Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
174452d5 by Salvatore Bonaccorso at 2026-07-17T07:30:26+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,30 +1,30 @@
CVE-2026-57077
- - libyaml-syck-perl <unfixed>
+ - libyaml-syck-perl <unfixed> (bug #1142267)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/4
NOTE: Fixed by:
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
(1.47)
CVE-2026-57076
- - libyaml-syck-perl <unfixed>
+ - libyaml-syck-perl <unfixed> (bug #1142267)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/3
NOTE: Fixed by:
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
(1.47)
CVE-2026-57075
- - libyaml-syck-perl <unfixed>
+ - libyaml-syck-perl <unfixed> (bug #1142267)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/2
NOTE: Fixed by:
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
(1.47)
CVE-2026-13713
- - libyaml-syck-perl <unfixed>
+ - libyaml-syck-perl <unfixed> (bug #1142267)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/17/1
NOTE: Fixed by:
https://github.com/toddr/YAML-Syck/commit/44c90a109ec3215ee7ce747bd11209835e123d8b
(1.47)
CVE-2026-62321
- - netatalk <unfixed>
+ - netatalk <unfixed> (bug #1142270)
NOTE: https://netatalk.io/security/CVE-2026-62321
CVE-2026-62320
- - netatalk <unfixed>
+ - netatalk <unfixed> (bug #1142270)
NOTE: https://netatalk.io/security/CVE-2026-62320
CVE-2026-62319
- - netatalk <unfixed>
+ - netatalk <unfixed> (bug #1142270)
NOTE: https://netatalk.io/security/CVE-2026-62319
CVE-2026-62318
- - netatalk <unfixed>
+ - netatalk <unfixed> (bug #1142270)
NOTE: https://netatalk.io/security/CVE-2026-62318
CVE-2026-57074
- libxml-bare-perl 0.53-5 (bug #1142227)
@@ -298,7 +298,7 @@ CVE-2026-62685 (File Browser is a file managing interface
for uploading, deletin
CVE-2026-62683 (File Browser is a file managing interface for uploading,
deleting, pre ...)
NOT-FOR-US: File Browser
CVE-2026-62389 (ws before 8.21.1 contains a memory exhaustion vulnerability in
lib/rec ...)
- - node-ws <unfixed>
+ - node-ws <unfixed> (bug #1142271)
NOTE: https://github.com/websockets/ws/issues/2331
NOTE: Fixed by:
https://github.com/websockets/ws/commit/f197ac65140920bdcecdab74bfc69c2d7858e55d
(8.21.1)
CVE-2026-62378 (RustFS Console is a web management console for the RustFS
distributed ...)
@@ -489,7 +489,7 @@ CVE-2026-59236 (Authorization Bypass Through
User-Controlled Key (CWE-639) in th
CVE-2026-59235 (Missing Authorization (CWE-862) in BankAccountListController
(app/Http ...)
NOT-FOR-US: prospero-flow-crm
CVE-2026-58660 (Kanboard through 1.2.52, fixed in commit 564cc30,
BoardAjaxController ...)
- - kanboard <unfixed>
+ - kanboard <unfixed> (bug #1142272)
NOTE: https://github.com/kanboard/kanboard/issues/5852
NOTE: https://github.com/kanboard/kanboard/pull/5853
NOTE: Fixed by:
https://github.com/kanboard/kanboard/commit/564cc30e1e360959572e01e158734d9475c05903
@@ -852,11 +852,11 @@ CVE-2026-59836 (A improper certificate validation
vulnerability in Fortinet Fort
CVE-2026-59835 (A exposure of resource to wrong sphere vulnerability in
Fortinet Forti ...)
NOT-FOR-US: Fortinet
CVE-2026-59733 (Rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1142269)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-fqj9-69pf-6pjg
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/015fd0eba1cb138eef081517795fed47a2873f2d
(v1.74.4)
CVE-2026-59732 (Rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1142269)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-4vr5-p2gc-h23p
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/1a746732441e8158f32fab35924b23701e719a8c
(v1.74.4)
CVE-2026-59674 (A UNIX Symbolic Link (Symlink) Following vulnerability in
openSUSE Tum ...)
@@ -864,17 +864,17 @@ CVE-2026-59674 (A UNIX Symbolic Link (Symlink) Following
vulnerability in openSU
CVE-2026-59246 (Allocation of resources without limits vulnerability in
elixir-mint mi ...)
NOT-FOR-US: elixir-mint mint
CVE-2026-59205 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow's
ImageCms ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-9hw9-ch79-4vh6
NOTE: https://github.com/python-pillow/Pillow/pull/9715
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721
(12.3.0)
CVE-2026-59204 (Pillow is a Python imaging library. From 8.2.0 through 12.2.0,
src/lib ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j
NOTE: https://github.com/python-pillow/Pillow/pull/9704
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/13ada41172142f2fd9f0906f615a00ea623a11ca
(12.3.0)
CVE-2026-59203 (Pillow is a Python imaging library. From 12.0.0 through
12.2.0, Pillow ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
[trixie] - pillow <not-affected> (Vulnerable code not present)
[bookworm] - pillow <not-affected> (BeginBinary support introduced in
v12.0.0)
[bullseye] - pillow <not-affected> (BeginBinary support introduced in
v12.0.0)
@@ -883,22 +883,22 @@ CVE-2026-59203 (Pillow is a Python imaging library. From
12.0.0 through 12.2.0,
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83
(12.3.0)
NOTE: Introduced by:
https://github.com/python-pillow/Pillow/commit/03992618118b4a76b6163cd72ab5ecd684133b83
(12.0.0)
CVE-2026-59200 (Pillow is a Python imaging library. From 5.1.0 until 12.3.0,
PdfParser ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-jjj6-mw9f-p565
NOTE: https://github.com/python-pillow/Pillow/pull/9718
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/f7a31ea75e460e108c37126da1f47812f21f6b09
(12.3.0)
CVE-2026-59199 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow
public ima ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-6r8x-57c9-28j4
NOTE: https://github.com/python-pillow/Pillow/pull/9703
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b
(12.3.0)
CVE-2026-59198 (Pillow is a Python imaging library. From 5.2.0 until 12.3.0,
Pillow's ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-fj7v-r99m-22gq
NOTE: https://github.com/python-pillow/Pillow/pull/9709
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/eada3cbd7fb9963ee90673fb7b5270124a0d5f4b
(12.3.0)
CVE-2026-59197 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow's
public r ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr
NOTE: https://github.com/python-pillow/Pillow/pull/9695
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/cce3bdb867c77a3420261ed1bfdb6b0787ec8fc1
(12.3.0)
@@ -1365,7 +1365,7 @@ CVE-2026-54982 (Integer underflow (wrap or wraparound) in
Reliable Multicast Tra
CVE-2026-54684 (jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a
malicious .xa ...)
NOT-FOR-US: jadx
CVE-2026-54572 (Rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1142269)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265
(v1.74.4)
CVE-2026-54429 (A vulnerability has been identified in SIMATIC S7-PLCSIM
Advanced (All ...)
@@ -1413,7 +1413,7 @@ CVE-2026-54108 (External control of file name or path in
Microsoft Office ShareP
CVE-2026-54107 (Concurrent execution using shared resource with improper
synchronizati ...)
NOT-FOR-US: Microsoft
CVE-2026-54058 (Pillow is a Python imaging library. Prior to 12.3.0, when
Pillow loads ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93
NOTE: https://github.com/python-pillow/Pillow/pull/9719
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d
(12.3.0)
@@ -1444,7 +1444,7 @@ CVE-2026-51808 (Buffer Overflow vulnerability in
OpenHTJ2K v.0.18.4 and before a
CVE-2026-51807 (Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before
allows ...)
NOT-FOR-US: OpenHTJ2K
CVE-2026-51105 (Buffer Overflow vulnerability in aMULE-Project aMule v.2.3.3
allows a ...)
- - amule <unfixed>
+ - amule <unfixed> (bug #1142276)
NOTE: https://github.com/amule-project/amule/issues/445
NOTE: https://github.com/amule-project/amule/pull/447
NOTE: Fixed by:
https://github.com/amule-project/amule/commit/2ca5f40625a051edb6a3695683351ad65d5359cf
(3.0.0)
@@ -1984,15 +1984,15 @@ CVE-2026-49978 (DOMPurify is a DOM-only cross-site
scripting sanitizer for HTML,
NOTE:
https://github.com/cure53/DOMPurify/security/advisories/GHSA-rp9w-3fw7-7cwq
NOTE: Fixed by:
https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff
(3.4.7)
CVE-2026-49855 (Tornado is a Python web framework and asynchronous networking
library. ...)
- - python-tornado <unfixed>
+ - python-tornado <unfixed> (bug #1142277)
NOTE:
https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56
NOTE: Fixed by:
https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff
(v6.5.6)
CVE-2026-49854 (Tornado is a Python web framework and asynchronous networking
library. ...)
- - python-tornado <unfixed>
+ - python-tornado <unfixed> (bug #1142277)
NOTE:
https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9
NOTE: Fixed by:
https://github.com/tornadoweb/tornado/commit/96dc88c2a05705287856b2cd6b4b4034f9a6aaac
(v6.5.6)
CVE-2026-49853 (Tornado is a Python web framework and asynchronous networking
library. ...)
- - python-tornado <unfixed>
+ - python-tornado <unfixed> (bug #1142277)
NOTE:
https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf
CVE-2026-49808 (Concurrent execution using shared resource with improper
synchronizati ...)
NOT-FOR-US: Microsoft
@@ -4322,11 +4322,11 @@ CVE-2026-53657 (Lima launches Linux virtual machines,
typically on macOS, for ru
CVE-2026-53653 (Grav is a file-based Web platform. Prior to 1.7.53 and
2.0.0-rc.8, Gra ...)
NOT-FOR-US: Grav CMS
CVE-2026-53450 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
- - coturn <unfixed>
+ - coturn <unfixed> (bug #1142275)
NOTE:
https://github.com/coturn/coturn/security/advisories/GHSA-w4hf-cr3w-6h79
NOTE: Fixed by:
https://github.com/coturn/coturn/commit/b057acbebe721c8f2f202ddad5e16289e295c754
(4.13.0)
CVE-2026-53449 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
- - coturn <unfixed>
+ - coturn <unfixed> (bug #1142275)
NOTE:
https://github.com/coturn/coturn/security/advisories/GHSA-jj76-vwjw-w34r
NOTE: Fixed by:
https://github.com/coturn/coturn/commit/e72930f571beba3bc7a9f97661af2614aae92a55
(4.13.0)
CVE-2026-53448 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
@@ -5414,51 +5414,51 @@ CVE-2026-35210 (OpenCTI is an open source platform for
managing cyber threat int
CVE-2026-31309 (Improper authorization in the /tequilapi/config/user endpoint
of Myste ...)
NOT-FOR-US: Mysterium Node
CVE-2026-15174 (Catapult DCT2000 protocol dissector crash in Wireshark 4.6.0
to 4.6.6 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-52.html
CVE-2026-15173 (pcapng file parser crash in Wireshark 4.6.0 to 4.6.6 allows
denial of ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-53.html
CVE-2026-15172 (FMP/NOTIFY protocol dissector crash in Wireshark 4.6.0 to
4.6.6 and 4. ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-54.html
CVE-2026-15171 (SSH protocol dissector crash in Wireshark 4.6.0 to 4.6.6 and
4.4.0 to ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-55.html
CVE-2026-15170 (Z39.50 protocol dissector crash in Wireshark 4.6.0 to 4.6.6
and 4.4.0 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-58.html
CVE-2026-15169 (UMTS FP protocol dissector crash in Wireshark 4.6.0 to 4.6.6
and 4.4.0 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-59.html
CVE-2026-15168 (BLF file parser in Wireshark 4.6.0 to 4.6.6 and 4.4.0 to
4.4.16 allows ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-60.html
CVE-2026-15167 (DBS Etherwatch file parser crash in Wireshark 4.6.0 to 4.6.6
and 4.4.0 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-62.html
CVE-2026-15166 (IEEE 802.11 protocol dissector crash in Wireshark 4.6.0 to
4.6.6 and 4 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-57.html
CVE-2026-15165 (TLS ECH decryptor crash in Wireshark 4.6.0 to 4.6.6 allows
denial of s ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-56.html
CVE-2026-15164 (Crash in ciscodump 4.6.0 to 4.6.6 and 4.4.0 to 4.4.16 allows
denial of ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-63.html
CVE-2026-15163 (Multiple protocol dissector infinite loops in Wireshark 4.6.0
to 4.6.6 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1142268)
[trixie] - wireshark <no-dsa> (Minor issue)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-61.html
CVE-2026-15154 (A flaw was found in `guardrails-detectors`, a component of Red
Hat Ope ...)
@@ -7110,14 +7110,14 @@ CVE-2026-55798 (Pillow is a Python imaging library.
Prior to 12.3.0, WindowsView
- pillow <not-affected> (Only affects Windows specific WindowsViewer)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-4x4j-2g7c-83w6
CVE-2026-55380 (Pillow is a Python imaging library. Prior to 12.3.0,
PIL/GdImageFile.p ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
[trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue)
[bullseye] - pillow <postponed> (Minor issue)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-phj9-mv4w-65pm
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/f39b0ae6624eb2d7c5c5d651d9bb5fdbd96a8675
(12.3.0)
CVE-2026-55379 (Pillow is a Python imaging library. Prior to 12.3.0,
PIL/BdfFontFile.p ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
[trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue)
[bullseye] - pillow <postponed> (Minor issue)
@@ -7131,14 +7131,14 @@ CVE-2026-54291 (pgjdbc is an open source postgresql
JDBC Driver. In releases 42.
NOTE:
https://github.com/pgjdbc/pgjdbc/security/advisories/GHSA-j92g-9f8w-j867
NOTE: Fixed by:
https://github.com/pgjdbc/pgjdbc/commit/77df98e4e66c12936ded3478a0954f6f580bad99
(REL42.7.12)
CVE-2026-54060 (Pillow is a Python imaging library. Prior to 12.3.0,
PIL/FontFile.py F ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
[trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue)
[bullseye] - pillow <postponed> (Minor issue)
NOTE:
https://github.com/python-pillow/Pillow/security/advisories/GHSA-5x94-69rx-g8h2
NOTE: Fixed by:
https://github.com/python-pillow/Pillow/commit/0a263e6264aa5399988d9acd3bbfbca2ca3ec77d
(12.3.0)
CVE-2026-54059 (Pillow is a Python imaging library. Prior to 12.3.0,
PIL/PcfFontFile.p ...)
- - pillow <unfixed>
+ - pillow <unfixed> (bug #1142274)
[trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue)
[bullseye] - pillow <postponed> (Minor issue)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/174452d59c0c5bfd0497c87abe8f2e9791ac3bda
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/174452d59c0c5bfd0497c87abe8f2e9791ac3bda
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits