Sylvain Beucler pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
31a41dd6 by Sylvain Beucler at 2026-07-15T07:55:48+02:00
CVE-2026-60103/blender: bookworm,bullseye postponed

- - - - -
9b3b264a by Sylvain Beucler at 2026-07-15T07:55:50+02:00
CVE-2026-12725,CVE-2026-12969/dnsmasq: bookworm,bullseye postponed

- - - - -
befba73a by Sylvain Beucler at 2026-07-15T07:55:53+02:00
CVE-2026-11623/tmux: bookworm,bullseye not-affected

(trixie probably neither, cf. possible introductory commit at 
https://ubuntu.com/security/CVE-2026-11623 )

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -329,6 +329,8 @@ CVE-2026-60121 (Vitec Flamingo 4.12.2 contains an 
unauthenticated OS command inj
 CVE-2026-60103 (Blender 3.0.0 through 5.1.2 contains an out-of-bounds read 
vulnerabili ...)
        - blender <unfixed>
        [trixie] - blender <no-dsa> (Minor issue)
+       [bookworm] - blender <postponed> (Minor issue, OOB read)
+       [bullseye] - blender <postponed> (Minor issue, OOB read)
        NOTE: https://projects.blender.org/blender/blender/pulls/161273
        NOTE: Fixed by: 
https://projects.blender.org/blender/blender/commit/968972a918b5ed2d534295b639c54449d7de11cd
 CVE-2026-59523 (Missing Authorization vulnerability in NSquared Simply 
Schedule Appoin ...)
@@ -15596,6 +15598,8 @@ CVE-2026-13007 (Tenable Identity Exposure contains 
multiple unauthenticated API
 CVE-2026-12969 (An out-of-bounds read vulnerability exists in dnsmasq's 
find_soa() fun ...)
        - dnsmasq 2.93-1
        [trixie] - dnsmasq <no-dsa> (Minor issue)
+       [bookworm] - dnsmasq <postponed> (Minor issue)
+       [bullseye] - dnsmasq <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2491663
        NOTE: Fixed by: 
https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=14094e88beca519c53151184cc4553656672b54f
 (v2.93rc1)
 CVE-2026-12958 (Missing symlink validation in Language Servers for AWS may 
allow an ar ...)
@@ -16318,6 +16322,8 @@ CVE-2026-12862 (Untrusted user data was passed verbatim 
to Excel exports for adm
 CVE-2026-12725 (A heap-based buffer overflow was found in dnsmasq. When DNSSEC 
validat ...)
        - dnsmasq 2.93-1
        [trixie] - dnsmasq <no-dsa> (Minor issue)
+       [bookworm] - dnsmasq <postponed> (Minor issue)
+       [bullseye] - dnsmasq <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490763
        NOTE: Fixed by: 
https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=36d081e37477027fd721fea498f3760f529034ad
 (v2.93test10)
 CVE-2026-12628 (IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM 
Storage Pro ...)
@@ -24374,9 +24380,11 @@ CVE-2026-24315 (SAP Fiori Launchpad allows attackers 
to craft malicious URLs tha
 CVE-2026-11623 (A security vulnerability has been detected in tmux up to 3.6a. 
Affecte ...)
        - tmux 3.6b-1 (bug #1140487)
        [trixie] - tmux <no-dsa> (Minor issue)
-       [bullseye] - tmux <postponed> (minor issue; hard to exploit)
+       [bookworm] - tmux <not-affected> (SIXEL support introduced in v3.4)
+       [bullseye] - tmux <not-affected> (SIXEL support introduced in v3.4)
        NOTE: Fixed by: 
https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03 
(3.7)
        NOTE: Fixed by: 
https://github.com/tmux/tmux/commit/b8434182c9ead062be8d50a1ff88e98b41108c1f 
(3.6b)
+       NOTE: 
https://gist.github.com/XlabAITeam/f0d9952595f795129a3258ba73bbc3cb
 CVE-2026-11621 (A weakness has been identified in Dcat-Admin up to 2.2.3-beta. 
This im ...)
        NOT-FOR-US: Dcat-Admin
 CVE-2026-11620 (A security flaw has been discovered in TOTOLINK EX200 
4.0.3c.7646. Thi ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/082c7270ec24861f176297e81391971ac24bfbe8...befba73ad7ae4374e014225d08eb113d16617e85

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/082c7270ec24861f176297e81391971ac24bfbe8...befba73ad7ae4374e014225d08eb113d16617e85
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to