Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6be42162 by Moritz Muehlenhoff at 2026-08-21T20:18:30+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -221,6 +221,7 @@ CVE-2026-72852 (hank-ai/darknet sizes a convolutional
layer's weight and output
NOT-FOR-US: hank-ai/darknet
CVE-2026-72847 (broot renders each file and directory name in its interactive
tree vie ...)
- rust-broot <unfixed> (bug #1145024)
+ [trixie] - rust-broot <no-dsa> (Minor issue)
NOTE: https://github.com/Canop/broot/issues/1188
NOTE: Fixed by:
https://github.com/Canop/broot/commit/4ba40f7d47af78457c7656f15eba71d63d97fce5
NOTE: Fixed by:
https://github.com/Canop/broot/commit/0717a94b3c0efa19c7bbcfe0fb49a2374752a168
@@ -514,8 +515,12 @@ CVE-2026-18482 (Neo.mjs contains a command injection
vulnerability within the Fi
TODO: check
CVE-2026-18309 (GIMP APNG File Parsing Integer Overflow Remote Code Execution
Vulnerab ...)
- gimp <unfixed>
+ [trixie] - gimp <not-affected> (Vulnerable code not present)
+ [bookworm] - gimp <not-affected> (Vulnerable code not present)
+ [bullseye] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-462/
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/c760c8309d18bdf5259f1e04ced0779462c7c636
+ NOTE: Introduced by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/bb9c43102fd3013ada9c99990c31171c5b99f104
(GIMP_3_1_2)
CVE-2026-18308 (GIMP TIF File Parsing Integer Overflow Remote Code Execution
Vulnerabi ...)
- gimp <unfixed>
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-461/
@@ -698,6 +703,7 @@ CVE-2026-XXXX [OSSN-0103]
NOTE: https://bugs.launchpad.net/manila/+bug/2161287
CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
- openssl <unfixed>
+ [trixie] - openssl <postponed> (Minor issue, fix along with future
update)
NOTE:
https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a
(openssl-4.0)
NOTE:
https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b
(openssl-3.6)
NOTE:
https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34
(openssl-3.5)
@@ -5111,6 +5117,7 @@ CVE-2026-63639 (Valkey is a distributed key-value
database. Prior to 7.2.14, 8.0
TODO: check redis and redict
CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for
machine le ...)
- onnx <unfixed>
+ [trixie] - onnx <no-dsa> (Minor issue)
NOTE:
https://github.com/onnx/onnx/security/advisories/GHSA-p893-rvq9-2xf9
NOTE: https://github.com/onnx/onnx/pull/7880
NOTE: Fixed by:
https://github.com/onnx/onnx/commit/e9c74f596eaa0250f89e52a54160a25bbcb25b66
(v1.22.0)
@@ -23475,9 +23482,13 @@ CVE-2026-46712 (Misskey is an open source, federated
social media platform. Vers
NOT-FOR-US: Misskey
CVE-2026-42169 (A heap-buffer-overflow vulnerability exists in the APNG
(Animated PNG) ...)
- gimp 3.2.4-1
+ [trixie] - gimp <not-affected> (Vulnerable code not present)
+ [bookworm] - gimp <not-affected> (Vulnerable code not present)
+ [bullseye] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16158
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2743
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/691785113a1b5dc8cd42818fbd7bf29e8d6ed814
(GIMP_3_2_4)
+ NOTE: Introduced by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/bb9c43102fd3013ada9c99990c31171c5b99f104
(GIMP_3_1_2)
CVE-2026-41447 (FirmaCheck for Windows before 1.3.16 contains a DLL hijacking
vulnerab ...)
NOT-FOR-US: FirmaCheck for Windows
CVE-2026-18739 (A flaw was found in popt, a command-line option parsing
library. An of ...)
@@ -23857,8 +23868,12 @@ CVE-2026-6695 (A flaw was found in GIMP. A remote
attacker could exploit this by
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/55256210f85b79b2ef72ea2bc6c84b52cb5ff335
(GIMP_3_2_4)
CVE-2026-6694 (A flaw was found in GIMP's file-png plugin. A remote attacker
can expl ...)
- gimp 3.2.4-1
+ [trixie] - gimp <not-affected> (Vulnerable code not present)
+ [bookworm] - gimp <not-affected> (Vulnerable code not present)
+ [bullseye] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16150
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/bfec7079f0196fa1b3156e574f6778537cb4a5b6
(GIMP_3_2_4)
+ NOTE: Introduced by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/bb9c43102fd3013ada9c99990c31171c5b99f104
(GIMP_3_1_2)
CVE-2026-65875 (BaserCMS provided by baserCMS Users Community contains a CSV
file inje ...)
NOT-FOR-US: BaserCMS
CVE-2026-59652 (In Bouncy Castle for Java before 1.85, LDAP filter injection
in legacy ...)
@@ -48262,12 +48277,20 @@ CVE-2025-14785 (The Website Builder by SeedProd -
Theme Builder, Landing Page Bu
NOT-FOR-US: WordPress plugin
CVE-2026-58382
- gimp 3.2.4-1
+ [trixie] - gimp <not-affected> (Vulnerable code not present)
+ [bookworm] - gimp <not-affected> (Vulnerable code not present)
+ [bullseye] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16212
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/de76a6044f4b9d7cf126056dd3e408aad97d2552
(GIMP_3_2_4)
+ NOTE: Introduced by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/6395c37425cc2bf81300ffffadc9e3e75f6c0ecd
(GIMP_3_1_2)
CVE-2026-58383
- gimp 3.2.4-1
+ [trixie] - gimp <not-affected> (Vulnerable code not present)
+ [bookworm] - gimp <not-affected> (Vulnerable code not present)
+ [bullseye] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16213
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/fb63e036f89382ce739da1d0cd8aaaf47e3cbb4e
(GIMP_3_2_4)
+ NOTE: Introduced by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/6395c37425cc2bf81300ffffadc9e3e75f6c0ecd
(GIMP_3_1_2)
CVE-2026-58385
- gimp 3.2.4-1
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16221
=====================================
data/dsa-needed.txt
=====================================
@@ -46,7 +46,7 @@ freecad
--
gegl (jmm)
--
-gimp
+gimp (jmm)
--
gst-plugins-bad1.0 (jmm)
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6be421628345dea0bcf7ed64ece3b8f26436c122
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6be421628345dea0bcf7ed64ece3b8f26436c122
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits