Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
88e47b73 by Salvatore Bonaccorso at 2026-07-31T07:41:03+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -37,7 +37,7 @@ CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable
to Cross-Site Reque
CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr
Information ...)
NOT-FOR-US: E-Commerce Pack
CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for
asyncio an ...)
- - python-aiohttp <unfixed>
+ - python-aiohttp <unfixed> (bug #1143160)
[trixie] - python-aiohttp <no-dsa> (Minor issue)
NOTE:
https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7
NOTE: https://github.com/aio-libs/aiohttp/pull/12978
@@ -47,7 +47,7 @@ CVE-2026-59310 (VMware vCenter contains a directory traversal
vulnerability in t
CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability
in the ...)
NOT-FOR-US: VMware
CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request
forgery vulne ...)
- - kanboard <unfixed>
+ - kanboard <unfixed> (bug #1143159)
NOTE: https://gist.github.com/sermikr0/67c8acfc395e465127e729dc309da3ae
TODO: check upstream report
CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution
vulnerability in ...)
@@ -1640,22 +1640,22 @@ CVE-2026-16610 (The Admin and Site Enhancements (ASE)
Pro plugin for WordPress i
CVE-2026-16553 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-16531 (An unauthenticated remote attacker can exploit a path
traversal vulner ...)
- - pcp <unfixed>
+ - pcp <unfixed> (bug #1143154)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506037
CVE-2026-16530 (A flaw was found in the PCP (Performance Co-Pilot) `pmproxy`
service. ...)
- - pcp <unfixed>
+ - pcp <unfixed> (bug #1143154)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506033
CVE-2026-16529 (A signed integer overflow in the PCP __pmGetPDU() function can
be expl ...)
- - pcp <unfixed>
+ - pcp <unfixed> (bug #1143154)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506032
CVE-2026-16527 (An unauthenticated remote attacker can bypass access controls
by sendi ...)
- - pcp <unfixed>
+ - pcp <unfixed> (bug #1143154)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506031
CVE-2026-16526 (A flaw in the PCP linux_sockets module exposes an unsecured
internal c ...)
- - pcp <unfixed>
+ - pcp <unfixed> (bug #1143154)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506026
CVE-2026-16524 (A command injection flaw in PCP's linux_sockets PMDA allows
malicious ...)
- - pcp <unfixed>
+ - pcp <unfixed> (bug #1143154)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506023
CVE-2026-16339
REJECTED
@@ -2042,12 +2042,12 @@ CVE-2026-57834 (Apache Traffic Server allows request
smuggling if chunked messag
- trafficserver <unfixed> (bug #1143062)
NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output
paths. Gramma ...)
- - bison <unfixed>
+ - bison <unfixed> (bug #1143158)
[trixie] - bison <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389/
NOTE:
https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a448c925513742d4efcf0
CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program
during HTML ...)
- - bison <unfixed>
+ - bison <unfixed> (bug #1143158)
[trixie] - bison <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389
NOTE:
https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b
@@ -3820,10 +3820,10 @@ CVE-2026-17523 (A flaw was found in the Linux kernel in
net/can/bcm.c in can: bc
CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to
0.12.3. ...)
NOT-FOR-US: ZJONSSON node-unzipper
CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b.
Affected i ...)
- - whisper.cpp <unfixed>
+ - whisper.cpp <unfixed> (bug #1143157)
NOTE: https://github.com/ggml-org/whisper.cpp/issues/3924
CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp
1.8.4-58. This ...)
- - whisper.cpp <unfixed>
+ - whisper.cpp <unfixed> (bug #1143157)
NOTE: https://github.com/ggml-org/whisper.cpp/issues/3923
NOTE: https://github.com/ggml-org/whisper.cpp/pull/3925
CVE-2026-17192 (A VCO feature does not sufficiently validate caller-supplied
input, al ...)
@@ -3889,11 +3889,11 @@ CVE-2026-9830 (The bookingpress-appointment-booking-pro
WordPress plugin before
CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control
vulnerabilit ...)
NOT-FOR-US: Leantime
CVE-2026-17501 (A flaw has been found in ggml-org llama.cpp e15efe0. This
vulnerabilit ...)
- - llama.cpp <unfixed>
+ - llama.cpp <unfixed> (bug #1143156)
NOTE: https://github.com/ggml-org/llama.cpp/issues/25283
NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp
d006858/e15efe0. Th ...)
- - llama.cpp <unfixed>
+ - llama.cpp <unfixed> (bug #1143156)
NOTE: https://github.com/ggml-org/llama.cpp/issues/25284
NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
CVE-2026-15928 (XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable
to a ref ...)
@@ -6775,7 +6775,7 @@ CVE-2026-24552 (Contributor SQL Injection in Create by
Mediavine <= 2.5.3 versio
CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP
Accessibility ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially
crafted ICO f ...)
- - gdk-pixbuf <unfixed>
+ - gdk-pixbuf <unfixed> (bug #1143155)
[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
[bookworm] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in
the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the
rendered image; unfixed upstream)
[bullseye] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in
the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the
rendered image; unfixed upstream)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88e47b73d36f69b92d5eabe2632cdc88880f775e
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88e47b73d36f69b92d5eabe2632cdc88880f775e
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits