Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c26215d9 by Moritz Muehlenhoff at 2026-09-27T22:46:54+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1216,10 +1216,11 @@ CVE-2026-88389 (Espruino 2v29 (commit bffc6d0) contains
a NULL pointer dereferen
CVE-2026-88388 (Espruino 2v29 (commit bffc6d0) contains a stack-based buffer
overflow ...)
NOT-FOR-US: Espruino
CVE-2026-88387 (LibRaw 0.22.0 contains an incorrect numeric conversion
vulnerability i ...)
- - libraw <unfixed> (bug #1149063)
+ - libraw <unfixed> (bug #1149063; unimportant)
NOTE: https://github.com/LibRaw/LibRaw/issues/844
NOTE: https://github.com/LibRaw/LibRaw/pull/853
NOTE: Fixed by:
https://github.com/LibRaw/LibRaw/commit/b41cbbd61951783e0440590dae55411a16185bdf
(master)
+ NOTE: Negligible security impact
CVE-2026-88386 (libsndfile 1.2.2 contains a misaligned memory access issue in
psf_binh ...)
- libsndfile <unfixed> (bug #1149062)
[trixie] - libsndfile <no-dsa> (Minor issue)
@@ -6700,6 +6701,7 @@ CVE-2026-95511
REJECTED
CVE-2026-95508 (A heap-based buffer overflow was found in the DHCPv6 and TFTP
response ...)
- libslirp 4.9.5-1 (bug #1148836)
+ [trixie] - libslirp <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537748
NOTE: Fixed by:
https://gitlab.freedesktop.org/slirp/libslirp/-/commit/97f2dd0afea0db8b31135f768ecafe0775722a25
(v4.9.5)
NOTE: Fixed by:
https://gitlab.freedesktop.org/slirp/libslirp/-/commit/5815f119c334c26e6e7a14ac87eca12b69918627
(v4.9.5)
@@ -6707,6 +6709,7 @@ CVE-2026-95508 (A heap-based buffer overflow was found in
the DHCPv6 and TFTP re
NOTE: is only for the DHCPv6 part
CVE-2026-95507
- libslirp 4.9.5-1 (bug #1148835)
+ [trixie] - libslirp <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537747
NOTE: Fixed by:
https://gitlab.freedesktop.org/slirp/libslirp/-/commit/b4b2b07812fcadd2754281e5ae8d9fe2bfb3c96a
(v4.9.5)
CVE-2026-95503 (A flaw was found in the Kerberos federation provider of
Keycloak, an o ...)
@@ -6785,6 +6788,7 @@ CVE-2026-90882 (The open-vsx.org deployment returned
Access-Control-Allow-Origin
NOT-FOR-US: open-vsx.org
CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access
provide ...)
- sssd <unfixed> (bug #1148827)
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479483
CVE-2026-8849 (Use After Free vulnerability in RTI Connext Professional
(Security Plu ...)
NOT-FOR-US: RTI Connext
=====================================
data/dsa-needed.txt
=====================================
@@ -76,6 +76,8 @@ kitty
libheif (aron)
Wait until new upstream release lands in sid
--
+libwebsockets (jmm)
+--
linux (carnil)
Wait until more issues have piled up, though try to regulary rebase for point
releases to more 6.12.y versions
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c26215d9fbe27fa9e1a22b6ce8d3b9d514751c73
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c26215d9fbe27fa9e1a22b6ce8d3b9d514751c73
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits