Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
21245c89 by Moritz Muehlenhoff at 2026-09-11T19:07:04+02:00
bugnums

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -155,12 +155,12 @@ CVE-2026-79724 (IBM Langflow OSS 1.0.0 through 1.11.5 
could allow a remote attac
 CVE-2026-79723 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote 
authenticat ...)
        NOT-FOR-US: IBM
 CVE-2026-79592 (An out-of-bounds read vulnerability exists in the 
xls_dumpSummary() fu ...)
-       - r-cran-readxl <unfixed>
+       - r-cran-readxl <unfixed> (bug #1147420)
        [trixie] - r-cran-readxl <no-dsa> (Minor issue)
        NOTE: https://github.com/libxls/libxls/issues/162
        NOTE: 
https://github.com/libxls/libxls/pull/165/changes/6eed8bc1d51d6649faebab0184b21ab8768d8fa6
 CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists 
in the  ...)
-       - r-cran-readxl <unfixed>
+       - r-cran-readxl <unfixed> (bug #1147420)
        [trixie] - r-cran-readxl <no-dsa> (Minor issue)
        NOTE: https://github.com/libxls/libxls/issues/161
        NOTE: 
https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c
@@ -6065,7 +6065,7 @@ CVE-2022-51011 (PocketMine-MP before 4.2.10 fails to 
validate the total length o
 CVE-2022-51010 (PocketMine-MP versions before 4.4.2 fail to properly validate 
item IDs ...)
        NOT-FOR-US: PocketMine-MP
 CVE-2026-78254 (The ftp and scp tasks of Apache Ant can download files from a 
remote s ...)
-       - ant <unfixed>
+       - ant <unfixed> (bug #1147425)
        [trixie] - ant <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/06/2
        NOTE: 
https://github.com/apache/ant/commit/07ee9c418e3bd3e7d0287fc9aaba3011e88f0dc2 
(ANT_1.10.18_RC1)
@@ -12072,7 +12072,7 @@ CVE-2026-82629 (A vulnerability was determined in 
jeecgboot jeewx-boot up to 641
 CVE-2026-82217 (In Eclipse Theia versions 1.73.0 up to but not including 
1.75.0, the A ...)
        NOT-FOR-US: Eclipse
 CVE-2026-81624 (Undertow is a flexible performant web server used in JBoss EAP 
and Wil ...)
-       - undertow <unfixed>
+       - undertow <unfixed> (bug #1147427)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524868
 CVE-2026-79750 (MCPHub is a unified hub for centrally managing and dynamically 
orchest ...)
        NOT-FOR-US: MCPHub
@@ -13564,11 +13564,10 @@ CVE-2026-82328 (A flaw was found in the file-ico 
plugin in GIMP. When processing
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
 CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library 
used by R ...)
-       - libsolv <unfixed>
+       - libsolv <unfixed> (bug #1147424)
        [trixie] - libsolv <no-dsa> (Minor issue)
        [bookworm] - libsolv <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
-       TODO: check upstream status, no references from Red Hat
 CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. 
When proce ...)
        - gimp <unfixed> (bug #1146132; unimportant)
        NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16584
@@ -14653,7 +14652,7 @@ CVE-2026-82072 (Out of bounds read in V8 in Google 
Chrome prior to 151.0.7922.72
        - chromium 151.0.7922.71-1
        [bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-81934 (Redis contains a use-after-free vulnerability in the 
'tlsProcessPendin ...)
-       - redis <unfixed>
+       - redis <unfixed> (bug #1147423)
        NOTE: 
https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834 
(8.8.2)
 CVE-2026-81931 (Unrestricted Upload of File with Dangerous Type in the product 
photo u ...)
        NOT-FOR-US: Roskus Prospero Flow CRM
@@ -54869,7 +54868,7 @@ CVE-2026-64257 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: 
https://git.kernel.org/linus/8986c932905ea508d66da421eb2eb6e676ace1fe (7.2-rc4)
 CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated 
attacke ...)
        {DLA-4722-1}
-       - redis <unfixed>
+       - redis <unfixed> (bug #1147422)
        NOTE: Fixed by: 
https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c 
(8.6.5)
        NOTE: Fixed by: 
https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf 
(7.2.15)
        NOTE: fixed by: 
https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 
(6.2.23)
@@ -118863,7 +118862,7 @@ CVE-2026-25588 (RedisTimeSeries is a time-series 
module for Redis. In all versio
 CVE-2026-25243 (Redis is an in-memory data structure store. In versions of 
redis-serve ...)
        {DLA-4682-1}
        [experimental] - redis 5:8.6.3-1
-       - redis <unfixed>
+       - redis <unfixed> (bug #1147421)
        [bullseye] - redis <not-affected> (Vulnerable code not present; checks 
for dups introduced later)
        NOTE: 
https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4
        NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-25243-deep-dive
@@ -118872,7 +118871,7 @@ CVE-2026-25243 (Redis is an in-memory data structure 
store. In versions of redis
 CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of 
redis-s ...)
        {DLA-4682-1}
        [experimental] - redis 5:8.6.3-1
-       - redis <unfixed>
+       - redis <unfixed> (bug #1147421)
        [bullseye] - redis <ignored> (Invasive to backport entire timedOut 
mechanism etc.)
        NOTE: 
https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826
        NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-23631-dark-replica
@@ -118880,7 +118879,7 @@ CVE-2026-23631 (Redis is an in-memory data structure 
store. In all versions of r
        TODO: check redict and valkey
 CVE-2026-23479 (Redis is an in-memory data structure store. In redis-server 
from 7.2.0 ...)
        [experimental] - redis 5:8.6.3-1
-       - redis <unfixed>
+       - redis <unfixed> (bug #1147421)
        [bookworm] - redis <not-affected> (Vulnerable code not present)
        [bullseye] - redis <not-affected> (Vulnerable code not present)
        NOTE: 
https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21245c89020fff8ab82455594ee90a0e77acb7c8

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21245c89020fff8ab82455594ee90a0e77acb7c8
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to