Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
45de1efc by Salvatore Bonaccorso at 2026-09-18T22:32:41+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -57,9 +57,9 @@ CVE-2026-93687 (braces through 3.0.3 contains a stack
overflow vulnerability in
CVE-2026-93685 (A flaw was found in the multicluster-observability-addon. A
remote att ...)
NOT-FOR-US: multicluster-observability-addon (Red Hat Advanced Cluster
Management for Kubernetes 2)
CVE-2026-93660 (SQLBot through 1.10.1 fails to verify dashboard ownership in
update_re ...)
- TODO: check
+ NOT-FOR-US: SQLBot
CVE-2026-93659 (Concrete CMS Community Store before 2.7.8 renders
customer-supplied or ...)
- TODO: check
+ NOT-FOR-US: Concrete CMS Community Store
CVE-2026-93658 (uutils coreutils versions before 0.10.0 apply setuid or setgid
mode to ...)
TODO: check
CVE-2026-93657 (hickory-resolver versions before 0.26.2 fail to propagate
bogus DNSSEC ...)
@@ -67,17 +67,17 @@ CVE-2026-93657 (hickory-resolver versions before 0.26.2
fail to propagate bogus
CVE-2026-93653 (A denial of service flaw was found in Poppler's Splash
backend. A craf ...)
TODO: check
CVE-2026-93652 (Integer overflow in \xb5D3TN v0.15.0 TCPCLv3 handshake causes
heap ove ...)
- TODO: check
+ NOT-FOR-US: ud3tn
CVE-2026-93650 (A vulnerability was determined in Saleor up to
3.20.118/3.21.54/3.22.4 ...)
- TODO: check
+ NOT-FOR-US: Saleor
CVE-2026-93606 (vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape
in `VM` ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-93605 (vm2 NodeVM versions before 3.12.1 contain a sandbox escape
vulnerabili ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-93604 (vm2 through 3.12.0 exposes Node.js's crypto.setFips() function
to untr ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-93603 (vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle
a nulli ...)
- TODO: check
+ NOT-FOR-US: Node.js vm2
CVE-2026-93602 (rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5
contain fau ...)
TODO: check
CVE-2026-93601 (rustls-webpki (the Rust webpki fork used by rustls) versions
>= 0.101. ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45de1efc7f4ac64ac4cbcc2868b5e8f08153ed13
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45de1efc7f4ac64ac4cbcc2868b5e8f08153ed13
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits