Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
25be8f09 by Utkarsh Gupta at 2026-07-24T23:18:25+05:30
lts: triage fastdds in bookworm/bullseye

- - - - -
d3f09ca9 by Utkarsh Gupta at 2026-07-24T23:21:40+05:30
lts: triage jupyterhub in bookworm

- - - - -
f8c98d54 by Utkarsh Gupta at 2026-07-24T23:25:02+05:30
lts: kas postponed in bookworm/bullseye (CVE-2026-54548)

- - - - -
6eb64cfe by Utkarsh Gupta at 2026-07-24T23:28:20+05:30
lts: kcoreaddons postponed in bookworm/bullseye (CVE-2026-41526)

- - - - -
4101c104 by Utkarsh Gupta at 2026-07-24T23:31:45+05:30
lts: ldns postponed in bookworm/bullseye (CVE-2026-10846)

- - - - -
84b28e5a by Utkarsh Gupta at 2026-07-24T23:35:10+05:30
lts: lemonldap-ng postponed in bookworm/bullseye (CVE-2026-12804)

- - - - -
4169488c by Utkarsh Gupta at 2026-07-24T23:38:30+05:30
lts: triage liboauth2 in bookworm/bullseye

- - - - -
c9d29434 by Utkarsh Gupta at 2026-07-24T23:41:55+05:30
lts: triage libzypp in bookworm/bullseye

- - - - -
27067676 by Utkarsh Gupta at 2026-07-24T23:45:20+05:30
lts: triage mistune in bookworm/bullseye

- - - - -
f1f7eebd by Utkarsh Gupta at 2026-07-24T23:48:50+05:30
lts: neovim not-affected in bookworm/bullseye (CVE-2026-11487)

