Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
61524efe by Moritz Muehlenhoff at 2026-08-08T10:50:33+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -534,12 +534,14 @@ CVE-2026-70633 (TimescaleDB through 2.29.1, fixed in 
commit 517c13e, contains an
        NOT-FOR-US: Timescale TimescaleDB
 CVE-2026-70632 (FFmpeg versions from 4.4 up to, but not including, 9.0 contain 
an out- ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23898
        NOTE: Introduced with: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1006a2151236f9235bf02822f263b3fb0532111e
 (n4.4)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/16b2049d4d5222db6cd7c031409058571c94f6a9
 (n9.0)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/db05df9d135fb56a4babb836d5e9f5c1d984e087
 (master)
 CVE-2026-70631 (FFmpeg versions from 0.5 up to, but not including, 9.0 contain 
an unin ...)
        - ffmpeg <unfixed>
+       [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream 
branch)
        NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23899
        NOTE: Introduced with: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a991b1fecbd8c9e6f4fc31c191bd12e4be27dbf7
 ((v0.5)
        NOTE: Fixed by: 
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2f234ea34c81288e3840fca632dd16481d8de39f
 (master)
@@ -1695,9 +1697,11 @@ CVE-2026-67871 (Buffer Overflow vulnerability in 
Systerel S2OPC 1.7.3 allows a r
        NOT-FOR-US: Systerel S2OPC
 CVE-2026-67870 (In open62541 v1.5.5, the server-side AddReferences 
implementation cont ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8172
 CVE-2026-67869 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a 
remote atta ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8171
 CVE-2026-67867 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a 
remote  ...)
        NOT-FOR-US: Systerel S2OPC
@@ -1707,9 +1711,11 @@ CVE-2026-67865 (S2OPC 1.7.3 contains an out-of-bounds 
read in RepublishResponse
        NOT-FOR-US: Systerel S2OPC
 CVE-2026-67864 (An issue in open62541 v.1.5.5 and before allows a remote 
attacker to c ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8133
 CVE-2026-67863 (In open62541 1.5.5, a server-side use-after-free exists in the 
local M ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8131
 CVE-2026-67531 (FrontMCP is a TypeScript-first framework for the Model Context 
Protoco ...)
        NOT-FOR-US: FrontMCP
@@ -2666,27 +2672,35 @@ CVE-2026-67979 (Incorrect access control in the 
Executive Services dynamic appli
        NOT-FOR-US: NASA cFS
 CVE-2026-67862 (open62541 1.5.5 contains a buffer-overflow in the high-level 
attribute ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8139
 CVE-2026-67861 (An issue in open62541 v.1.5.5 and before allows a remote 
attacker to c ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8140
 CVE-2026-67860 (open62541 1.5.5 contains a heap-based buffer overflow in the 
default H ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8091
 CVE-2026-67859 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a 
remote atta ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8095
 CVE-2026-67858 (Buffer Overflow vulnerability exists in open62541 1.5.5 when 
the Local ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8094
 CVE-2026-67857 (open62541 1.5.5 contains an out-of-bounds read in the 
client-side func ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8104
 CVE-2026-67856 (An issue in open62541 v.1.5.5 and before allows a remote 
attacker to c ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8092
 CVE-2026-67855 (open62541 contains a heap use-after-free in the GDS 
PushManagement cer ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8093
 CVE-2026-67592 (It was not possible to govern the maximum number of transfer 
frames pe ...)
        NOT-FOR-US: Apache software not packaged in Debian
@@ -3117,9 +3131,11 @@ CVE-2026-18787 (A vulnerability was identified in 
GL.iNet AX1800 up to 4.8.3. Th
        NOT-FOR-US: GL.iNet
 CVE-2026-18785 (A vulnerability was determined in o6 open62541 
ca356b088ada7dee824d1b4 ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8131
 CVE-2026-18784 (A vulnerability was found in o6 open62541 up to 1.5.5. This 
issue affe ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8139
 CVE-2026-18775 (A vulnerability has been found in NousResearch hermes-agent up 
to 0.16 ...)
        NOT-FOR-US: NousResearch
@@ -4312,14 +4328,17 @@ CVE-2026-67307 (Wazuh 5.0.0-beta1 (fixed in 
5.0.0-beta3) does not validate or ov
        NOT-FOR-US: Wazuh
 CVE-2026-68580 (FreeRDP before 3.29.0 contains integer overflow 
vulnerabilities in the ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-69xf-pqrw-596x
 CVE-2026-68579 (FreeRDP before 3.30.0 (<= 3.29.0) contains a heap-based buffer 
overflo ...)
        - freerdp3 3.30.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-m37j-jcr2-8gcc
 CVE-2026-67306 (FreeRDP versions 3.28.0 and earlier contain an out-of-bounds 
read vuln ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qrxx-7g3c-j6w3
 CVE-2026-67305 (FreeRDP Windows client before 3.29.0 contains a heap buffer 
overflow v ...)
@@ -4328,78 +4347,97 @@ CVE-2026-67305 (FreeRDP Windows client before 3.29.0 
contains a heap buffer over
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-cj9v-h4hq-29jr
 CVE-2026-67304 (FreeRDP before 3.29.0 contains a null pointer dereference 
vulnerabilit ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-78jj-45vh-jpm5
 CVE-2026-67303 (FreeRDP before 3.29.0 contains a reachable assertion 
(WINPR_ASSERT(Out ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pfxq-3qmw-8vjx
 CVE-2026-67302 (FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a 
divide- ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v89x-pc32-hqr7
 CVE-2026-67301 (FreeRDP before 3.29.0 contains out-of-bounds read 
vulnerabilities in t ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vxp3-7g6q-rq2w
 CVE-2026-67300 (FreeRDP before 3.29.0 contains client-side heap use-after-free 
vulnera ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-33gg-h66j-3697
 CVE-2026-67299 (FreeRDP before 3.29.0 contains a client-side heap 
use-after-free in th ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-33gg-h66j-3697
 CVE-2026-67298 (FreeRDP versions 3.28.0 and earlier contain a heap buffer 
overflow in  ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-qmvw-52ph-q5pv
 CVE-2026-67297 (FreeRDP before 3.29.0 fails to enforce the RESPONSE_SIZE_LIMIT 
when pr ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-2c6r-4pr4-9x8m
 CVE-2026-67296 (FreeRDP before 3.29.0 contains a denial of service 
vulnerability in th ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-jm8r-22j6-4m4v
 CVE-2026-67295 (FreeRDP before 3.29.0 fails to properly validate 
server-supplied RDPDR ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8xqm-wp3f-rfp9
 CVE-2026-67294 (FreeRDP before 3.29.0 improperly validates the Extended Key 
Usage (EKU ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-89c6-jjrw-96h4
 CVE-2026-67293 (FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains 
an improp ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-5wr6-8m8j-3h7f
 CVE-2026-67292 (FreeRDP before 3.29.0 contains a buffer over-disclosure 
vulnerability  ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8v6m-2cmc-chx9
 CVE-2026-67291 (FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains a 
heap ou ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-hgj8-g595-wfc6
 CVE-2026-67290 (FreeRDP before 3.29.0 contains a heap out-of-bounds read 
vulnerability ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-whq8-c3v3-p8v8
 CVE-2026-67289 (FreeRDP before 3.29.0 (affected versions <= 3.28.0) does not 
validate  ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-mwwh-mhp9-q7vm
 CVE-2026-67288 (FreeRDP before 3.29.0 contains a null pointer dereference 
vulnerabilit ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-ph3q-f9w8-7jf3
 CVE-2026-66402 (FreeRDP before 3.29.0 (affected versions <= 3.28.0) contains 
multiple  ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-43hh-p3vw-hfx3
 CVE-2026-66401 (FreeRDP before 3.29.0 contains an out-of-bounds heap read 
vulnerabilit ...)
        - freerdp3 3.29.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-8jj2-67pg-j6mg
 CVE-2026-55735 (Improper Verification of Cryptographic Signature in ueberauth 
guardian ...)
@@ -5086,6 +5124,7 @@ CVE-2026-65834 (Capsule is a multi-tenancy and 
policy-based framework for Kubern
        NOT-FOR-US: Capsule
 CVE-2026-65423 (An integer overflow in the UA_Variant arrayDimensions product  
computa ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/8098907673099afe6b726de05675146066b24d9c
 (v1.3.19, v1.4.18, v1.5.6)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/a1257feec0c539f191cb2d40f72f116a901d3322
 (v1.3.19, v1.4.18, v1.5.6)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/2da371bcdaadeb23051635a60e38f31039af9fd8
 (v1.3.19 v1.4.18, v1.5.6)
@@ -5096,6 +5135,7 @@ CVE-2026-64816 (RapidRAW before 1.6.0 does not validate 
the lutPath field in pre
        NOT-FOR-US: RapidRAW
 CVE-2026-63559 (An integer overflow in the UA_Variant arrayDimensions product  
computa ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/8098907673099afe6b726de05675146066b24d9c
 (v1.3.19, v1.4.18, v1.5.6)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/a1257feec0c539f191cb2d40f72f116a901d3322
 (v1.3.19, v1.4.18, v1.5.6)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/2da371bcdaadeb23051635a60e38f31039af9fd8
 (v1.3.19, v1.4.18, v1.5.6)
@@ -5104,6 +5144,7 @@ CVE-2026-63550 (The MMS BER decoder contains a 
boundary-handling flaw in the pro
        NOT-FOR-US: MZ Automation
 CVE-2026-63362 (An unsigned integer underflow in the PubSub signature 
verification pat ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/8098907673099afe6b726de05675146066b24d9c
 (v1.3.19, v1.4.18, v1.5.6)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/a1257feec0c539f191cb2d40f72f116a901d3322
 (v1.3.19, v1.4.18, v1.5.6)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/2da371bcdaadeb23051635a60e38f31039af9fd8
 (v1.3.19, v1.4.18, v1.5.6)
@@ -5118,6 +5159,7 @@ CVE-2026-63220 (CodeIgniter is a PHP full-stack web 
framework. In versions prior
        - codeigniter <itp> (bug #471583)
 CVE-2026-63035 (A heap use-after-free vulnerability in the 
TransferSubscriptions servi ...)
        - open62541 <unfixed>
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/8098907673099afe6b726de05675146066b24d9c
 (v1.3.19, v1.4.18, v1.5.6)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/a1257feec0c539f191cb2d40f72f116a901d3322
 (v1.3.19, v1.4.18, v1.5.6)
        NOTE: Fixed by: 
https://github.com/open62541/open62541/commit/2da371bcdaadeb23051635a60e38f31039af9fd8
 (v1.3.19, v1.4.18, v1.5.6)
@@ -9421,8 +9463,9 @@ CVE-2026-58662 (Improper Validation of Specified Quantity 
in Input, Out-of-bound
        - thrift <unfixed>
        NOTE: https://lists.apache.org/thread/13mzvylr3r3nktxrh5k1h30ng1t1sw1d
 CVE-2026-58389 (Allocation of Resources Without Limits or Throttling 
vulnerability in  ...)
-       - thrift <unfixed>
+       - thrift <unfixed> (unimportant)
        NOTE: https://lists.apache.org/thread/ht2mjt8m3vz9v0h5pqzvc4r4nzfxwtrw
+       NOTE: rust bindings not built in Debian package
 CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when 
reconstruct ...)
        - erlang 1:29.0.4+dfsg-1 (bug #1142985)
        NOTE: 
https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw
@@ -9447,13 +9490,15 @@ CVE-2026-55971 (Heap-based Buffer Overflow 
vulnerability in Apache Thrift C++ bi
        NOTE: https://lists.apache.org/thread/xjs36m6kjxpmrmzwck636msg3nvoqnmx
 CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings.  
This is ...)
        - thrift <unfixed>
+       [trixie] - thrift <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/8pbnw4dyxxc9opp6qq725jhrzg25v8q7
 CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift 
C++, c_g ...)
        - thrift <unfixed>
        NOTE: https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo
 CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources 
Without Li ...)
-       - thrift <unfixed>
+       - thrift <unfixed> (unimportant)
        NOTE: https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp
+       NOTE: nodejs bindings not built in Debian package
 CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does 
not veri ...)
        - erlang 1:29.0.4+dfsg-1 (bug #1142985)
        NOTE: 
https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882
@@ -9510,13 +9555,15 @@ CVE-2026-51244
 CVE-2026-51235
        REJECTED
 CVE-2026-49158 (Improper Handling of Highly Compressed Data (Data 
Amplification) vulne ...)
-       - thrift <unfixed>
+       - thrift <unfixed> (unimportant)
        NOTE: https://lists.apache.org/thread/fmjl8l415tj9zwlob8v2dr5hq1d0hts7
+       NOTE: ruby bindings not built in Debian package
 CVE-2026-48586 (Improper Handling of Highly Compressed Data (Data 
Amplification) vulne ...)
        - thrift <unfixed>
        NOTE: https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq
 CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch 
vulnerability in ...)
        - thrift <unfixed>
+       [trixie] - thrift <no-dsa> (Minor issue)
        NOTE: https://lists.apache.org/thread/2popgc4ks1l87jjho1w5fpk5k4x06b7h
 CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch 
vulnerability in ...)
        - thrift <unfixed>
@@ -9826,21 +9873,25 @@ CVE-2026-16043
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/b0411a1747ac9b205633011f62ac85436f354f35
 (v10.0.12)
 CVE-2026-15705
        - qemu 1:11.0.3+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Introduced with: 
https://gitlab.com/qemu-project/qemu/-/commit/b2d1fe67d09d2b6c7da647fbcea6ca0148c206d3
 (v1.4.0-rc0)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/6229fbcef1f878b2df081c7911c7eaae12e54da5
 (v11.0.3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/e3da91c85971de1d5a31f5f2a5b0f6ef34a4e8a7
 (v10.0.12)
 CVE-2026-15578
        - qemu 1:11.0.3+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/issues/3976
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/147e214e9cbd701c0569193004800c4f75bf9575
 (v11.0.3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/7467c162c0b19a0ac1822172e131d34943ca54ad
 (v10.0.12)
 CVE-2026-8348 [hw/9pfs: add xattr FID limit to prevent memory exhaustion]
        - qemu 1:11.0.3+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Introduced with: 
https://gitlab.com/qemu-project/qemu/-/commit/10b468bdc5335b58f610817215f30847c1429f24
 (v0.14.0-rc0)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/c57644a542b11e578309b07b3bf7623d566e6a81
 (v11.0.3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/4f9e9601d0ec69748b2019a34dde148578b2c5a4
 (v10.0.12)
 CVE-2026-9238 [hw/9pfs: cap Treaddir allocation]
        - qemu 1:11.0.3+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Introduced with: 
https://gitlab.com/qemu-project/qemu/-/commit/2149675b195f2d9a1a4e3b966d45aba234def69b
 (v5.2.0-rc0)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/d2a298f359477fd6fa30dd6aa7357115b596012d
 (v11.0.3)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/169537e616a894175cd7c876c83b4801fe099232
 (v10.0.12)
@@ -11417,17 +11468,23 @@ CVE-2026-66373 (Redis before 8.8.0, in the unusual 
case where an authenticated a
        NOTE: Issue exists because of an incomplete fix for CVE-2026-25243.
 CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is 
established thr ...)
        - libsoup3 <unfixed> (bug #1142846)
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506951
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/534
 CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding 
parser uses ...)
        - libsoup3 <unfixed> (bug #1142845)
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506950
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/533
 CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in 
the soup ...)
        - libsoup3 <unfixed> (bug #1142844)
+       [trixie] - libsoup3 <no-dsa> (Minor issue)
        - libsoup2.4 <removed>
+       [trixie] - libsoup2.4 <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506949
        NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/532
 CVE-2026-66041 (FFmpeg 7.0 through 8.1.2, fixed in commit 4da9812, contains a 
heap out ...)
@@ -12899,11 +12956,12 @@ CVE-2026-7232 (The FormCraft plugin for WordPress is 
vulnerable to Stored Cross-
 CVE-2026-7120 (@fastify/static evaluates the allowedPath callback before 
normalizing  ...)
        NOT-FOR-US: fastify/static
 CVE-2026-6390 (A flaw was found in GNU nano's multi-buffer error message 
handling. Wh ...)
-       - nano <unfixed>
+       - nano 9.0-1
+       [trixie] - nano <no-dsa> (Minor issue)
        [bookworm] - nano <postponed> (Minor issue)
        [bullseye] - nano <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2458767
-       TODO: check upstream status
+       NOTE: 
https://cgit.git.savannah.gnu.org/cgit/nano.git/commit/?id=0b7328bce452bf1b0bbff81276425d4809a9b6fd
 CVE-2026-64829 (Question2Answer through 1.8.8 contains a session invalidation 
vulnerab ...)
        NOT-FOR-US: Question2Answer
 CVE-2026-64798 (Joomla Extension - regularlabs.com - Insecure login URL keys 
in IP log ...)
@@ -16373,6 +16431,7 @@ CVE-2026-16447 (A vulnerability has been found in 
D-Link DNS-320 1.0.2. Impacted
        NOT-FOR-US: D-Link
 CVE-2026-16445 (A flaw was found in dracut. A remote attacker on the adjacent 
network  ...)
        - dracut 112-1
+       [trixie] - dracut <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2459963
 CVE-2026-16441 (In Eclipse OpenJ9 versions up to 0.60, when executing class 
files wher ...)
        NOT-FOR-US: Eclipse
@@ -16896,6 +16955,7 @@ CVE-2026-63730 (HyperDX before 2.31.0 contains a 
server-side request forgery vul
        NOT-FOR-US: HyperDX
 CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) shipped with TeX Live 
and embedd ...)
        - texlive-bin 2026.20260303.78225+ds-2
+       [trixie] - texlive-bin <no-dsa> (Minor issue)
        - texstudio 4.9.6+ds-1
        - okular <unfixed>
        NOTE: Fixed by: 
https://github.com/TeX-Live/texlive-source/commit/002dcd3eac30db5c352f53d4181737961cc7ee9a
 (svn78081)
@@ -17106,10 +17166,12 @@ CVE-2026-64622 (Network-AI (npm: network-ai) versions 
5.12.2 through 5.13.3 fail
        NOT-FOR-US: Network-AI
 CVE-2026-64621 (FreeRDP before 3.28.0 (affected 3.x through 3.27.1) contains a 
double- ...)
        - freerdp3 3.28.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-f27x-frr8-j9hc
 CVE-2026-64620 (FreeRDP before 3.28.0 (affected <=3.27.1) contains a 
heap-based buffer ...)
        - freerdp3 3.28.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-pjqx-v446-x7fc
 CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG 
image rea ...)
@@ -24108,6 +24170,7 @@ CVE-2026-15691 (A security flaw has been discovered in 
Tenda BE12 Pro 16.03.66.2
        NOT-FOR-US: Tenda
 CVE-2026-15690 (A vulnerability was identified in open62541 up to 1.5.5. 
Affected by t ...)
        - open62541 <unfixed> (bug #1143066)
+       [trixie] - open62541 <no-dsa> (Minor issue)
        NOTE: https://github.com/open62541/open62541/issues/8104
 CVE-2026-15643 (AWS HealthLake MCP Server (awslabs.healthlake-mcp-server) is a 
Model C ...)
        NOT-FOR-US: Amazon
@@ -24930,15 +24993,19 @@ CVE-2026-41041 (URL path injection via unencoded 
user-supplied identifiers vulne
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-40553 (Buffer overflow vulnerability has been found in 
"extension/readdir.c"  ...)
        - gawk <unfixed> (bug #1142071)
+       [trixie] - gawk <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=cca0366144336b49aaa7d5d949966ce8e2c70843
 CVE-2026-40469 (Integer overflow vulnerability has been found in "builtin.c" 
program f ...)
        - gawk <unfixed> (bug #1142071)
+       [trixie] - gawk <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=ae1b2d508f46913269a9e62aceda3636afe8147b
 CVE-2026-40468 (Integer overflow vulnerability has been found in "builtin.c" 
program f ...)
        - gawk <unfixed> (bug #1142071)
+       [trixie] - gawk <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=062f2f2581b991362c046f7f2e238ffa34e6f8c7
 CVE-2026-40467 (Use After Free vulnerability has been found in "io.c" program 
file of  ...)
        - gawk <unfixed> (bug #1142071)
+       [trixie] - gawk <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/gawk.git/commit/?id=a2d18c74109e41bec29a23098eba2e00057286d8
 CVE-2026-26396 (OpenBMB XAgent v1.0.0 and before is vulnerable to path 
traversal in th ...)
        NOT-FOR-US: OpenBMB XAgent
@@ -26650,6 +26717,7 @@ CVE-2026-1365 (Insertion of sensitive information into 
sent data vulnerability i
 CVE-2026-15308 (The incremental HTML parser (html.parser.HTMLParser) allows 
for CPU de ...)
        - python3.14 <unfixed>
        - python3.13 <unfixed>
+       [trixie] - python3.13 <no-dsa> (Minor issue)
        - python3.11 <removed>
        [bookworm] - python3.11 <postponed> (CPU-only DoS; the quadratic rescan 
needs feed() driven in small chunks, a single feed() of the whole document 
stays linear; no upstream fix for this branch)
        - python3.9 <removed>
@@ -26661,7 +26729,7 @@ CVE-2026-15308 (The incremental HTML parser 
(html.parser.HTMLParser) allows for
        NOTE: https://github.com/python/cpython/pull/153031
        NOTE: 
https://github.com/python/cpython/commit/e9f92ac0b298292e7ff998e52cb8ccacfb27a0bd
 (v3.15.0b4)
        NOTE: 
https://github.com/python/cpython/commit/07efb08123ba9367a7107325adb9d5626dca1ca9
 (3.14 branch)
-       NOTE: 
https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced
 (3.13 branch)
+       NOTE: 
https://github.com/python/cpython/commit/7933f4bf7131aa4140750f9404f5de0aa2969ced
 (v3.13.15)
 CVE-2026-15204 (A vulnerability was detected in TOTOLINK X5000R 
9.1.0cu.2415_B20250515 ...)
        NOT-FOR-US: TOTOLINK
 CVE-2026-15202 (A security vulnerability has been detected in YzmCMS up to 
7.5. Affect ...)
@@ -27602,6 +27670,7 @@ CVE-2026-56298 (Capgo before 12.128.2 fails to strip 
EXIF metadata from images u
        NOT-FOR-US: Cap-go
 CVE-2026-56297 (FreeRDP before 3.22.0 contains a use-after-free vulnerability 
in dvcma ...)
        - freerdp3 3.22.0+dfsg-1
+       [trixie] - freerdp3 <no-dsa> (Minor issue)
        - freerdp2 <removed>
        NOTE: 
https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-3mv2-5q57-2v8h
        NOTE: 
https://github.com/FreeRDP/FreeRDP/commit/e02e052f6692550e539d10f99de9c35a23492db2
 (3.22.0)
@@ -33782,7 +33851,7 @@ CVE-2026-4360 (In the Tarfile.extract() function, the 
filter parameter is not pa
        NOTE: https://github.com/python/cpython/pull/151988
        NOTE: 
https://github.com/python/cpython/commit/7b57e8d51446297b8c7c482d224bc5f1938e4301
 (3.15 branch)
        NOTE: 
https://github.com/python/cpython/commit/5e0ef3f1afe892e4f64eb83368db57ac4c40cba0
 (3.14 branch)
-       NOTE: 
https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e
 (3.13 branch)
+       NOTE: 
https://github.com/python/cpython/commit/eee3ddf0ca10283cc7fea724aae9cd8665f8d15e
 (v3.13.15)
        NOTE: Same code situation as with CVE-2025-4435.
 CVE-2026-49877 (Improper Authorization vulnerability in Apache ActiveMQ.  An 
authentic ...)
        - activemq <unfixed> (bug #1141385)
@@ -40496,6 +40565,7 @@ CVE-2026-0864 (When using the "configparser" module to 
write configuration files
        NOTE: https://github.com/python/cpython/pull/152004 (3.13)
        NOTE: https://github.com/python/cpython/pull/152006 (3.11)
        NOTE: 
https://github.com/python/cpython/commit/5858e42c539dac8394636a6e9b30472b8994851f
 (main)
+       NOTE: 
https://github.com/python/cpython/commit/aaf850fd333cd89e9aada03d92aaa788a6cb1bb8
 (v3.13.15)
 CVE-2025-71382 (MuPDF before 1.27.0-rc1 contains an uncontrolled recursion 
vulnerabili ...)
        - mupdf 1.27.0+ds1-2
        [trixie] - mupdf <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/61524efebd992a82ba8df0154b2f1b67fece35ac

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/61524efebd992a82ba8df0154b2f1b67fece35ac
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to