Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6c32ba7f by Salvatore Bonaccorso at 2026-09-11T17:40:06+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -48,7 +48,7 @@ CVE-2026-88061 (career-ops is an open-source AI-assisted job
search and applicat
CVE-2026-87958 (IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.5 is
vulnerable ...)
NOT-FOR-US: IBM
CVE-2026-87908 (multiparty is a Node.js library for parsing
multipart/form-data reques ...)
- - node-multiparty <unfixed>
+ - node-multiparty <unfixed> (bug #1147414)
NOTE:
https://github.com/pillarjs/multiparty/security/advisories/GHSA-5h46-2939-q3wh
CVE-2026-86815 (The BackWPup WordPress plugin before 5.7.5 does not properly
restrict ...)
NOT-FOR-US: WordPress plugin
@@ -285,7 +285,7 @@ CVE-2026-88914 (A flaw was found in GStreamer's
gst-plugins-good isomp4 plugin.
CVE-2026-89011 (isomorphic-git before 1.42.0 contains a prototype pollution
vulnerabil ...)
NOT-FOR-US: isomorphic-git
CVE-2026-89092 (The nscd service in the GNU C Library 2.3.4 onwards may crash
due to a ...)
- - glibc <unfixed>
+ - glibc <unfixed> (bug #1147395)
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34624
NOTE:
https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0016
CVE-2026-9338 (IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to
a denia ...)
@@ -303,15 +303,15 @@ CVE-2026-8323 (URL redirection to untrusted site ('open
redirect') vulnerability
CVE-2026-89049 (A server-side request forgery issue due to improper validation
of equi ...)
NOT-FOR-US: Amazon
CVE-2026-89046 (zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an
out-of-bounds re ...)
- - zstd-jni-java <unfixed>
+ - zstd-jni-java <unfixed> (bug #1147397)
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-rm53-6wf5-f34m
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/dd08685ef913a32e76fb27f43470035c06758646
(v1.5.7-14)
CVE-2026-89045 (zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate
negative l ...)
- - zstd-jni-java <unfixed>
+ - zstd-jni-java <unfixed> (bug #1147397)
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-9jx2-gfp9-phfm
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/dd08685ef913a32e76fb27f43470035c06758646
(v1.5.7-14)
CVE-2026-89044 (Netty versions 4.1.133.Final through 4.1.137.Final and
4.2.13.Final th ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1147398)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-hcvj-94mj-jp5c
NOTE: Fixed by:
https://github.com/netty/netty/commit/640d4d3324f7b811a4903d0730c8ccb35500500c
(netty-4.2.18.Final)
NOTE: Fixed by:
https://github.com/netty/netty/commit/ca87393b0e9e13c493d213a268e727a6d44e1585
(netty-4.1.138.Final)
@@ -330,7 +330,7 @@ CVE-2026-88938 (knowns through 0.33.0 fails to confine the
path argument of the
CVE-2026-88937 (knowns through 0.33.0 fails to properly validate template
destination ...)
NOT-FOR-US: knowns-dev/knowns
CVE-2026-88924 (A flaw was found in the admin backend of gvfs. The privileged
gvfsd-ad ...)
- - gvfs <unfixed>
+ - gvfs <unfixed> (bug #1147399)
[trixie] - gvfs <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/issues/875
NOTE: https://gitlab.gnome.org/GNOME/gvfs/-/merge_requests/352
@@ -420,7 +420,7 @@ CVE-2026-88861 (Capgo (Cap-go/capgo.app) contains an
authentication bypass affec
CVE-2026-88860 (Capgo fails to clean up channel permission overrides when a
user's las ...)
NOT-FOR-US: Cap-go
CVE-2026-88859 (A flaw was found in Evolution. A remote attacker can exploit
this vuln ...)
- - evolution <unfixed>
+ - evolution <unfixed> (bug #1147400)
NOTE: https://gitlab.gnome.org/GNOME/evolution/-/work_items/3388
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/evolution/-/commit/a6f37ef58f9889e361022d46e70b8a53b6f9fd97
(3.62.0)
CVE-2026-88790 (A security vulnerability has been detected in proma-ai Proma
up to 0.1 ...)
@@ -476,10 +476,10 @@ CVE-2026-88269 (GeoVision GV-LPC2211 V1.13 allows a Guest
user to retrieve persi
CVE-2026-88268 (GeoVision GV-LPC2211 V1.13 contains an authenticated stack
buffer over ...)
NOT-FOR-US: GeoVision
CVE-2026-88265 (A flaw was found in crun. After pivot_root, reopening
/dev/null for st ...)
- - crun <unfixed>
+ - crun <unfixed> (bug #1147401)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531224
CVE-2026-88264 (A flaw was found in crun. When the container configuration
does not gi ...)
- - crun <unfixed>
+ - crun <unfixed> (bug #1147401)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531223
CVE-2026-88060 (Angular is a development platform for building mobile and
desktop web ...)
- angular.js <unfixed>
@@ -499,61 +499,61 @@ CVE-2026-88056 (Angular is a development platform for
building mobile and deskto
CVE-2026-88055 (AnythingLLM is an application that turns pieces of content
into contex ...)
NOT-FOR-US: AnythingLLM
CVE-2026-88054 (Tesseract is an open source OCR engine. In version 5.5.3 and
earlier, ...)
- - tesseract <unfixed>
+ - tesseract <unfixed> (bug #1147403)
[trixie] - tesseract <no-dsa> (Minor issue)
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-f6h7-cqr4-6fx4
NOTE: Fixed by:
https://github.com/tesseract-ocr/tesseract/commit/552771236b0d80cbdb0c7dd856120fa21a4672e5
CVE-2026-88053 (Tesseract is an open source OCR engine. In version 5.5.3 and
earlier, ...)
- - tesseract <unfixed>
+ - tesseract <unfixed> (bug #1147403)
[trixie] - tesseract <no-dsa> (Minor issue)
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-rphx-x795-5qjv
NOTE: Fixed by:
https://github.com/tesseract-ocr/tesseract/commit/8b0574680f3b22f246ade6a4c8e3029104255c63
CVE-2026-88052 (Tesseract is an open source OCR engine. In version 5.5.3 and
earlier, ...)
- - tesseract <unfixed>
+ - tesseract <unfixed> (bug #1147403)
[trixie] - tesseract <no-dsa> (Minor issue)
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-2hm8-q5c7-c373
NOTE: Fixed by:
https://github.com/tesseract-ocr/tesseract/commit/2d04d640db2e8c7e3bab2369d599343b5a8b8443
CVE-2026-88051 (Tesseract is an open source OCR engine. In version 5.5.3 and
earlier, ...)
- - tesseract <unfixed>
+ - tesseract <unfixed> (bug #1147403)
[trixie] - tesseract <no-dsa> (Minor issue)
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-88qp-4g94-3rf3
NOTE: Fixed by:
https://github.com/tesseract-ocr/tesseract/commit/56e09ca12e751623fe796ce1554ce704bffd2ef0
CVE-2026-88050 (Tesseract is an open source OCR engine. In version 5.5.3 and
earlier, ...)
- - tesseract <unfixed>
+ - tesseract <unfixed> (bug #1147403)
[trixie] - tesseract <no-dsa> (Minor issue)
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7v9h-3q3m-w68g
NOTE: Fixed by:
https://github.com/tesseract-ocr/tesseract/commit/c94a5532ee04db5a4919542832fd94caee5ea58f
CVE-2026-88049 (Tesseract is an open source OCR engine. In version 5.5.3 and
earlier, ...)
- - tesseract <unfixed>
+ - tesseract <unfixed> (bug #1147403)
[trixie] - tesseract <no-dsa> (Minor issue)
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-jgq8-pprg-vc68
NOTE: Fixed by:
https://github.com/tesseract-ocr/tesseract/commit/b494ac18925f9d9aff9ef5815475de9943ab19bf
CVE-2026-88048 (Tesseract is an open source OCR engine. In version 5.5.3 and
earlier, ...)
- - tesseract <unfixed>
+ - tesseract <unfixed> (bug #1147403)
[trixie] - tesseract <no-dsa> (Minor issue)
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-q44c-23p6-5mw6
NOTE: Fixed by:
https://github.com/tesseract-ocr/tesseract/commit/103dc134eb36411ddc6833ec20aa2c76795bd0ff
CVE-2026-88047 (Tesseract is an open source OCR engine. In version 5.5.3 and
earlier, ...)
- - tesseract <unfixed>
+ - tesseract <unfixed> (bug #1147403)
[trixie] - tesseract <no-dsa> (Minor issue)
NOTE:
https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-5j2p-r5vc-q7f3
NOTE: Fixed by:
https://github.com/tesseract-ocr/tesseract/commit/1bda5079b1c8a7e25f523486837426903d29ce84
CVE-2026-88046 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-38xv-hf3p-h7mq
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/57842c5ee4e1407eda06a414a36510cce2db4252
(v1.75.1)
CVE-2026-88045 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-2p48-j3qc-rx9f
NOTE: https://github.com/rclone/rclone/issues/9616
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/7c1dfd99f3e6a22fcefd8686cc478226a15e63a1
(v1.75.1)
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/ab1f458013aaf6356e4bdeca61f7cb9139f8eb86
(v1.75.1)
CVE-2026-88044 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-p569-5gjg-9cmj
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/739403963abf6f58003c2becd5f7c4ad0d644153
(v1.75.1)
CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP
cookies, use ...)
- - node-cookies <unfixed>
+ - node-cookies <unfixed> (bug #1147405)
NOTE:
https://github.com/pillarjs/cookies/security/advisories/GHSA-x44v-5gxf-r6hf
NOTE: Fixed by:
https://github.com/pillarjs/cookies/commit/edf9512022d710dea2a1acca2dc215fa9ff7900c
(v0.9.2)
CVE-2026-88036 (Improper neutralization of special elements in data query
logic in the ...)
@@ -571,24 +571,24 @@ CVE-2026-88034 (Improper neutralization of special
elements in data query logic
NOTE: https://jira.mongodb.org/browse/CXX-3556
NOTE: Fixed by:
https://github.com/mongodb/mongo-cxx-driver/commit/5e52e715bf820d2d4efff01b8520eb8640c98b29
(r4.5.3)
CVE-2026-88033 (Improper neutralization of special elements in data query
logic in the ...)
- - mongo-java-driver <unfixed>
+ - mongo-java-driver <unfixed> (bug #1147406)
[trixie] - mongo-java-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/JAVA-6283
CVE-2026-88032 (A use-after-free in the reactive client-side encryption
component of t ...)
- - mongo-java-driver <unfixed>
+ - mongo-java-driver <unfixed> (bug #1147406)
[trixie] - mongo-java-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/JAVA-6276
CVE-2026-88031 (Improper neutralization of special elements in data query
logic in the ...)
- - golang-mongodb-mongo-driver <unfixed>
+ - golang-mongodb-mongo-driver <unfixed> (bug #1147410)
[trixie] - golang-mongodb-mongo-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/GODRIVER-4081
NOTE: Fixed by:
https://github.com/mongodb/mongo-go-driver/commit/806e132f9501a2665d05ebaba3b6f0d787ceaa96
(v1.17.10)
CVE-2026-88030 (Improper neutralization of special elements in data query
logic in the ...)
- - ruby-mongo <unfixed>
+ - ruby-mongo <unfixed> (bug #1147409)
NOTE: https://jira.mongodb.org/browse/RUBY-3941
NOTE: Fixed by:
https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d
(v2.26.0)
CVE-2026-88029 (Improper neutralization of special elements in data query
logic in the ...)
- - pymongo <unfixed>
+ - pymongo <unfixed> (bug #1147408)
NOTE: https://jira.mongodb.org/browse/PYTHON-5994
NOTE: Fixed by:
https://github.com/mongodb/mongo-python-driver/commit/fa676586ba4b399168a4d1d41c30dc2166cc44fd
(v4.18.1)
CVE-2026-88028 (Improper neutralization of special elements in data query
logic in the ...)
@@ -608,30 +608,30 @@ CVE-2026-88022 (Improper neutralization of special
elements in data query logic
CVE-2026-88021 (Consul and Consul Enterprise are vulnerable to an
authorization bypass ...)
- consul <removed>
CVE-2026-88018 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-xwwr-4h3p-r22c
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/90595f34f27f569be6b27c57fe5ab65057d323bd
(1.75.1)
CVE-2026-88017 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-c476-6w5q-jw77
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/c6af0b57c2b4af848bc968c2b407354476184b99
(v1.75.1)
CVE-2026-88016 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/17b0c03338a857bcb0a68d2d4c82ddbdec3f7893
(v1.75.1)
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/a7ab39d3d1958afa1446982c1dc4e4a73a887e3e
(v1.75.1)
CVE-2026-88015 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9
(v1.75.1)
CVE-2026-88014 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-66hp-wgxq-6f5q
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/5dae3adbf571a6cd9ba501eb47397a7e871e1ae0
(v1.75.1)
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/6507e13d5a83789f500af96d7188c302c9d74d98
(v1.75.1)
TODO: check, said to affect only 1.72.0 onwards
CVE-2026-88013 (rclone is a command-line program to sync files and directories
to and ...)
- - rclone <unfixed>
+ - rclone <unfixed> (bug #1147404)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-486v-q2wf-fp2r
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/22859b7e696cea3c563c6ba04c6b7f91f74456b4
(v1.75.1)
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/79fbc0842f74e02cb84f0e3e7261d169983c8831
(v1.75.1)
@@ -1098,7 +1098,7 @@ CVE-2026-87928 (MaxSite CMS versions 0.94 through 109.6
contain a cross-site scr
CVE-2026-87927 (MaxSite CMS through 109.6 contains a local file inclusion
vulnerabilit ...)
NOT-FOR-US: MaxSite CMS
CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail to validate closed
state in set ...)
- - zstd-jni-java <unfixed>
+ - zstd-jni-java <unfixed> (bug #1147397)
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-2jw3-mg7f-vw4q
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e
(v1.5.7-14)
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555
(v1.5.7-14)
@@ -1122,16 +1122,16 @@ CVE-2026-87853 (A flaw was found in SSSD's IdP
authentication provider. The eval
CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose
a system ...)
NOT-FOR-US: KGUARD DVR devices
CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free
vulnerability where ...)
- - zstd-jni-java <unfixed>
+ - zstd-jni-java <unfixed> (bug #1147397)
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-947w-pxjj-c7m9
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555
(v1.5.7-14)
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936
(v1.5.7-14)
CVE-2026-87824 (zstd-jni before 1.5.7-14 fails to validate the samples buffer
capacity ...)
- - zstd-jni-java <unfixed>
+ - zstd-jni-java <unfixed> (bug #1147397)
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-257p-3h6w-pg7h
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/bba6cfca2c0897f1fa004f4193247479f10da853
(v1.5.7-14)
CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks
on three ...)
- - zstd-jni-java <unfixed>
+ - zstd-jni-java <unfixed> (bug #1147397)
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-jfr6-9xqw-2g2q
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/d7a1c99322d5e1fc71932e722c0b5bb2fc525d3f
(v1.5.7-14)
CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid
means duri ...)
@@ -1172,7 +1172,7 @@ CVE-2026-87807 (siyuan versions before v3.8.2 contain an
authenticated SQL injec
CVE-2026-87806 (Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7
contain ...)
NOT-FOR-US: Parse Server
CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to validate offset and
length p ...)
- - zstd-jni-java <unfixed>
+ - zstd-jni-java <unfixed> (bug #1147397)
NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb
(v1.5.7-14)
CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection
vulnera ...)
@@ -5719,7 +5719,7 @@ CVE-2026-86479 (In JetBrains YouTrack before
2026.2.18788, 2026.1.14055, 2025.
CVE-2026-86478 (In JetBrains YouTrack before 2025.3.161254, 2026.1.14042
improper aut ...)
NOT-FOR-US: JetBrains
CVE-2026-86469 (A flaw was found in GLib2. When g_file_replace() is used with
G_FILE_C ...)
- - glib2.0 <unfixed>
+ - glib2.0 <unfixed> (bug #1147411)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2473839
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/4044
CVE-2026-86452 (Affected versions of MISP permit unauthenticated or weakly
constrained ...)
@@ -19621,7 +19621,7 @@ CVE-2026-76846 (Grav before 2.0.16 contains an
incomplete default denylist in th
CVE-2026-76839 (Grav before 2.0.16 allows sandboxed Twig templates to access
sensitive ...)
NOT-FOR-US: Grav CMS
CVE-2026-76816 (Netty is an asynchronous, event-driven network application
framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1147398)
NOTE:
https://github.com/netty/netty/security/advisories/GHSA-43fm-7cxg-hf3j
NOTE: Fixed by:
https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7
(netty-4.2.17.Final)
NOTE: Fixed by:
https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961
(netty-4.1.137.Final)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c32ba7fd6bc9f9dd0863a3544aae79da0539580
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6c32ba7fd6bc9f9dd0863a3544aae79da0539580
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits