Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d5e62ac2 by Moritz Muehlenhoff at 2026-09-22T19:48:10+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -576,6 +576,7 @@ CVE-2026-93433 (A flaw was found in libstoragemgmt. An 
attacker with control ove
        NOT-FOR-US: libstoragemgmt
 CVE-2026-94184 (A stack-based buffer overflow flaw was found in fetchmail when 
built w ...)
        - fetchmail <unfixed>
+       [trixie] - fetchmail <no-dsa> (Minor issue)
        NOTE: https://www.fetchmail.info/fetchmail-SA-2026-01.txt
        NOTE: Fixed by: 
https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92
 (6.6.7.rc1)
 CVE-2026-94449 (A flaw was found in the SmallRye Fault Tolerance library, 
which is use ...)
@@ -927,6 +928,7 @@ CVE-2026-93963 (A security vulnerability has been detected 
in itsourcecode Leave
        NOT-FOR-US: itsourcecode System
 CVE-2026-93962 (A weakness has been identified in Kamailio up to 
5.8.8/6.0.7/6.1.4/6.2 ...)
        - kamailio <unfixed>
+       [trixie] - kamailio <postponed> (Minor issue, fix along with future DSA)
        NOTE: https://github.com/kamailio/kamailio/issues/4876
        NOTE: https://github.com/kamailio/kamailio/pull/4877
        NOTE: Fixed by: 
https://github.com/kamailio/kamailio/commit/38711a3e788de0130d48cb485578c482b57d9351
 (master)
@@ -5792,6 +5794,7 @@ CVE-2026-82561 (Apache NiFi 1.5.0 through 2.11.0 provide 
REST API methods that r
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-81872 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. 
Prior to v ...)
        - golang-opentelemetry-otel <unfixed>
+       [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
        NOTE: 
https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hjf4-fphr-2h65
        NOTE: https://github.com/open-telemetry/opentelemetry-go/issues/6797
        NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/8620
@@ -5799,17 +5802,20 @@ CVE-2026-81872 (OpenTelemetry-Go is the Go 
implementation of OpenTelemetry. Prio
        NOTE: Fixed by: 
https://github.com/open-telemetry/opentelemetry-go/commit/ba71b09e6ed272e93a669aeaec1e98b1df4cc582
 (v1.45.0)
 CVE-2026-81871 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. 
Prior to v ...)
        - golang-opentelemetry-otel <unfixed>
+       [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
        NOTE: 
https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x
        NOTE: Introduced with: 
https://github.com/open-telemetry/opentelemetry-go/commit/d99c76fa32fbbcf3e1e0cee4c49a7f181b0697bb
 (v1.28.0)
        NOTE: Fixed by: 
https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c
 (v1.45.0)
 CVE-2026-81870 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. 
From versi ...)
        - golang-opentelemetry-otel <unfixed>
+       [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
        NOTE: 
https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg
        NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/8438
        NOTE: Introduced with: 
https://github.com/open-telemetry/opentelemetry-go/commit/a1fff3c2588c783d1f3f6fd2315aa2660fc6d330
 (v1.5.0)
        NOTE: Fixed by: 
https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38
 (v1.45.0)
 CVE-2026-81869 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. 
From versi ...)
        - golang-opentelemetry-otel 1.43.0-1
+       [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
        NOTE: 
https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-p9f8-wvj8-2fg8
        NOTE: https://github.com/open-telemetry/opentelemetry-go/issues/5996
        NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/5997
@@ -12336,6 +12342,7 @@ CVE-2026-85892 (Concurrent execution using shared 
resource with improper synchro
        NOT-FOR-US: Microsoft
 CVE-2026-84445 (gRPC-Go is the Go language implementation of gRPC. Prior to 
1.82.2 and ...)
        - golang-google-grpc <unfixed>
+       [trixie] - golang-google-grpc <no-dsa> (Minor issue)
        [bookworm] - golang-google-grpc <postponed> (Limited support, minor 
issue; DoS, clean crash)
        NOTE: 
https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj
        NOTE: https://github.com/grpc/grpc-go/issues/9354
@@ -15146,9 +15153,12 @@ CVE-2026-89260 (MoguBlog through 6.2 contains an XML 
external entity injection v
        NOT-FOR-US: MoguBlog
 CVE-2026-89259 (Hugo is a static site generator. From v0.161.0, Hugo executes 
Node too ...)
        - hugo 0.165.0-1
+       [trixie] - hugo <not-affected> (Incomplete fix for CVE-2026-44301 not 
shipped)
+       [bookworm] - hugo <not-affected> (Incomplete fix for CVE-2026-44301 not 
shipped)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-vrm6-x8vp-mv2r
 CVE-2026-89258 (Hugo is a static site generator. In versions after v0.123.0 
and before ...)
        - hugo 0.165.0-1
+       [trixie] - hugo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-vrv5-r5rf-6v4j
 CVE-2026-89257 (AVideo through 29.0 contains an insecure direct object 
reference (IDOR ...)
        NOT-FOR-US: WWBN AVideo
@@ -127827,6 +127837,7 @@ CVE-2026-44301 (Hugo is a static site generator. From 
0.43 to before 0.161.0, wh
        [bookworm] - hugo <no-dsa> (Minor issue)
        [bullseye] - hugo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-x597-9fr4-5857
+       NOTE: When fixing in stable releases, CVE-2026-89259 is needed
 CVE-2026-44296 (Deskflow is a keyboard and mouse sharing app. Prior to 
1.26.0.167, a r ...)
        - deskflow 1.26.0+dfsg-3
        [trixie] - deskflow <no-dsa> (Minor issue)


=====================================
data/dsa-needed.txt
=====================================
@@ -40,6 +40,8 @@ erlang
 --
 exim4
 --
+expat
+-
 firebird3.0
 --
 firebird4.0
@@ -51,8 +53,13 @@ gegl (jmm)
 --
 ghostscript (carnil)
 --
+graphicsmagick
+--
 gst-plugins-good1.0
 --
+hplip
+  security patches first need to be isolated
+--
 jackson-databind
 --
 jetty9



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5e62ac24b6f297f19d33cd703b5b09197771f55

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5e62ac24b6f297f19d33cd703b5b09197771f55
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to