Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bf090717 by Moritz Muehlenhoff at 2026-08-24T23:08:32+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -368,8 +368,9 @@ CVE-2026-71905 (Multiple DrayTek VigorAP models contain a 
command injection vuln
 CVE-2026-71904 (Multiple DrayTek VigorAP models contain a command injection 
vulnerabil ...)
        NOT-FOR-US: DrayTek
 CVE-2026-71832 (Aria2 version 1.37.0 and below is affected by a Divide By Zero 
issue i ...)
-       - aria2 <unfixed>
+       - aria2 <unfixed> (unimportant)
        NOTE: https://github.com/aria2/aria2/issues/2371
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-71509 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
        NOT-FOR-US: Dolibarr
 CVE-2026-71508 (Dolibarr before 24.0.0 contains an improper authorization 
vulnerabilit ...)
@@ -35767,6 +35768,7 @@ CVE-2026-14282 (The GoDAM \u2013 Organize WordPress 
Media Library & File Manager
        NOT-FOR-US: WordPress plugin
 CVE-2026-14257 (brace-expansion through 5.0.7 is vulnerable to denial of 
service via m ...)
        - node-brace-expansion <unfixed> (bug #1142832)
+       [trixie] - node-brace-expansion <no-dsa> (Minor issue)
        NOTE: 
https://github.com/juliangruber/brace-expansion/commit/a1bd33999ea75262c4749fff3bbb0d1372bd07b5
 (v5.0.8)
        NOTE: When fixing this issue make sure to make it complete and not open 
CVE-2026-69152.
 CVE-2026-13119 (The Registrations For The Events Calendar plugin for WordPress 
is vuln ...)
@@ -39270,6 +39272,7 @@ CVE-2026-16493 (A flaw was found in ansible-core. The 
_extract_collection_from_g
        TODO: check upstream details
 CVE-2026-16461 (A stack-based buffer overflow was found in rpcbind's rpcinfo 
utility.  ...)
        - rpcbind <unfixed> (bug #1142716)
+       [trixie] - rpcbind <no-dsa> (Minor issue)
        [bookworm] - rpcbind <postponed> (Minor issue)
        [bullseye] - rpcbind <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502719
@@ -40341,6 +40344,7 @@ CVE-2026-16312
        REJECTED
 CVE-2026-16277 (A stack-based buffer overflow was found in rpcbind's rpcinfo 
utility.  ...)
        - rpcbind <unfixed> (bug #1142506)
+       [trixie] - rpcbind <no-dsa> (Minor issue)
        [bookworm] - rpcbind <postponed> (Minor issue)
        [bullseye] - rpcbind <postponed> (Minor issue)
        NOTE: Fixed by: 
https://git.linux-nfs.org/?p=steved/rpcbind.git;a=commitdiff;h=bb9bb7286a4c345442946dc2ce3c9e7f67e96d4d
 (rpcbind-1_2_9)


=====================================
data/dsa-needed.txt
=====================================
@@ -65,6 +65,8 @@ jupyterlab
 --
 kamailio
 --
+kitty
+--
 libapache2-mod-auth-openidc (jmm)
 --
 libdbi-perl (carnil)
@@ -113,6 +115,8 @@ py7zr
 python-authlib
   possibly move trixie to 1.6.12
 --
+python-git
+--
 python-msgpack
   Problems with autopkgtests, maintainer pinged and waiting for feedback
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf09071721a37e3acaf0028a476a0cdb5d58f917

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bf09071721a37e3acaf0028a476a0cdb5d58f917
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to