Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5f134322 by Moritz Muehlenhoff at 2026-09-08T11:12:03+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -235,16 +235,19 @@ CVE-2026-86426 (LibreNMS before 26.8.0 contains an 
authentication bypass vulnera
        NOT-FOR-US: LibreNMS
 CVE-2026-86425 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 
contains a heap ...)
        - imagemagick <unfixed>
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/5bff96a5c8d0b3dafa4ad4fa7916db4cae72a11d
 (7.1.2-30)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/e006a69e03f3aff34e9a7af90a0793ec6d879b48
 (6.9.13-55)
 CVE-2026-86424 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a 
time-of-check-tim ...)
        - imagemagick <unfixed>
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/a44ef50cc494253f7d9f0229bb25c064a8e2ae69
 (7.1.2-30)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/0b47fb7e3d5650b2be88fd3a8c15096765970ce3
 (6.9.13-55)
 CVE-2026-86423 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 
contains a heap ...)
        - imagemagick <unfixed>
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5m9j-96ff-j6qc
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/1d3e98913f6a8fa34b5a4180eadb9ed195b918a8
 (7.1.2-30)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/ed44f0ba6e2ab57983a6d030c868d009514dc470
 (6.9.13-55)
@@ -253,11 +256,13 @@ CVE-2026-86422 (ImageMagick before 7.1.2-30 contains a 
time-of-check-time-of-use
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x8g2-7r3w-h44p
 CVE-2026-86421 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory 
leak in th ...)
        - imagemagick <unfixed>
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/c83153dfc128de8e7c538f879c532c7d36a75abb
 (7.1.2-30)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/d56cab9f2253373e57c2e77809ab12abbbbdd680
 (6.9.13-55)
 CVE-2026-86420 (ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly 
lower the  ...)
        - imagemagick <unfixed>
+       [trixie] - imagemagick <no-dsa> (Minor issue)
        NOTE: 
https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick/commit/6ac07556a93b2de00c845cd535ca256f45a47154
 (7.1.2-30)
        NOTE: Fixed by: 
https://github.com/ImageMagick/ImageMagick6/commit/29f17f3fe5008fc56f00c1fbc96adf46169db245
 (6.9.13-55)
@@ -4126,7 +4131,9 @@ CVE-2026-79754 (Nuclio is a "Serverless" framework for 
Real-Time Events and Data
        NOT-FOR-US: Nuclio
 CVE-2026-78689 (Description   NGINX JavaScript (njs) has a vulnerability in 
the XML mo ...)
        - libnginx-mod-js 1.0.1-1
+       [trixie] - libnginx-mod-js <no-dsa> (Minor issue)
        NOTE: https://my.f5.com/manage/s/article/K000162602
+       NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
 CVE-2026-78609 (Incorrect Authorization (CWE-863) in Elastic Cloud on 
Kubernetes (ECK) ...)
        NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
 CVE-2026-78604 (Incorrect Permission Assignment for Critical Resource 
(CWE-732) in Ela ...)
@@ -4169,7 +4176,10 @@ CVE-2026-78408 (The nsenter --join-cgroup option opens 
the target cgroup.procs f
        NOTE: 
https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj
 CVE-2026-78222 (A vulnerability exists in NGINX JavaScript where a malformed 
HTTP resp ...)
        - libnginx-mod-js 1.0.1-1
+       [trixie] - libnginx-mod-js <no-dsa> (Minor issue)
        NOTE: https://my.f5.com/manage/s/article/K000162603
+       NOTE: 
https://github.com/nginx/njs/commit/a62feb4831e75c75c446298ca4a23862dcfcbab4 
(1.0.1)
+       NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
 CVE-2026-78153 (The Restrict User Access WordPress plugin before 2.8.1 does 
not normal ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-77794 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not 
validat ...)
@@ -4328,7 +4338,11 @@ CVE-2026-18672 (In Progress\xae Telerik\xae UI for AJAX 
prior to v2026.3.812, in
        NOT-FOR-US: Progress Software
 CVE-2026-18329 (Description  NGINX JavaScript (njs)and QuickJS (qjs) 
engineshave a vul ...)
        - libnginx-mod-js 1.0.1-1
+       [trixie] - libnginx-mod-js <not-affected> (Vulnerable code not present, 
only affects 0.9.9 and later)
+       [bookworm] - libnginx-mod-js <not-affected> (Vulnerable code not 
present, only affects 0.9.9 and later)
        NOTE: https://my.f5.com/manage/s/article/K000162599
+       NOTE: 
https://github.com/nginx/njs/commit/6898f7c9f844ca30af2aed9e8b1fe10f393644a5 
(1.0.1)
+       NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
 CVE-2026-18058 (The mobile Smart Connect dashboard UI was subject to 
manipulation by 3 ...)
        NOT-FOR-US: Lenovo
 CVE-2026-17563 (The User Frontend WordPress plugin before 4.3.11 does not 
enforce its  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f1343224b39a670dc05d64e59b40b26fa719202

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f1343224b39a670dc05d64e59b40b26fa719202
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to