Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
aa961736 by Salvatore Bonaccorso at 2026-09-12T17:37:45+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1783,7 +1783,7 @@ CVE-2026-8303 (Incorrect privilege assignment
vulnerability in TUBITAK BILGEM So
CVE-2026-8301 (Improper neutralization of special elements used in an OS
command ('OS ...)
NOT-FOR-US: Pardus Boot Repair
CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access
to the ...)
- - multipath-tools <unfixed>
+ - multipath-tools <unfixed> (bug #1147523)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470013
NOTE:
https://github.com/opensvc/multipath-tools/security/advisories/GHSA-hmcm-9cq4-r2xm
CVE-2026-89298 (A flaw was found in the Dynamic Client Registration service of
Keycloa ...)
@@ -1909,11 +1909,11 @@ CVE-2026-87910 (When tarfile extracts a link on a
system that doesn't support li
NOTE: https://github.com/python/cpython/pull/157266
NOTE:
https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2
(main)
CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In
versions b ...)
- - node-morgan <unfixed>
+ - node-morgan <unfixed> (bug #1147520)
NOTE:
https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
NOTE: Fixed by:
https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee
(1.12.1)
CVE-2026-87776 (compression is a Node.js and Express compression middleware.
In versio ...)
- - node-compression <unfixed>
+ - node-compression <unfixed> (bug #1147519)
NOTE:
https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95
NOTE: Fixed by:
https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff
(v1.8.2)
CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal
vulnerabi ...)
@@ -1939,7 +1939,7 @@ CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a
hard-coded credential for
CVE-2026-84390 (A inclusion of sensitive information in source code
vulnerability in F ...)
NOT-FOR-US: Fortinet
CVE-2026-82617 (The two built-in name-finder patterns exposed by
opennlp.tools.namefin ...)
- - apache-opennlp <unfixed>
+ - apache-opennlp <unfixed> (bug #1147511)
NOTE: https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3
CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier
allow an au ...)
NOT-FOR-US: NextGen Connect (Mirth Connect)
@@ -1978,7 +1978,7 @@ CVE-2026-79393 (A heap-based buffer overflow
vulnerability in the WS-Addressing
CVE-2026-79362 (Certain Woltlab products are affected by RCE via Cache
Poisoning. WCF ...)
NOT-FOR-US: Woltlab
CVE-2026-78807 (An issue in wpa_supplicant all versions before v.2.12 allows a
local a ...)
- - wpa <unfixed>
+ - wpa <unfixed> (bug #1147510)
NOTE:
https://w1.fi/security/2026-2/missing-network-context-validation-for-pmksa-caching.txt
NOTE: Fixed by:
https://git.w1.fi/cgit/hostap/commit/?id=de5e73a03c34d83568afb3183b2b28c8d7641a30
CVE-2026-78224 (The XSLT Transformer Step builds a bare TransformerFactory
without the ...)
@@ -2021,7 +2021,7 @@ CVE-2026-6640 (The Media Library Assistant plugin for
WordPress is vulnerable to
CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3 rendered
remote ...)
NOT-FOR-US: Concrete CMS
CVE-2026-68497 (jackson-databind binds a JSON string to a
javax.xml.datatype.Duration ...)
- - jackson-databind <unfixed>
+ - jackson-databind <unfixed> (bug #1147507)
NOTE:
https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7
NOTE: https://github.com/FasterXML/jackson-databind/pull/6127
NOTE: Fixed by:
https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd
(jackson-databind-2.18.10)
@@ -2151,7 +2151,7 @@ CVE-2026-89094 (Forgejo before 16.0.4 allows remote code
execution via a crafted
CVE-2026-89089 (A SQL injection vulnerability exists in the
JasperReports-based report ...)
NOT-FOR-US: OpenNMS
CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
- - ocaml-cstruct <unfixed>
+ - ocaml-cstruct <unfixed> (bug #1147522)
NOTE: https://osv.dev/vulnerability/OSEC-2026-20
NOTE: https://github.com/mirage/ocaml-cstruct/pull/324 (v6.3.0)
CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to
validate ...)
@@ -2818,7 +2818,7 @@ CVE-2026-85228 (An integer overflow in the tensor buffer
validation component in
CVE-2026-85217 (A maliciously crafted add-in, when installed and executed in
Autodesk ...)
NOT-FOR-US: Autodesk
CVE-2026-84828 (A flaw was found in PCS (Pacemaker Configuration System). A
local atta ...)
- - pcs <unfixed>
+ - pcs <unfixed> (bug #1147515)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527320
NOTE: Introduced with:
https://github.com/ClusterLabs/pcs/commit/9178b78d11baa70e700a5c0d9fc1c17f27d452fa
(0.10.8)
NOTE: Fixed by:
https://github.com/ClusterLabs/pcs/commit/b41eaf3c6e2ecfc575c42442fb02b8ef05b4dd6a
@@ -3048,7 +3048,7 @@ CVE-2026-87011 (Open WebUI is an extensible,
feature-rich, and user-friendly sel
CVE-2026-85645 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop
Contact For ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84939 (Path traversal vulnerability in Apache FreeMarker template
loading mec ...)
- - libfreemarker-java <unfixed>
+ - libfreemarker-java <unfixed> (bug #1147516)
NOTE: https://lists.apache.org/thread/hrd7o2ylwkkswdyhyzllgqt0f80kyd5y
CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with
unrestricted u ...)
NOT-FOR-US: BurgerEditor
@@ -3242,10 +3242,10 @@ CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail
to validate closed state
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e
(v1.5.7-14)
NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555
(v1.5.7-14)
CVE-2026-87876 (Two case-insensitive comparisons on request-derived usernames
outside ...)
- - cups <unfixed>
+ - cups <unfixed> (bug #1147521)
NOTE:
https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2
CVE-2026-87875 (The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c
lacks a sour ...)
- - cups <unfixed>
+ - cups <unfixed> (bug #1147521)
NOTE:
https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq
CVE-2026-87874 (A flaw was found in the memcached cache plugin of the
community.genera ...)
- ansible <unfixed>
@@ -3424,7 +3424,7 @@ CVE-2026-85102 (Improper certificate trust validation
during VPN negotiation in
NOT-FOR-US: Check Point
CVE-2026-83530 (A user could provide an expression whose string length is
longer than ...)
- golang-cel-cel-go 0.32.0+ds-1
- - golang-github-google-cel-go <unfixed>
+ - golang-github-google-cel-go <unfixed> (bug #1147513)
NOTE: https://github.com/cel-expr/cel-go/pull/1302
NOTE: Fixed by:
https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a
(v0.29.0)
CVE-2026-82563 (An attacker could impersonate the camera and place themselves
in a man ...)
@@ -5052,7 +5052,7 @@ CVE-2026-87050
CVE-2026-87049
NOT-FOR-US: operator-foundry
CVE-2026-86564 (A flaw was found in DPDK lib/vhost. Missing length validation
before r ...)
- - dpdk <unfixed>
+ - dpdk <unfixed> (bug #1147518)
[trixie] - dpdk <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2529682
CVE-2026-85630 (HTML::FormHandler versions before 0.410002 for Perl render
field attri ...)
@@ -5835,7 +5835,7 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python
bindings enabled. A remo
NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/397
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/libxml2/-/commit/f41e1865781f74d1cadfe2fbdfeefed946026f12
(v2.15.3)
CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts
user-supplied ZIP a ...)
- - gnome-tweaks <unfixed>
+ - gnome-tweaks <unfixed> (bug #1147509)
[trixie] - gnome-tweaks <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/gnome-tweaks/-/issues/542
CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability
in the s ...)
@@ -8363,7 +8363,7 @@ CVE-2026-86231 (A security flaw has been discovered in
mwiede jsch up to 2.28.5.
CVE-2026-86228 (A security vulnerability has been detected in JeecgBoot up to
3.9.3. T ...)
NOT-FOR-US: JeecgBoot
CVE-2026-86227 (A weakness has been identified in valkey-io valkey up to
9.0.5/9.1.1. ...)
- - valkey <unfixed>
+ - valkey <unfixed> (bug #1147517)
NOTE: https://github.com/valkey-io/valkey/issues/4222
NOTE: https://github.com/valkey-io/valkey/pull/4229
NOTE: Fixed by:
https://github.com/valkey-io/valkey/commit/4691888e7fab3df128f0bde5750c9fde2ae552fa
(unstable)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aa961736ae34cc770f97999966ccc1b31399f99b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aa961736ae34cc770f97999966ccc1b31399f99b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits