Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d1f808c6 by Salvatore Bonaccorso at 2026-08-15T14:53:26+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -545,10 +545,10 @@ CVE-2026-74440 [drm/xe: Wait on external BO kernel fences 
in exec IOCTL]
 CVE-2026-8840 (The Booking calendar, Appointment Booking System plugin for 
WordPress  ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-74250 (In OpenStack Ironic before 38.0.1, the autodetect deploy 
interface may ...)
-       - ironic <unfixed>
+       - ironic <unfixed> (bug #1144458)
        NOTE: https://bugs.launchpad.net/ossa/+bug/2163017
 CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles quality of service 
(QoS) p ...)
-       - octavia <unfixed>
+       - octavia <unfixed> (bug #1144459)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/12
        NOTE: https://bugs.launchpad.net/octavia/+bug/2161500
 CVE-2026-74247 (A flaw was found in Red Hat Quay. A user with 
FEATURE_BUILD_SUPPORT en ...)
@@ -4838,7 +4838,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0221]
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0221.html
        NOTE: https://github.com/smol-rs/event-listener/pull/163
 CVE-2026-12876
-       - nltk <unfixed>
+       - nltk <unfixed> (bug #1144456)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf
 CVE-2026-12841
        - nltk 3.10.3-1
@@ -4908,7 +4908,7 @@ CVE-2026-73489 (Russh is a Rust SSH client & server 
library. Prior to 0.62.4, an
        NOTE: 
https://github.com/Eugeny/russh/security/advisories/GHSA-cqjc-rmpq-xprq
        NOTE: Fixed by: 
https://github.com/Eugeny/russh/commit/8912512371820167a12a0a638bd666856ce458ad 
(v0.62.4)
 CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory 
and file n ...)
-       - gdu <unfixed>
+       - gdu <unfixed> (bug #1144461)
        NOTE: https://github.com/dundee/gdu/issues/615
        NOTE: https://github.com/dundee/gdu/pull/616
        NOTE: Fixed by: 
https://github.com/dundee/gdu/commit/5d76fab735f190fd645896de90ac9982b6382aeb
@@ -4921,11 +4921,11 @@ CVE-2026-73421 (NextAuth.js provides authentication for 
Next.js. From next-auth
 CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to 
@auth/core 0 ...)
        NOT-FOR-US: Next.js
 CVE-2026-73417 (jupyterlab is an extensible environment for interactive and 
reproducib ...)
-       - jupyterlab <unfixed>
+       - jupyterlab <unfixed> (bug #1144463)
        NOTE: 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj
        NOTE: Fixed by: 
https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c
 (v4.5.10)
 CVE-2026-73416 (jupyterlab is an extensible environment for interactive and 
reproducib ...)
-       - jupyterlab <unfixed>
+       - jupyterlab <unfixed> (bug #1144464)
        NOTE: 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-89vp-jrxv-24w8
        NOTE: Fixed by: 
https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c
 (v4.5.10)
 CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 
3.39.18, packag ...)
@@ -7520,7 +7520,7 @@ CVE-2026-63134 (Malcolm is a network traffic analysis 
tool suite. Prior to versi
 CVE-2026-63133 (Malcolm is a network traffic analysis tool suite. Prior to 
version 26. ...)
        NOT-FOR-US: Malcolm
 CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 
SSH bac ...)
-       - libgit2 <unfixed>
+       - libgit2 <unfixed> (bug #1144465)
        NOTE: Fixed by: 
https://github.com/libgit2/libgit2/commit/b2105b8e60798cb28086d4c648b1cb4854eadccb
 (v1.9.7)
 CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The 
file-upload comp ...)
        NOT-FOR-US: Malcolm
@@ -9409,14 +9409,14 @@ CVE-2026-17061 (A Deserialization of Untrusted Data 
vulnerability affecting SIMU
 CVE-2026-15567 (A flaw was found in Wildfly. A remote unauthenticated attacker 
can tri ...)
        - wildfly <itp> (bug #752018)
 CVE-2026-15565 (A flaw was found in Undertow. A remote attacker can cause Out 
of Memor ...)
-       - undertow <unfixed>
+       - undertow <unfixed> (bug #1144457)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490628
 CVE-2026-15563 (A flaw was found in EAP's IIOP. The listener's NameService 
would accep ...)
        NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15562 (A flaw was found in EAP's jboss-remoting. A remote 
unauthenticated att ...)
        NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15561 (A flaw was found in EAP's undertow http/1.1 chunked-transfer 
decoder.  ...)
-       - undertow <unfixed>
+       - undertow <unfixed> (bug #1144457)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2483133
 CVE-2026-15560 (when EAP runs with -secmgr, the openjdk-orb's JDKBridge 
honours attack ...)
        NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
@@ -9425,12 +9425,12 @@ CVE-2026-15556 (A flaw was found in Picketlink's SP 
signature validation; a SAML
 CVE-2026-15555 (A flaw was found in JBoss marshalling. The Infinispan session 
replicat ...)
        NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15554 (the Undertow AJP listener honours forged ssl_cert and is_ssl 
AJP attri ...)
-       - undertow <unfixed>
+       - undertow <unfixed> (bug #1144457)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2480601
 CVE-2026-15426 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and 
Marketing Auto ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14180 (A flaw was found in the ChunkReader component of the Undertow 
HTTP ser ...)
-       - undertow <unfixed>
+       - undertow <unfixed> (bug #1144457)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2494771
 CVE-2026-13739 (A legacy endpoint in Command Center contained an 
unauthenticated serve ...)
        NOT-FOR-US: Commvault
@@ -12438,7 +12438,7 @@ CVE-2026-12570 (A vulnerability in keras-team/keras 
versions <= 3.15.0 allows fo
        - keras <removed>
        [bullseye] - keras <end-of-life> (EOL in bullseye LTS)
 CVE-2026-12372 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
nltk/nltk ...)
-       - nltk <unfixed>
+       - nltk <unfixed> (bug #1144456)
        [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513003
 CVE-2026-70395 (Improper Neutralization of Special Elements in Data Query 
Logic vulner ...)
@@ -13666,7 +13666,7 @@ CVE-2026-12584 (The Payment Gateway for Redsys & 
WooCommerce Lite WordPress plug
 CVE-2026-12501 (The WP Travel Engine WordPress plugin before 6.8.2 does not 
verify tha ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-12261 (A vulnerability in `nltk.downloader` in nltk/nltk versions <= 
3.9.4 al ...)
-       - nltk <unfixed>
+       - nltk <unfixed> (bug #1144456)
        [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: https://huntr.com/bounties/8b8c381e-08a8-4e4f-bb46-a320c96a364f
 CVE-2026-11976 (The official MonsterInsights Pro update distribution bucket 
(`monster- ...)
@@ -16606,7 +16606,7 @@ CVE-2026-18243 (Certain HP DesignJet products may be 
potentially vulnerable to c
 CVE-2026-15430 (Improper access control in the IRP_MJ_WRITE command interface 
in Wellb ...)
        NOT-FOR-US: Wellbia XIGNCODE3
 CVE-2026-12259 (In nltk version 3.9.4, the 
`nltk.downloader.Downloader._download_packa ...)
-       - nltk <unfixed>
+       - nltk <unfixed> (bug #1144456)
        [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: https://huntr.com/bounties/659ccf6d-12d4-4d4a-84c0-078633c35a5d
 CVE-2026-0392 (eParakst\u012bt\u0101js 3.0 for Windows before version 1.10.0 
retrieve ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1f808c65911651d293791be04db07e6edb4db43

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1f808c65911651d293791be04db07e6edb4db43
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to