Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e9ed6385 by Salvatore Bonaccorso at 2026-08-26T14:09:22+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1281,7 +1281,7 @@ CVE-2026-58108 (The personal access token removal query
selects fromPersonalAcce
CVE-2026-58097 (mp_SetEnddisc() copied a user-supplied PSN endpoint value
without leng ...)
NOT-FOR-US: FreeBSD
CVE-2026-58096 (LcpDecodeConfig() did not validate the length of received
endpoint dis ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58095 (mp_Enddisc() used incorrect length calculations when
formatting endpoi ...)
NOT-FOR-US: FreeBSD
CVE-2026-58094 (The FIOSSHMLPGCNF ioctl(2) operation configures the page size
for a la ...)
@@ -1293,35 +1293,35 @@ CVE-2026-58092 (In FreeBSD 15.0, the kernel structure
used to represent user cre
CVE-2026-58091 (The implementation of this ioctl attempts to acquire locks on
all chan ...)
NOT-FOR-US: FreeBSD
CVE-2026-58090 (The SOCK_STREAM receive path in the unix socket implementation
failed ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-58089 (When a process calls execve(2) to execute a setuid or setgid
image, hw ...)
- TODO: check
+ NOT-FOR-US: FreeBSD
CVE-2026-57171 (Compliance-trestle (Trestle) is a Python SDK and command-line
tool for ...)
- TODO: check
+ NOT-FOR-US: compliance-trestle
CVE-2026-57170 (Compliance-trestle (Trestle) is a Python SDK and command-line
tool for ...)
- TODO: check
+ NOT-FOR-US: compliance-trestle
CVE-2026-55805 (Improper Neutralization of Input During Web Page Generation
("Cross-si ...)
NOT-FOR-US: Drupal core and addons
CVE-2026-55588 (ORAS (OCI Registry As Storage) is a CLI and library for
managing artif ...)
TODO: check
CVE-2026-54757 (Compliance-trestle (Trestle) is a Python SDK and command-line
tool for ...)
- TODO: check
+ NOT-FOR-US: compliance-trestle
CVE-2026-54467 (On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform
before 00d1b ...)
TODO: check
CVE-2026-53965 (The MCP PHP SDK (Composer package mcp/sdk) is the official
Model Conte ...)
- TODO: check
+ NOT-FOR-US: MCP PHP SDK (Composer package mcp/sdk)
CVE-2026-52776 (Compliance-trestle (Trestle) is a tooling platform for
managing compli ...)
- TODO: check
+ NOT-FOR-US: compliance-trestle
CVE-2026-52491 (An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938
allows an ...)
TODO: check
CVE-2026-52489 (Buffer Overflow vulnerability in gpac
31becc9e08b88e525a4a62013a4000de ...)
TODO: check
CVE-2026-51368 (An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the
Spring H ...)
- TODO: check
+ NOT-FOR-US: tongweb
CVE-2026-45019 (Chainlit is a Python framework for building production-ready
conversat ...)
- TODO: check
+ NOT-FOR-US: Chainlit
CVE-2026-45018 (Chainlit is a Python framework for building production-ready
conversat ...)
- TODO: check
+ NOT-FOR-US: Chainlit
CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In
version 1.9.0, ...)
TODO: check
CVE-2026-43670 (A Content Security Policy bypass was addressed with improved
enforceme ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9ed6385555980285d8ae8c44c6a0fb4e898c9fd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9ed6385555980285d8ae8c44c6a0fb4e898c9fd
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits