Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits: 31a41dd6 by Sylvain Beucler at 2026-07-15T07:55:48+02:00 CVE-2026-60103/blender: bookworm,bullseye postponed - - - - - 9b3b264a by Sylvain Beucler at 2026-07-15T07:55:50+02:00 CVE-2026-12725,CVE-2026-12969/dnsmasq: bookworm,bullseye postponed - - - - - befba73a by Sylvain Beucler at 2026-07-15T07:55:53+02:00 CVE-2026-11623/tmux: bookworm,bullseye not-affected (trixie probably neither, cf. possible introductory commit at https://ubuntu.com/security/CVE-2026-11623 ) - - - - - 1 changed file: - data/CVE/list Changes: ===================================== data/CVE/list ===================================== @@ -329,6 +329,8 @@ CVE-2026-60121 (Vitec Flamingo 4.12.2 contains an unauthenticated OS command inj CVE-2026-60103 (Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerabili ...) - blender <unfixed> [trixie] - blender <no-dsa> (Minor issue) + [bookworm] - blender <postponed> (Minor issue, OOB read) + [bullseye] - blender <postponed> (Minor issue, OOB read) NOTE: https://projects.blender.org/blender/blender/pulls/161273 NOTE: Fixed by: https://projects.blender.org/blender/blender/commit/968972a918b5ed2d534295b639c54449d7de11cd CVE-2026-59523 (Missing Authorization vulnerability in NSquared Simply Schedule Appoin ...) @@ -15596,6 +15598,8 @@ CVE-2026-13007 (Tenable Identity Exposure contains multiple unauthenticated API CVE-2026-12969 (An out-of-bounds read vulnerability exists in dnsmasq's find_soa() fun ...) - dnsmasq 2.93-1 [trixie] - dnsmasq <no-dsa> (Minor issue) + [bookworm] - dnsmasq <postponed> (Minor issue) + [bullseye] - dnsmasq <postponed> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2491663 NOTE: Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=14094e88beca519c53151184cc4553656672b54f (v2.93rc1) CVE-2026-12958 (Missing symlink validation in Language Servers for AWS may allow an ar ...) @@ -16318,6 +16322,8 @@ CVE-2026-12862 (Untrusted user data was passed verbatim to Excel exports for adm CVE-2026-12725 (A heap-based buffer overflow was found in dnsmasq. When DNSSEC validat ...) - dnsmasq 2.93-1 [trixie] - dnsmasq <no-dsa> (Minor issue) + [bookworm] - dnsmasq <postponed> (Minor issue) + [bullseye] - dnsmasq <postponed> (Minor issue) NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490763 NOTE: Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=36d081e37477027fd721fea498f3760f529034ad (v2.93test10) CVE-2026-12628 (IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Pro ...) @@ -24374,9 +24380,11 @@ CVE-2026-24315 (SAP Fiori Launchpad allows attackers to craft malicious URLs tha CVE-2026-11623 (A security vulnerability has been detected in tmux up to 3.6a. Affecte ...) - tmux 3.6b-1 (bug #1140487) [trixie] - tmux <no-dsa> (Minor issue) - [bullseye] - tmux <postponed> (minor issue; hard to exploit) + [bookworm] - tmux <not-affected> (SIXEL support introduced in v3.4) + [bullseye] - tmux <not-affected> (SIXEL support introduced in v3.4) NOTE: Fixed by: https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03 (3.7) NOTE: Fixed by: https://github.com/tmux/tmux/commit/b8434182c9ead062be8d50a1ff88e98b41108c1f (3.6b) + NOTE: https://gist.github.com/XlabAITeam/f0d9952595f795129a3258ba73bbc3cb CVE-2026-11621 (A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This im ...) NOT-FOR-US: Dcat-Admin CVE-2026-11620 (A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. Thi ...) View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/082c7270ec24861f176297e81391971ac24bfbe8...befba73ad7ae4374e014225d08eb113d16617e85 -- View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/082c7270ec24861f176297e81391971ac24bfbe8...befba73ad7ae4374e014225d08eb113d16617e85 You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
_______________________________________________ debian-security-tracker-commits mailing list [email protected] https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits
