Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
626d476a by Salvatore Bonaccorso at 2026-08-22T08:49:20+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -391,7 +391,8 @@ CVE-2026-53991
CVE-2026-53974
REJECTED
CVE-2026-53804 (OTRS Community Edition contains an authenticated OS command
injection ...)
- TODO: check
+ NOT-FOR-US: OTRS
+ NOTE: Could possibly affect Znuny, we'll let their security team figure
it out
CVE-2026-53762 (VeraCrypt provides disk encryption with strong security based
on TrueC ...)
NOT-FOR-US: VeraCrypt
CVE-2026-52021 (An issue in code100xDevs 100xdevs CMS v.1.0 (2026-04-30)
allows a remo ...)
@@ -440,11 +441,11 @@ CVE-2026-43798 (A single crafted SSH message gives an
unauthenticated network at
CVE-2026-43679 (This issue was addressed with improved permissions checking.
This issu ...)
NOT-FOR-US: Apple
CVE-2026-41451 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0
contain a ...)
- TODO: check
+ NOT-FOR-US: UAC (Unix-like Artifacts Collector)
CVE-2026-41450 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0
contain a ...)
- TODO: check
+ NOT-FOR-US: UAC (Unix-like Artifacts Collector)
CVE-2026-41449 (UAC (Unix-like Artifacts Collector) versions prior to 3.3.0
contain a ...)
- TODO: check
+ NOT-FOR-US: UAC (Unix-like Artifacts Collector)
CVE-2026-39909 (llama.cpp before b8585 contains a use-after-free vulnerability
in the ...)
TODO: check
CVE-2026-35163 (OctoPrint provides a web interface for controlling consumer 3D
printer ...)
@@ -452,7 +453,7 @@ CVE-2026-35163 (OctoPrint provides a web interface for
controlling consumer 3D p
CVE-2026-27875 (Cleartext Storage of Sensitive Information in Memory
vulnerability in ...)
NOT-FOR-US: Johnson Controls
CVE-2026-22681 (OpenViking before 0.3.4contains a server-side request forgery
vulnerab ...)
- TODO: check
+ NOT-FOR-US: OpenViking
CVE-2026-20679 (The issue was addressed with improved checks. This issue is
fixed in m ...)
NOT-FOR-US: Apple
CVE-2026-19848 (The ProfilePress WordPress plugin before 4.17.1 does not strip
shortco ...)
@@ -460,7 +461,7 @@ CVE-2026-19848 (The ProfilePress WordPress plugin before
4.17.1 does not strip s
CVE-2026-19783 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
local atta ...)
NOT-FOR-US: IBM
CVE-2026-19755 (NoSleep 1.5.1 exposes a privileged XPC Mach service and
accepts raw di ...)
- TODO: check
+ NOT-FOR-US: NoSleep
CVE-2026-19449 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a
vulnerability in c ...)
NOT-FOR-US: IBM
CVE-2026-19448 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 A stack memory
corruptio ...)
@@ -470,7 +471,7 @@ CVE-2026-19446 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS
4.1 allows a remote un
CVE-2026-19442 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 has a pointer
validation ...)
NOT-FOR-US: IBM
CVE-2026-19441 (Missing authentication for critical function vulnerability in
IKAS Tec ...)
- TODO: check
+ NOT-FOR-US: Rush
CVE-2026-19437 (IBM AIX 7.2, and 7.3 and IBM PowerVM VIOS 4.1 could allow a
remote att ...)
NOT-FOR-US: IBM
CVE-2026-19435 (The Duplicate Post WordPress plugin before 1.5.6 does not
check the us ...)
@@ -628,11 +629,11 @@ CVE-2026-16576 (The Dokan: AI Powered WooCommerce
Multivendor Marketplace Soluti
CVE-2026-16575 (The Dokan: AI Powered WooCommerce Multivendor Marketplace
Solution Wo ...)
NOT-FOR-US: WordPress plugin
CVE-2026-16520 (Improper input validation and Exposure of sensitive
information throug ...)
- TODO: check
+ NOT-FOR-US: Genians
CVE-2026-16323 (Execution after redirect (EAR) vulnerability in FuyaWeb
Internet and I ...)
- TODO: check
+ NOT-FOR-US: ArchitectPanel Web Admin Panel
CVE-2026-15580 (vault token disclosure via unvalidated postMessage
vulnerability in N- ...)
- TODO: check
+ NOT-FOR-US: PassPortal browser extension
CVE-2026-15576 (Improper authentication in the agent receiver of Checkmk
<2.5.0p10 all ...)
- check-mk <removed>
CVE-2026-15150 (The myCred WordPress plugin before 3.2.5 does not verify that
the rece ...)
@@ -644,7 +645,7 @@ CVE-2026-14601 (The Link Whisper Free WordPress plugin
before 0.9.7 does not pro
CVE-2026-14325 (The Drag and Drop Multiple File Upload for Contact Form 7
WordPress pl ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14208 (Remote Utilities Host <=7.7.3.0 sets insecure ACLs on all DLL
files in ...)
- TODO: check
+ NOT-FOR-US: Remote Utilities Host
CVE-2026-13736 (The NewPath WildApricotPress Add-on WordPress plugin through
1.0.0 do ...)
NOT-FOR-US: WordPress plugin
CVE-2026-13176 (The Eventin WordPress plugin before 4.1.21 does not validate a
user-su ...)
@@ -658,7 +659,7 @@ CVE-2026-11830
CVE-2026-11427
REJECTED
CVE-2025-52182 (The Library Corporation LS2 Admin v5.7 to v5.8.0 was
discovered to con ...)
- TODO: check
+ NOT-FOR-US: Library Corporation LS2 Admin
CVE-2025-3127
REJECTED
CVE-2025-2795
@@ -1170,9 +1171,9 @@ CVE-2026-53993
CVE-2026-53569 (Frappe is a full-stack web application framework. In version
16.31.0 a ...)
NOT-FOR-US: Frappe
CVE-2026-53425 (Insufficient Verification of Data Authenticity vulnerability
in dropbo ...)
- TODO: check
+ NOT-FOR-US: dropbox samly
CVE-2026-53424 (Authentication Bypass by Capture-replay vulnerability in
dropbox samly ...)
- TODO: check
+ NOT-FOR-US: dropbox samly
CVE-2026-49996 (SecureDrop Client is a desktop app for journalists to securely
communi ...)
NOT-FOR-US: SecureDrop Client
CVE-2026-49825 (lxml is a library for processing XML and HTML in the Python
language. ...)
@@ -1193,11 +1194,11 @@ CVE-2026-46534
CVE-2026-46533
REJECTED
CVE-2026-44725 (EMQX is a scalable and reliable MQTT broker for AI, IoT, IIoT,
and con ...)
- TODO: check
+ NOT-FOR-US: EMQX
CVE-2026-43678 (An unauthenticated remote peer can crash any
NIOWebSocket-based server ...)
NOT-FOR-US: Apple
CVE-2026-40345 (deepmerge-ts is a typescript library providing functionality
to deep m ...)
- TODO: check
+ NOT-FOR-US: deepmerge-ts
CVE-2026-2334 (An issue was discovered in vsDesk v14.0101. An authenticated
attacker ...)
NOT-FOR-US: vsDesk
CVE-2026-28164 (Cross-Site Request Forgery (CSRF) vulnerability in HashThemes
Easy Ele ...)
@@ -1220,7 +1221,7 @@ CVE-2026-18917 (A flaw was found in libvirt. An
unprivileged local user could ex
NOTE: Introduced with:
https://gitlab.com/libvirt/libvirt/-/commit/34f2d0319d2098c77c8cc27d8350616029125a2b
(v1.2.6-rc1)
NOTE: Fixed by:
https://gitlab.com/libvirt/libvirt/-/commit/5a62cbf2907d4590283597b46da9c0f41e7b4d4f
CVE-2026-18482 (Neo.mjs contains a command injection vulnerability within the
FileSyst ...)
- TODO: check
+ NOT-FOR-US: Neo.mjs
CVE-2026-18309 (GIMP APNG File Parsing Integer Overflow Remote Code Execution
Vulnerab ...)
- gimp <unfixed>
[trixie] - gimp <not-affected> (Vulnerable code not present)
@@ -1329,7 +1330,7 @@ CVE-2026-18267 (Kenwood DNR1007XR Firmware Update Link
Following Code Execution
CVE-2026-18265 (OSNEXUS QuantaStor Missing Authentication Remote Code
Execution Vulner ...)
NOT-FOR-US: PXNEXUS
CVE-2026-18264 (NoMachine getstat Command Injection Remote Code Execution
Vulnerabilit ...)
- TODO: check
+ NOT-FOR-US: NoMachine
CVE-2026-18263 (Parallels RAS Client RDP Backend Service Exposed Dangerous
Function Lo ...)
NOT-FOR-US: Parallels
CVE-2026-18262 (Parallels RAS Client RDP Backend Service Exposed Dangerous
Function Lo ...)
@@ -1356,11 +1357,11 @@ CVE-2026-15743 (Catalyst::Plugin::Static::Simple
versions through 0.38 for Perl
NOTE:
https://github.com/perl-catalyst/Catalyst-Plugin-Static-Simple/pull/3
NOTE:
https://security.metacpan.org/patches/C/Catalyst-Plugin-Static-Simple/0.38/CVE-2026-15743-r1.patch
CVE-2026-15706 (Missing authentication for critical function vulnerability in
Baylan M ...)
- TODO: check
+ NOT-FOR-US: Baylan Smart Meter Management Application (BMS)
CVE-2026-15686 (Adminer multi_query Incorrect Check of Function Return Value
Remote Co ...)
TODO: check
CVE-2026-15679 (Hugging Face PyTorch Image Models checkpoint Deserialization
of Untrus ...)
- TODO: check
+ NOT-FOR-US: Hugging Face PyTorch Image Models
CVE-2026-14953 (A low-privileged remote attacker can enumerate all configured
users an ...)
NOT-FOR-US: Frauscher Sensortechnik
CVE-2026-14952 (An unauthenticated remote attacker can retrieve sensible files
from th ...)
@@ -2761,7 +2762,7 @@ CVE-2026-17494 (IBM Power Systems Firmware FW1120.00, and
FW1110.00 through FW11
CVE-2026-17429 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
NOT-FOR-US: IBM
CVE-2026-17183 (An authenticated user with permission to create or edit alert
rules ca ...)
- TODO: check
+ NOT-FOR-US: Grafana
CVE-2026-17100 (Power Systems FirmwareFW1120.00, FW1110.00 through FW1110.30,
FW1060.0 ...)
NOT-FOR-US: IBM
CVE-2026-17093 (IBM Power Systems Firmware FW1120.00, FW1110.00 through
FW1110.30, FW1 ...)
@@ -4863,7 +4864,7 @@ CVE-2026-47720 (FUXA is a web-based Process Visualization
(SCADA/HMI/Dashboard)
CVE-2026-47719 (FUXA is a web-based Process Visualization
(SCADA/HMI/Dashboard) softwa ...)
NOT-FOR-US: FUXA
CVE-2026-47699 (Confidential Containers Guest Components provides guest tools
and comp ...)
- TODO: check
+ NOT-FOR-US: Confidential Containers Guest Components
CVE-2026-41921 (Koha before 26.05.02, 25.11.07, and 25.05.13 contains a stored
cross-s ...)
- koha <itp> (bug #702134)
CVE-2026-27365 (Improper Neutralization of Input During Web Page Generation
('Cross-si ...)
@@ -4907,7 +4908,7 @@ CVE-2026-18777 (The TrueBooker WordPress plugin before
1.2.7 does not have prop
CVE-2026-18776 (The TrueBooker WordPress plugin before 1.2.7 does not have
proper aut ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18504 (fastify is a fast and low overhead web framework for Node.js.
Versions ...)
- TODO: check
+ NOT-FOR-US: fastify
CVE-2026-18466 (The WP Maps WordPress plugin before 4.9.8 does not perform a
capabili ...)
NOT-FOR-US: WordPress plugin
CVE-2026-18231 (The WP Directory Kit WordPress plugin before 1.5.7 does not
perform an ...)
@@ -6082,7 +6083,7 @@ CVE-2026-32444 (Contributor Remote Code Execution (RCE)
in Cwicly <= 1.4.4 versi
CVE-2026-32333 (Unauthenticated Cross Site Scripting (XSS) in Mayosis Core <=
5.4.7 ve ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-30250 (Cross-site scripting vulnerability in the user documentation
field in ...)
- TODO: check
+ NOT-FOR-US: Beta Systems Software AG ANOW! Automate
CVE-2026-28571 (Unauthenticated Broken Access Control in FormyChat <= 2.15.7
versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28570 (Unauthenticated Local File Inclusion in Vavo Core <= 2.3.0
versions.)
@@ -6151,7 +6152,7 @@ CVE-2026-1199 (Zabbix API and Frontend login lockout
mechanism has a flaw where
[bookworm] - zabbix <ignored> (The WEB UI is only supported for access
by trusted users, no security updates issued for it, #1124558)
NOTE: https://support.zabbix.com/browse/ZBX-28076
CVE-2026-19869 (@neo4j/graphqlfrom5.2.0until the patched versions fails to
enforce fie ...)
- TODO: check
+ NOT-FOR-US: neo4j/graphql
CVE-2026-19608 (A flaw was found in the group policy provider of Keycloak
authorizatio ...)
NOT-FOR-US: Red Hat build of Keycloak
CVE-2026-19501 (CSV export functionality in Brainstorm Force SureForms
version, <= 2.1 ...)
@@ -6163,7 +6164,7 @@ CVE-2026-19447 (Improper neutralization of input during
web page generation ('cr
CVE-2026-18963 (A flaw was found in the reset-credentials flow of the
keycloak-service ...)
NOT-FOR-US: Red Hat build of Keycloak
CVE-2026-18929 (Carbone is vulnerable to Denial of Service due to lack of
protection a ...)
- TODO: check
+ NOT-FOR-US: Carbone
CVE-2026-18751 (External control of file name or path vulnerability in Citrix
WorkSpac ...)
NOT-FOR-US: Citrix
CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the
address bar ...)
@@ -6189,7 +6190,7 @@ CVE-2026-17084 (The "stringprep" module didn't process
characters from RFC 3454
NOTE: Fixed by:
https://github.com/python/cpython/commit/7e109d084d55e7eb25837a5f3b47ef9beee547bc
(main)
NOTE: Fixed by:
https://github.com/python/cpython/commit/5181304bcec9cfc3c15311741c9154cdff2e3fd7
(3.15 branch)
CVE-2026-16309 (Authorization bypass through User-Controlled key vulnerability
in Neti ...)
- TODO: check
+ NOT-FOR-US: EdoWEB
CVE-2026-15806 (The HTTPPasswordMgr class in the urllib.request module, along
with its ...)
- python3.15 <unfixed>
- python3.14 <unfixed>
@@ -6209,7 +6210,7 @@ CVE-2026-15806 (The HTTPPasswordMgr class in the
urllib.request module, along wi
NOTE: Fixed by:
https://github.com/python/cpython/commit/a0d023fbd23773e24b35d8368789470e22cda5d8
(3.14 branch)
NOTE: Fixed by:
https://github.com/python/cpython/commit/a2773a34183b7d94a243bb98fd658926cc5348ce
(3.13 branch)
CVE-2026-15585 (Improper Limitation of a Pathname to a Restricted Directory
('Path Tra ...)
- TODO: check
+ NOT-FOR-US: AKINSOFT
CVE-2026-12564 (A flaw was found in the AAP Controller's HashiCorp Vault
credential pl ...)
NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2025-9211 (Unescaped stored values in application security page in Otalio
Ship Pr ...)
@@ -6505,7 +6506,7 @@ CVE-2026-39255 (Buffer Overflow vulnerability in
SteelSeries GG (macOS) v.107.0.
CVE-2026-39254 (Buffer Overflow vulnerability in SteelSeries GG (macOS)
v.107.0.0 allo ...)
NOT-FOR-US: SteelSeries GG
CVE-2026-38165 (A Server-Side Template Injection (SSTI) vulnerability in the
Velocity ...)
- TODO: check
+ NOT-FOR-US: xdocreport
CVE-2026-35219 (Budibase is an open-source low-code platform. Prior to 3.41.3,
automat ...)
NOT-FOR-US: n8n
CVE-2026-34789 (FreeCAD is a free and open-source multiplatform 3D parametric
modeler. ...)
@@ -6534,7 +6535,7 @@ CVE-2026-28984 (The issue was addressed with improved
memory handling. This issu
CVE-2026-19650 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-19589 (Packer up to 1.15.4 is vulnerable to an issue in the
third-party plugi ...)
- TODO: check
+ NOT-FOR-US: Packer
CVE-2026-19478 (GitLab has remediated an issue in GitLab CE/EE affecting all
versions ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-15748 (The Forminator Forms plugin for WordPress is vulnerable to
Arbitrary F ...)
@@ -6896,7 +6897,7 @@ CVE-2026-15754 (Mattermost versions 11.7.x <= 11.7.6,
11.8.x <= 11.8.3 The acces
CVE-2026-15218 (A flaw was found in the maas-api and maas-controller
ServiceAccounts w ...)
NOT-FOR-US: maas-api and maas-controller ServiceAccounts within Red Hat
OpenShift AI
CVE-2026-14564 (Insufficiently Protected Credentials vulnerability in Innotim
Software ...)
- TODO: check
+ NOT-FOR-US: Logsign SIEM
CVE-2026-13202 (A vulnerability in OpenText Opentext Directory Services allows
Input D ...)
NOT-FOR-US: OpenText
CVE-2026-12630 (Zephyr's 6LoWPAN IP Header Compression (IPHC) uncompression
code conta ...)
@@ -14777,7 +14778,7 @@ CVE-2026-14479 (A maliciously crafted input, when
processed by the Autodesk Inst
CVE-2026-14478 (A maliciously created executable, when executed on the
victim's machin ...)
NOT-FOR-US: Autodesk
CVE-2026-11325 (Description Cloudflare was recently notified by external
researcher ...)
- TODO: check
+ NOT-FOR-US: Cloudflare wrangler-action
CVE-2025-59327 (In CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4,
bootxsa.efi ...)
NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
CVE-2025-59326 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails
to enforc ...)
@@ -14797,11 +14798,11 @@ CVE-2025-59320 (CPSD CryptoPro Secure Disk for
Bitlocker before v7.7.4 stores TP
CVE-2025-59319 (CPSD CryptoPro Secure Disk for Bitlocker before v7.7.4 fails
to certif ...)
NOT-FOR-US: CPSD CryptoPro Secure Disk for BitlockerUpTrain
CVE-2025-41771 (An authenticated attacker with low privileges can access an
endpoint i ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2025-41770 (An unauthenticated denial-of-service vulnerability in the
device's PLC ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2025-41769 (The device's PROFINET service is affected by a buffer overflow
vulnera ...)
- TODO: check
+ NOT-FOR-US: Phoenix Contact
CVE-2025-35988
REJECTED
CVE-2025-35977
@@ -17089,13 +17090,13 @@ CVE-2025-48506 (Uncontrolled search paths in
Vitis\u2122 Unified installation pa
CVE-2025-48505 (Weak permissions in the Vitis\u2122 Unified installation path
on local ...)
NOT-FOR-US: AMD
CVE-2025-35987 (Omission of security-relevant information for some Intel(R)
Software G ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2025-31356 (Insufficient verification of data authenticity for some
Intel(R) Trust ...)
- TODO: check
+ NOT-FOR-US: Intel
CVE-2025-31114 (Fooocus is an image generating software. In versions 2.5.5 and
prior, ...)
- TODO: check
+ NOT-FOR-US: Fooocus
CVE-2025-0046 (Incorrect directory permissions could allow a local user to
escalate t ...)
- TODO: check
+ NOT-FOR-US: AMD
CVE-2025-0041 (Uncontrolled search paths in the Vitis\u2122 Embedded Single
File Down ...)
NOT-FOR-US: AMD
CVE-2023-54374
@@ -18255,7 +18256,7 @@ CVE-2026-15059 (Local unprivileged users can terminate
arbitrary local processes
NOTE: Fixed by:
https://github.com/systemd/systemd/commit/cde88c4ea364e816619f385a870d074ebc12fe0f
(v261-rc3)
NOTE: Fixed by:
https://github.com/systemd/systemd/commit/a8feb2f23565d39df5c90a753c851c1934a53117
(v258.9)
CVE-2026-13206 (Improper neutralization of special elements used in an OS
command ('OS ...)
- TODO: check
+ NOT-FOR-US: WAH7601
CVE-2026-12984 (Insufficiently Protected Credentials vulnerability in Zyxel
Networks W ...)
NOT-FOR-US: Zyxel
CVE-2026-12624 (Vault\u2019s ACL policy engine did not consistently enforce a
wildcard ...)
@@ -18263,7 +18264,7 @@ CVE-2026-12624 (Vault\u2019s ACL policy engine did not
consistently enforce a wi
CVE-2026-12339 (A Zip Slip vulnerability in the WebUI ISP Upgrade
functionality allows ...)
NOT-FOR-US: TPLink
CVE-2026-10754 (Pega Platform versions 8.5.0 through 25.1.2 are affected by an
imprope ...)
- TODO: check
+ NOT-FOR-US: Pega Platform
CVE-2026-68870 (The Azure Key Vault secrets backend in Apache Airflow's
Microsoft Azur ...)
NOT-FOR-US: Apache Airflow provider
CVE-2026-68871 (The Yandex Lockbox secrets backend in Apache Airflow's Yandex
provider ...)
@@ -536611,11 +536612,11 @@ CVE-2021-43720
CVE-2021-43719
RESERVED
CVE-2021-43718 (An Authentication Bypass vulnerability exists in EPSON
EH-TW5350 EPSON ...)
- TODO: check
+ NOT-FOR-US: EPSON
CVE-2021-43717 (An issue exists in pson EH-TW5350 Epson iProjection.apk
v3.2.6. If you ...)
- TODO: check
+ NOT-FOR-US: EPSON
CVE-2021-43716 (Verification Bypass vulnerability exists in EPSON
150075647YWWV110 Eas ...)
- TODO: check
+ NOT-FOR-US: EPSON
CVE-2021-43715
RESERVED
CVE-2021-43714
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/626d476a18d1a2a7275d0f6707d984cc4de87df4
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/626d476a18d1a2a7275d0f6707d984cc4de87df4
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits