Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d871d68a by Moritz Muehlenhoff at 2026-08-27T08:48:42+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -391,9 +391,11 @@ CVE-2026-80233 (CAYIN CMS-WS, CMS-SE, and SMP series 
products developed by CAYIN
        NOT-FOR-US: CAYIN CMS-WS and CMS-SE and SMP series products
 CVE-2026-80206 (NLTK before 3.10.3 contains a regular expression denial of 
service (Re ...)
        - nltk 3.10.3-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-w3v8-gmh9-3wv7
 CVE-2026-80205 (NLTK versions before 3.10.0 contain a regular expression 
denial of ser ...)
        - nltk 3.10.0-1
+       [trixie] - nltk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nltk/nltk/security/advisories/GHSA-rrv8-h7p8-rx55
 CVE-2026-80204 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 
does not a ...)
        NOT-FOR-US: Grav plugin
@@ -420,6 +422,7 @@ CVE-2026-77801 (GitLab has remediated an issue in GitLab 
CE/EE affecting all ver
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia 
diagram  ...)
        - dia <unfixed>
+       [trixie] - dia <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/581
 CVE-2026-77557 (A malicious actor with access to the network could exploit an 
Improper ...)
        NOT-FOR-US: Ubiquiti UniFi
@@ -476,8 +479,9 @@ CVE-2026-75960 (Rently Smart Home versions 20.1.0 and prior 
are vulnerable to an
 CVE-2026-75896 (Use of Hard-coded Credentials vulnerability in T\xdcB\u0130TAK 
B\u0130 ...)
        NOT-FOR-US: Liderahenk
 CVE-2026-75466 (libjpeg-turbo 3.2.0 contains an integer division-by-zero 
vulnerability ...)
-       - libjpeg-turbo <unfixed>
+       - libjpeg-turbo <not-affected> (Vulnerable code introduced later)
        NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/911
+       NOTE: Introduced by: 
https://github.com/sysfce2/libjpeg-turbo/commit/285744829a1ed5b12dfff61a6a39da0eea0b8405
 (3.1.90)
        NOTE: Fixed by: 
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f14656395b7c83f66ac248c48dc844caebcc1127
 CVE-2026-75325 (DWSurvey v6.14.0 is is vulnerable to authentication bypass via 
the '/a ...)
        NOT-FOR-US: DWSurvey
@@ -756,10 +760,12 @@ CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive 
without limiting how m
        NOT-FOR-US: LeafWiki
 CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ, 
the Linux ...)
        - bluez <unfixed>
+       [trixie] - bluez <no-dsa> (Minor issue)
        NOTE: 
https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
 CVE-2026-80185 (BlueZ sdp-xml.c type confusion via 
RegisterProfile(ServiceRecord) can  ...)
        - bluez <unfixed>
+       [trixie] - bluez <no-dsa> (Minor issue)
        NOTE: 
https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
        NOTE: Fixed by: 
https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
 CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or 
escape the ...)
@@ -2312,7 +2318,6 @@ CVE-2026-78562 (The Verdure Core plugin for WordPress is 
vulnerable to Local Fil
        NOT-FOR-US: WordPress plugin
 CVE-2026-78468
        REJECTED
-       NOT-FOR-US: WordPress plugin
 CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the 
python_ ...)
        NOT-FOR-US: Amazon
 CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a 
maliciou ...)
@@ -2905,10 +2910,8 @@ CVE-2026-78470 (The WP Project Manager Pro plugin for 
WordPress is vulnerable to
        NOT-FOR-US: WordPress plugin
 CVE-2026-78467
        REJECTED
-       NOT-FOR-US: WordPress plugin
 CVE-2026-78466
        REJECTED
-       NOT-FOR-US: WordPress plugin
 CVE-2026-78435 (A vulnerability has been found in Faveo Helpdesk up to 2.0.3. 
Affected ...)
        NOT-FOR-US: Faveo Helpdesk
 CVE-2026-78434 (A flaw has been found in Faveo Helpdesk up to 2.0.3. This 
impacts the  ...)
@@ -7770,6 +7773,13 @@ CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 
could allow a remote attac
        NOT-FOR-US: IBM
 CVE-2026-19672 (The tarfile module's tar and data  extraction filters created 
director ...)
        - python3.15 <unfixed>
+       - python3.14 <unfixed>
+       - python3.13 <unfixed>
+       [trixie] - python3.13 <no-dsa> (Minor issue)
+       - python3.11 <removed>
+       - python3.9 <removed>
+       - pypy3 <unfixed>
+       [trixie] - pypy3 <no-dsa> (Minor issue)
        NOTE: 
https://mail.python.org/archives/list/[email protected]/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/
        NOTE: https://github.com/python/cpython/issues/155999
        NOTE: https://github.com/python/cpython/pull/156000


=====================================
data/dsa-needed.txt
=====================================
@@ -23,12 +23,14 @@ amd64-microcode (carnil)
 bouncycastle
   possibly move to 1.85 for trixie
 --
+bubblewrap (jmm)
+--
 cacti
   probably best to move to 1.2.31
 --
 chromium (dilinger)
 --
-cockpit
+cockpit (jmm)
 --
 containerd
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d871d68aa86f841ce8d5ebd1d3fc034747573804

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d871d68aa86f841ce8d5ebd1d3fc034747573804
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to