Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6be42162 by Moritz Muehlenhoff at 2026-08-21T20:18:30+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -221,6 +221,7 @@ CVE-2026-72852 (hank-ai/darknet sizes a convolutional 
layer's weight and output
        NOT-FOR-US: hank-ai/darknet
 CVE-2026-72847 (broot renders each file and directory name in its interactive 
tree vie ...)
        - rust-broot <unfixed> (bug #1145024)
+       [trixie] - rust-broot <no-dsa> (Minor issue)
        NOTE: https://github.com/Canop/broot/issues/1188
        NOTE: Fixed by: 
https://github.com/Canop/broot/commit/4ba40f7d47af78457c7656f15eba71d63d97fce5
        NOTE: Fixed by: 
https://github.com/Canop/broot/commit/0717a94b3c0efa19c7bbcfe0fb49a2374752a168
@@ -514,8 +515,12 @@ CVE-2026-18482 (Neo.mjs contains a command injection 
vulnerability within the Fi
        TODO: check
 CVE-2026-18309 (GIMP APNG File Parsing Integer Overflow Remote Code Execution 
Vulnerab ...)
        - gimp <unfixed>
+       [trixie] - gimp <not-affected> (Vulnerable code not present)
+       [bookworm] - gimp <not-affected> (Vulnerable code not present)
+       [bullseye] - gimp <not-affected> (Vulnerable code not present)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-462/
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/c760c8309d18bdf5259f1e04ced0779462c7c636
+       NOTE: Introduced by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/bb9c43102fd3013ada9c99990c31171c5b99f104
 (GIMP_3_1_2)
 CVE-2026-18308 (GIMP TIF File Parsing Integer Overflow Remote Code Execution 
Vulnerabi ...)
        - gimp <unfixed>
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-461/
@@ -698,6 +703,7 @@ CVE-2026-XXXX [OSSN-0103]
        NOTE: https://bugs.launchpad.net/manila/+bug/2161287
 CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
        - openssl <unfixed>
+       [trixie] - openssl <postponed> (Minor issue, fix along with future 
update)
        NOTE: 
https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a
 (openssl-4.0)
        NOTE: 
https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b
 (openssl-3.6)
        NOTE: 
https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34
 (openssl-3.5)
@@ -5111,6 +5117,7 @@ CVE-2026-63639 (Valkey is a distributed key-value 
database. Prior to 7.2.14, 8.0
        TODO: check redis and redict
 CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for 
machine le ...)
        - onnx <unfixed>
+       [trixie] - onnx <no-dsa> (Minor issue)
        NOTE: 
https://github.com/onnx/onnx/security/advisories/GHSA-p893-rvq9-2xf9
        NOTE: https://github.com/onnx/onnx/pull/7880
        NOTE: Fixed by: 
https://github.com/onnx/onnx/commit/e9c74f596eaa0250f89e52a54160a25bbcb25b66 
(v1.22.0)
@@ -23475,9 +23482,13 @@ CVE-2026-46712 (Misskey is an open source, federated 
social media platform. Vers
        NOT-FOR-US: Misskey
 CVE-2026-42169 (A heap-buffer-overflow vulnerability exists in the APNG 
(Animated PNG) ...)
        - gimp 3.2.4-1
+       [trixie] - gimp <not-affected> (Vulnerable code not present)
+       [bookworm] - gimp <not-affected> (Vulnerable code not present)
+       [bullseye] - gimp <not-affected> (Vulnerable code not present)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16158
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2743
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/691785113a1b5dc8cd42818fbd7bf29e8d6ed814
 (GIMP_3_2_4)
+       NOTE: Introduced by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/bb9c43102fd3013ada9c99990c31171c5b99f104
 (GIMP_3_1_2)
 CVE-2026-41447 (FirmaCheck for Windows before 1.3.16 contains a DLL hijacking 
vulnerab ...)
        NOT-FOR-US: FirmaCheck for Windows
 CVE-2026-18739 (A flaw was found in popt, a command-line option parsing 
library. An of ...)
@@ -23857,8 +23868,12 @@ CVE-2026-6695 (A flaw was found in GIMP. A remote 
attacker could exploit this by
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/55256210f85b79b2ef72ea2bc6c84b52cb5ff335
 (GIMP_3_2_4)
 CVE-2026-6694 (A flaw was found in GIMP's file-png plugin. A remote attacker 
can expl ...)
        - gimp 3.2.4-1
+       [trixie] - gimp <not-affected> (Vulnerable code not present)
+       [bookworm] - gimp <not-affected> (Vulnerable code not present)
+       [bullseye] - gimp <not-affected> (Vulnerable code not present)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16150
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/bfec7079f0196fa1b3156e574f6778537cb4a5b6
 (GIMP_3_2_4)
+       NOTE: Introduced by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/bb9c43102fd3013ada9c99990c31171c5b99f104
 (GIMP_3_1_2)
 CVE-2026-65875 (BaserCMS provided by baserCMS Users Community contains a CSV 
file inje ...)
        NOT-FOR-US: BaserCMS
 CVE-2026-59652 (In Bouncy Castle for Java before 1.85, LDAP filter injection 
in legacy ...)
@@ -48262,12 +48277,20 @@ CVE-2025-14785 (The Website Builder by SeedProd - 
Theme Builder, Landing Page Bu
        NOT-FOR-US: WordPress plugin
 CVE-2026-58382
        - gimp 3.2.4-1
+       [trixie] - gimp <not-affected> (Vulnerable code not present)
+       [bookworm] - gimp <not-affected> (Vulnerable code not present)
+       [bullseye] - gimp <not-affected> (Vulnerable code not present)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16212
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/de76a6044f4b9d7cf126056dd3e408aad97d2552
 (GIMP_3_2_4)
+       NOTE: Introduced by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/6395c37425cc2bf81300ffffadc9e3e75f6c0ecd
 (GIMP_3_1_2)
 CVE-2026-58383
        - gimp 3.2.4-1
+       [trixie] - gimp <not-affected> (Vulnerable code not present)
+       [bookworm] - gimp <not-affected> (Vulnerable code not present)
+       [bullseye] - gimp <not-affected> (Vulnerable code not present)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16213
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/fb63e036f89382ce739da1d0cd8aaaf47e3cbb4e
 (GIMP_3_2_4)
+       NOTE: Introduced by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/6395c37425cc2bf81300ffffadc9e3e75f6c0ecd
 (GIMP_3_1_2)
 CVE-2026-58385
        - gimp 3.2.4-1
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16221


=====================================
data/dsa-needed.txt
=====================================
@@ -46,7 +46,7 @@ freecad
 --
 gegl (jmm)
 --
-gimp
+gimp (jmm)
 --
 gst-plugins-bad1.0 (jmm)
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6be421628345dea0bcf7ed64ece3b8f26436c122

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6be421628345dea0bcf7ed64ece3b8f26436c122
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to