Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
960e6cdc by Moritz Muehlenhoff at 2026-08-18T09:18:32+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -723,16 +723,23 @@ CVE-2026-19971 (A flaw has been found in LB-Link WR1210M 
1.0.3. This impacts the
        NOT-FOR-US: LB-Link
 CVE-2026-19970 (A vulnerability was detected in Open Asset Import Library 
Assimp 17c12 ...)
        - assimp <unfixed>
+       [trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
        NOTE: https://github.com/assimp/assimp/issues/6632
 CVE-2026-19969 (A security vulnerability has been detected in Open Asset 
Import Librar ...)
        - assimp <unfixed>
+       [trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
        NOTE: https://github.com/assimp/assimp/issues/6631
 CVE-2026-19968 (A weakness has been identified in Open Asset Import Library 
Assimp 17c ...)
        - assimp <unfixed>
+       [trixie] - assimp <no-dsa> (Minor issue)
        NOTE: https://github.com/assimp/assimp/issues/6630
        NOTE: https://github.com/assimp/assimp/pull/6717
+       NOTE: 
https://github.com/assimp/assimp/commit/c39d8c15dbbe03174af61d8eedbbf90120f4eb9f
+       NOTE: 
https://github.com/assimp/assimp/commit/0f6bcfe7acd4c16bc198560db1be848757f953a8
+       NOTE: 
https://github.com/assimp/assimp/commit/924bb602e387e10ca7c64acaac83a26d6ad1d8c6
 CVE-2026-19967 (A security flaw has been discovered in Open Asset Import 
Library Assim ...)
        - assimp <unfixed>
+       [trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
        NOTE: https://github.com/assimp/assimp/issues/6624
 CVE-2026-19966 (A vulnerability was identified in CodeCanyon TimeCamp 
Integration for  ...)
        NOT-FOR-US: CodeCanyon TimeCamp Integration for CRM
@@ -5811,6 +5818,7 @@ CVE-2026-19884 (In Eclipse Theia versions up to and 
including 1.69.0, opening a
        NOT-FOR-US: Eclipse
 CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on 
Java (l ...)
        - logback <unfixed>
+       [trixie] - logback <no-dsa> (Minor issue)
        NOTE: https://logback.qos.ch/news.html#1.6.3
 CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP 
response ...)
        - undertow <unfixed>
@@ -8648,10 +8656,12 @@ CVE-2026-73250 (Notepad++ is a free and open-source 
source code editor. Prior to
        NOT-FOR-US: Notepad++
 CVE-2026-73249 (calibre is an e-book manager. Prior to 9.12.0, the calibre 
Content Ser ...)
        - calibre 9.12.0+ds+~0.10.6-1
+       [trixie] - calibre <no-dsa> (Minor issue)
        NOTE: 
https://github.com/kovidgoyal/calibre/security/advisories/GHSA-5x64-w63v-x2g6
        NOTE: Fixed by: 
https://github.com/kovidgoyal/calibre/commit/71295e8b62801e1ccecaa4fac47e6942f11cfe1e
 (v9.12.0)
 CVE-2026-73248 (calibre is an e-book manager. Prior to 9.12.0, calibre 
processes attac ...)
        - calibre 9.12.0+ds+~0.10.6-1
+       [trixie] - calibre <no-dsa> (Minor issue)
        NOTE: 
https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx
        NOTE: Fixed by: 
https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8
 (v9.12.0)
 CVE-2026-73247 (Kestra is an open-source, event-driven orchestration platform. 
Prior t ...)
@@ -14287,7 +14297,9 @@ CVE-2026-62996 (Smarty is a template engine for PHP, 
facilitating the separation
        NOTE: Fixed by: 
https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e
 (v5.8.4)
 CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the 
separation of pr ...)
        - smarty4 <unfixed>
+       [trixie] - smarty4 <no-dsa> (Minor issue)
        - smarty3 <unfixed>
+       [trixie] - smarty3 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/smarty-php/smarty/security/advisories/GHSA-f6wf-28g6-769x
        NOTE: Fixed by: 
https://github.com/smarty-php/smarty/commit/99c048ce7a590c519b79fbd38ad0143a08183a1f
 (v5.8.2)
        NOTE: Fixed by: 
https://github.com/smarty-php/smarty/commit/a1ccdb0518021a559b4066c37b76a42c86bbce90
 (v4.5.7)
@@ -16270,12 +16282,15 @@ CVE-2026-71231 (IOTSmartHome's gui/login.php 
checkCookie function builds an auth
        NOT-FOR-US: IOTSmartHome
 CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence 
an applic ...)
        - libkcapi <unfixed> (bug #1143974)
+       [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462867
 CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error: 
libkcapi's one ...)
        - libkcapi <unfixed> (bug #1143974)
+       [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462114
 CVE-2026-71225 (A flaw was found in libkcapi. When performing one-shot 
symmetric ciphe ...)
        - libkcapi <unfixed> (bug #1143974)
+       [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
 CVE-2026-71215 (art-template's sub-template resolution logic 
(src/compile/adapter/reso ...)
        NOT-FOR-US: art-template
@@ -21923,6 +21938,7 @@ CVE-2026-64556 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: 
https://git.kernel.org/linus/037a3c43edfb597665dd34457cd22b14692f2ba3 (7.2-rc2)
 CVE-2026-62995 (joserfc is a Python library that provides an implementation of 
several ...)
        - joserfc 1.7.2-1
+       [trixie] - joserfc <no-dsa> (Minor issue)
        NOTE: 
https://github.com/authlib/joserfc/security/advisories/GHSA-5jhw-7jv7-qcqq
 CVE-2026-60113 (AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) 
Interface befo ...)
        NOT-FOR-US: AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN) 
Interface
@@ -34830,6 +34846,7 @@ CVE-2026-49977 (tarteaucitron.js is a compliant and 
accessible cookie banner. Pr
        NOT-FOR-US: tarteaucitron.js
 CVE-2026-49852 (joserfc is a Python library that provides an implementation of 
several ...)
        - joserfc 1.6.8-1
+       [trixie] - joserfc <no-dsa> (Minor issue)
        NOTE: 
https://github.com/authlib/joserfc/security/advisories/GHSA-gg9x-qcx2-xmrh
        NOTE: Fixed by: 
https://github.com/authlib/joserfc/commit/86d00910b2b2d2d07503fee9b572906daefab7f1
 (1.6.8)
 CVE-2026-49834 (sigstore-go is a Go library for Sigstore signing and 
verification. Pri ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -162,6 +162,8 @@ vips
 --
 weechat
 --
+wireshark
+--
 xorg-server
 --
 xrdp



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/960e6cdc573414c34734fda2a10b678851ed9d13

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/960e6cdc573414c34734fda2a10b678851ed9d13
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to