Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f88d4a11 by Salvatore Bonaccorso at 2026-08-08T10:00:03+02:00
Process some new NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,7 +3,7 @@ CVE-2026-9031 (An input validation vulnerability exists in the 
HTTP-WRITEOEM han
 CVE-2026-9030 (A denial-of-service vulnerability exists in httpd service on 
Archer A6 ...)
        NOT-FOR-US: TPLink
 CVE-2026-8798 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 2.1.3, 
the nati ...)
-       TODO: check
+       NOT-FOR-US: FIPS provider for Bouncycastle, not part of the Debian 
package for Bouncycastle
 CVE-2026-71381 (Adobe Genuine Software Integrity Service was affected by an 
Incorrect  ...)
        NOT-FOR-US: Adobe
 CVE-2026-70624
@@ -11,71 +11,71 @@ CVE-2026-70624
 CVE-2026-70623
        REJECTED
 CVE-2026-69207 (Hono is a Web application framework that provides support for 
any Java ...)
-       TODO: check
+       NOT-FOR-US: Hono
 CVE-2026-66151 (SonicWall Global VPN Client version 4.10.8.1108 and earlier is 
vulnera ...)
        NOT-FOR-US: SonicWall
 CVE-2026-66061 (Home Assistant is open source home automation software focused 
on loca ...)
-       TODO: check
+       NOT-FOR-US: Home Assistant
 CVE-2026-66060 (Home Assistant is open source home automation software focused 
on loca ...)
-       TODO: check
+       NOT-FOR-US: Home Assistant
 CVE-2026-65819 (gopacket provides packet processing capabilities for Go. 
Through versi ...)
        TODO: check
 CVE-2026-64676 (Kata Containers is an open source implementation of 
lightweight Virtua ...)
-       TODO: check
+       NOT-FOR-US: Kata Containers
 CVE-2026-62296 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
-       TODO: check
+       NOT-FOR-US: HAPI FHIR
 CVE-2026-62295 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
-       TODO: check
+       NOT-FOR-US: HAPI FHIR
 CVE-2026-62293 (HAPI FHIR is a complete implementation of the HL7 FHIR 
standard for he ...)
-       TODO: check
+       NOT-FOR-US: HAPI FHIR
 CVE-2026-61808 (LightRAG provides simple and fast retrieval-augmented 
generation. Thro ...)
-       TODO: check
+       NOT-FOR-US: LightRAG
 CVE-2026-59717 (Home Assistant is open source home automation software focused 
on loca ...)
-       TODO: check
+       NOT-FOR-US: Home Assistant
 CVE-2026-58262 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
-       TODO: check
+       NOT-FOR-US: Klever-Go
 CVE-2026-54338 (JupyterHub is software that allows users to create a 
multi-user server ...)
        TODO: check
 CVE-2026-52880 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
-       TODO: check
+       NOT-FOR-US: Klever-Go
 CVE-2026-52879 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
-       TODO: check
+       NOT-FOR-US: Klever-Go
 CVE-2026-52878 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
-       TODO: check
+       NOT-FOR-US: Klever-Go
 CVE-2026-49343 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
-       TODO: check
+       NOT-FOR-US: Klever-Go
 CVE-2026-48170 (`scim-patch`, a library to perform SCIM patch, prior to 
version 0.9.1  ...)
-       TODO: check
+       NOT-FOR-US: scim-patch
 CVE-2026-48169 (PraisonAI is a multi-agent teams system. Versions prior to 
0.1.4 of th ...)
-       TODO: check
+       NOT-FOR-US: PraisonAI
 CVE-2026-48122 (Ruby LSP is an implementation of the language server protocol 
for Ruby ...)
-       TODO: check
+       NOT-FOR-US: VS Code extension for Ruby LSP (not in src:ruby-ruby-lsp )
 CVE-2026-48120 (Kakoune is a code editor. Prior to version 2026.05.21, the 
bundled, en ...)
        TODO: check
 CVE-2026-48047 (XWiki Platform WebJars API is a package for XWiki, a generic 
wiki plat ...)
        NOT-FOR-US: XWiki
 CVE-2026-48039 (Meta Ads MCP is a Model Context Protocol (MCP) server that 
lets AI ass ...)
-       TODO: check
+       NOT-FOR-US: Meta Ads MCP
 CVE-2026-48026 (lakeFS is an open-source tool that transforms object storage 
into a Gi ...)
-       TODO: check
+       NOT-FOR-US: lakeFS
 CVE-2026-48007 (Element Call is a native Matrix video conferencing 
application. Versio ...)
        TODO: check
 CVE-2026-47664 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
-       TODO: check
+       NOT-FOR-US: Pathling
 CVE-2026-47663 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
-       TODO: check
+       NOT-FOR-US: Pathling
 CVE-2026-47662 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
-       TODO: check
+       NOT-FOR-US: Pathling
 CVE-2026-47661 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
-       TODO: check
+       NOT-FOR-US: Pathling
 CVE-2026-47660 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
-       TODO: check
+       NOT-FOR-US: Pathling
 CVE-2026-47659 (Pathling is a set of tools that make it easier to use FHIR and 
clinica ...)
-       TODO: check
+       NOT-FOR-US: Pathling
 CVE-2026-47249 (Klever-Go is the Go implementation of the Klever blockchain 
protocol.  ...)
-       TODO: check
+       NOT-FOR-US: Klever-Go
 CVE-2026-47127 (Ghostfolio is an open source wealth management software. Prior 
to vers ...)
-       TODO: check
+       NOT-FOR-US: Ghostfolio
 CVE-2026-46409 (OpenYak is a local-first agent runtime for reliable tool-using 
models, ...)
        TODO: check
 CVE-2026-46405 (OpenBao is an open source identity-based secrets management 
system. Pr ...)
@@ -151,7 +151,7 @@ CVE-2026-15970 (Consul Community Edition and Consul 
Enterprise 1.20.1 through 2.
 CVE-2026-14526 (The AI Copilot \u2013 Content Generator plugin for WordPress 
is vulner ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-13505 (In Bouncy Castle for Java FIPS (BC-FJA) before bc-fips 1.0.2.7 
(1.0.X  ...)
-       TODO: check
+       NOT-FOR-US: FIPS provider for Bouncycastle, not part of the Debian 
package for Bouncycastle
 CVE-2026-11743 (The SF32LB MPI QSPI NOR flash driver 
(drivers/flash/flash_sf32lb_mpi_q ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-11742 (The kernel queue helper z_queue_node_peek() in kernel/queue.c 
derefere ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f88d4a113abb066cc3357aa6b3b36a2a974c65cb

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f88d4a113abb066cc3357aa6b3b36a2a974c65cb
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to