Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
eef7db4e by Moritz Muehlenhoff at 2026-09-01T14:55:08+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -370,22 +370,26 @@ CVE-2026-82855 (@hulumi/policies versions before 1.3.2 
contain an evidence valid
        NOT-FOR-US: Hulumi
 CVE-2026-82854 (Nodemailer before 8.0.4 is vulnerable to SMTP command 
injection throug ...)
        - node-nodemailer 8.0.4+~7.0.11-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-c7w3-x93f-qmm8
 CVE-2026-82853 (Nodemailer versions before 8.0.5 contain an SMTP command 
injection vul ...)
        - node-nodemailer 8.0.11+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-vvjj-xcjg-gr5g
 CVE-2026-82838 (The default docker image shipped for Venueless did not 
properly ensure ...)
        NOT-FOR-US: rami.io products
 CVE-2026-82823
        REJECTED
 CVE-2026-82821 (A vulnerability was determined in FLVMeta up to 1.2.2. 
Affected by thi ...)
-       - flvmeta <unfixed>
+       - flvmeta <unfixed> (unimportant)
        NOTE: https://github.com/noirotm/flvmeta/issues/28
        NOTE: Fixed by: 
https://github.com/noirotm/flvmeta/commit/52642f7dfb76ec7334016622dde60b1ae963d79b
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-82820 (A vulnerability was found in FLVMeta up to 1.2.2. Affected is 
the func ...)
-       - flvmeta <unfixed>
+       - flvmeta <unfixed> (unimportant)
        NOTE: https://github.com/noirotm/flvmeta/issues/27
        NOTE: Fixed by: 
https://github.com/noirotm/flvmeta/commit/f412a33b9a84c2d1a9dee145a868feddbf64879e
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-82818 (A vulnerability was determined in dibo-software diboot 3.8.0. 
This aff ...)
        NOT-FOR-US: dibo-software diboot
 CVE-2026-82817 (A vulnerability was found in dibo-software diboot 3.8.0. 
Affected by t ...)
@@ -416,6 +420,7 @@ CVE-2026-82801 (A vulnerability was detected in NASA 
earthdata-search 1.0.0. Aff
        NOT-FOR-US: NASA earthdata-search
 CVE-2026-82797 (Uncontrolled Recursion vulnerability in Samsung Open Source 
rlottie al ...)
        - rlottie <unfixed>
+       [trixie] - rlottie <no-dsa> (Minor issue)
        NOTE: https://github.com/Samsung/rlottie/pull/603
 CVE-2026-82703 (A security flaw has been discovered in Edimax BR-6214K 1.40. 
This vuln ...)
        NOT-FOR-US: Edimax
@@ -913,6 +918,7 @@ CVE-2026-82592 (A vulnerability was detected in D-Link 
DIR-825M 1.1.8. This affe
        NOT-FOR-US: D-Link
 CVE-2026-82591 (A security vulnerability has been detected in Open Asset 
Import Librar ...)
        - assimp <unfixed>
+       [trixie] - assimp <no-dsa> (Minor issue)
        NOTE: https://github.com/assimp/assimp/pull/6718
        NOTE: Fixed by: 
https://github.com/assimp/assimp/commit/bf9dabb617c46e5133dac65cca6bff177917afcb
 CVE-2026-82590 (A weakness has been identified in Open5GS up to 2.7.7. The 
affected el ...)
@@ -1287,6 +1293,7 @@ CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport 
to every network inter
        NOT-FOR-US: Argo CD
 CVE-2026-82455 (RubyGems fails to re-validate path containment after 
filesystem symlin ...)
        - rubygems <unfixed>
+       [trixie] - rubygems <no-dsa> (Minor issue)
        NOTE: https://github.com/ruby/rubygems/pull/9493
        NOTE: Fixed by (merge): 
https://github.com/ruby/rubygems/commit/103ca4230deacb31b9fcd813de109e83b5fc71ac
 CVE-2026-82454 (The Omnivore API (packages/api) before the fix in commit 
abf53d6 conta ...)
@@ -2920,6 +2927,7 @@ CVE-2026-81522 (A weakness in the MongoDB C++ Driver's 
handling of caller-suppli
        NOTE: https://jira.mongodb.org/browse/CXX-3552
 CVE-2026-81521 (The MongoDB Go Driver's client-level bulk write operation may 
accept a ...)
        - golang-mongodb-mongo-driver <unfixed>
+       [trixie] - golang-mongodb-mongo-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/GODRIVER-4075
 CVE-2026-78618 (A business logic flaw in WatchGuard Dimension allows an 
authenticated  ...)
        NOT-FOR-US: WatchGuard
@@ -6626,15 +6634,19 @@ CVE-2026-79773 (Winter CMS before 1.2.13 contains a 
local file inclusion vulnera
        NOT-FOR-US: Winter CMS
 CVE-2026-79772 (Nokogiri versions before 1.19.1 fail to check the return value 
from xm ...)
        - ruby-nokogiri 1.19.1+dfsg-1
+       [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-8532
 CVE-2026-79771 (Nokogiri versions before 1.19.3 contain a memory leak in the 
XSLT Styl ...)
        - ruby-nokogiri 1.19.3+dfsg-1
+       [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v2fc-qm4h-8hqv
 CVE-2026-79770 (Nokogiri versions before 1.19.3 contain regular expression 
denial of s ...)
        - ruby-nokogiri 1.19.3+dfsg-1
+       [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-c4rq-3m3g-8wgx
 CVE-2026-79769 (Nokogiri versions before 1.19.4 contain a possible invalid 
(out-of-bou ...)
        - ruby-nokogiri 1.19.4+dfsg-1
+       [trixie] - ruby-nokogiri <no-dsa> (Minor issue)
        NOTE: 
https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-g9g8-vgvw-g3vf
 CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found 
in galaxy ...)
        NOT-FOR-US: Ansible Galaxy server plugin for Pulp
@@ -7523,6 +7535,7 @@ CVE-2026-52490 (An issue in libtiff 
85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 all
        NOTE: Fixed by: 
https://gitlab.com/libtiff/libtiff/-/commit/b04e935cb6242f22cc8b63c99a372cf3ea825e4e
 (v4.7.2rc2)
 CVE-2026-45404 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. 
From versi ...)
        - golang-opentelemetry-otel <unfixed>
+       [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
        NOTE: 
https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-42cj-99w8-cp2p
 CVE-2026-34968 (Adminer before 5.4.3 contains an arbitrary file deletion 
vulnerability ...)
        - adminer 5.4.3+dfsg-1
@@ -15291,6 +15304,7 @@ CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer 
Copy without Checking Si
        NOT-FOR-US: Dell / EMC
 CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based 
application ...)
        - rabbitmq-java-client <unfixed> (bug #1144958)
+       [trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-93j5-89vc-pph4
        NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
        NOTE: Fixed by: 
https://github.com/rabbitmq/rabbitmq-java-client/commit/09af76fce136f3136931654a0a1d43095c80e2f0
 (main)
@@ -15298,6 +15312,7 @@ CVE-2026-69220 (The RabbitMQ Java client library allows 
Java and JVM-based appli
        NOTE: Fixed by: 
https://github.com/rabbitmq/rabbitmq-java-client/commit/db89e34809fbc6ba4e946615f297f3684ccd0acc
 (v5.33.1)
 CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based 
application ...)
        - rabbitmq-java-client <unfixed> (bug #1144958)
+       [trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg
        NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
        NOTE: Fixed by: 
https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2
 (main)
@@ -15463,6 +15478,7 @@ CVE-2026-5224 (Cleartext storage of sensitive 
information vulnerability in Kript
        NOT-FOR-US: Cryptosim
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 
1.11.1, JN ...)
        - lz4-java 1.11.2+ds1-1 (bug #1145019)
+       [trixie] - lz4-java <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
        NOTE: Fixed by: 
https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da
 (v1.11.1)
 CVE-2026-59940 (Seroval facilitates JS value stringification, including 
complex struct ...)
@@ -22000,6 +22016,7 @@ CVE-2026-13196 (Nozomi Networks Labs identified a 
CWE-787: Out-of-bounds Write v
        NOT-FOR-US: KUNBUS
 CVE-2026-13002 (A flow has been identified into dnssec.c library, causing an 
infinite  ...)
        - dnsmasq <unfixed> (bug #1144649)
+       [trixie] - dnsmasq <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2486360
 CVE-2026-12366 (Zephyr's dynamic kernel-object disposal path unref_check() in 
kernel/u ...)
        NOT-FOR-US: Zephyr, different from src:zephyr
@@ -30811,9 +30828,10 @@ CVE-2026-19079 (A TOCTOU (Time-of-Check-Time-of-Use) 
race condition vulnerabilit
        [trixie] - policycoreutils <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/SELinuxProject/selinux/commit/a556538c2d5d2583273e025b45c02651fef47679
 CVE-2026-18497 (A heap-buffer-overflow vulnerability exists in the nothings 
stb TrueTy ...)
-       - libstb <unfixed>
+       - libstb <unfixed> (unimportant)
        NOTE: https://www.kb.cert.org/vuls/id/987105
        NOTE: https://github.com/nothings/stb/issues/1905
+       NOTE: truetype parser only supported for trusted font files
 CVE-2026-17603 (Nexus Repository 3 did not sufficiently restrict which 
HikariCP connec ...)
        NOT-FOR-US: Sonatype
 CVE-2026-17601 (A user holding a permission to update privilege definitions 
could modi ...)
@@ -36031,6 +36049,7 @@ CVE-2026-54722 (DSSRF is a Node.js library that 
provides a wide range of utiliti
        NOT-FOR-US: DSSRF
 CVE-2026-54522 (MessagePack for Ruby is an implementation of the MessagePack 
binary se ...)
        - ruby-msgpack 1.8.3-1
+       [trixie] - ruby-msgpack <no-dsa> (Minor issue)
        [bookworm] - ruby-msgpack <postponed> (minor issue)
        [bullseye] - ruby-msgpack <postponed> (minor issue)
        NOTE: 
https://github.com/msgpack/msgpack-ruby/security/advisories/GHSA-4mrv-5p47-p938
@@ -51352,6 +51371,7 @@ CVE-2026-54171 (Excon is usable, fast, simple HTTP 1.1 
for Ruby. Prior to 1.5.0,
        NOTE: Fixed by: 
https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 
(v1.5.0)
 CVE-2026-54163 (secure_headers manages application of security headers with 
many safe  ...)
        - ruby-secure-headers 7.3.0-1
+       [trixie] - ruby-secure-headers <no-dsa> (Minor issue)
        NOTE: 
https://github.com/github/secure_headers/security/advisories/GHSA-rqq5-2gf9-4w4q
        NOTE: Fixed by: 
https://github.com/github/secure_headers/commit/286a79dea80c6a9be4ca93e0f284c923cf77e539
 (7.3.0)
 CVE-2026-54159 (PrestaShop ps_facetedsearch is a module that adds layered 
navigation f ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -55,6 +55,8 @@ jetty9
 --
 jetty12
 --
+jpeg-xl (jmm)
+--
 jq (aron)
   For regression in #1144075
 --
@@ -72,6 +74,8 @@ libde265 (jmm)
 --
 libevent
 --
+libheif
+--
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more 6.12.y versions



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eef7db4e362174dc2453e6045587bf5d9cd76cb0

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eef7db4e362174dc2453e6045587bf5d9cd76cb0
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to