- - - - -
7e4a890e by Utkarsh Gupta at 2026-07-24T23:52:11+05:30
lts: nix not-affected in bookworm (CVE-2026-39860)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -15453,47 +15453,65 @@ CVE-2026-59937 (pypdf is a free and open-source 
pure-python PDF library. Prior t
 CVE-2026-59930 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <postponed> (Minor issue)
+       [bullseye] - mistune <not-affected> (Directive system introduced after 
0.8.4)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-2hm2-hc3v-44h9
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/c4093c4742ed0d10d9332fb8edb455869b7b581b
 (v3.3.0)
 CVE-2026-59929 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <postponed> (Minor issue)
+       [bullseye] - mistune <postponed> (Minor issue)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-qfrw-5rxm-mhh2
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc
 (v3.3.0)
 CVE-2026-59928 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <not-affected> (Vulnerable parser construct 
introduced in 3.x rewrite)
+       [bullseye] - mistune <not-affected> (Vulnerable parser construct 
introduced in 3.x rewrite)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-ffq3-xpv3-j92q
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/2b04d7ba341c16ac78fe82d3076bdd5c3de87c69
 (v3.3.0)
 CVE-2026-59927 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <postponed> (Minor issue)
+       [bullseye] - mistune <not-affected> (Directive system introduced after 
0.8.4)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-8mpj-m6qm-5qr8
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993
 (v3.3.0)
 CVE-2026-59926 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <not-affected> (Admonition :class: option 
introduced in 3.x)
+       [bullseye] - mistune <not-affected> (Admonition :class: option 
introduced in 3.x)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-g97x-gvcm-x72h
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/a3cb6e5655308797e8be021d6c7b5bab13cbace2
 (v3.2.1)
 CVE-2026-59925 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <not-affected> (Vulnerable parser construct 
introduced in 3.x rewrite)
+       [bullseye] - mistune <not-affected> (Vulnerable parser construct 
introduced in 3.x rewrite)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-4j32-57v6-6g45
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/5de41fb8e527004dbc363e047a3c380c9288c74f
 (v3.3.0)
 CVE-2026-59924 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <postponed> (Minor issue)
+       [bullseye] - mistune <not-affected> (Directive system introduced after 
0.8.4)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-r4rv-85jg-w4mf
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/1bef343ade163fc3bb95572b15be720084cdb993
 (v3.3.0)
 CVE-2026-59923 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <postponed> (Minor issue)
+       [bullseye] - mistune <postponed> (Minor issue)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-8c25-4j27-2rv3
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/c7101fcbb6e8790e8e39157c5ca2238fc6dd6cbc
 (v3.3.0)
 CVE-2026-59922 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <not-affected> (Vulnerable parser construct 
introduced in 3.x rewrite)
+       [bullseye] - mistune <not-affected> (Vulnerable parser construct 
introduced in 3.x rewrite)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-c8j7-8cv4-2xmq
        NOTE: Fixed by: 
https://github.com/lepture/mistune/commit/96d0f57f8fe9eeb06bb4cff521962a27d7c402e7
 (v3.3.0)
 CVE-2026-59897 (Hono is a Web application framework that provides support for 
any Java ...)
@@ -16787,46 +16805,68 @@ CVE-2024-56141 (Minosoft is an open-source, 
multi-version Minecraft Java Edition
 CVE-2026-49861
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-53589
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <not-affected> (RTPSEndpointQos deserializer 
introduced upstream in 3.2)
+       [bullseye] - fastdds <not-affected> (RTPSEndpointQos deserializer 
introduced upstream in 3.2)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-45098
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-49862
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <not-affected> (regex-based IPLocator::isIPv4 
introduced after 2.1.0)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-55063
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-49863
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-53588
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-53590
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/aeba2db3640d1f79d9f1f0430b10a475ea4c47cb
 CVE-2026-45096
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104
 (v3.6.2)
 CVE-2026-45095
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104
 (v3.6.2)
 CVE-2026-45094
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/d9f4b373c90179c96f3b1542e72f16e282ef0104
 (v3.6.2)
 CVE-2026-59089 (A flaw was found in GIMP. The PlayStation TIM loader, 
responsible for  ...)
        - gimp <unfixed>
@@ -18442,10 +18482,14 @@ CVE-2026-54886 (Loop with Unreachable Exit Condition 
('Infinite Loop') vulnerabi
 CVE-2026-54431 (In liboauth2 the Demonstrating Proof-of-Possession (DPoP) 
verifier acc ...)
        - liboauth2 2.3.0-1
        [trixie] - liboauth2 <no-dsa> (Minor issue)
+       [bookworm] - liboauth2 <postponed> (Minor issue)
+       [bullseye] - liboauth2 <postponed> (Minor issue)
        NOTE: Fixed by: 
https://github.com/OpenIDC/liboauth2/commit/c0b57152ed6a0af33aeb04a60bd7f5bff5ab8800
 (v2.3.0)
 CVE-2026-54430 (liboauth2 is vulnerable to Server-Side Request Forgery 
inoauth2_jose_j ...)
        - liboauth2 2.3.0-1
        [trixie] - liboauth2 <no-dsa> (Minor issue)
+       [bookworm] - liboauth2 <not-affected> (Vulnerable code introduced in 
2.1.0)
+       [bullseye] - liboauth2 <not-affected> (Vulnerable code introduced in 
2.1.0)
        NOTE: Fixed by: 
https://github.com/OpenIDC/liboauth2/commit/347507ac5b51f48c2933bbe49b2ee07c2af4712b
 (v2.3.0)
 CVE-2026-54409 (A malicious actor with access to the network and under certain 
conditi ...)
        NOT-FOR-US: UniFi
@@ -18496,7 +18540,10 @@ CVE-2026-49779 (Customer Path Traversal in Tax Exempt 
for WooCommerce <= 1.9.3 v
 CVE-2026-44941 (A relative path traversal in the "keyhint" option in 
repomd.xml parsin ...)
        - libzypp 17.38.12-1
        [trixie] - libzypp <no-dsa> (Minor issue)
+       [bookworm] - libzypp <not-affected> (keyhint support introduced in 
17.26.0; absent in 17.25.7)
+       [bullseye] - libzypp <not-affected> (keyhint support introduced in 
17.26.0; absent in 17.25.7)
        NOTE: Fixed by: 
https://github.com/openSUSE/libzypp/commit/294b1bad442d089ca671c5c03adc8031e3b29e04
 (17.38.12)
+       NOTE: Introduced with: 
https://github.com/openSUSE/libzypp/commit/beb0e764a86e7effc13cde04ff3db652c5c758a4
 (17.26.0)
 CVE-2026-44935 (Missing validation of "valuesFrom" references in Helm Deployer 
of SUSE ...)
        NOT-FOR-US: Rancher Fleet
 CVE-2026-42382 (Unauthenticated Local File Inclusion in Audrey <= 1.5 
versions.)
@@ -22587,6 +22634,8 @@ CVE-2026-36848 (Gigamon GVOS v5.16.1 and below is 
vulnerable to Directory Traver
 CVE-2026-25707 (A relative path traversal bug problem when processing 
repository metad ...)
        - libzypp 17.38.11-1
        [trixie] - libzypp <no-dsa> (Minor issue)
+       [bookworm] - libzypp <postponed> (Minor issue; requires 
attacker-controlled repo; unsanitized metadata paths present in 17.25.7)
+       [bullseye] - libzypp <postponed> (Minor issue; requires 
attacker-controlled repo; unsanitized metadata paths present in 17.25.7)
        NOTE: 
https://github.com/openSUSE/libzypp/commit/f09feda7fca03c941218aab0bb161cc82b185b6b
 (17.38.10)
 CVE-2026-22078 (Because O+ Connect's IPC service does not authenticate 
clients, extern ...)
        NOT-FOR-US: Oppo
@@ -25769,6 +25818,8 @@ CVE-2026-53131 (In the Linux kernel, the following 
vulnerability has been resolv
 CVE-2026-54548
        - kas 5.4-1
        [trixie] - kas <no-dsa> (Minor issue)
+       [bookworm] - kas <postponed> (Minor issue)
+       [bullseye] - kas <postponed> (Minor issue)
        NOTE: 
https://github.com/siemens/kas/security/advisories/GHSA-mv8m-v9v6-5f94
 CVE-2026-9787 (Quest NetVault Backup NVBULogDaemon Command Injection Remote 
Code Exec ...)
        NOT-FOR-US: Quest
@@ -26379,6 +26430,8 @@ CVE-2026-49980 (Rclone is a command-line program to 
sync files and directories t
 CVE-2026-49851 (Mistune is a Python Markdown parser with renderers and 
plugins. Prior  ...)
        - mistune <unfixed> (bug #1141770)
        [trixie] - mistune <no-dsa> (Minor issue)
+       [bookworm] - mistune <not-affected> (Vulnerable parser construct 
introduced in 3.x rewrite)
+       [bullseye] - mistune <not-affected> (Vulnerable parser construct 
introduced in 3.x rewrite)
        NOTE: 
https://github.com/lepture/mistune/security/advisories/GHSA-qcq2-496w-v96p
 CVE-2026-49269 (Apple M1 GPUs retain register file data between compute shader 
dispatc ...)
        NOT-FOR-US: Apple Silicon HW issue
@@ -29315,6 +29368,8 @@ CVE-2026-56229 (Capgo before 12.128.2 contains an 
authorization bypass vulnerabi
 CVE-2026-12804 (A vulnerability was detected in lemonldap-ng up to 2.23.0. 
Impacted is ...)
        - lemonldap-ng <unfixed>
        [trixie] - lemonldap-ng <no-dsa> (Minor issue)
+       [bookworm] - lemonldap-ng <postponed> (Minor issue; open redirect in 
rarely-used SAML CDC endpoint; fix in 2.23.1)
+       [bullseye] - lemonldap-ng <postponed> (Minor issue; open redirect in 
rarely-used SAML CDC endpoint; fix in 2.23.1)
        NOTE: https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/work_items/3619
        NOTE: 
https://gitlab.ow2.org/lemonldap-ng/lemonldap-ng/-/merge_requests/979
 CVE-2026-12799 (A security vulnerability has been detected in BerriAI litellm 
up to 1. ...)
@@ -30229,6 +30284,8 @@ CVE-2026-46580 (In Eclipse Theia versions prior to 
1.71.0, files matching the pa
 CVE-2026-44942 (A path traversal in handling the "path" component of .repo 
files proce ...)
        - libzypp 17.38.13-1
        [trixie] - libzypp <no-dsa> (Minor issue)
+       [bookworm] - libzypp <postponed> (Minor issue; requires 
attacker-controlled repo; unsanitized .repo path= handling present in 17.25.7)
+       [bullseye] - libzypp <postponed> (Minor issue; requires 
attacker-controlled repo; unsanitized .repo path= handling present in 17.25.7)
        NOTE: https://bugzilla.suse.com/show_bug.cgi?id=1267874
 CVE-2026-44691 (In Eclipse Theia versions prior to 1.69.0, custom task 
definitions in  ...)
        NOT-FOR-US: Eclipse
@@ -35718,6 +35775,8 @@ CVE-2026-11799 (UXSS in Focus for iOS / Klar Webkit 
navigation. This vulnerabili
 CVE-2026-10846 (NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when 
used in ...)
        - ldns 1.9.2-1 (bug #1139627)
        [trixie] - ldns <no-dsa> (Minor issue)
+       [bookworm] - ldns <postponed> (Minor issue; off-path response spoofing 
only for apps using ldns as UDP stub resolver, e.g. drill; no addr/port/ID 
matching in ldns_udp_send_from)
+       [bullseye] - ldns <postponed> (Minor issue; off-path response spoofing 
only for apps using ldns as UDP stub resolver, e.g. drill; no addr/port/ID 
matching in ldns_udp_send_from)
        NOTE: https://www.nlnetlabs.nl/downloads/ldns/CVE-2026-10846.txt
 CVE-2026-10238
        REJECTED
@@ -38092,6 +38151,8 @@ CVE-2026-11488 (A vulnerability has been found in 
code-projects Simple Flight Ti
 CVE-2026-11487 (A flaw has been found in Neovim up to 0.12.2. Affected by this 
issue i ...)
        - neovim 0.12.3-1 (bug #1139999)
        [trixie] - neovim <no-dsa> (Minor issue)
+       [bookworm] - neovim <not-affected> (Vulnerable code not present; 
vim.secure added upstream in 0.9)
+       [bullseye] - neovim <not-affected> (Vulnerable code not present; 
vim.secure added upstream in 0.9)
        NOTE: https://github.com/neovim/neovim/issues/39914
        NOTE: https://github.com/neovim/neovim/pull/39918
        NOTE: 
https://github.com/neovim/neovim/commit/f83e0dcaf8cf18de94828341b0a1a61a86c75baf
 (v0.12.3)
@@ -50027,6 +50088,7 @@ CVE-2026-41069 (libheif is a HEIF and AVIF file format 
decoder and encoder. In v
 CVE-2026-40864 (JupyterHub is software that allows users to create a 
