Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c399f5a9 by Moritz Muehlenhoff at 2026-06-30T11:44:36+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,6 +3,7 @@ CVE-2026-57964
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493580
 CVE-2026-44605
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2482481
 CVE-2026-13606
        - graphicsmagick <unfixed>
@@ -228,6 +229,7 @@ CVE-2026-50229 (Improper Neutralization of Script-Related 
HTML Tags in a Web Pag
        NOTE: 
https://github.com/apache/tomcat/commit/de5a950415fc67713f17fab63d0c7809e0fca80b
 (9.0.119)
 CVE-2026-13758 (CryptX versions before 0.088_001 for Perl compare AEAD 
authentication  ...)
        - libcryptx-perl 0.089-1
+       [trixie] - libcryptx-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41398101/
        NOTE: Fixed by: 
https://github.com/DCIT/perl-CryptX/commit/7e56347d420aaf43b2ee1586f4a230492ccf1642
 (v0.089)
 CVE-2026-13593 (CSS::Minifier::XS versions before 0.14 for Perl have a memory 
leak whe ...)
@@ -1489,6 +1491,7 @@ CVE-2026-57231 (Podman is a tool for managing OCI 
containers and pods. From 1.8.
        NOTE: Fixed by: 
https://github.com/podman-container-tools/podman/commit/85832029d537c2c0df89e47d4a03d55ba099a848
 (v5.8.4)
 CVE-2026-56876 (extract-zip does not validate symlink targets when extracting 
zip arch ...)
        - node-extract-zip <unfixed>
+       [trixie] - node-extract-zip <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ziad626/extract-zip-security-research/security/advisories/GHSA-x7jf-2287-qcpf
 CVE-2026-56823 (AutoGPT is a workflow automation platform for creating, 
deploying, and ...)
        NOT-FOR-US: AutoGPT
@@ -2485,6 +2488,7 @@ CVE-2026-11999 (X.509 trust-chain bypass (path-depth 
exhaustion) in the OpenSSL
        TODO: check
 CVE-2026-12844 (List::SomeUtils::XS versions before 0.59 for Perl have a heap 
buffer o ...)
        - liblist-someutils-xs-perl 0.59-1
+       [trixie] - liblist-someutils-xs-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/41398142/
        NOTE: Fixed by: 
https://github.com/houseabsolute/List-SomeUtils-XS/commit/22549f78669b780d6aa338a2d2e49a3dedfffaa6
 (v0.59)
 CVE-2026-40211 (An attacker can send crafted DNS over HTTP/3 queries, 
triggering an ex ...)
@@ -5777,9 +5781,9 @@ CVE-2025-71337 (Flowise before 3.0.10 (affected versions 
3.0.7 and earlier) cont
 CVE-2025-62180 (Pega Platform versions 8.3.0 through Infinity 25.1.2 are 
affected by a ...)
        NOT-FOR-US: Pega Platform
 CVE-2025-61029 (An issue in the sqlo_untry component of openlink 
virtuoso-opensource v ...)
-       - virtuoso-opensource <undetermined>
+       - virtuoso-opensource 7.2.12+dfsg-0.2
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1228
-       TODO: check, pinpoint commit, upstream issue say "This issue has been 
fixed by recent commits to the develop/7 branch" and might be in v7.2.12
+       NOTE: Fixed by: 
https://github.com/openlink/virtuoso-opensource/commit/9df21ea5c2100b90503ee83d828dae6a3d56444a
 (v7.2.12)
 CVE-2025-61028 (An issue in the time_t_to_dt component of openlink 
virtuoso-opensource ...)
        - virtuoso-opensource 7.2.12+dfsg-0.2
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1233
@@ -5793,25 +5797,25 @@ CVE-2025-61025 (An issue in the sslr_qst_get component 
of openlink virtuoso-open
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1229
        NOTE: Fixed by: 
https://github.com/openlink/virtuoso-opensource/commit/d1774339a7ff48f924ac6bc486f541851166091b
 (v7.2.12)
 CVE-2025-61024 (An issue in the sqlo_try_in_loop component of openlink 
virtuoso-openso ...)
-       - virtuoso-opensource <undetermined>
+       - virtuoso-opensource 7.2.12+dfsg-0.2
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1227
-       TODO: check, pinpoint commit, upstream issue say "This issue has been 
fixed by recent commits to the develop/7 branch" and might be in v7.2.12
+       NOTE: Fixed by: 
https://github.com/openlink/virtuoso-opensource/commit/9df21ea5c2100b90503ee83d828dae6a3d56444a
 (v7.2.12)
 CVE-2025-61023 (An issue in the st_compare component of openlink 
virtuoso-opensource v ...)
        - virtuoso-opensource 7.2.12+dfsg-0.2
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1230
        NOTE: Fixed by: 
https://github.com/openlink/virtuoso-opensource/commit/b27928d04343730b2cb6c23d1c23d52770347940
 (v7.2.12)
 CVE-2025-61022 (An issue in the sqlo_tb_col_preds component of openlink 
virtuoso-opens ...)
-       - virtuoso-opensource <undetermined>
+       - virtuoso-opensource 7.2.12+dfsg-0.2
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1226
-       TODO: check, pinpoint commit, upstream issue say "This issue has been 
fixed by recent commits to the develop/7 branch" and might be in v7.2.12
+       NOTE: Fixed by: 
https://github.com/openlink/virtuoso-opensource/commit/9df21ea5c2100b90503ee83d828dae6a3d56444a
 (v7.2.12)
 CVE-2025-61021 (An issue in the sqlo_natural_join_cond component of openlink 
virtuoso- ...)
        - virtuoso-opensource 7.2.12+dfsg-0.2
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1223
        NOTE: Fixed by: 
https://github.com/openlink/virtuoso-opensource/commit/99e0c0a22691a08e69958875b1b30007baa82b8e
 (v7.2.12)
 CVE-2025-61020 (An issue in the sqlo_strip_in_join component of openlink 
virtuoso-open ...)
-       - virtuoso-opensource <undetermined>
+       - virtuoso-opensource 7.2.12+dfsg-0.2
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1225
-       TODO: check, pinpoint commit, upstream issue say "This issue has been 
fixed by recent commits to the develop/7 branch" and might be in v7.2.12
+       NOTE: Fixed by: 
https://github.com/openlink/virtuoso-opensource/commit/9df21ea5c2100b90503ee83d828dae6a3d56444a
 (v7.2.12)
 CVE-2025-61019 (An issue in the sqlo_key_part_best component of openlink 
virtuoso-open ...)
        - virtuoso-opensource 7.2.12+dfsg-0.2
        NOTE: https://github.com/openlink/virtuoso-opensource/issues/1222
@@ -6798,6 +6802,7 @@ CVE-2026-49344 (Mercator is an open source web 
application that enables mapping
        NOT-FOR-US: Mercator
 CVE-2026-49342 (YARD is a documentation generation tool for the Ruby 
programming langu ...)
        - yard 0.9.44-1
+       [trixie] - yard <no-dsa> (Minor issue)
        NOTE: 
https://github.com/lsegal/yard/security/advisories/GHSA-pxcc-8665-phx8
        NOTE: 
https://github.com/lsegal/yard/commit/f78c19f0dd33a407085b4ed181bb60c0aa0078b4 
(v0.9.44)
 CVE-2026-49340 (gonic is a music streaming server / free-software subsonic 
server API  ...)
@@ -42370,7 +42375,7 @@ CVE-2026-38991 (Cockpit 2.13.5 and earlier is affected 
by a misconfiguration wit
        NOT-FOR-US: Cockpit-HQ/Cockpit
 CVE-2026-37555 (An issue was discovered in libsndfile 1.2.2 IMA ADPCM codec. 
The AIFF  ...)
        - libsndfile <unfixed> (bug #1135346)
-       [trixie] - libsndfile <postponed> (Minor issue, revisit when fixed 
upstream)
+       [trixie] - libsndfile <no-dsa> (Minor issue)
        [bookworm] - libsndfile <postponed> (Minor issue, revisit when fixed 
upstream)
        [bullseye] - libsndfile <postponed> (Minor issue; can be fixed in next 
update)
        NOTE: https://www.openwall.com/lists/oss-security/2026/04/30/7


=====================================
data/dsa-needed.txt
=====================================
@@ -93,6 +93,10 @@ rust-wasmtime
 --
 shaarli
 --
+tomcat10
+--
+tomcat11
+--
 util-linux (carnil)
   Maintainer is preparing updates
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c399f5a968413d5cc771b1d841f3e2fdef94a928

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c399f5a968413d5cc771b1d841f3e2fdef94a928
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to