Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6c49e9b2 by Moritz Muehlenhoff at 2026-08-24T08:38:05+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -149,16 +149,19 @@ CVE-2026-68769
        REJECTED
 CVE-2026-68768 (hashcat contains a heap-based buffer overflow (out-of-bounds 
write) in ...)
        - hashcat <unfixed> (bug #1145171)
+       [trixie] - hashcat <no-dsa> (Minor issue)
        NOTE: https://github.com/hashcat/hashcat/issues/4740
        NOTE: https://github.com/hashcat/hashcat/pull/4754
        NOTE: Fixed by: 
https://github.com/hashcat/hashcat/commit/68f56a2d8712867a8520bf4dcf07f6145c23df89
 CVE-2026-68767 (hashcat's fgetl() function in src/filehandling.c writes a null 
termina ...)
-       - hashcat <unfixed> (bug #1145171)
+       - hashcat <unfixed> (bug #1145171; unimportant)
        NOTE: https://github.com/hashcat/hashcat/issues/4739
        NOTE: https://github.com/hashcat/hashcat/pull/4750
        NOTE: Fixed by: 
https://github.com/hashcat/hashcat/commit/93b55d37d3b2340013d4036f10181ddc67d44249
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-68766 (hashcat fails to restrict command-line options when parsing 
restore fi ...)
        - hashcat <unfixed> (bug #1145171)
+       [trixie] - hashcat <no-dsa> (Minor issue)
        NOTE: https://github.com/hashcat/hashcat/issues/4738
        NOTE: Fixed by: 
https://github.com/hashcat/hashcat/commit/fcae69f2438ff8eae0dc8e206b78067a1e465ed4
 CVE-2026-66917 (Joomla Extension - joomgalleryfriends.net - Stored XSS in 
JoomGallery  ...)
@@ -1280,6 +1283,7 @@ CVE-2026-72843 (The customer update route in EverShop is 
declared with "access":
        NOT-FOR-US: EverShop
 CVE-2026-72818 (The URLS regular expression in nltk/tokenize/casual.py, 
compiled into  ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: https://github.com/nltk/nltk/issues/3704
        NOTE: Fixed by: 
https://github.com/nltk/nltk/commit/7808692d451b962711005d954859bb83aabcf8fa 
(v3.10.3-rc1)
 CVE-2026-71862 (Checkmate is an open-source, self-hosted tool designed to 
track and mo ...)
@@ -2033,6 +2037,7 @@ CVE-2026-73196 (A flaw was found in FreeIPA. A 
low-privilege authenticated user
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2474712
 CVE-2026-72854 (msgpack_unpacker_expand_buffer in src/unpack.c, reached 
through the pu ...)
        - msgpack-c <unfixed>
+       [trixie] - msgpack-c <postponed> (Minor issue, revisit when fixed 
upstream)
        NOTE: https://github.com/msgpack/msgpack-c/issues/1181
 CVE-2026-72852 (hank-ai/darknet sizes a convolutional layer's weight and 
output heap b ...)
        NOT-FOR-US: hank-ai/darknet
@@ -2260,6 +2265,7 @@ CVE-2026-55586 (SumatraPDF is a multi-format reader for 
Windows. In 3.6.1 and ea
        NOT-FOR-US: SumatraPDF
 CVE-2026-55558 (aiosmtplib is an asynchronous SMTP client for use with 
asyncio. Prior  ...)
        - aiosmtplib 5.1.2-1
+       [trixie] - aiosmtplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/cole/aiosmtplib/security/advisories/GHSA-vxj7-4xrp-5vr4
        NOTE: Fixed by: 
https://github.com/cole/aiosmtplib/commit/9fab7ba1361dbf7622ede1315a24be805cff09c9
 (v5.1.2)
 CVE-2026-55095 (OpenProject is open-source, web-based project management 
software. In  ...)
@@ -2480,6 +2486,7 @@ CVE-2026-15706 (Missing authentication for critical 
function vulnerability in Ba
        NOT-FOR-US: Baylan Smart Meter Management Application (BMS)
 CVE-2026-15686 (Adminer multi_query Incorrect Check of Function Return Value 
Remote Co ...)
        - adminer 5.4.3+dfsg-1
+       [trixie] - adminer <no-dsa> (Minor issue)
        NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-478/
        NOTE: 
https://github.com/vrana/adminer/security/advisories/GHSA-3582-q6xq-5vf7
 CVE-2026-15679 (Hugging Face PyTorch Image Models checkpoint Deserialization 
of Untrus ...)
@@ -7094,6 +7101,7 @@ CVE-2026-54552 (sh provides Python process launching. 
Prior to 2.2.4, the _uid o
        NOTE: Fixed by: 
https://github.com/amoffat/sh/commit/3d855daba91f87a089b490c0d1cf1df3faace2f1 
(2.2.4)
 CVE-2026-53533 (aiosmtplib is an asynchronous SMTP client for use with 
asyncio. Prior  ...)
        - aiosmtplib 5.1.2-1
+       [trixie] - aiosmtplib <no-dsa> (Minor issue)
        NOTE: 
https://github.com/cole/aiosmtplib/security/advisories/GHSA-v3q9-hj7j-63hq
        NOTE: Fixed by: 
https://github.com/cole/aiosmtplib/commit/8eaf6efc9a8f59e2e09d3ef11246a058c46bd3ba
 (v5.1.1)
 CVE-2026-52723 (ePA 3.x Integration implements the authorization workflow and 
writes M ...)
@@ -7495,6 +7503,7 @@ CVE-2026-68765 (hashcat master branch builds after v7.1.2 
contain a heap buffer
        NOTE: Fixed by: 
https://github.com/hashcat/hashcat/commit/6f374c4ff7d5dc951530fbbbcf6b45e3c169b100
 CVE-2026-68005 (An issue in ACME mini_httpd 1.30 and prior allows a remote 
attacker to ...)
        - mini-httpd <unfixed> (bug #1144953)
+       [trixie] - mini-httpd <no-dsa> (Minor issue)
 CVE-2026-68004 (An issue in OSSRS SRS (Simple Realtime Server) <v5.0.213 
allows a remo ...)
        NOT-FOR-US: OSSRS SRS (Simple Realtime Server)
 CVE-2026-67967 (Buffer Overflow vulnerability in Tenda W20E V16.01.0.6(2782) 
allows an ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -77,6 +77,8 @@ linux (carnil)
 --
 lxd
 --
+nagios4
+--
 nats-server
   maybe move to 2.12.2 if sufficiently backwards compatible
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c49e9b246fe0a669cd28dd5f426896d9de9549b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c49e9b246fe0a669cd28dd5f426896d9de9549b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to