multi-user server ...)
        - jupyterhub <unfixed>
        [trixie] - jupyterhub <no-dsa> (Minor issue)
+       [bookworm] - jupyterhub <not-affected> (Vulnerable Sec-Fetch-Mode 
handling introduced with the 4.1.0 XSRF rework)
        NOTE: 
https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-m68r-v472-jgq9
        NOTE: Fixed by: 
https://github.com/jupyterhub/jupyterhub/commit/9c5ec277d3cda5a59de2d8c8117efa77bd941127
 (5.4.5)
 CVE-2026-40610 (BentoML is a Python library for building online serving 
systems optimi ...)
@@ -66347,6 +66409,8 @@ CVE-2026-41602 (Integer Overflow or Wraparound 
vulnerability in Apache Thrift TF
 CVE-2026-41526 (In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended 
to safel ...)
        - kcoreaddons 5.116.0-2 (bug #1135179)
        [trixie] - kcoreaddons <no-dsa> (Minor issue)
+       [bookworm] - kcoreaddons <postponed> (Minor issue)
+       [bullseye] - kcoreaddons <postponed> (Minor issue)
        - kf6-kcoreaddons 6.26.0-1 (bug #1135178)
        [trixie] - kf6-kcoreaddons <no-dsa> (Minor issue)
        NOTE: https://kde.org/info/security/advisory-20260427-1.txt
@@ -77815,6 +77879,7 @@ CVE-2025-14732 (The Elementor Website Builder \u2013 
More Than Just a Page Build
 CVE-2026-39860 (Nix is a package manager for Linux and other Unix systems. A 
bug in th ...)
        - nix 2.34.6+dfsg-1 (bug #1133004)
        [trixie] - nix <no-dsa> (Minor issue)
+       [bookworm] - nix <not-affected> (Vulnerable code introduced by the 
CVE-2024-27297 fix in 2.21; that fix was never applied to 2.8.0)
        [bullseye] - nix <postponed> (regresssion of postponed CVE-2024-27297; 
revisit when fixing CVE-2024-27297)
        NOTE: 
https://github.com/NixOS/nix/security/advisories/GHSA-g3g9-5vj6-r3gj
        NOTE: Introduced with: 
https://github.com/NixOS/nix/commit/a3163b9eabb952b4aa96e376dea95ebcca97b31a 
(2.21.0)
@@ -79567,6 +79632,7 @@ CVE-2026-34052 (LTI JupyterHub Authenticator is a 
JupyterHub authenticator for L
 CVE-2026-33709 (JupyterHub is software that allows one to create a multi-user 
server f ...)
        - jupyterhub <unfixed> (bug #1132715)
        [trixie] - jupyterhub <no-dsa> (Minor issue)
+       [bookworm] - jupyterhub <postponed> (Minor issue; open redirect 
requiring user interaction)
        NOTE: 
https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-3vff-hjqv-m7h8
 CVE-2026-33184 (nimiq/core-rs-albatross is a Rust implementation of the Nimiq 
Proof-of ...)
        NOT-FOR-US: nimiq/core-rs-albatross
@@ -126891,18 +126957,26 @@ CVE-2025-66845 (A reflected Cross-Site Scripting 
(XSS) vulnerability has been id
 CVE-2026-45097
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <not-affected> (xtypes DynamicDataImpl introduced 
in 3.0; 2.x ships legacy dynamic-types)
+       [bullseye] - fastdds <not-affected> (xtypes DynamicDataImpl introduced 
in 3.0; 2.x ships legacy dynamic-types)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284
 (v3.6.2)
 CVE-2026-45092
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284
 (v3.6.2)
 CVE-2026-45093
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284
 (v3.6.2)
 CVE-2025-65865 (An integer overflow in eProsima Fast-DDS v3.3 allows attackers 
to caus ...)
        - fastdds <unfixed> (bug #1141768)
        [trixie] - fastdds <no-dsa> (Minor issue)
+       [bookworm] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
+       [bullseye] - fastdds <postponed> (Minor issue; DoS via crafted input, 
vulnerable code present)
        NOTE: Fixed by: 
https://github.com/eProsima/Fast-DDS/commit/42e0d08ef2d32c52ceb1c637ab3ea5e521124284
 (v3.6.2)
 CVE-2025-65713 (Home Assistant Core before v2025.8.0 is vulnerable to 
Directory Traver ...)
        NOT-FOR-US: Home Assistant Core



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee0457739c13ffbf0086719cc26a5f2225dbe7e3...7e4a890e49fd3b4131a905d5e5fd29b02e3115f7

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ee0457739c13ffbf0086719cc26a5f2225dbe7e3...7e4a890e49fd3b4131a905d5e5fd29b02e3115f7
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to