Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
bc460655 by Moritz Muehlenhoff at 2026-08-26T10:06:23+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1674,6 +1674,7 @@ CVE-2026-59984 (OpenEXR is the reference implementation 
and specification for th
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/c550555a1657398e6a9f96c3530f8b1370a6fd94
 (v3.2.11-rc)
 CVE-2026-59983 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
        - openexr 3.4.14-0.1
+       [trixie] - openexr <no-dsa> (Minor issue)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p42q-g5c9-mh9w
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/0efec58d2d28a0ee322f5028dee6fb57d459580e
 (v3.4.14-rc)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/f0e404f7298cd8563a1d30a64a1c982dbd68fc49
 (v3.3.13-rc)
@@ -1690,17 +1691,20 @@ CVE-2026-59335 (Improper handling of case sensitivity 
(CWE-178) in the identity
        NOT-FOR-US: Cloud Foundry
 CVE-2026-59189 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
        - openexr 3.4.14-0.1
+       [trixie] - openexr <no-dsa> (Minor issue)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c
 (v3.4.14-rc)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec
 (v3.3.13-rc)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1
 (v3.2.11-rc)
 CVE-2026-59187 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
        - openexr 3.4.14-0.1
+       [trixie] - openexr <no-dsa> (Minor issue)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585
 (v3.4.14-rc)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94
 (v3.3.13-rc)
 CVE-2026-59186 (OpenEXR is the reference implementation and specification for 
the EXR  ...)
        - openexr 3.4.14-0.1
+       [trixie] - openexr <no-dsa> (Minor issue)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab
 (v3.4.14-rc)
        NOTE: 
https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b
 (v3.3.13-rc)
@@ -19473,8 +19477,9 @@ CVE-2026-29036 (cJSON versions 1.5.0 through 1.7.19 
contain an incorrectly-resol
        - cjson <unfixed>
        TODO: check, report upstream status
 CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer 
overflow v ...)
-       - civetweb <unfixed>
-       TODO: check details upstream
+       - civetweb <unfixed> (unimportant)
+       NOTE: https://github.com/civetweb/civetweb/issues/1381
+       NOTE: MG_EXPERIMENTAL_INTERFACES not enabled in Debian build
 CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API 
(`snowflake.co ...)
        NOT-FOR-US: Snowflake Python API
 CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung 
Open Sour ...)
@@ -22271,10 +22276,10 @@ CVE-2026-71391 (GNU Emacs for Android contains an 
off-by-one error in the gvar t
        NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
        NOTE: Fixed by: 
https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe
 CVE-2026-70622 (tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape 
vulnera ...)
-       - rustc <undetermined>
-       - rust-tar <unfixed> (bug #1144402)
+       - rust-tar <unfixed> (bug #1144402; unimportant)
        NOTE: 
https://gist.github.com/thesmartshadow/e7dac0bb690ee17b9cc142154cb11726
-       TODO: check, unclear if reported upstream
+       NOTE: Clarified as not in scope by upstream:
+       NOTE: 
https://github.com/composefs/tar-rs/commit/cd94c46e0d74fbcc50eea3f30665a1b1159254cc
 CVE-2026-6374 (Use of Hard-coded Credentials vulnerability in Zyxel Networks 
WAH7601  ...)
        NOT-FOR-US: Zyxel
 CVE-2026-6373 (Exposure of sensitive system information to an unauthorized 
control sp ...)
@@ -260071,6 +260076,7 @@ CVE-2025-30154 (reviewdog/action-setup is a GitHub 
action that installs reviewdo
        NOT-FOR-US: reviewdog/action-setup GitHub action
 CVE-2025-30153 (kin-openapi is a Go project for handling OpenAPI files. Prior 
to 0.131 ...)
        - golang-github-getkin-kin-openapi 0.135.0-1
+       [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
        [bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        [bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; 
out of LTS support)
        NOTE: 
https://github.com/getkin/kin-openapi/security/advisories/GHSA-wq9g-9vfc-cfq9


=====================================
data/dsa-needed.txt
=====================================
@@ -153,7 +153,7 @@ sogo
 starlette
   Matheus Polkorny is proposing an update for review
 --
-suricata-update
+suricata-update (jmm)
   Maintainer prepared debdiff, acked for upload
 --
 tomcat10
@@ -172,7 +172,7 @@ vips
 weechat
   Upstream recommends to use branch from 
https://github.com/weechat/weechat/commits/4.6/, cf #1142597
 --
-wireshark
+wireshark (jmm)
   Matheus Polkorny prepared an update for review, 
https://salsa.debian.org/debian/wireshark/-/merge_requests/8
 --
 wordpress



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc460655724e4f857ec7edc5c2fbdc64206c6465

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc460655724e4f857ec7edc5c2fbdc64206c6465
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to