Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8e031ce7 by Salvatore Bonaccorso at 2026-08-23T21:25:34+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1446,7 +1446,7 @@ CVE-2026-57835
 CVE-2026-56875
        REJECTED
 CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and 
earlier, Caps ...)
-       - capstone <unfixed>
+       - capstone <unfixed> (bug #1145195)
        [trixie] - capstone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/capstone-engine/capstone/security/advisories/GHSA-gf2c-xwcp-hvf4
        NOTE: https://github.com/capstone-engine/capstone/pull/2968
@@ -1454,7 +1454,7 @@ CVE-2026-55894 (Capstone is a disassembly framework. In 
6.0.0-Alpha9 and earlier
        NOTE: https://github.com/capstone-engine/capstone/pull/2969
        NOTE: Fixed by: 
https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed
 (v5 branch)
 CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and 
earlier, Caps ...)
-       - capstone <unfixed>
+       - capstone <unfixed> (bug #1145195)
        [trixie] - capstone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh
        NOTE: https://github.com/capstone-engine/capstone/pull/2968
@@ -1527,7 +1527,7 @@ CVE-2026-49244 (SFTPGo is an open source, event-driven 
file transfer solution. F
 CVE-2026-49217 (Mailu is a mail server as a set of Docker images. Prior to 
version 202 ...)
        NOT-FOR-US: Mailu
 CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function 
builds the ex ...)
-       - onnx <unfixed>
+       - onnx <unfixed> (bug #1145196)
        [trixie] - onnx <no-dsa> (Minor issue)
        NOTE: 
https://github.com/onnx/onnx/security/advisories/GHSA-q56x-g2fj-4rj6
 CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder 
(XmlBuilder module ...)
@@ -1813,7 +1813,7 @@ CVE-2026-74580 (In the Linux kernel, the following 
vulnerability has been resolv
        - linux 7.1.9-1
        NOTE: 
https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
 CVE-2026-19685
-       - network-manager <unfixed>
+       - network-manager <unfixed> (bug #1145199)
        [trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not 
applied)
        NOTE: 
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513
        NOTE: Introduced with: 
https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf
 (1.57.1-dev)
@@ -7002,7 +7002,7 @@ CVE-2026-63639 (Valkey is a distributed key-value 
database. Prior to 7.2.14, 8.0
        NOTE: Fixed by: 
https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778
 (8.0.10)
        TODO: check redis and redict
 CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for 
machine le ...)
-       - onnx <unfixed>
+       - onnx <unfixed> (bug #1145196)
        [trixie] - onnx <no-dsa> (Minor issue)
        NOTE: 
https://github.com/onnx/onnx/security/advisories/GHSA-p893-rvq9-2xf9
        NOTE: https://github.com/onnx/onnx/pull/7880
@@ -7209,7 +7209,7 @@ CVE-2026-45115 (MyBB is free and open source forum 
software. Prior to 1.8.40, th
 CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until 
3.21.67, 3.22.6 ...)
        NOT-FOR-US: Saleor
 CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in 
ninenines cow ...)
-       - erlang-cowlib <unfixed>
+       - erlang-cowlib <unfixed> (bug #1145197)
        [trixie] - erlang-cowlib <not-affected> (Vulnerable code not present)
        [bookworm] - erlang-cowlib <not-affected> (Vulnerable code not present)
        [bullseye] - erlang-cowlib <not-affected> (Vulnerable code not present)
@@ -7338,7 +7338,7 @@ CVE-2026-18534 (ArcSearch for iOS versions prior to 
1.48.0 could keep the addres
 CVE-2026-18392
        REJECTED
 CVE-2026-17106 (The tar extraction routines in moby/go-archive (Unpack, 
UnpackLayer, U ...)
-       - golang-github-moby-go-archive <unfixed>
+       - golang-github-moby-go-archive <unfixed> (bug #1145200)
        NOTE: 
https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h
 CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 
3454 tables ...)
        - python3.15 <unfixed>
@@ -14708,7 +14708,7 @@ CVE-2026-19744 (Cross-site Scripting in the Markdown 
renderer in maalfer Pentest
 CVE-2026-19734 (Missing Authorization and Authorization Bypass Through 
User-Controlled ...)
        NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19730 (The 'podman quadlet install --replace' command opens the 
existing dest ...)
-       - podman <unfixed>
+       - podman <unfixed> (bug #1145198)
        [trixie] - podman <not-affected> (Vulnerable code not present)
        [bookworm] - podman <not-affected> (Vulnerable code not present)
        [bullseye] - podman <not-affected> (Vulnerable code not present)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e031ce7683fb39cfd31a4a8ff2b270dc6184649

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e031ce7683fb39cfd31a4a8ff2b270dc6184649
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to