Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
dae2554a by Moritz Muehlenhoff at 2026-08-18T12:37:51+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -590,6 +590,7 @@ CVE-2026-20000 (A vulnerability was detected in 
itsourcecode Hospital Management
        NOT-FOR-US: itsourcecode System
 CVE-2026-19999 (A security vulnerability has been detected in Open Asset 
Import Librar ...)
        - assimp <unfixed>
+       [trixie] - assimp <no-dsa> (Minor issue)
        NOTE: https://github.com/assimp/assimp/issues/6633
        NOTE: https://github.com/assimp/assimp/pull/6759
        NOTE: 
https://github.com/assimp/assimp/commit/50d767984e78d51b53e2020fdf0967fd624bc377
@@ -652,10 +653,13 @@ CVE-2025-27621 (UpTrain is an open-source platform to 
evaluate and improve gener
        TODO: check
 CVE-2026-XXXX [heap out-of-bounds write during Unicode font-name conversion]
        - antiword <unfixed> (bug #1144645)
+       [trixie] - antiword <postponed> (Revisit when fixed upstream)
 CVE-2026-XXXX [heap out-of-bounds write during OLE PPS name decoding]
        - antiword <unfixed> (bug #1144644)
+       [trixie] - antiword <postponed> (Revisit when fixed upstream)
 CVE-2026-XXXX [heap out-of-bounds write when appending font-table entry]
        - antiword <unfixed> (bug #1144643)
+       [trixie] - antiword <postponed> (Revisit when fixed upstream)
 CVE-2026-XXXX [out-of-bounds read in szLpstr/xstrdup may expose adjacent heap 
data]
        - antiword <unfixed> (bug #1144642; unimportant)
        NOTE: Crash in CLI tool, no security impact
@@ -6262,8 +6266,9 @@ CVE-2026-19746 (A vulnerability has been found in Calix 
GigaSpire 26.1.0. The af
 CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is 
an unknow ...)
        NOT-FOR-US: Calix GigaSpire
 CVE-2026-19617 (A flaw was found in libdm. A local attacker could craft a 
malicious Lo ...)
-       - lvm2 <unfixed>
+       - lvm2 <unfixed> (unimportant)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2514626
+       NOTE: Doesn't cross any meaningful security boundary
 CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 
6.0.1.0 ...)
        NOT-FOR-US: IBM
 CVE-2026-19297 (IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote 
attacker to  ...)
@@ -11930,6 +11935,7 @@ CVE-2026-15060 (When systemd-machined >= v259 (or v258 
with a custom `polkit` po
        NOTE: Fixed by: 
https://github.com/systemd/systemd/commit/8eb162df81b4f684c9d444e458dbf22674f964fb
 (v261.2)
 CVE-2026-15059 (Local unprivileged users can terminate arbitrary local 
processes via a ...)
        - systemd 261~rc3-1
+       [trixie] - systemd <no-dsa> (Minor issue)
        NOTE: 
https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6
        NOTE: Fixed by: 
https://github.com/systemd/systemd/commit/cde88c4ea364e816619f385a870d074ebc12fe0f
 (v261-rc3)
        NOTE: Fixed by: 
https://github.com/systemd/systemd/commit/a8feb2f23565d39df5c90a753c851c1934a53117
 (v258.9)
@@ -24047,7 +24053,9 @@ CVE-2026-17500 (A vulnerability was detected in 
ggml-org llama.cpp d006858/e15ef
        NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
 CVE-2026-15928 (XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable 
to a ref ...)
        - xmlrpc-c <unfixed> (bug #1143065)
-       TODO: check upstream status
+       [trixie] - xmlrpc-c <no-dsa> (Minor issue)
+       NOTE: 
https://www.themissinglink.com.au/security-advisories/cve-2026-15928
+       NOTE: https://sourceforge.net/p/xmlrpc-c/code/3342/
 CVE-2026-14827 (The Calendar WordPress plugin before 1.3.18 does not properly 
escape a ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-14820 (The Quiz and Survey Master (QSM)  WordPress plugin before 
11.1.3 does  ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -46,6 +46,8 @@ gimp
 --
 gst-plugins-bad1.0 (jmm)
 --
+gst-plugins-good1.0
+--
 jackson-databind
 --
 jetty9



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dae2554aa3d00e20a47a40cc7660ef8e2955b248

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dae2554aa3d00e20a47a40cc7660ef8e2955b248
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to