookworm] - mruby <no-dsa> (Minor issue)
        NOTE: https://github.com/mruby/mruby/issues/6701
@@ -546,7 +546,7 @@ CVE-2026-25578 (Navidrome is an open source web-based music 
collection server an
 CVE-2026-25575 (NavigaTUM is a website and API to search for rooms, buildings 
and othe ...)
        NOT-FOR-US: NavigaTUM
 CVE-2026-25547 (@isaacs/brace-expansion is a hybrid CJS/ESM TypeScript fork of 
brace-e ...)
-       - node-brace-expansion <unfixed>
+       - node-brace-expansion <unfixed> (bug #1127313)
        NOTE: 
https://github.com/isaacs/brace-expansion/security/advisories/GHSA-7h2j-956f-4vf2
        NOTE: Fixed by: 
https://github.com/isaacs/brace-expansion/commit/59d12f1e23accdec8c395ca824cf942c1fdea860
 CVE-2026-25546 (Godot MCP is a Model Context Protocol (MCP) server for 
interacting wit ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f0fe21fc6e2ea45b0daeac58ed6e66782548f7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/83f0fe21fc6e2ea45b0daeac58ed6e66782548f7
You're receiving this email because of your account on salsa.debian.org.


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to