Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
4e25df9c by Moritz Muehlenhoff at 2026-09-25T14:01:12+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -275,6 +275,7 @@ CVE-2026-88376 (Bento4 1.6.0.0 contains an integer 
underflow vulnerability in AP
        NOT-FOR-US: Bento4
 CVE-2026-88373 (libde265 commit 4d45a6b contains a NULL pointer dereference 
vulnerabil ...)
        - libde265 1.1.2-1
+       [trixie] - libde265 <no-dsa> (Minor issue)
        NOTE: https://github.com/strukturag/libde265/issues/534
        NOTE: Fixed by: 
https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea
 (v1.1.2)
 CVE-2026-88372 (libsndfile 1.2.2 contains an integer overflow vulnerability in 
mat4_re ...)
@@ -298,6 +299,7 @@ CVE-2026-88365 (minimp3 commit ea99364f contains an integer 
overflow vulnerabili
        NOT-FOR-US: minimp3
 CVE-2026-88362 (MuJS e892c9fdb contains an incorrect numeric conversion 
vulnerability  ...)
        - mujs <unfixed>
+       [trixie] - mujs <no-dsa> (Minor issue)
        NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=709636
        NOTE: Fixed by: 
https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mujs.git/commit/?id=8a32c397b28fe45747ac4e9e4f3dca049825eda7
 CVE-2026-88361 (SumatraPDF 3.6.1 contains an integer overflow vulnerability in 
EngineM ...)
@@ -1854,12 +1856,14 @@ CVE-2026-88843 (The MasterStudy LMS WordPress Plugin  
WordPress plugin before 3.
        NOT-FOR-US: WordPress plugin
 CVE-2026-88840 (BusyBox TLS get_client_hello() reads past the end of the input 
buffer  ...)
        - busybox <unfixed>
+       [trixie] - busybox <not-affected> (Vulnerable code not present)
+       [bookworm] - busybox <not-affected> (Vulnerable code not present)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531354
-       TODO: check
+       NOTE: Introduced by: 657fbcd62c6cb1e15692ad471bc94cfe6efd8a5f (1_38_0)
 CVE-2026-88839 (BusyBox passwd/group tokenize() references a stale endpoint 
pointer af ...)
        - busybox <unfixed>
+       [trixie] - busybox <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531353
-       TODO: check
 CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as 
plaintext durin ...)
        - busybox <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
@@ -6147,6 +6151,7 @@ CVE-2026-63199 (Perses is an open-source dashboard and 
visualization project for
        NOT-FOR-US: Perses
 CVE-2026-62943 (btrbk is a tool for creating snapshots and remote backups of 
Btrfs sub ...)
        - btrbk <unfixed> (bug #1148559)
+       [trixie] - btrbk <no-dsa> (Minor issue)
        NOTE: 
https://github.com/digint/btrbk/security/advisories/GHSA-pf45-7g54-65h5
        NOTE: Introduced with: 
https://github.com/digint/btrbk/commit/8d0d7edda7cc775b87fd450266b756885f1eaa80 
(v0.29.0)
        NOTE: Fixed by: 
https://github.com/digint/btrbk/commit/29ca3c093205395bdeb9dd98677ab4139c458aec 
(v0.32.7)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e25df9c0e39ba0d2bff4e484daed0d1b4ec1db2

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e25df9c0e39ba0d2bff4e484daed0d1b4ec1db2
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to