Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
bc460655 by Moritz Muehlenhoff at 2026-08-26T10:06:23+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1674,6 +1674,7 @@ CVE-2026-59984 (OpenEXR is the reference implementation
and specification for th
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/c550555a1657398e6a9f96c3530f8b1370a6fd94
(v3.2.11-rc)
CVE-2026-59983 (OpenEXR is the reference implementation and specification for
the EXR ...)
- openexr 3.4.14-0.1
+ [trixie] - openexr <no-dsa> (Minor issue)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p42q-g5c9-mh9w
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/0efec58d2d28a0ee322f5028dee6fb57d459580e
(v3.4.14-rc)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/f0e404f7298cd8563a1d30a64a1c982dbd68fc49
(v3.3.13-rc)
@@ -1690,17 +1691,20 @@ CVE-2026-59335 (Improper handling of case sensitivity
(CWE-178) in the identity
NOT-FOR-US: Cloud Foundry
CVE-2026-59189 (OpenEXR is the reference implementation and specification for
the EXR ...)
- openexr 3.4.14-0.1
+ [trixie] - openexr <no-dsa> (Minor issue)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c
(v3.4.14-rc)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec
(v3.3.13-rc)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1
(v3.2.11-rc)
CVE-2026-59187 (OpenEXR is the reference implementation and specification for
the EXR ...)
- openexr 3.4.14-0.1
+ [trixie] - openexr <no-dsa> (Minor issue)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585
(v3.4.14-rc)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94
(v3.3.13-rc)
CVE-2026-59186 (OpenEXR is the reference implementation and specification for
the EXR ...)
- openexr 3.4.14-0.1
+ [trixie] - openexr <no-dsa> (Minor issue)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab
(v3.4.14-rc)
NOTE:
https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b
(v3.3.13-rc)
@@ -19473,8 +19477,9 @@ CVE-2026-29036 (cJSON versions 1.5.0 through 1.7.19
contain an incorrectly-resol
- cjson <unfixed>
TODO: check, report upstream status
CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer
overflow v ...)
- - civetweb <unfixed>
- TODO: check details upstream
+ - civetweb <unfixed> (unimportant)
+ NOTE: https://github.com/civetweb/civetweb/issues/1381
+ NOTE: MG_EXPERIMENTAL_INTERFACES not enabled in Debian build
CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API
(`snowflake.co ...)
NOT-FOR-US: Snowflake Python API
CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung
Open Sour ...)
@@ -22271,10 +22276,10 @@ CVE-2026-71391 (GNU Emacs for Android contains an
off-by-one error in the gvar t
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
NOTE: Fixed by:
https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe
CVE-2026-70622 (tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape
vulnera ...)
- - rustc <undetermined>
- - rust-tar <unfixed> (bug #1144402)
+ - rust-tar <unfixed> (bug #1144402; unimportant)
NOTE:
https://gist.github.com/thesmartshadow/e7dac0bb690ee17b9cc142154cb11726
- TODO: check, unclear if reported upstream
+ NOTE: Clarified as not in scope by upstream:
+ NOTE:
https://github.com/composefs/tar-rs/commit/cd94c46e0d74fbcc50eea3f30665a1b1159254cc
CVE-2026-6374 (Use of Hard-coded Credentials vulnerability in Zyxel Networks
WAH7601 ...)
NOT-FOR-US: Zyxel
CVE-2026-6373 (Exposure of sensitive system information to an unauthorized
control sp ...)
@@ -260071,6 +260076,7 @@ CVE-2025-30154 (reviewdog/action-setup is a GitHub
action that installs reviewdo
NOT-FOR-US: reviewdog/action-setup GitHub action
CVE-2025-30153 (kin-openapi is a Go project for handling OpenAPI files. Prior
to 0.131 ...)
- golang-github-getkin-kin-openapi 0.135.0-1
+ [trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue;
out of LTS support)
NOTE:
https://github.com/getkin/kin-openapi/security/advisories/GHSA-wq9g-9vfc-cfq9
=====================================
data/dsa-needed.txt
=====================================
@@ -153,7 +153,7 @@ sogo
starlette
Matheus Polkorny is proposing an update for review
--
-suricata-update
+suricata-update (jmm)
Maintainer prepared debdiff, acked for upload
--
tomcat10
@@ -172,7 +172,7 @@ vips
weechat
Upstream recommends to use branch from
https://github.com/weechat/weechat/commits/4.6/, cf #1142597
--
-wireshark
+wireshark (jmm)
Matheus Polkorny prepared an update for review,
https://salsa.debian.org/debian/wireshark/-/merge_requests/8
--
wordpress
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc460655724e4f857ec7edc5c2fbdc64206c6465
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc460655724e4f857ec7edc5c2fbdc64206c6465
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits