Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
81b0d837 by Moritz Muehlenhoff at 2026-09-12T19:46:09+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,9 +3,11 @@ CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly 
validate email address
        NOTE: Fixed by: 
https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2
 (v5.1.3)
 CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and 
password to an ...)
        - ironic <unfixed>
+       [trixie] - ironic <no-dsa> (Minor issue)
        NOTE: https://bugs.launchpad.net/ironic/+bug/2162816
 CVE-2026-90460 (An issue was discovered in OpenStack Keystone before 29.0.3. 
Tokens ob ...)
        - keystone <unfixed>
+       [trixie] - keystone <no-dsa> (Minor issue)
        NOTE: https://bugs.launchpad.net/keystone/+bug/2159643
        NOTE: https://bugs.launchpad.net/keystone/+bug/2158931
        NOTE: https://review.opendev.org/c/openstack/keystone/+/1002330
@@ -1985,6 +1987,7 @@ CVE-2026-78224 (The XSLT Transformer Step builds a bare 
TransformerFactory witho
        NOT-FOR-US: NextGen Healthcare
 CVE-2026-77159 (A symlink-following flaw was found in libvirt's 
qemuTPMEmulatorPrepare ...)
        - libvirt 12.7.0-1
+       [trixie] - libvirt <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/libvirt/libvirt/-/work_items/909
        NOTE: Fixed by: 
https://gitlab.com/libvirt/libvirt/-/commit/68e03ee02ff4826827f23d67d6b9eae49d7b9fb1
 (v12.7.0-rc1)
 CVE-2026-72710 (SPIP before 4.4.18 contains a remote code execution 
vulnerability in t ...)
@@ -2611,9 +2614,11 @@ CVE-2026-88268 (GeoVision GV-LPC2211 V1.13 contains an 
authenticated stack buffe
        NOT-FOR-US: GeoVision
 CVE-2026-88265 (A flaw was found in crun. After pivot_root, reopening 
/dev/null for st ...)
        - crun <unfixed> (bug #1147401)
+       [trixie] - crun <postponed> (Minor issue, revisit when fixed upstream)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531224
 CVE-2026-88264 (A flaw was found in crun. When the container configuration 
does not gi ...)
        - crun <unfixed> (bug #1147401)
+       [trixie] - crun <postponed> (Minor issue, revisit when fixed upstream)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531223
 CVE-2026-88060 (Angular is a development platform for building mobile and 
desktop web  ...)
        - angular.js <unfixed>
@@ -3070,8 +3075,9 @@ CVE-2026-79516 (An out-of-bounds read in the 
stbsp_vsnprintf function (stb_sprin
        - libstb <unfixed>
        NOTE: https://github.com/nothings/stb/issues/1963
 CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of 
nothings ...)
-       - libstb <unfixed>
+       - libstb <unfixed> (unimportant)
        NOTE: https://github.com/nothings/stb/issues/1962
+       NOTE: truetype parser only supported for trusted font files
 CVE-2026-79514 (An out-of-bounds read in the gf_dm_data_received function 
(downloader. ...)
        - gpac <removed>
 CVE-2026-79513 (A divide-by-zero vulnerability in the 
gf_dash_get_timeline_duration fu ...)
@@ -11451,11 +11457,13 @@ CVE-2026-XXXX [heap-use-after-free in 
decoder_context::reset() via dangling prev
        NOTE: 
https://github.com/strukturag/libde265/commit/07bc500d45f781a7e2915afb7eebc2d6d9a541c9
 (v1.1.2)
 CVE-2026-56855 (Previously, after a channel has been established, a malicious 
peer cou ...)
        - golang-go.crypto 1:0.56.0-1
+       [trixie] - golang-go.crypto <no-dsa> (Minor issue)
        [bookworm] - golang-go.crypto <postponed> (Limited support)
        NOTE: https://github.com/golang/go/issues/81317
        NOTE: Fixed by: 
https://github.com/golang/crypto/commit/86efde54dc7069251a8b007026c500d28e4239ce
 (v0.56.0)
 CVE-2026-78662 (Previously, a channel registered in the mux's chanList is not 
usable u ...)
        - golang-go.crypto 1:0.56.0-1
+       [trixie] - golang-go.crypto <no-dsa> (Minor issue)
        [bookworm] - golang-go.crypto <postponed> (Limited support)
        NOTE: https://github.com/golang/go/issues/81316
        NOTE: Fixed by: 
https://github.com/golang/crypto/commit/a6cdac60840750226b15617ac8858be44361b36b
 (v0.56.0)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b0d83736d7557a3c362a3cf33d0abe16a982f9

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b0d83736d7557a3c362a3cf33d0abe16a982f9
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to