Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d871d68a by Moritz Muehlenhoff at 2026-08-27T08:48:42+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -391,9 +391,11 @@ CVE-2026-80233 (CAYIN CMS-WS, CMS-SE, and SMP series
products developed by CAYIN
NOT-FOR-US: CAYIN CMS-WS and CMS-SE and SMP series products
CVE-2026-80206 (NLTK before 3.10.3 contains a regular expression denial of
service (Re ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-w3v8-gmh9-3wv7
CVE-2026-80205 (NLTK versions before 3.10.0 contain a regular expression
denial of ser ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE:
https://github.com/nltk/nltk/security/advisories/GHSA-rrv8-h7p8-rx55
CVE-2026-80204 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18
does not a ...)
NOT-FOR-US: Grav plugin
@@ -420,6 +422,7 @@ CVE-2026-77801 (GitLab has remediated an issue in GitLab
CE/EE affecting all ver
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia
diagram ...)
- dia <unfixed>
+ [trixie] - dia <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/581
CVE-2026-77557 (A malicious actor with access to the network could exploit an
Improper ...)
NOT-FOR-US: Ubiquiti UniFi
@@ -476,8 +479,9 @@ CVE-2026-75960 (Rently Smart Home versions 20.1.0 and prior
are vulnerable to an
CVE-2026-75896 (Use of Hard-coded Credentials vulnerability in T\xdcB\u0130TAK
B\u0130 ...)
NOT-FOR-US: Liderahenk
CVE-2026-75466 (libjpeg-turbo 3.2.0 contains an integer division-by-zero
vulnerability ...)
- - libjpeg-turbo <unfixed>
+ - libjpeg-turbo <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/911
+ NOTE: Introduced by:
https://github.com/sysfce2/libjpeg-turbo/commit/285744829a1ed5b12dfff61a6a39da0eea0b8405
(3.1.90)
NOTE: Fixed by:
https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f14656395b7c83f66ac248c48dc844caebcc1127
CVE-2026-75325 (DWSurvey v6.14.0 is is vulnerable to authentication bypass via
the '/a ...)
NOT-FOR-US: DWSurvey
@@ -756,10 +760,12 @@ CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive
without limiting how m
NOT-FOR-US: LeafWiki
CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ,
the Linux ...)
- bluez <unfixed>
+ [trixie] - bluez <no-dsa> (Minor issue)
NOTE:
https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
NOTE: Fixed by:
https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
CVE-2026-80185 (BlueZ sdp-xml.c type confusion via
RegisterProfile(ServiceRecord) can ...)
- bluez <unfixed>
+ [trixie] - bluez <no-dsa> (Minor issue)
NOTE:
https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
NOTE: Fixed by:
https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or
escape the ...)
@@ -2312,7 +2318,6 @@ CVE-2026-78562 (The Verdure Core plugin for WordPress is
vulnerable to Local Fil
NOT-FOR-US: WordPress plugin
CVE-2026-78468
REJECTED
- NOT-FOR-US: WordPress plugin
CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the
python_ ...)
NOT-FOR-US: Amazon
CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a
maliciou ...)
@@ -2905,10 +2910,8 @@ CVE-2026-78470 (The WP Project Manager Pro plugin for
WordPress is vulnerable to
NOT-FOR-US: WordPress plugin
CVE-2026-78467
REJECTED
- NOT-FOR-US: WordPress plugin
CVE-2026-78466
REJECTED
- NOT-FOR-US: WordPress plugin
CVE-2026-78435 (A vulnerability has been found in Faveo Helpdesk up to 2.0.3.
Affected ...)
NOT-FOR-US: Faveo Helpdesk
CVE-2026-78434 (A flaw has been found in Faveo Helpdesk up to 2.0.3. This
impacts the ...)
@@ -7770,6 +7773,13 @@ CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0
could allow a remote attac
NOT-FOR-US: IBM
CVE-2026-19672 (The tarfile module's tar and data extraction filters created
director ...)
- python3.15 <unfixed>
+ - python3.14 <unfixed>
+ - python3.13 <unfixed>
+ [trixie] - python3.13 <no-dsa> (Minor issue)
+ - python3.11 <removed>
+ - python3.9 <removed>
+ - pypy3 <unfixed>
+ [trixie] - pypy3 <no-dsa> (Minor issue)
NOTE:
https://mail.python.org/archives/list/[email protected]/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/
NOTE: https://github.com/python/cpython/issues/155999
NOTE: https://github.com/python/cpython/pull/156000
=====================================
data/dsa-needed.txt
=====================================
@@ -23,12 +23,14 @@ amd64-microcode (carnil)
bouncycastle
possibly move to 1.85 for trixie
--
+bubblewrap (jmm)
+--
cacti
probably best to move to 1.2.31
--
chromium (dilinger)
--
-cockpit
+cockpit (jmm)
--
containerd
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d871d68aa86f841ce8d5ebd1d3fc034747573804
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d871d68aa86f841ce8d5ebd1d3fc034747573804
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits