Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
6674333c by Moritz Muehlenhoff at 2026-09-28T09:32:43+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -280,6 +280,7 @@ CVE-2026-100741 (Eval injection in the JScript event-script 
dispatcher in Progre
        NOT-FOR-US: hMailServer
 CVE-2026-XXXX [Infinite loops and heap OOB read when parsing malformed ASF 
headers]
        - libmms <unfixed> (bug #1149047)
+       [trixie] - libmms <no-dsa> (Minor issue)
 CVE-2026-XXXX [unbounded list indices from a Word document reach a wild 
pointer dereference in wvAssembleSimplePAP]
        - wv <unfixed> (bug #1148725)
 CVE-2026-XXXX [GHSA-h547-rmjf-5m2m: Table permission bypass using trailing 
newlines in table names]
@@ -481,6 +482,7 @@ CVE-2026-XXXX [TROVE-2026-053]
        NOTE: 
https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog
 CVE-2026-95510 [use of uninitialized struct sigaction]
        - inetutils <unfixed>
+       [trixie] - inetutils <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/26/1
        NOTE: Introduced with: 
https://codeberg.org/inetutils/inetutils/commit/9476515fd31e416739d850c1948e9222a53deea9
 (inetutils-1_9)
        NOTE: Fixed by: 
https://codeberg.org/inetutils/inetutils/commit/f756321da9b964fc27fc43652b73913117883047
@@ -583,18 +585,26 @@ CVE-2026-100695 (Adminer before 6.0.2 contains a 
cross-site scripting vulnerabil
        NOTE: Fixed by: 
https://github.com/vrana/adminer/commit/fd258bbd9e07f0e578f16dde3674648be5444b83
 (v6.0.2)
 CVE-2026-100694 (Hugo is a static site generator. In versions from v0.56.0 
through v0.1 ...)
        - hugo 0.166.0-1
+       [trixie] - hugo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-pq74-mj4h-cjq2
 CVE-2026-100693 (Hugo versions from v0.162.0 before v0.166.0 contain a 
case-sensitive v ...)
        - hugo 0.166.0-1
+       [trixie] - hugo <not-affected> (Vulnerable code not present, only 
affects 0.162 and later)
+       [bookworm] - hugo <not-affected> (Vulnerable code not present, only 
affects 0.162 and later)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-pmrv-x7gp-2rjw
 CVE-2026-100692 (Hugo is a static site generator. In versions after v0.123.0 
and before ...)
        - hugo 0.166.0-1
+       [trixie] - hugo <no-dsa> (Minor issue)
+       [bookworm] - hugo <not-affected> (Vulnerable code not present, only 
affects 0.123 and later)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-797m-7j5g-3rpr
 CVE-2026-100691 (Hugo versions 0.75.0 through 0.165.x contain a stored 
cross-site scrip ...)
        - hugo 0.166.0-1
+       [trixie] - hugo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-q4xf-287f-98r8
 CVE-2026-100690 (Hugo versions from v0.161.0 through v0.165.0 run Node.js 
tools (css.Po ...)
        - hugo 0.166.0-1
+       [trixie] - hugo <not-affected> (Vulnerable code not present, only 
affects 0.161 and later)
+       [bookworm] - hugo <not-affected> (Vulnerable code not present, only 
affects 0.161 and later)
        NOTE: 
https://github.com/gohugoio/hugo/security/advisories/GHSA-x3mx-cm49-8m9c
 CVE-2026-100689 (GitPython before 3.1.62 does not validate the `path` field 
read from a ...)
        - python-git 3.1.62-1
@@ -1087,6 +1097,7 @@ CVE-2026-100501 (Flame through 2.4.0 contains an improper 
restriction of excessi
        NOT-FOR-US: Flame
 CVE-2026-100419 (gitoxide gix-fs before 0.23.0 contains a path validation 
bypass vulner ...)
        - rust-gix-fs <unfixed>
+       [trixie] - rust-gix-fs <no-dsa> (Minor issue)
        NOTE: 
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5
        NOTE: Fixed by: 
https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875
 (gix-fs-v0.23.0)
 CVE-2026-100418 (Flame through 2.4.0 contains an information exposure 
vulnerability in  ...)
@@ -1293,6 +1304,7 @@ CVE-2026-93897 (The GeoDirectory \u2013 WP Business 
Directory Plugin and Classif
        NOT-FOR-US: WordPress plugin
 CVE-2026-93834 (A use-after-free vulnerability was found in QEMU's 9pfs 
subsystem. A r ...)
        - qemu <unfixed> (bug #1149064)
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4491
        NOTE: Introduced with: 
https://gitlab.com/qemu-project/qemu/-/commit/02cb7f3a256517cbf3136caff2863fbafc57b540
 (v1.0-rc0)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/fe9e30899ffceef25cf345ec83f76546afca19dd
 (master)
@@ -3459,6 +3471,7 @@ CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0) 
contains an uncontrolled me
 CVE-2026-88378 (QuickJS commit 04be24600 contains a heap out-of-bounds write 
condition ...)
        - quickjs-ng <unfixed>
        - quickjs <unfixed>
+       [trixie] - quickjs <no-dsa> (Minor issue)
        NOTE: https://github.com/bellard/quickjs/issues/549
        NOTE: https://github.com/bellard/quickjs/pull/553
 CVE-2026-88377 (Bento4 1.6.0.0 contains an integer underflow vulnerability in 
the avcC ...)
@@ -3503,9 +3516,8 @@ CVE-2026-88362 (MuJS e892c9fdb contains an incorrect 
numeric conversion vulnerab
 CVE-2026-88361 (SumatraPDF 3.6.1 contains an integer overflow vulnerability in 
EngineM ...)
        NOT-FOR-US: SumatraPDF
 CVE-2026-88360 (libvips 8.19.0 contains a memory access vulnerability when 
processing  ...)
-       - vips <unfixed> (bug #1149056; unimportant)
+       NOTE: Bogus CVE assignment for vips, was also filed at #1149056
        NOTE: https://github.com/libvips/libvips/issues/5187
-       NOTE: Not considered a security issue by upstream
 CVE-2026-88359 (libfyaml 0.9.6 contains a stack exhaustion vulnerability in 
fy_atom_it ...)
        - libfyaml <unfixed> (bug #1149055)
        [trixie] - libfyaml <no-dsa> (Minor issue)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6674333c11ec2c955ecc6232678ecacf97bc5438

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6674333c11ec2c955ecc6232678ecacf97bc5438
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to