Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6d4052dd by Moritz Muehlenhoff at 2026-08-10T14:22:40+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,6 +9,7 @@ CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read 
and resultant in
        NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
 CVE-2026-19389 (Multiple integer overflow and underflow vulnerabilities were 
found in  ...)
        - gst-plugins-ugly1.0 1.28.6-1
+       [trixie] - gst-plugins-ugly1.0 <no-dsa> (Minor issue)
        NOTE: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12233
        NOTE: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12243
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a598edfef83878f714ea53925ae802f49c3b31a6
 (1.28.6)
@@ -1037,6 +1038,7 @@ CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and 
detects violations of a
        NOT-FOR-US: PHP_CodeSniffer
 CVE-2026-67422 (pymdown-extensions is a collection of extensions for the 
Python Markdo ...)
        - pymdown-extensions 11.0.1-1
+       [trixie] - pymdown-extensions <no-dsa> (Minor issue)
        NOTE: 
https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-gm37-52c6-37mw
        NOTE: Fixed by: 
https://github.com/facelessuser/pymdown-extensions/commit/c68498598d7b13011bb4571350b6e3612a4ce44b
 (11.0.1)
 CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows 
an auth ...)
@@ -1083,6 +1085,7 @@ CVE-2026-62830 (Missing authorization in Azure SRE Agent 
allows an authorized at
        NOT-FOR-US: Microsoft
 CVE-2026-61632 (PyMdown Extensions is a set of extensions for the 
Python-Markdown mark ...)
        - pymdown-extensions 11.0.1-1
+       [trixie] - pymdown-extensions <no-dsa> (Minor issue)
        NOTE: 
https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-9xwg-3r6f-jcx2
 CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in 
os/net/app-layer/mqtt ...)
        NOT-FOR-US: Contiki-NG
@@ -1257,6 +1260,7 @@ CVE-2026-19054 (A vulnerability was detected in Lspace-io 
lspace-server up to 79
        NOT-FOR-US: Lspace-io lspace-server
 CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser 
reads web ad ...)
        - epiphany-browser <unfixed> (bug #1143966)
+       [trixie] - epiphany-browser <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897
        NOTE: 
https://gitlab.gnome.org/GNOME/epiphany/-/commit/13dd600719d7aac532ed6c84ea0d12dd372d4ac4
 CVE-2026-18367 (A privilege escalation vulnerability allows local users to 
execute arb ...)
@@ -1381,6 +1385,7 @@ CVE-2024-39024 (In Packetfence 13.2.0, the WebGui 
interface setting allows authe
        TODO: check
 CVE-2026-18938 (A flaw was found in p11-kit. A local attacker, or one with 
equivalent  ...)
        - p11-kit <unfixed>
+       [trixie] - p11-kit <no-dsa> (Minor issue)
        NOTE: https://github.com/p11-glue/p11-kit/pull/777
        NOTE: Fixed by: 
https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc
 (0.26.5)
 CVE-2026-64638 (WordPress is vulnerable to a pre-auth reflected XSS 
vulnerability on t ...)
@@ -5059,6 +5064,7 @@ CVE-2026-54909 (pion/stun is a Go implementation of STUN. 
Prior to 3.1.3, XORMap
        NOTE: Fixed by: 
https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423 
(v3.1.3)
 CVE-2026-54787 (sigstore-go is a Go library for Sigstore signing and 
verification. Pri ...)
        - sigstore-go 1.2.1-1
+       [trixie] - sigstore-go <no-dsa> (Minor issue)
        NOTE: 
https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm
        NOTE: https://github.com/sigstore/sigstore-go/pull/642
        NOTE: 
https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f
 (v1.2.1)
@@ -10261,9 +10267,11 @@ CVE-2025-50455 (SQL injection vulnerability exists in 
the order_by parameter of
 CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
        - unzip <unfixed> (bug #1142906)
 CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
-       - unzip <unfixed> (bug #1142905)
+       - unzip <unfixed> (bug #1142905; unimportant)
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-XXXX [heap OOB read in EF_IZUNIX3 extra field handler]
-       - unzip <unfixed> (bug #1142904)
+       - unzip <unfixed> (bug #1142904; unimportant)
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin 
before 5.7.3 ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control 
vulnerabilit ...)
@@ -10360,6 +10368,7 @@ CVE-2026-49478
        NOTE: Fixed by: 
https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1
 (v1.8.6)
 CVE-2026-48702
        - rekor 1.5.2-1
+       [trixie] - rekor <no-dsa> (Minor issue)
        NOTE: https://github.com/sigstore/rekor/pull/2831
        NOTE: Fixed by: 
https://github.com/sigstore/rekor/commit/759b98e2a7c39ea9779b6a51299c5f0f987f8802
 (v1.5.2)
 CVE-2026-50540 (Kata Containers is an open source project focusing on a 
standard imple ...)
@@ -12615,6 +12624,7 @@ CVE-2026-6454 (The Firelight Lightbox plugin for 
WordPress is vulnerable to Stor
        NOT-FOR-US: WordPress plugin
 CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass 
via an EXT ...)
        - zaqar 22.0.0-3 (bug #1142858)
+       [trixie] - zaqar <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/7
        NOTE: https://launchpad.net/bugs/2161254
 CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, 
aproject-scoped user  ...)
@@ -12893,6 +12903,7 @@ CVE-2026-65919 (Meshery before 1.0.57 contains an 
unauthenticated arbitrary file
        NOT-FOR-US: Meshery
 CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, 
contains  ...)
        - pytorch-vision <unfixed> (bug #1142689)
+       [trixie] - pytorch-vision <no-dsa> (Minor issue)
        NOTE: https://github.com/pytorch/vision/issues/9551
        NOTE: https://github.com/pytorch/vision/pull/9520
        NOTE: Fixed by: 
https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed
@@ -13218,6 +13229,7 @@ CVE-2026-64799 (Joomla Extension - regularlabs.com - 
SSRF via remote image downl
        NOT-FOR-US: Joomla
 CVE-2026-64611 (A flaw was found in libcupsfilters. The 
cfIEEE1284NormalizeMakeModel() ...)
        - libcupsfilters <unfixed> (bug #1142686)
+       [trixie] - libcupsfilters <no-dsa> (Minor issue)
        [bookworm] - libcupsfilters <postponed> (Minor issue)
        [bullseye] - libcupsfilters <postponed> (Minor issue)
        NOTE: 
https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4
@@ -21824,6 +21836,7 @@ CVE-2026-46341 (The Apify MCP server enables AI agents 
to extract data from webs
        NOT-FOR-US: Apify MCP server
 CVE-2026-46338 (PyMdown Extensions is a set of extensions for the 
Python-Markdown mark ...)
        - pymdown-extensions 11.0.1-1
+       [trixie] - pymdown-extensions <no-dsa> (Minor issue)
        NOTE: 
https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-62q4-447f-wv8h
        NOTE: Fixed by: 
https://github.com/facelessuser/pymdown-extensions/commit/63b7835776d703d6c339cf2110d9888f676efc0c
 (10.21.3)
 CVE-2026-46336 (Manyfold is an open source, self-hosted web application for 
managing a ...)
@@ -23010,14 +23023,17 @@ CVE-2026-59888 (jackson-databind contains the 
general-purpose data-binding funct
        NOTE: Fixed by: 
https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d
 (jackson-databind-2.18.8)
 CVE-2026-59886 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, 
the univ ...)
        - pyasn1 0.6.4-1 (bug #1142388)
+       [trixie] - pyasn1 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r
        NOTE: Fixed by: 
https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886
 (v0.6.4)
 CVE-2026-59885 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, 
the BER, ...)
        - pyasn1 0.6.4-1 (bug #1142388)
+       [trixie] - pyasn1 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj
        NOTE: Fixed by: 
https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9
 (v0.6.4)
 CVE-2026-59884 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, 
the BER  ...)
        - pyasn1 0.6.4-1 (bug #1142388)
+       [trixie] - pyasn1 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j
        NOTE: Fixed by: 
https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5
 (v0.6.4)
 CVE-2026-59841 (A improper restriction of communication channel to intended 
endpoints  ...)
@@ -24248,10 +24264,12 @@ CVE-2026-49783 (Improperly implemented security check 
for standard in Windows Se
        NOT-FOR-US: Microsoft
 CVE-2026-49477 (Soup Sieve is a CSS selector library designed to be used with 
Beautifu ...)
        - soupsieve 2.8.4-1
+       [trixie] - soupsieve <no-dsa> (Minor issue)
        NOTE: 
https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37
        NOTE: Fixed by: 
https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3
 (2.8.4)
 CVE-2026-49476 (Soup Sieve is a CSS selector library designed to be used with 
Beautifu ...)
        - soupsieve 2.8.4-1
+       [trixie] - soupsieve <no-dsa> (Minor issue)
        NOTE: 
https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x
        NOTE: Fixed by: 
https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39
 (2.8.4)
 CVE-2026-49459 (DOMPurify is a DOM-only cross-site scripting sanitizer for 
HTML, MathM ...)
@@ -41403,9 +41421,11 @@ CVE-2026-56221 (Cap-go before 12.128.2 contains 
multiple SQL injection vulnerabi
        NOT-FOR-US: Cap-go
 CVE-2026-55655 (A flaw was found in OpenSSH. A local unprivileged attacker on 
a Linux  ...)
        - openssh <unfixed> (bug #1143936)
+       [trixie] - openssh <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462250
 CVE-2026-55654 (A flaw was found in OpenSSH. This vulnerability, a heap 
out-of-bounds  ...)
        - openssh <unfixed> (bug #1143924)
+       [trixie] - openssh <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462493
 CVE-2026-55653 (A flaw was found in OpenSSH. A malicious SSH server can 
exploit a doub ...)
        - openssh <not-affected> (Only an issue with FIPS patch which is not in 
Debian/upstream)


=====================================
data/dsa-needed.txt
=====================================
@@ -49,6 +49,10 @@ firebird4.0
 --
 gimp
 --
+gst-plugins-bad1.0
+--
+ironic
+--
 jackson-databind
 --
 jetty9
@@ -144,6 +148,8 @@ tomcat11
 unbound
   Michael Tokarev is working on rebasing to 1.25.2 (possibly 1.26.0)
 --
+unzip
+--
 util-linux (carnil)
   Maintainer is preparing updates
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d4052ddcfd70277a9a16cadf6d41420c341e5c9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d4052ddcfd70277a9a16cadf6d41420c341e5c9
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to