Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9ebab6c6 by Moritz Muehlenhoff at 2026-08-18T17:45:30+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -452,6 +452,7 @@ CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential
DoS attack via WebSocke
NOT-FOR-US: JetBrains
CVE-2026-68520 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
- glances 4.5.6+dfsg-1
+ [trixie] - glances <no-dsa> (Minor issue)
NOTE:
https://github.com/nicolargo/glances/security/advisories/GHSA-4h34-v6r8-mmjc
NOTE: Fixed by:
https://github.com/nicolargo/glances/commit/8d0f8276c2abd2e9d400bd6c84bdfba0dfcab065
(v4.5.6)
CVE-2026-68519 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
@@ -463,10 +464,12 @@ CVE-2026-68519 (Glances is an open-source system
cross-platform monitoring tool.
NOTE: CVE exists because of an incomplete fix for CVE-2026-53925.
CVE-2026-68518 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
- glances 4.5.6+dfsg-1
+ [trixie] - glances <no-dsa> (Minor issue)
NOTE:
https://github.com/nicolargo/glances/security/advisories/GHSA-qcpp-8x79-hhp3
NOTE: Fixed by:
https://github.com/nicolargo/glances/commit/9c280eae5419da680827024b60f6265956e31994
(v4.5.6)
CVE-2026-68517 (Glances is an open-source system cross-platform monitoring
tool. Prior ...)
- glances 4.5.6+dfsg-1
+ [trixie] - glances <no-dsa> (Minor issue)
NOTE:
https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg
NOTE: Fixed by:
https://github.com/nicolargo/glances/commit/890858944ab9d03730ec6b1ba42d4015e6d85db5
(v4.5.6)
CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription
component. T ...)
@@ -787,10 +790,12 @@ CVE-2026-66797
NOT-FOR-US: Red Hat cluster-backup-operator
CVE-2026-18725
- open-iscsi <unfixed>
+ [trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462023
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
CVE-2026-18724
- open-iscsi <unfixed>
+ [trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2461994
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
CVE-2026-74579 (In the Linux kernel, the following vulnerability has been
resolved: n ...)
@@ -1660,9 +1665,11 @@ CVE-2026-8840 (The Booking calendar, Appointment Booking
System plugin for WordP
NOT-FOR-US: WordPress plugin
CVE-2026-74250 (In OpenStack Ironic before 38.0.1, the autodetect deploy
interface may ...)
- ironic <unfixed> (bug #1144458)
+ [trixie] - ironic <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ossa/+bug/2163017
CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles quality of service
(QoS) p ...)
- octavia <unfixed> (bug #1144459)
+ [trixie] - octavia <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/12
NOTE: https://bugs.launchpad.net/octavia/+bug/2161500
CVE-2026-74247 (A flaw was found in Red Hat Quay. A user with
FEATURE_BUILD_SUPPORT en ...)
@@ -5980,6 +5987,7 @@ CVE-2026-12841
[trixie] - nltk <no-dsa> (Minor issue)
CVE-2026-XXXX [RUSTSEC-2026-0257]
- rust-webbrowser <unfixed> (bug #1144396)
+ [trixie] - rust-webbrowser <no-dsa> (Minor issue)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0257.html
NOTE:
https://github.com/amodm/webbrowser-rs/security/advisories/GHSA-2ph8-5cr8-hr33
NOTE:
https://github.com/amodm/webbrowser-rs/commit/31d1b924885551c0e553909d27c738ca6958a0f3
(v1.2.2)
@@ -6545,10 +6553,12 @@ CVE-2026-33818 (Enforce a recursion limit in Unmarshal
to prevent stack exhausti
NOTE: Fixed by:
https://github.com/golang/go/commit/8d01cbaad59021bd6d4f6e2dd864413872434250
(go1.25.13)
CVE-2026-16457
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3968
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/6682ea3391277e732a6d74c5758206ba834e1615
(v11.1.0-rc2)
CVE-2026-50626
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3882
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3921
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3923
@@ -6557,10 +6567,12 @@ CVE-2026-50626
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/d530f2dfbd2d973b17a6d0ffbfe2afb692bdd69c
(v11.1.0-rc2)
CVE-2026-63318
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4000
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/a0414545a212e27058fab7b057b018e75b8c4b13
(v11.1.0-rc2)
CVE-2026-66021
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3945
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/241095547a5d87ad6fa68cd674fe524e6596b958
(v11.1.0-rc3)
CVE-2026-73671 (Saurus CMS Community Edition contains an unauthenticated open
redirect ...)
@@ -6721,6 +6733,7 @@ CVE-2026-73532 (Fluent Forms Pro 6.2.7 contains an
embedded malicious code vulne
NOT-FOR-US: Fluent Forms Pro
CVE-2026-73515 (PostGIS before 3.7.0beta2 contains an out-of-bounds read
vulnerability ...)
- postgis <unfixed> (bug #1144647)
+ [trixie] - postgis <no-dsa> (Minor issue)
NOTE: https://gitea.osgeo.org/postgis/postgis/pulls/669
NOTE:
https://gitea.osgeo.org/postgis/postgis/commit/767fa40644253281f6d4e8b06811489b0a0f9b0d
(stable-3.6)
NOTE:
https://gitea.osgeo.org/postgis/postgis/commit/d2b5298d8b82ec1a4a667594422e9670b6dbd7e1
(stable-3.5)
@@ -7885,6 +7898,7 @@ CVE-2026-19656 (ScadaLTS 2.7.8.1exposes a server-side
method that lacks authoriz
NOT-FOR-US: ScadaLTS
CVE-2026-19654 (A unauthenticated remote peer may lead rsyslogd to crash due
to a flaw ...)
- rsyslog <unfixed> (bug #1144616)
+ [trixie] - rsyslog <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/22/5
NOTE: https://github.com/rsyslog/rsyslog/pull/7410
NOTE:
https://github.com/rsyslog/rsyslog/security/advisories/GHSA-cj5r-wh2m-7w29
@@ -7926,14 +7940,17 @@ CVE-2026-18744 (Any authenticated case participant can
fetch any OTHER vendor's
NOT-FOR-US: CERT/CC VINCE
CVE-2026-18728 (A flaw was found in open-iscsi. An integer underflow
vulnerability in ...)
- open-iscsi <unfixed>
+ [trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2463029
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
CVE-2026-18727 (A flaw was found in open-iscsi's iscsiuio component. This
vulnerabilit ...)
- open-iscsi <unfixed>
+ [trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462956
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
CVE-2026-18726 (A flaw was found in open-iscsi. This vulnerability allows a
remote att ...)
- open-iscsi <unfixed>
+ [trixie] - open-iscsi <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462331
NOTE: https://github.com/open-iscsi/open-iscsi/issues/543
CVE-2026-18679 (When kuma-dp is started against an HTTPS control plane and the
operato ...)
@@ -11899,10 +11916,12 @@ CVE-2026-18503 (Attacker-controlled CSV samples can
trigger super-linear regula
- python3.15 3.15.0~rc1-1
- python3.14 3.14.7-1
- python3.13 3.13.15-1
+ [trixie] - python3.13 <no-dsa> (Minor issue)
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
- pypy3 <unfixed>
+ [trixie] - pypy3 <no-dsa> (Minor issue)
NOTE:
https://mail.python.org/archives/list/[email protected]/thread/KQ7NBMCPAZJHRROQXJQE4GMXGLD5KHBS/
NOTE: https://github.com/python/cpython/issues/98820
NOTE: https://github.com/python/cpython/pull/153694
@@ -16764,6 +16783,7 @@ CVE-2026-7753 (The Cost Calculator Builder plugin for
WordPress is vulnerable to
NOT-FOR-US: WordPress plugin
CVE-2026-71201 (In OpenStack Ironic through 38.0.0, a project reader that
makes a craf ...)
- ironic 1:35.0.1-9 (bug #1143790)
+ [trixie] - ironic <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ironic/+bug/2162715
CVE-2026-70620 (Odysseus before commit 87babb5 contains a server-side request
forgery ...)
NOT-FOR-US: Odysseus
@@ -22130,6 +22150,7 @@ CVE-2026-54078 (veraPDF validation model is an
implementation of the veraPDF val
NOT-FOR-US: veraPDF
CVE-2026-52791 (fuse-overlayfs is an implementation of overlayfs in FUSE for
rootless ...)
- fuse-overlayfs <unfixed> (bug #1143058)
+ [trixie] - fuse-overlayfs <no-dsa> (Minor issue)
NOTE:
https://github.com/containers/fuse-overlayfs/security/advisories/GHSA-2cc4-p72c-v85h
NOTE: Fixed by:
https://github.com/containers/fuse-overlayfs/commit/97e0d968a782fc259ebde112db1e9b9ff1ad724f
(v1.17)
CVE-2026-51992
@@ -22851,6 +22872,7 @@ CVE-2026-21047 (Out-of-bounds write in ImsService prior
to SMR Jul-2026 Release
NOT-FOR-US: Samsung Mobile
CVE-2026-18107 (A flaw was found in CRIU's handling of restartable sequences
(rseq) du ...)
- criu 4.2-5
+ [trixie] - criu <no-dsa> (Minor issue)
NOTE: https://github.com/checkpoint-restore/criu/pull/3097
NOTE:
https://github.com/checkpoint-restore/criu/security/advisories/GHSA-fvqj-jvxf-x3wp
CVE-2026-18085 (An Improper Input Validation in the BlackBerry
UEMManagementConsoleofB ...)
@@ -70309,6 +70331,7 @@ CVE-2026-46599 (The TIFF decoder does not place a limit
on the size of PackBits-
NOTE: https://go-review.googlesource.com/c/image/+/759960
CVE-2026-46527 (cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTT ...)
- cpp-httplib <unfixed> (bug #1138578)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE:
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-hg3g-vrg8-578g
CVE-2026-46385 (iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the
Avro arr ...)
NOT-FOR-US: iskorotkov/avro
@@ -70326,9 +70349,11 @@ CVE-2026-45613 (Rizin is a UNIX-like reverse
engineering framework and command-l
NOT-FOR-US: Rizin
CVE-2026-45372 (cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTT ...)
- cpp-httplib <unfixed> (bug #1138578)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE:
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xjxg-64p4-vj4m
CVE-2026-45352 (cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTT ...)
- cpp-httplib <unfixed> (bug #1138578)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE:
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-h6wq-j5mv-f3q8
CVE-2026-45324 (Rizin is a UNIX-like reverse engineering framework and
command-line to ...)
NOT-FOR-US: Rizin
@@ -108826,6 +108851,7 @@ CVE-2026-34442 (FreeScout is a free help desk and
shared inbox built with PHP's
NOT-FOR-US: FreeScout
CVE-2026-34441 (cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTT ...)
- cpp-httplib 0.41.0+ds-3 (bug #1133187)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE:
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-jv63-rm9j-6jwc
NOTE: Fixed by:
https://github.com/yhirose/cpp-httplib/commit/6fd97aeca0faa1c6e1bd7ae8150c821dcff31c3b
(v0.40.0)
CVE-2026-34406 (APTRS (Automated Penetration Testing Reporting System) is a
Python and ...)
@@ -110381,6 +110407,7 @@ CVE-2026-33747 (BuildKit is a toolkit for converting
source code to build artifa
CVE-2026-33745 (cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTT ...)
[experimental] - cpp-httplib 0.41.0+ds-1
- cpp-httplib 0.41.0+ds-3 (bug #1132162)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE:
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-6hrp-7fq9-3qv2
CVE-2026-33744 (BentoML is a Python library for building online serving
systems optimi ...)
NOT-FOR-US: BentoML
@@ -119819,6 +119846,7 @@ CVE-2026-31871 (Parse Server is an open source
backend that can be deployed to a
CVE-2026-31870 (cpp-httplib is a C++11 single-file header-only cross platform
HTTP/HTT ...)
[experimental] - cpp-httplib 0.41.0+ds-1
- cpp-httplib 0.41.0+ds-3 (bug #1130505)
+ [trixie] - cpp-httplib <no-dsa> (Minor issue)
NOTE:
https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-39q5-hh6x-jpxx
NOTE: Fixed by:
https://github.com/yhirose/cpp-httplib/commit/e41ec36274a235d8b0bbf21d57e32068a30f6519
(v0.37.1)
CVE-2026-31868 (Parse Server is an open source backend that can be deployed to
any inf ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -146,6 +146,8 @@ shaarli
sogo
Regression update for #1144734, new batch of issues from 5.12.10 release
--
+spip
+--
srt (jmm)
--
starlette
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9ebab6c636821c27cc95fa62ac96cd26e9ba1fbc
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9ebab6c636821c27cc95fa62ac96cd26e9ba1fbc
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits