Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
45de1efc by Salvatore Bonaccorso at 2026-09-18T22:32:41+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -57,9 +57,9 @@ CVE-2026-93687 (braces through 3.0.3 contains a stack 
overflow vulnerability in
 CVE-2026-93685 (A flaw was found in the multicluster-observability-addon. A 
remote att ...)
        NOT-FOR-US: multicluster-observability-addon (Red Hat Advanced Cluster 
Management for Kubernetes 2)
 CVE-2026-93660 (SQLBot through 1.10.1 fails to verify dashboard ownership in 
update_re ...)
-       TODO: check
+       NOT-FOR-US: SQLBot
 CVE-2026-93659 (Concrete CMS Community Store before 2.7.8 renders 
customer-supplied or ...)
-       TODO: check
+       NOT-FOR-US: Concrete CMS Community Store
 CVE-2026-93658 (uutils coreutils versions before 0.10.0 apply setuid or setgid 
mode to ...)
        TODO: check
 CVE-2026-93657 (hickory-resolver versions before 0.26.2 fail to propagate 
bogus DNSSEC ...)
@@ -67,17 +67,17 @@ CVE-2026-93657 (hickory-resolver versions before 0.26.2 
fail to propagate bogus
 CVE-2026-93653 (A denial of service flaw was found in Poppler's Splash 
backend. A craf ...)
        TODO: check
 CVE-2026-93652 (Integer overflow in \xb5D3TN v0.15.0 TCPCLv3 handshake causes 
heap ove ...)
-       TODO: check
+       NOT-FOR-US: ud3tn
 CVE-2026-93650 (A vulnerability was determined in Saleor up to 
3.20.118/3.21.54/3.22.4 ...)
-       TODO: check
+       NOT-FOR-US: Saleor
 CVE-2026-93606 (vm2 (npm) versions 3.12.0 and earlier contain a sandbox escape 
in `VM` ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-93605 (vm2 NodeVM versions before 3.12.1 contain a sandbox escape 
vulnerabili ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-93604 (vm2 through 3.12.0 exposes Node.js's crypto.setFips() function 
to untr ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-93603 (vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle 
a nulli ...)
-       TODO: check
+       NOT-FOR-US: Node.js vm2
 CVE-2026-93602 (rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 
contain fau ...)
        TODO: check
 CVE-2026-93601 (rustls-webpki (the Rust webpki fork used by rustls) versions 
>= 0.101. ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45de1efc7f4ac64ac4cbcc2868b5e8f08153ed13

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45de1efc7f4ac64ac4cbcc2868b5e8f08153ed13
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to