Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9ebab6c6 by Moritz Muehlenhoff at 2026-08-18T17:45:30+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -452,6 +452,7 @@ CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential 
DoS attack via WebSocke
        NOT-FOR-US: JetBrains
 CVE-2026-68520 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        - glances 4.5.6+dfsg-1
+       [trixie] - glances <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nicolargo/glances/security/advisories/GHSA-4h34-v6r8-mmjc
        NOTE: Fixed by: 
https://github.com/nicolargo/glances/commit/8d0f8276c2abd2e9d400bd6c84bdfba0dfcab065
 (v4.5.6)
 CVE-2026-68519 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
@@ -463,10 +464,12 @@ CVE-2026-68519 (Glances is an open-source system 
cross-platform monitoring tool.
        NOTE: CVE exists because of an incomplete fix for CVE-2026-53925.
 CVE-2026-68518 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        - glances 4.5.6+dfsg-1
+       [trixie] - glances <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nicolargo/glances/security/advisories/GHSA-qcpp-8x79-hhp3
        NOTE: Fixed by: 
https://github.com/nicolargo/glances/commit/9c280eae5419da680827024b60f6265956e31994
 (v4.5.6)
 CVE-2026-68517 (Glances is an open-source system cross-platform monitoring 
tool. Prior ...)
        - glances 4.5.6+dfsg-1
+       [trixie] - glances <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg
        NOTE: Fixed by: 
https://github.com/nicolargo/glances/commit/890858944ab9d03730ec6b1ba42d4015e6d85db5
 (v4.5.6)
 CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription 
component. T ...)
@@ -787,10 +790,12 @@ CVE-2026-66797
        NOT-FOR-US: Red Hat cluster-backup-operator
 CVE-2026-18725
        - open-iscsi <unfixed>
+       [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462023
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
 CVE-2026-18724
        - open-iscsi <unfixed>
+       [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2461994
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
 CVE-2026-74579 (In the Linux kernel, the following vulnerability has been 
resolved:  n ...)
@@ -1660,9 +1665,11 @@ CVE-2026-8840 (The Booking calendar, Appointment Booking 
System plugin for WordP
        NOT-FOR-US: WordPress plugin
 CVE-2026-74250 (In OpenStack Ironic before 38.0.1, the autodetect deploy 
interface may ...)
        - ironic <unfixed> (bug #1144458)
+       [trixie] - ironic <no-dsa> (Minor issue)
        NOTE: https://bugs.launchpad.net/ossa/+bug/2163017
 CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles quality of service 
(QoS) p ...)
        - octavia <unfixed> (bug #1144459)
+       [trixie] - octavia <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/12
        NOTE: https://bugs.launchpad.net/octavia/+bug/2161500
 CVE-2026-74247 (A flaw was found in Red Hat Quay. A user with 
FEATURE_BUILD_SUPPORT en ...)
@@ -5980,6 +5987,7 @@ CVE-2026-12841
        [trixie] - nltk <no-dsa> (Minor issue)
 CVE-2026-XXXX [RUSTSEC-2026-0257]
        - rust-webbrowser <unfixed> (bug #1144396)
+       [trixie] - rust-webbrowser <no-dsa> (Minor issue)
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0257.html
        NOTE: 
https://github.com/amodm/webbrowser-rs/security/advisories/GHSA-2ph8-5cr8-hr33
        NOTE: 
https://github.com/amodm/webbrowser-rs/commit/31d1b924885551c0e553909d27c738ca6958a0f3
 (v1.2.2)
@@ -6545,10 +6553,12 @@ CVE-2026-33818 (Enforce a recursion limit in Unmarshal 
to prevent stack exhausti
        NOTE: Fixed by: 
https://github.com/golang/go/commit/8d01cbaad59021bd6d4f6e2dd864413872434250 
(go1.25.13)
 CVE-2026-16457
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3968
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/6682ea3391277e732a6d74c5758206ba834e1615
 (v11.1.0-rc2)
 CVE-2026-50626
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3882
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3921
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3923
@@ -6557,10 +6567,12 @@ CVE-2026-50626
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/d530f2dfbd2d973b17a6d0ffbfe2afb692bdd69c
 (v11.1.0-rc2)
 CVE-2026-63318
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4000
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/a0414545a212e27058fab7b057b018e75b8c4b13
 (v11.1.0-rc2)
 CVE-2026-66021
        - qemu 1:11.1.0+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3945
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/241095547a5d87ad6fa68cd674fe524e6596b958
 (v11.1.0-rc3)
 CVE-2026-73671 (Saurus CMS Community Edition contains an unauthenticated open 
redirect ...)
@@ -6721,6 +6733,7 @@ CVE-2026-73532 (Fluent Forms Pro 6.2.7 contains an 
embedded malicious code vulne
        NOT-FOR-US: Fluent Forms Pro
 CVE-2026-73515 (PostGIS before 3.7.0beta2 contains an out-of-bounds read 
vulnerability ...)
        - postgis <unfixed> (bug #1144647)
+       [trixie] - postgis <no-dsa> (Minor issue)
        NOTE: https://gitea.osgeo.org/postgis/postgis/pulls/669
        NOTE: 
https://gitea.osgeo.org/postgis/postgis/commit/767fa40644253281f6d4e8b06811489b0a0f9b0d
 (stable-3.6)
        NOTE: 
https://gitea.osgeo.org/postgis/postgis/commit/d2b5298d8b82ec1a4a667594422e9670b6dbd7e1
 (stable-3.5)
@@ -7885,6 +7898,7 @@ CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side 
method that lacks authoriz
        NOT-FOR-US: ScadaLTS
 CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due 
to a flaw ...)
        - rsyslog <unfixed> (bug #1144616)
+       [trixie] - rsyslog <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/5
        NOTE: https://github.com/rsyslog/rsyslog/pull/7410
        NOTE: 
https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
@@ -7926,14 +7940,17 @@ CVE-2026-18744 (Any authenticated case participant can 
fetch any OTHER vendor's
        NOT-FOR-US: CERT/CC VINCE
 CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow 
vulnerability in  ...)
        - open-iscsi <unfixed>
+       [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2463029
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
 CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This 
vulnerabilit ...)
        - open-iscsi <unfixed>
+       [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462956
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
 CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a 
remote att ...)
        - open-iscsi <unfixed>
+       [trixie] - open-iscsi <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462331
        NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
 CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the 
operato ...)
@@ -11899,10 +11916,12 @@ CVE-2026-18503 (Attacker-controlled CSV samples can 
trigger super-linear  regula
        - python3.15 3.15.0~rc1-1
        - python3.14 3.14.7-1
        - python3.13 3.13.15-1
+       [trixie] - python3.13 <no-dsa> (Minor issue)
        - python3.11 <removed>
        - python3.9 <removed>
        - python2.7 <removed>
        - pypy3 <unfixed>
+       [trixie] - pypy3 <no-dsa> (Minor issue)
        NOTE: 
https://mail.python.org/archives/list/[email protected]/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/
        NOTE: https://github.com/python/cpython/issues/98820
        NOTE: https://github.com/python/cpython/pull/153694
@@ -16764,6 +16783,7 @@ CVE-2026-7753 (The Cost Calculator Builder plugin for 
WordPress is vulnerable to
        NOT-FOR-US: WordPress plugin
 CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that 
makes a craf ...)
        - ironic 1:35.0.1-9 (bug #1143790)
+       [trixie] - ironic <no-dsa> (Minor issue)
        NOTE: https://bugs.launchpad.net/ironic/+bug/2162715
 CVE-2026-70620 (Odysseus before commit 87babb5 contains a server-side request 
forgery  ...)
        NOT-FOR-US: Odysseus
@@ -22130,6 +22150,7 @@ CVE-2026-54078 (veraPDF validation model is an 
implementation of the veraPDF val
        NOT-FOR-US: veraPDF
 CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for 
rootless  ...)
        - fuse-overlayfs <unfixed> (bug #1143058)
+       [trixie] - fuse-overlayfs <no-dsa> (Minor issue)
        NOTE: 
https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h
        NOTE: Fixed by: 
https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f
 (v1.17)
 CVE-2026-51992
@@ -22851,6 +22872,7 @@ CVE-2026-21047 (Out-of-bounds write in ImsService prior 
to SMR Jul-2026 Release
        NOT-FOR-US: Samsung Mobile
 CVE-2026-18107 (A flaw was found in CRIU's handling of restartable sequences 
(rseq) du ...)
        - criu 4.2-5
+       [trixie] - criu <no-dsa> (Minor issue)
        NOTE: https://github.com/checkpoint-restore/criu/pull/3097
        NOTE: 
https://github.com/checkpoint-restore/criu/security/advisories/GHSA-fvqj-jvxf-x3wp
 CVE-2026-18085 (An Improper Input Validation in the BlackBerry 
UEMManagementConsoleofB ...)
@@ -70309,6 +70331,7 @@ CVE-2026-46599 (The TIFF decoder does not place a limit 
on the size of PackBits-
        NOTE: https://go-review.googlesource.com/c/image/+/759960
 CVE-2026-46527 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)
        - cpp-httplib <unfixed> (bug #1138578)
+       [trixie] - cpp-httplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-hg3g-vrg8-578g
 CVE-2026-46385 (iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the 
Avro arr ...)
        NOT-FOR-US: iskorotkov/avro
@@ -70326,9 +70349,11 @@ CVE-2026-45613 (Rizin is a UNIX-like reverse 
engineering framework and command-l
        NOT-FOR-US: Rizin
 CVE-2026-45372 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)
        - cpp-httplib <unfixed> (bug #1138578)
+       [trixie] - cpp-httplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjxg-64p4-vj4m
 CVE-2026-45352 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)
        - cpp-httplib <unfixed> (bug #1138578)
+       [trixie] - cpp-httplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h6wq-j5mv-f3q8
 CVE-2026-45324 (Rizin is a UNIX-like reverse engineering framework and 
command-line to ...)
        NOT-FOR-US: Rizin
@@ -108826,6 +108851,7 @@ CVE-2026-34442 (FreeScout is a free help desk and 
shared inbox built with PHP's
        NOT-FOR-US: FreeScout
 CVE-2026-34441 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)
        - cpp-httplib 0.41.0+ds-3 (bug #1133187)
+       [trixie] - cpp-httplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-jv63-rm9j-6jwc
        NOTE: Fixed by: 
https://github.com/yhirose/cpp-httplib/commit/6fd97aeca0faa1c6e1bd7ae8150c821dcff31c3b
 (v0.40.0)
 CVE-2026-34406 (APTRS (Automated Penetration Testing Reporting System) is a 
Python and ...)
@@ -110381,6 +110407,7 @@ CVE-2026-33747 (BuildKit is a toolkit for converting 
source code to build artifa
 CVE-2026-33745 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)
        [experimental] - cpp-httplib 0.41.0+ds-1
        - cpp-httplib 0.41.0+ds-3 (bug #1132162)
+       [trixie] - cpp-httplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-6hrp-7fq9-3qv2
 CVE-2026-33744 (BentoML is a Python library for building online serving 
systems optimi ...)
        NOT-FOR-US: BentoML
@@ -119819,6 +119846,7 @@ CVE-2026-31871 (Parse Server is an open source 
backend that can be deployed to a
 CVE-2026-31870 (cpp-httplib is a C++11 single-file header-only cross platform 
HTTP/HTT ...)
        [experimental] - cpp-httplib 0.41.0+ds-1
        - cpp-httplib 0.41.0+ds-3 (bug #1130505)
+       [trixie] - cpp-httplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-39q5-hh6x-jpxx
        NOTE: Fixed by: 
https://github.com/yhirose/cpp-httplib/commit/e41ec36274a235d8b0bbf21d57e32068a30f6519
 (v0.37.1)
 CVE-2026-31868 (Parse Server is an open source backend that can be deployed to 
any inf ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -146,6 +146,8 @@ shaarli
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --
+spip
+--
 srt (jmm)
 --
 starlette



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9ebab6c636821c27cc95fa62ac96cd26e9ba1fbc

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9ebab6c636821c27cc95fa62ac96cd26e9ba1fbc
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to