Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
88e47b73 by Salvatore Bonaccorso at 2026-07-31T07:41:03+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37,7 +37,7 @@ CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable 
to Cross-Site Reque
 CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr 
Information  ...)
        NOT-FOR-US: E-Commerce Pack
 CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for 
asyncio an ...)
-       - python-aiohttp <unfixed>
+       - python-aiohttp <unfixed> (bug #1143160)
        [trixie] - python-aiohttp <no-dsa> (Minor issue)
        NOTE: 
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7
        NOTE: https://github.com/aio-libs/aiohttp/pull/12978
@@ -47,7 +47,7 @@ CVE-2026-59310 (VMware vCenter contains a directory traversal 
vulnerability in t
 CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability 
in the  ...)
        NOT-FOR-US: VMware
 CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request 
forgery vulne ...)
-       - kanboard <unfixed>
+       - kanboard <unfixed> (bug #1143159)
        NOTE: https://gist.github.com/sermikr0/67c8acfc395e465127e729dc309da3ae
        TODO: check upstream report
 CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution 
vulnerability in ...)
@@ -1640,22 +1640,22 @@ CVE-2026-16610 (The Admin and Site Enhancements (ASE) 
Pro plugin for WordPress i
 CVE-2026-16553 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-16531 (An unauthenticated remote attacker can exploit a path 
traversal vulner ...)
-       - pcp <unfixed>
+       - pcp <unfixed> (bug #1143154)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506037
 CVE-2026-16530 (A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` 
service.  ...)
-       - pcp <unfixed>
+       - pcp <unfixed> (bug #1143154)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506033
 CVE-2026-16529 (A signed integer overflow in the PCP __pmGetPDU() function can 
be expl ...)
-       - pcp <unfixed>
+       - pcp <unfixed> (bug #1143154)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506032
 CVE-2026-16527 (An unauthenticated remote attacker can bypass access controls 
by sendi ...)
-       - pcp <unfixed>
+       - pcp <unfixed> (bug #1143154)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506031
 CVE-2026-16526 (A flaw in the PCP linux_sockets module exposes an unsecured 
internal c ...)
-       - pcp <unfixed>
+       - pcp <unfixed> (bug #1143154)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506026
 CVE-2026-16524 (A command injection flaw in PCP's linux_sockets PMDA allows 
malicious  ...)
-       - pcp <unfixed>
+       - pcp <unfixed> (bug #1143154)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506023
 CVE-2026-16339
        REJECTED
@@ -2042,12 +2042,12 @@ CVE-2026-57834 (Apache Traffic Server allows request 
smuggling if chunked messag
        - trafficserver <unfixed> (bug #1143062)
        NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output 
paths. Gramma ...)
-       - bison <unfixed>
+       - bison <unfixed> (bug #1143158)
        [trixie] - bison <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389/
        NOTE: 
https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a448c925513742d4efcf0
 CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program 
during HTML  ...)
-       - bison <unfixed>
+       - bison <unfixed> (bug #1143158)
        [trixie] - bison <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389
        NOTE: 
https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b
@@ -3820,10 +3820,10 @@ CVE-2026-17523 (A flaw was found in the Linux kernel in 
net/can/bcm.c in can: bc
 CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to 
0.12.3. ...)
        NOT-FOR-US: ZJONSSON node-unzipper
 CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. 
Affected i ...)
-       - whisper.cpp <unfixed>
+       - whisper.cpp <unfixed> (bug #1143157)
        NOTE: https://github.com/ggml-org/whisper.cpp/issues/3924
 CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp 
1.8.4-58. This  ...)
-       - whisper.cpp <unfixed>
+       - whisper.cpp <unfixed> (bug #1143157)
        NOTE: https://github.com/ggml-org/whisper.cpp/issues/3923
        NOTE: https://github.com/ggml-org/whisper.cpp/pull/3925
 CVE-2026-17192 (A VCO feature does not sufficiently validate caller-supplied 
input, al ...)
@@ -3889,11 +3889,11 @@ CVE-2026-9830 (The bookingpress-appointment-booking-pro 
WordPress plugin before
 CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control 
vulnerabilit ...)
        NOT-FOR-US: Leantime
 CVE-2026-17501 (A flaw has been found in ggml-org llama.cpp e15efe0. This 
vulnerabilit ...)
-       - llama.cpp <unfixed>
+       - llama.cpp <unfixed> (bug #1143156)
        NOTE: https://github.com/ggml-org/llama.cpp/issues/25283
        NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
 CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp 
d006858/e15efe0. Th ...)
-       - llama.cpp <unfixed>
+       - llama.cpp <unfixed> (bug #1143156)
        NOTE: https://github.com/ggml-org/llama.cpp/issues/25284
        NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
 CVE-2026-15928 (XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable 
to a ref ...)
@@ -6775,7 +6775,7 @@ CVE-2026-24552 (Contributor SQL Injection in Create by 
Mediavine <= 2.5.3 versio
 CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP 
Accessibility  ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially 
crafted ICO f ...)
-       - gdk-pixbuf <unfixed>
+       - gdk-pixbuf <unfixed> (bug #1143155)
        [trixie] - gdk-pixbuf <no-dsa> (Minor issue)
        [bookworm] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in 
the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the 
rendered image; unfixed upstream)
        [bullseye] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in 
the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the 
rendered image; unfixed upstream)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88e47b73d36f69b92d5eabe2632cdc88880f775e

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88e47b73d36f69b92d5eabe2632cdc88880f775e
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to