Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
45b34d58 by Moritz Muehlenhoff at 2026-08-30T19:04:25+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -101,6 +101,7 @@ CVE-2026-58581
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/e0397dbe1a295e037f16f154aaaa3cff3341fc3d
 (v11.0.4)
 CVE-2026-82562 (### Summary    When `qs.parse` is called with `comma: true` 
and `throw ...)
        - node-qs <unfixed>
+       [trixie] - node-qs <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx
        NOTE: Fixed by: 
https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464 
(v6.16.0)
 CVE-2026-82482 (A security vulnerability has been detected in 
coppermine-gallery Coppe ...)
@@ -121,6 +122,7 @@ CVE-2026-82421 (A vulnerability was identified in 
itsourcecode Sales and Invento
        NOT-FOR-US: itsourcecode System
 CVE-2026-82417 (### Summary    `qs.stringify` throws a `TypeError` when it 
serializes  ...)
        - node-qs <unfixed>
+       [trixie] - node-qs <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g
        NOTE: Fixed by: 
https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6 
(v6.16.0)
 CVE-2026-81766 (The Really Simple Security  WordPress plugin before 9.8.0 does 
not che ...)
@@ -153,6 +155,7 @@ CVE-2026-14307 (The geotargetingwp WordPress plugin before 
3.5.6.2 does not sani
        NOT-FOR-US: WordPress plugin
 CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory 
traversal.)
        - ocaml-cohttp <unfixed> (bug #1146137)
+       [trixie] - ocaml-cohttp <no-dsa> (Minor issue)
        NOTE: https://github.com/mirage/ocaml-cohttp/pull/1145 (6.3.0)
 CVE-2026-82477 (In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an 
SSRF iss ...)
        NOT-FOR-US: MITRE SAF Heimdall
@@ -162,6 +165,7 @@ CVE-2026-82475 (iFlytek astron-agent through 1.1.1 contains 
an authorization byp
        NOT-FOR-US: iFlytek astron-agent
 CVE-2026-82474 (Sudo through 1.9.17p2 fails to apply intercept policy checks 
to the ex ...)
        - sudo <unfixed> (bug #1146136)
+       [trixie] - sudo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/sudo-project/sudo/commit/71fbe42dcd5a1c8f799540583a2dfb2ae6221edf
 CVE-2026-82473 (KubeEdge CloudCore through 1.23.1 accepts node task status 
reports on  ...)
        NOT-FOR-US: KubeEdge CloudCore
@@ -231,6 +235,7 @@ CVE-2026-14494 (The Sigma Forms Pro plugin for WordPress is 
vulnerable to Remote
        NOT-FOR-US: WordPress plugin
 CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When 
processing a spe ...)
        - gimp <unfixed> (bug #1146135)
+       [trixie] - gimp <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/6b6a3e6d8ccdf2a7d6488d0df28ec033a9801a38
 CVE-2026-82333 (multer is a middleware for handling multipart/form-data in 
Node.js. A  ...)
@@ -462,6 +467,7 @@ CVE-2026-55634 (Pimcore is an Open Source Data & Experience 
Management Platform.
        NOT-FOR-US: Pimcore
 CVE-2026-55584 (phpSysInfo is a customizable PHP script that displays system 
informati ...)
        - phpsysinfo <unfixed>
+       [trixie] - phpsysinfo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/phpsysinfo/phpsysinfo/security/advisories/GHSA-786w-p5pm-cvgh
        NOTE: 
https://github.com/phpsysinfo/phpsysinfo/commit/019fa2d7e568ea11461adb4bd33da5dc87c4b9ab
 (v3.4.6)
 CVE-2026-55569 (aqua is a declarative command-line version manager written in 
Go. Prio ...)
@@ -725,6 +731,7 @@ CVE-2026-82330 (A flaw was found in the file-pvr plugin in 
GIMP. When processing
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/ae584e9338774388db9705bd8ff5cb4bd308268a
 CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When 
processing a spe ...)
        - gimp <unfixed> (bug #1146133)
+       [trixie] - gimp <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
 CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library 
used by R ...)
@@ -732,9 +739,10 @@ CVE-2026-82327 (A flaw was found in libsolv, a 
dependency-resolution library use
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
        TODO: check upstream status, no references from Red Hat
 CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. 
When proce ...)
-       - gimp <unfixed> (bug #1146132)
+       - gimp <unfixed> (bug #1146132; unimportant)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16584
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/2fba61f28efaebdc170e951e499e42820fbf633a
+       NOTE: Building of optional Plug-In for Amiga IFF/ILBM not enabled.
 CVE-2026-82261 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with 
experime ...)
        NOT-FOR-US: SvelteKit
 CVE-2026-82260 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with 
experime ...)
@@ -749,9 +757,11 @@ CVE-2026-82256 (SvelteKit before 2.69.1 fails to properly 
validate remote form f
        NOT-FOR-US: SvelteKit
 CVE-2026-82255 (gitoxide versions from 0.25.4 contain an HTTP credential leak 
vulnerab ...)
        - rust-gix-transport 0.57.0-1
+       [trixie] - rust-gix-transport <no-dsa> (Minor issue)
        NOTE: 
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-9857-6mw7-fq2m
 CVE-2026-82254 (gitoxide before 0.69.0 contains unchecked array indexing in 
delta appl ...)
        - rust-gix-pack 0.70.0-1
+       [trixie] - rust-gix-pack <no-dsa> (Minor issue)
        NOTE: 
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-x494-mj8g-cj27
 CVE-2026-82253 (gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 
0.10.0) contai ...)
        TODO: check
@@ -761,6 +771,7 @@ CVE-2026-82251 (gitoxide before 0.52.1 fails to validate 
submodule names from .g
        TODO: check
 CVE-2026-82250 (gitoxide gix-packetline versions before 0.21.5 contain a panic 
vulnera ...)
        - rust-gix-packetline 0.22.0-1
+       [trixie] - rust-gix-packetline <no-dsa> (Minor issue)
        NOTE: 
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-2vh6-hw4j-32ww
 CVE-2026-82249 (gitoxide before 0.38.2 fails to validate carriage return 
characters in ...)
        TODO: check
@@ -768,6 +779,7 @@ CVE-2026-82248 (gix-worktree-state before 0.33.0 (part of 
gitoxide) allows writi
        TODO: check
 CVE-2026-82247 (gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a 
hand-roll ...)
        - rust-gix-url 0.37.1-1
+       [trixie] - rust-gix-url <no-dsa> (Minor issue)
        - rust-gix-transport 0.58.1-1
        NOTE: 
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-jrcm-326h-gpp8
 CVE-2026-82246 (Budibase Server before 3.41.3 contains a server-side request 
forgery v ...)
@@ -985,6 +997,7 @@ CVE-2026-37237 (vLLM up to and including 0.17.0 allows 
remote attackers to cause
        - vllm <itp> (bug #1095237)
 CVE-2026-37236 (grpc-gateway v2.28.0 is vulnerable to Incorrect Access 
Control. The ap ...)
        - golang-github-grpc-ecosystem-grpc-gateway 2.30.0-1
+       [trixie] - golang-github-grpc-ecosystem-grpc-gateway <no-dsa> (Minor 
issue)
        NOTE: 
https://github.com/grpc-ecosystem/grpc-gateway/commit/72123cd4f32545f6e1376873f412dcdcbcf29acc
 (v2.29.0)
 CVE-2026-33607 (An attacker that has valid credentials can use IMAP LIST 
command to co ...)
        - dovecot <unfixed> (bug #1146018)
@@ -1016,6 +1029,7 @@ CVE-2026-18393 (A flaw was found in FFmpeg. The 
tdsc_load_cursor() function writ
        TODO: check
 CVE-2026-15603 (morgan is an HTTP request logger middleware for Node.js. In 
versions p ...)
        - node-morgan <unfixed>
+       [trixie] - node-morgan <no-dsa> (Minor issue)
        NOTE: 
https://github.com/expressjs/morgan/security/advisories/GHSA-jxfw-x594-9x9m
 CVE-2026-14942
        REJECTED
@@ -2175,6 +2189,7 @@ CVE-2026-10036 (SpeechBrain before 1.1.1 contains an 
arbitrary code execution vu
        NOT-FOR-US: SpeechBrain
 CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially 
crafted JPEG  ...)
        - gdk-pixbuf <unfixed> (bug #1145988)
+       [trixie] - gdk-pixbuf <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
        NOTE: Introduced with: 
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/4af78023ce7d3b5e3cec422a59bb4f48fa4f5886
 (2.43.4)
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01
@@ -2197,6 +2212,7 @@ CVE-2026-81500
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-9pqw-c7m4-xvg7
 CVE-2026-18374 (Passing an effectively empty string to the `,ccs=` syntax 
extension of ...)
        - glibc <unfixed>
+       [trixie] - glibc <no-dsa> (Minor issue)
        NOTE: 
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015
 CVE-2026-81827 (Affected versions of Flowintel incorrectly attempted to 
validate login ...)
        NOT-FOR-US: Flowintel
@@ -2856,6 +2872,7 @@ CVE-2026-79938 (Dell PowerProtect Cyber Recovery, 
versions prior to 20.3, contai
        NOT-FOR-US: Dell / EMC
 CVE-2026-79921 (amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a 
comprom ...)
        - golang-github-rabbitmq-amqp091-go 1.14.0-1 (bug #1145982)
+       [trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp
        NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
        NOTE: Fixed by (merge): 
https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0
 (v1.13.0)
@@ -3161,18 +3178,22 @@ CVE-2025-70340 (A Broken Access Control vulnerability 
exists in ThingsBoard Prof
        NOT-FOR-US: ThingsBoard
 CVE-2025-70293 (An issue was discovered in Denx U-Boot before 2026.04. An 
integer over ...)
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
        NOTE: 
https://source.denx.de/u-boot/u-boot/-/commit/fc16c847a1c9c6e0ee1f605849cc500a04c21602
 (v2026.04-rc1)
 CVE-2025-70292
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
        NOTE: 
https://source.denx.de/u-boot/u-boot/-/commit/870aff99a279ed428c5a2560b2441b3079ddb34b
 (v2026.04-rc1)
 CVE-2025-70291
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
        NOTE: 
https://source.denx.de/u-boot/u-boot/-/commit/99416665f006b925db12f6c02b11f9da02c10c5a
 (v2026.04-rc1)
 CVE-2025-70290 (An issue was discovered in Denx U-Boot before 2026.04. An 
integer over ...)
        - u-boot <unfixed>
+       [trixie] - u-boot <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
        NOTE: 
https://source.denx.de/u-boot/u-boot/-/commit/c8f0294285f6588322363e1711bc57118e6fc9a3
 (v2026.04-rc1)
 CVE-2025-62341 (HCL Connections is vulnerable to server-side request forgery 
(SSRF) wh ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -26,10 +26,14 @@ bouncycastle
 cacti
   probably best to move to 1.2.31
 --
+chromum (dilinger)
+--
 containerd
 --
 cups
 --
+dovecot
+--
 dulwich
 --
 firebird3.0
@@ -88,6 +92,8 @@ nodejs
 --
 node-dompurify
 --
+nsd
+--
 openexr
 --
 pacemaker
@@ -139,6 +145,8 @@ runc
 rust-wasmtime
   for CVE-2026-34987 CVE-2026-34971, rest would also be fine to ignore
 --
+sabnzbdplus
+--
 shaarli
 --
 sogo



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45b34d589d21a31ed64d71d73b03b95c54862fa1

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45b34d589d21a31ed64d71d73b03b95c54862fa1
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to