Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
464e5ce4 by Salvatore Bonaccorso at 2026-08-09T07:37:21+02:00
Add Debian bug references for reported issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -112,7 +112,7 @@ CVE-2026-59717 (Home Assistant is open source home
automation software focused o
CVE-2026-58262 (Klever-Go is the Go implementation of the Klever blockchain
protocol. ...)
NOT-FOR-US: Klever-Go
CVE-2026-54338 (JupyterHub is software that allows users to create a
multi-user server ...)
- - jupyterhub <unfixed>
+ - jupyterhub <unfixed> (bug #1143967)
NOTE:
https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h
NOTE: Fixed by:
https://github.com/jupyterhub/jupyterhub/commit/d6dc595f84b7509969686da31d87d6d69e7fce0a
(5.5.0)
CVE-2026-52880 (Klever-Go is the Go implementation of the Klever blockchain
protocol. ...)
@@ -130,7 +130,7 @@ CVE-2026-48169 (PraisonAI is a multi-agent teams system.
Versions prior to 0.1.4
CVE-2026-48122 (Ruby LSP is an implementation of the language server protocol
for Ruby ...)
NOT-FOR-US: VS Code extension for Ruby LSP (not in src:ruby-ruby-lsp )
CVE-2026-48120 (Kakoune is a code editor. Prior to version 2026.05.21, the
bundled, en ...)
- - kakoune <unfixed>
+ - kakoune <unfixed> (bug #1143968)
NOTE:
https://github.com/mawww/kakoune/security/advisories/GHSA-h99r-h8cp-vwcq
NOTE: Fixed by:
https://github.com/mawww/kakoune/commit/25c7b13b244fd1ddacc63ecfe1784b5ebc2ba825
(v2026.05.21)
CVE-2026-48047 (XWiki Platform WebJars API is a package for XWiki, a generic
wiki plat ...)
@@ -454,7 +454,7 @@ CVE-2026-19082 (Imager versions from 0.45_02 before 1.034
for Perl may expose ad
NOTE:
https://github.com/tonycoz/imager/security/advisories/GHSA-hx46-55wp-hv6m
NOTE: Fixed by:
https://github.com/tonycoz/imager/commit/24bde0427a113264d53f45a9c29ae756d84c82fe
(v1.034)
CVE-2026-19079 (A TOCTOU (Time-of-Check-Time-of-Use) race condition
vulnerability was ...)
- - policycoreutils <unfixed>
+ - policycoreutils <unfixed> (bug #1143965)
NOTE: Fixed by:
https://github.com/SELinuxProject/selinux/commit/a556538c2d5d2583273e025b45c02651fef47679
CVE-2026-18497 (A heap-buffer-overflow vulnerability exists in the nothings
stb TrueTy ...)
TODO: check
@@ -919,7 +919,7 @@ CVE-2026-19058 (A vulnerability was found in
FoundationAgents MetaGPT up to 0.8.
CVE-2026-19054 (A vulnerability was detected in Lspace-io lspace-server up to
79f02fe5 ...)
NOT-FOR-US: Lspace-io lspace-server
CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser
reads web ad ...)
- - epiphany-browser <unfixed>
+ - epiphany-browser <unfixed> (bug #1143966)
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897
NOTE:
https://gitlab.gnome.org/GNOME/epiphany/-/commit/13dd600719d7aac532ed6c84ea0d12dd372d4ac4
CVE-2026-18367 (A privilege escalation vulnerability allows local users to
execute arb ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/464e5ce4ff78a672aa57fefe450e0170828ac420
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/464e5ce4ff78a672aa57fefe450e0170828ac420
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits