Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
21e593c5 by Moritz Muehlenhoff at 2026-09-20T20:55:24+02:00
bugnums

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -445,7 +445,7 @@ CVE-2026-76790 (The Estatik Real Estate Plugin WordPress 
plugin before 4.3.5 doe
 CVE-2026-76554 (The WP Import Export Lite WordPress plugin before 3.9.35 does 
not veri ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-75895 (In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue 
was foun ...)
-       - libsmpp34 <unfixed>
+       - libsmpp34 <unfixed> (bug #1148557)
        [trixie] - libsmpp34 <no-dsa> (Minor issue)
        NOTE: 
https://cgit.osmocom.org/libsmpp34/commit/?id=af0e2912057551dab97bbe26e6a41f18a75f3bbb
 CVE-2026-75885 (A flaw was found in the OpenShift console. Unauthenticated 
access to t ...)
@@ -1051,7 +1051,7 @@ CVE-2026-75894 (In osmo-iuh from 0.1.0 through 1.8.0 a 
reachable assertion was f
        [trixie] - osmo-iuh <no-dsa> (Minor issue)
        NOTE: 
https://cgit.osmocom.org/osmo-iuh/commit/?id=f06967126f486bcb185ccf3d1a8f9bc02c4da1f6
 (1.8.1)
 CVE-2026-75893 (In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer 
overflow iss ...)
-       - osmo-bsc <unfixed>
+       - osmo-bsc <unfixed> (bug #1148556)
        [trixie] - osmo-bsc <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://cgit.osmocom.org/osmo-bsc/commit/?id=2852a03c153cd9418c2a86d0b2193ac41169dbb7
 CVE-2026-75892 (In osmo-ggsn 1.14.0 an out of bounds write issue was found in 
thegtp_d ...)
@@ -1093,7 +1093,7 @@ CVE-2026-65970 (OpenImageIO is a toolset for reading, 
writing, and manipulating
        NOTE: Fixed by: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/31201c22df477b105b105c0dcfbf5d3d46db431b
 (v3.2.0.3-beta1)
        NOTE: Introduced by: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/730687ae79bb6c3290afff535aa0e98b0531d165
 (v3.1.4.0-beta)
 CVE-2026-65969 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-9mwc-fjgj-8wmq
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5292
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/134977da625a84fc5a09a34321806f1fe0093c24
 (v3.2.0.3-beta1)
@@ -1103,12 +1103,12 @@ CVE-2026-64847 (AnyIO is a high level asynchronous 
concurrency and networking fr
        NOTE: https://github.com/agronholm/anyio/pull/1207
        NOTE: 
https://github.com/agronholm/anyio/commit/f1b7301c8264b0d2e8d24a5788fd29e93dea4040
 (4.14.2)
 CVE-2026-63638 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-9hxv-jvgr-3x8g
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5283
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/6f2b2e85b3b3933ccc5a46303d5535f99bfa39fb
 (v3.2.0.3-beta1)
 CVE-2026-63635 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-3c8w-9xvm-r6gf
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5282
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/50481b0f90932a4675f65f3cc26407139cb9e20e
 (v3.2.0.3-beta1)
@@ -1117,17 +1117,17 @@ CVE-2026-63458 (Perses is an open-source dashboard and 
visualization project for
 CVE-2026-63445 (Perses is an open-source dashboard and visualization project 
for obser ...)
        NOT-FOR-US: Perses
 CVE-2026-63422 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xh5r-whph-qmc5
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5295
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/7303134f13b0f9dc738b8ecabecd8c9f90cbd4c9
 (v3.2.0.3-beta1)
 CVE-2026-63420 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-x877-h4xx-5m5j
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5307
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/4995b25b8216552630e0aee0d8870e0d3aaae7ee
 (v3.2.0.3-beta1)
 CVE-2026-63419 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-w6wc-gcf4-5pj2
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5268
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/9cda48b150294c7f024e680a6c9b0402e50f4816
 (v3.2.0.3-beta1)
@@ -1146,7 +1146,7 @@ CVE-2026-63349 (AnyIO is a high level asynchronous 
concurrency and networking fr
 CVE-2026-63199 (Perses is an open-source dashboard and visualization project 
for obser ...)
        NOT-FOR-US: Perses
 CVE-2026-62943 (btrbk is a tool for creating snapshots and remote backups of 
Btrfs sub ...)
-       - btrbk <unfixed>
+       - btrbk <unfixed> (bug #1148559)
        NOTE: 
https://github.com/digint/btrbk/security/advisories/GHSA-pf45-7g54-65h5
        NOTE: 
https://github.com/digint/btrbk/commit/29ca3c093205395bdeb9dd98677ab4139c458aec 
(v0.32.7)
 CVE-2026-62282 (OpenCVE is a vulnerability intelligence platform. Prior to 
3.0.0, Open ...)
@@ -1170,19 +1170,19 @@ CVE-2026-61633 (NanoMQ is an MQTT broker. Prior to 
0.24.14, the NanoMQ client fu
 CVE-2026-60115
        REJECTED
 CVE-2026-59956 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-hjfv-gvxc-qgvh
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5251
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/f01bd16764b2a06f372899e3e302280a7f9c8c02
 (v3.2.0.3-beta1)
 CVE-2026-59181 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xh8r-vmqq-56pp
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5250
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/908f22f5528e88e5e96184c194caa26b54b2b85f
 (v3.2.0.3-beta1)
 CVE-2026-59163 (Mnemosyne is a memory layer for artificial intelligence 
agents. Prior  ...)
        NOT-FOR-US: Mnemosyne
 CVE-2026-59156 (OpenImageIO is a toolset for reading, writing, and 
manipulating image  ...)
-       - openimageio <unfixed>
+       - openimageio <unfixed> (bug #1148554)
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/security/advisories/GHSA-xvwr-x6ch-v2fq
        NOTE: https://github.com/AcademySoftwareFoundation/OpenImageIO/pull/5248
        NOTE: 
https://github.com/AcademySoftwareFoundation/OpenImageIO/commit/b0de7d40d06eb4abc7ef14c1321a1a2a976d8c1c
 (v3.2.0.3-beta1)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21e593c5f44ee0895853926cbc9f495ac221084a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21e593c5f44ee0895853926cbc9f495ac221084a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to