Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
05740c72 by Salvatore Bonaccorso at 2026-08-21T16:48:00+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -216,7 +216,7 @@ CVE-2026-72854 (msgpack_unpacker_expand_buffer in
src/unpack.c, reached through
CVE-2026-72852 (hank-ai/darknet sizes a convolutional layer's weight and
output heap b ...)
NOT-FOR-US: hank-ai/darknet
CVE-2026-72847 (broot renders each file and directory name in its interactive
tree vie ...)
- - rust-broot <unfixed>
+ - rust-broot <unfixed> (bug #1145024)
NOTE: https://github.com/Canop/broot/issues/1188
NOTE: Fixed by:
https://github.com/Canop/broot/commit/4ba40f7d47af78457c7656f15eba71d63d97fce5
NOTE: Fixed by:
https://github.com/Canop/broot/commit/0717a94b3c0efa19c7bbcfe0fb49a2374752a168
@@ -339,7 +339,7 @@ CVE-2026-64961 (ATutor is vulnerable to authentication
bypass .Although a token
CVE-2026-64960 (ATutor Gameme module allows users to upload files of any type
and exte ...)
NOT-FOR-US: ATutor
CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems.
Prior to 2. ...)
- - nix <unfixed>
+ - nix <unfixed> (bug #1145021)
NOTE:
https://github.com/NixOS/nix/security/advisories/GHSA-6h4g-g5j9-fm5f
NOTE: https://github.com/NixOS/nix/pull/15401
NOTE: Fixed by:
https://github.com/NixOS/nix/commit/26679828f74ee6e82a4100904e6361f993ff5390
(2.35.0)
@@ -548,7 +548,7 @@ CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow
Remote Code Execution Vul
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/b1f46e63c82065bd60e84359fb729380d5b043bf
TODO: check
CVE-2026-18300 (GIMP HDR File Parsing Integer Overflow Remote Code Execution
Vulnerabi ...)
- - gegl <unfixed>
+ - gegl <unfixed> (bug #1145018)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-453/
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gegl/-/commit/d3d262008299341c5b032b354021632ceadb2799
CVE-2026-18299 (GStreamer rtpsbcdepay Use-After-Free Remote Code Execution
Vulnerabili ...)
@@ -1091,14 +1091,14 @@ CVE-2026-75628 (Punk::OAuth2 versions before 0.03 for
Perl allow an attacker-cho
CVE-2026-75616 (An OS command injection vulnerability exists in the web
management int ...)
NOT-FOR-US: TPLink
CVE-2026-75596 (Netty is an asynchronous, event-driven network application
framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145017)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4
NOTE: https://github.com/netty/netty/pull/17213
NOTE: Fixed by:
https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7
(netty-4.2.17.Final)
NOTE: https://github.com/netty/netty/pull/17217
NOTE: Fixed by:
https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961
(netty-4.1.137.Final)
CVE-2026-75595 (Netty is an asynchronous, event-driven network application
framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145017)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4
NOTE: https://github.com/netty/netty/pull/17213
NOTE: Fixed by:
https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7
(netty-4.2.17.Final)
@@ -1143,7 +1143,7 @@ CVE-2026-68559 (Wekan is open source kanban built with
Meteor. From 9.57 until 9
CVE-2026-68558 (Wekan is open source kanban built with Meteor. From 8.36 until
9.74, t ...)
- wekan <itp> (bug #819238)
CVE-2026-68555 (Coturn is a free open source implementation of TURN and STUN
Server. I ...)
- - coturn <unfixed>
+ - coturn <unfixed> (bug #1145022)
NOTE:
https://github.com/coturn/coturn/security/advisories/GHSA-hpq3-g7x4-h7xx
NOTE: Fixed by:
https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7
(4.16.0)
CVE-2026-68554 (Coturn is a free open source implementation of TURN and STUN
Server. P ...)
@@ -5000,7 +5000,7 @@ CVE-2026-69189 (Hoppscotch is an open source API
development ecosystem. Prior to
CVE-2026-69160 (OpenList a file list program that supports multiple storage.
Prior to ...)
NOT-FOR-US: OpenList
CVE-2026-68939 (Pyenv provides simple Python version management. Prior to
2.8.0, is_ve ...)
- - pyenv <unfixed>
+ - pyenv <unfixed> (bug #1145023)
[trixie] - pyenv <no-dsa> (Minor issue)
NOTE:
https://github.com/pyenv/pyenv/security/advisories/GHSA-g478-f579-9vp9
NOTE: Fixed by:
https://github.com/pyenv/pyenv/commit/95df7dbc7b34595b47c9b922de198547effda819
(v2.8.0)
@@ -5153,7 +5153,7 @@ CVE-2026-61407 (Dell Watchdog Timer Driver versions prior
to 2.0.0.1 contain an
CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in
Kriptok Cr ...)
TODO: check
CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to
1.11.1, JN ...)
- - lz4-java <unfixed>
+ - lz4-java <unfixed> (bug #1145019)
NOTE:
https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
NOTE: Fixed by:
https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da
(v1.11.1)
CVE-2026-59940 (Seroval facilitates JS value stringification, including
complex struct ...)
@@ -6021,12 +6021,12 @@ CVE-2026-59910 (Dell ObjectScale, versions prior to
4.3.0.1, contain(s) an Impro
CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path
Travers ...)
NOT-FOR-US: Dell / EMC
CVE-2026-59903 (Netty is an asynchronous, event-driven network application
framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145017)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46
NOTE: https://github.com/netty/netty/pull/17213 (4.2-branch)
NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
CVE-2026-59902 (Netty is an asynchronous, event-driven network application
framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145017)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f
NOTE: https://github.com/netty/netty/pull/17213 (4.2-branch)
NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
@@ -20133,7 +20133,7 @@ CVE-2026-62996 (Smarty is a template engine for PHP,
facilitating the separation
NOTE: https://github.com/smarty-php/smarty/pull/1195
NOTE: Fixed by:
https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e
(v5.8.4)
CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the
separation of pr ...)
- - smarty4 <unfixed>
+ - smarty4 <unfixed> (bug #1145020)
[trixie] - smarty4 <no-dsa> (Minor issue)
- smarty3 <unfixed>
[trixie] - smarty3 <no-dsa> (Minor issue)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05740c724542f2781b0fb4989a148a590342becf
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05740c724542f2781b0fb4989a148a590342becf
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits