Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6c49e9b2 by Moritz Muehlenhoff at 2026-08-24T08:38:05+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -149,16 +149,19 @@ CVE-2026-68769
REJECTED
CVE-2026-68768 (hashcat contains a heap-based buffer overflow (out-of-bounds
write) in ...)
- hashcat <unfixed> (bug #1145171)
+ [trixie] - hashcat <no-dsa> (Minor issue)
NOTE: https://github.com/hashcat/hashcat/issues/4740
NOTE: https://github.com/hashcat/hashcat/pull/4754
NOTE: Fixed by:
https://github.com/hashcat/hashcat/commit/68f56a2d8712867a8520bf4dcf07f6145c23df89
CVE-2026-68767 (hashcat's fgetl() function in src/filehandling.c writes a null
termina ...)
- - hashcat <unfixed> (bug #1145171)
+ - hashcat <unfixed> (bug #1145171; unimportant)
NOTE: https://github.com/hashcat/hashcat/issues/4739
NOTE: https://github.com/hashcat/hashcat/pull/4750
NOTE: Fixed by:
https://github.com/hashcat/hashcat/commit/93b55d37d3b2340013d4036f10181ddc67d44249
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-68766 (hashcat fails to restrict command-line options when parsing
restore fi ...)
- hashcat <unfixed> (bug #1145171)
+ [trixie] - hashcat <no-dsa> (Minor issue)
NOTE: https://github.com/hashcat/hashcat/issues/4738
NOTE: Fixed by:
https://github.com/hashcat/hashcat/commit/fcae69f2438ff8eae0dc8e206b78067a1e465ed4
CVE-2026-66917 (Joomla Extension - joomgalleryfriends.net - Stored XSS in
JoomGallery ...)
@@ -1280,6 +1283,7 @@ CVE-2026-72843 (The customer update route in EverShop is
declared with "access":
NOT-FOR-US: EverShop
CVE-2026-72818 (The URLS regular expression in nltk/tokenize/casual.py,
compiled into ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/issues/3704
NOTE: Fixed by:
https://github.com/nltk/nltk/commit/7808692d451b962711005d954859bb83aabcf8fa
(v3.10.3-rc1)
CVE-2026-71862 (Checkmate is an open-source, self-hosted tool designed to
track and mo ...)
@@ -2033,6 +2037,7 @@ CVE-2026-73196 (A flaw was found in FreeIPA. A
low-privilege authenticated user
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2474712
CVE-2026-72854 (msgpack_unpacker_expand_buffer in src/unpack.c, reached
through the pu ...)
- msgpack-c <unfixed>
+ [trixie] - msgpack-c <postponed> (Minor issue, revisit when fixed
upstream)
NOTE: https://github.com/msgpack/msgpack-c/issues/1181
CVE-2026-72852 (hank-ai/darknet sizes a convolutional layer's weight and
output heap b ...)
NOT-FOR-US: hank-ai/darknet
@@ -2260,6 +2265,7 @@ CVE-2026-55586 (SumatraPDF is a multi-format reader for
Windows. In 3.6.1 and ea
NOT-FOR-US: SumatraPDF
CVE-2026-55558 (aiosmtplib is an asynchronous SMTP client for use with
asyncio. Prior ...)
- aiosmtplib 5.1.2-1
+ [trixie] - aiosmtplib <no-dsa> (Minor issue)
NOTE:
https://github.com/cole/aiosmtplib/security/advisories/GHSA-vxj7-4xrp-5vr4
NOTE: Fixed by:
https://github.com/cole/aiosmtplib/commit/9fab7ba1361dbf7622ede1315a24be805cff09c9
(v5.1.2)
CVE-2026-55095 (OpenProject is open-source, web-based project management
software. In ...)
@@ -2480,6 +2486,7 @@ CVE-2026-15706 (Missing authentication for critical
function vulnerability in Ba
NOT-FOR-US: Baylan Smart Meter Management Application (BMS)
CVE-2026-15686 (Adminer multi_query Incorrect Check of Function Return Value
Remote Co ...)
- adminer 5.4.3+dfsg-1
+ [trixie] - adminer <no-dsa> (Minor issue)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-478/
NOTE:
https://github.com/vrana/adminer/security/advisories/GHSA-3582-q6xq-5vf7
CVE-2026-15679 (Hugging Face PyTorch Image Models checkpoint Deserialization
of Untrus ...)
@@ -7094,6 +7101,7 @@ CVE-2026-54552 (sh provides Python process launching.
Prior to 2.2.4, the _uid o
NOTE: Fixed by:
https://github.com/amoffat/sh/commit/3d855daba91f87a089b490c0d1cf1df3faace2f1
(2.2.4)
CVE-2026-53533 (aiosmtplib is an asynchronous SMTP client for use with
asyncio. Prior ...)
- aiosmtplib 5.1.2-1
+ [trixie] - aiosmtplib <no-dsa> (Minor issue)
NOTE:
https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq
NOTE: Fixed by:
https://github.com/cole/aiosmtplib/commit/8eaf6efc9a8f59e2e09d3ef11246a058c46bd3ba
(v5.1.1)
CVE-2026-52723 (ePA 3.x Integration implements the authorization workflow and
writes M ...)
@@ -7495,6 +7503,7 @@ CVE-2026-68765 (hashcat master branch builds after v7.1.2
contain a heap buffer
NOTE: Fixed by:
https://github.com/hashcat/hashcat/commit/6f374c4ff7d5dc951530fbbbcf6b45e3c169b100
CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote
attacker to ...)
- mini-httpd <unfixed> (bug #1144953)
+ [trixie] - mini-httpd <no-dsa> (Minor issue)
CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213
allows a remo ...)
NOT-FOR-US: OSSRS SRS (Simple Realtime Server)
CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782)
allows an ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -77,6 +77,8 @@ linux (carnil)
--
lxd
--
+nagios4
+--
nats-server
maybe move to 2.12.2 if sufficiently backwards compatible
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c49e9b246fe0a669cd28dd5f426896d9de9549b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c49e9b246fe0a669cd28dd5f426896d9de9549b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits