Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
e2a99b6c by Moritz Muehlenhoff at 2026-09-06T12:53:16+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -277,6 +277,7 @@ CVE-2026-85781 (Unverified ownership of a storage access
point in the volume del
NOT-FOR-US: Amazon
CVE-2026-85769 (A flaw was found in libtpms, a library that provides software
TPM 2.0 ...)
- libtpms <unfixed>
+ [trixie] - libtpms <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2528538
NOTE: https://github.com/stefanberger/libtpms/issues/614
NOTE: Fixed by:
https://github.com/stefanberger/libtpms/commit/b1462888180d896af03cae0487e8d45009cc445e
@@ -490,7 +491,9 @@ CVE-2026-85538 (An incorrect authorization vulnerability in
MISP allowed authent
- misp <itp> (bug #1144317)
CVE-2026-85534 (A flaw was found in libsoup. When a client sends an HTTP/2
request bod ...)
- libsoup3 <unfixed>
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/551
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/561
CVE-2026-85533 (An authorization flaw in MISP allowed an authenticated user to
submit ...)
@@ -5169,7 +5172,9 @@ CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and
earlier allows remote au
NOT-FOR-US: cPanel
CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the
separation of pr ...)
- smarty4 <unfixed>
+ [trixie] - smarty4 <no-dsa> (Minor issue)
- smarty3 <unfixed>
+ [trixie] - smarty3 <no-dsa> (Minor issue)
NOTE:
https://github.com/smarty-php/smarty/security/advisories/GHSA-cq55-c7wv-pxmq
NOTE: https://github.com/smarty-php/smarty/pull/1194
NOTE: Fixed by:
https://github.com/smarty-php/smarty/commit/31e06fc087a8b5a9b236c1e5dacc1c2850a2c115
(v5.8.2)
@@ -6849,13 +6854,17 @@ CVE-2026-82254 (gitoxide before 0.69.0 contains
unchecked array indexing in delt
NOTE:
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-x494-mj8g-cj27
CVE-2026-82253 (gitoxide (Rust crates gix <= 0.72.0 and gix-validate <=
0.10.0) contai ...)
- rust-gix 0.83.0-1
+ [trixie] - rust-gix <no-dsa> (Minor issue)
- rust-gix-validate 0.11.1-1
+ [trixie] - rust-gix-validate <no-dsa> (Minor issue)
NOTE:
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-p3hw-mv63-rf9w
CVE-2026-82252 (gitoxide before 0.52.1 follows symlinks when reading the
worktree .git ...)
- rust-gix 0.83.0-1
+ [trixie] - rust-gix <no-dsa> (Minor issue)
NOTE:
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-pg4w-g64p-qwhj
CVE-2026-82251 (gitoxide before 0.52.1 fails to validate submodule names from
.gitmodu ...)
- rust-gix 0.83.0-1
+ [trixie] - rust-gix <no-dsa> (Minor issue)
NOTE:
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-fr8x-3vfx-f45h
CVE-2026-82250 (gitoxide gix-packetline versions before 0.21.5 contain a panic
vulnera ...)
- rust-gix-packetline 0.22.0-1
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2a99b6c0a448c55ab047821e2cae69beaebd4b0
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2a99b6c0a448c55ab047821e2cae69beaebd4b0
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits