Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
960e6cdc by Moritz Muehlenhoff at 2026-08-18T09:18:32+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -723,16 +723,23 @@ CVE-2026-19971 (A flaw has been found in LB-Link WR1210M
1.0.3. This impacts the
NOT-FOR-US: LB-Link
CVE-2026-19970 (A vulnerability was detected in Open Asset Import Library
Assimp 17c12 ...)
- assimp <unfixed>
+ [trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/assimp/assimp/issues/6632
CVE-2026-19969 (A security vulnerability has been detected in Open Asset
Import Librar ...)
- assimp <unfixed>
+ [trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/assimp/assimp/issues/6631
CVE-2026-19968 (A weakness has been identified in Open Asset Import Library
Assimp 17c ...)
- assimp <unfixed>
+ [trixie] - assimp <no-dsa> (Minor issue)
NOTE: https://github.com/assimp/assimp/issues/6630
NOTE: https://github.com/assimp/assimp/pull/6717
+ NOTE:
https://github.com/assimp/assimp/commit/c39d8c15dbbe03174af61d8eedbbf90120f4eb9f
+ NOTE:
https://github.com/assimp/assimp/commit/0f6bcfe7acd4c16bc198560db1be848757f953a8
+ NOTE:
https://github.com/assimp/assimp/commit/924bb602e387e10ca7c64acaac83a26d6ad1d8c6
CVE-2026-19967 (A security flaw has been discovered in Open Asset Import
Library Assim ...)
- assimp <unfixed>
+ [trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/assimp/assimp/issues/6624
CVE-2026-19966 (A vulnerability was identified in CodeCanyon TimeCamp
Integration for ...)
NOT-FOR-US: CodeCanyon TimeCamp Integration for CRM
@@ -5811,6 +5818,7 @@ CVE-2026-19884 (In Eclipse Theia versions up to and
including 1.69.0, opening a
NOT-FOR-US: Eclipse
CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on
Java (l ...)
- logback <unfixed>
+ [trixie] - logback <no-dsa> (Minor issue)
NOTE: https://logback.qos.ch/news.html#1.6.3
CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP
response ...)
- undertow <unfixed>
@@ -8648,10 +8656,12 @@ CVE-2026-73250 (Notepad++ is a free and open-source
source code editor. Prior to
NOT-FOR-US: Notepad++
CVE-2026-73249 (calibre is an e-book manager. Prior to 9.12.0, the calibre
Content Ser ...)
- calibre 9.12.0+ds+~0.10.6-1
+ [trixie] - calibre <no-dsa> (Minor issue)
NOTE:
https://github.com/kovidgoyal/calibre/security/advisories/GHSA-5x64-w63v-x2g6
NOTE: Fixed by:
https://github.com/kovidgoyal/calibre/commit/71295e8b62801e1ccecaa4fac47e6942f11cfe1e
(v9.12.0)
CVE-2026-73248 (calibre is an e-book manager. Prior to 9.12.0, calibre
processes attac ...)
- calibre 9.12.0+ds+~0.10.6-1
+ [trixie] - calibre <no-dsa> (Minor issue)
NOTE:
https://github.com/kovidgoyal/calibre/security/advisories/GHSA-4f7g-rjfp-hmvx
NOTE: Fixed by:
https://github.com/kovidgoyal/calibre/commit/dac9990458374a81a5372a768bba6527d965aac8
(v9.12.0)
CVE-2026-73247 (Kestra is an open-source, event-driven orchestration platform.
Prior t ...)
@@ -14287,7 +14297,9 @@ CVE-2026-62996 (Smarty is a template engine for PHP,
facilitating the separation
NOTE: Fixed by:
https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e
(v5.8.4)
CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the
separation of pr ...)
- smarty4 <unfixed>
+ [trixie] - smarty4 <no-dsa> (Minor issue)
- smarty3 <unfixed>
+ [trixie] - smarty3 <no-dsa> (Minor issue)
NOTE:
https://github.com/smarty-php/smarty/security/advisories/GHSA-f6wf-28g6-769x
NOTE: Fixed by:
https://github.com/smarty-php/smarty/commit/99c048ce7a590c519b79fbd38ad0143a08183a1f
(v5.8.2)
NOTE: Fixed by:
https://github.com/smarty-php/smarty/commit/a1ccdb0518021a559b4066c37b76a42c86bbce90
(v4.5.7)
@@ -16270,12 +16282,15 @@ CVE-2026-71231 (IOTSmartHome's gui/login.php
checkCookie function builds an auth
NOT-FOR-US: IOTSmartHome
CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence
an applic ...)
- libkcapi <unfixed> (bug #1143974)
+ [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462867
CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error:
libkcapi's one ...)
- libkcapi <unfixed> (bug #1143974)
+ [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462114
CVE-2026-71225 (A flaw was found in libkcapi. When performing one-shot
symmetric ciphe ...)
- libkcapi <unfixed> (bug #1143974)
+ [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
CVE-2026-71215 (art-template's sub-template resolution logic
(src/compile/adapter/reso ...)
NOT-FOR-US: art-template
@@ -21923,6 +21938,7 @@ CVE-2026-64556 (In the Linux kernel, the following
vulnerability has been resolv
NOTE:
https://git.kernel.org/linus/037a3c43edfb597665dd34457cd22b14692f2ba3 (7.2-rc2)
CVE-2026-62995 (joserfc is a Python library that provides an implementation of
several ...)
- joserfc 1.7.2-1
+ [trixie] - joserfc <no-dsa> (Minor issue)
NOTE:
https://github.com/authlib/joserfc/security/advisories/GHSA-5jhw-7jv7-qcqq
CVE-2026-60113 (AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN)
Interface befo ...)
NOT-FOR-US: AMMOS Instrument Toolkit (AIT) Deep Space Network (DSN)
Interface
@@ -34830,6 +34846,7 @@ CVE-2026-49977 (tarteaucitron.js is a compliant and
accessible cookie banner. Pr
NOT-FOR-US: tarteaucitron.js
CVE-2026-49852 (joserfc is a Python library that provides an implementation of
several ...)
- joserfc 1.6.8-1
+ [trixie] - joserfc <no-dsa> (Minor issue)
NOTE:
https://github.com/authlib/joserfc/security/advisories/GHSA-gg9x-qcx2-xmrh
NOTE: Fixed by:
https://github.com/authlib/joserfc/commit/86d00910b2b2d2d07503fee9b572906daefab7f1
(1.6.8)
CVE-2026-49834 (sigstore-go is a Go library for Sigstore signing and
verification. Pri ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -162,6 +162,8 @@ vips
--
weechat
--
+wireshark
+--
xorg-server
--
xrdp
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/960e6cdc573414c34734fda2a10b678851ed9d13
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/960e6cdc573414c34734fda2a10b678851ed9d13
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits