Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
6674333c by Moritz Muehlenhoff at 2026-09-28T09:32:43+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -280,6 +280,7 @@ CVE-2026-100741 (Eval injection in the JScript event-script
dispatcher in Progre
NOT-FOR-US: hMailServer
CVE-2026-XXXX [Infinite loops and heap OOB read when parsing malformed ASF
headers]
- libmms <unfixed> (bug #1149047)
+ [trixie] - libmms <no-dsa> (Minor issue)
CVE-2026-XXXX [unbounded list indices from a Word document reach a wild
pointer dereference in wvAssembleSimplePAP]
- wv <unfixed> (bug #1148725)
CVE-2026-XXXX [GHSA-h547-rmjf-5m2m: Table permission bypass using trailing
newlines in table names]
@@ -481,6 +482,7 @@ CVE-2026-XXXX [TROVE-2026-053]
NOTE:
https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog
CVE-2026-95510 [use of uninitialized struct sigaction]
- inetutils <unfixed>
+ [trixie] - inetutils <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/26/1
NOTE: Introduced with:
https://codeberg.org/inetutils/inetutils/commit/9476515fd31e416739d850c1948e9222a53deea9
(inetutils-1_9)
NOTE: Fixed by:
https://codeberg.org/inetutils/inetutils/commit/f756321da9b964fc27fc43652b73913117883047
@@ -583,18 +585,26 @@ CVE-2026-100695 (Adminer before 6.0.2 contains a
cross-site scripting vulnerabil
NOTE: Fixed by:
https://github.com/vrana/adminer/commit/fd258bbd9e07f0e578f16dde3674648be5444b83
(v6.0.2)
CVE-2026-100694 (Hugo is a static site generator. In versions from v0.56.0
through v0.1 ...)
- hugo 0.166.0-1
+ [trixie] - hugo <no-dsa> (Minor issue)
NOTE:
https://github.com/gohugoio/hugo/security/advisories/GHSA-pq74-mj4h-cjq2
CVE-2026-100693 (Hugo versions from v0.162.0 before v0.166.0 contain a
case-sensitive v ...)
- hugo 0.166.0-1
+ [trixie] - hugo <not-affected> (Vulnerable code not present, only
affects 0.162 and later)
+ [bookworm] - hugo <not-affected> (Vulnerable code not present, only
affects 0.162 and later)
NOTE:
https://github.com/gohugoio/hugo/security/advisories/GHSA-pmrv-x7gp-2rjw
CVE-2026-100692 (Hugo is a static site generator. In versions after v0.123.0
and before ...)
- hugo 0.166.0-1
+ [trixie] - hugo <no-dsa> (Minor issue)
+ [bookworm] - hugo <not-affected> (Vulnerable code not present, only
affects 0.123 and later)
NOTE:
https://github.com/gohugoio/hugo/security/advisories/GHSA-797m-7j5g-3rpr
CVE-2026-100691 (Hugo versions 0.75.0 through 0.165.x contain a stored
cross-site scrip ...)
- hugo 0.166.0-1
+ [trixie] - hugo <no-dsa> (Minor issue)
NOTE:
https://github.com/gohugoio/hugo/security/advisories/GHSA-q4xf-287f-98r8
CVE-2026-100690 (Hugo versions from v0.161.0 through v0.165.0 run Node.js
tools (css.Po ...)
- hugo 0.166.0-1
+ [trixie] - hugo <not-affected> (Vulnerable code not present, only
affects 0.161 and later)
+ [bookworm] - hugo <not-affected> (Vulnerable code not present, only
affects 0.161 and later)
NOTE:
https://github.com/gohugoio/hugo/security/advisories/GHSA-x3mx-cm49-8m9c
CVE-2026-100689 (GitPython before 3.1.62 does not validate the `path` field
read from a ...)
- python-git 3.1.62-1
@@ -1087,6 +1097,7 @@ CVE-2026-100501 (Flame through 2.4.0 contains an improper
restriction of excessi
NOT-FOR-US: Flame
CVE-2026-100419 (gitoxide gix-fs before 0.23.0 contains a path validation
bypass vulner ...)
- rust-gix-fs <unfixed>
+ [trixie] - rust-gix-fs <no-dsa> (Minor issue)
NOTE:
https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5
NOTE: Fixed by:
https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875
(gix-fs-v0.23.0)
CVE-2026-100418 (Flame through 2.4.0 contains an information exposure
vulnerability in ...)
@@ -1293,6 +1304,7 @@ CVE-2026-93897 (The GeoDirectory \u2013 WP Business
Directory Plugin and Classif
NOT-FOR-US: WordPress plugin
CVE-2026-93834 (A use-after-free vulnerability was found in QEMU's 9pfs
subsystem. A r ...)
- qemu <unfixed> (bug #1149064)
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4491
NOTE: Introduced with:
https://gitlab.com/qemu-project/qemu/-/commit/02cb7f3a256517cbf3136caff2863fbafc57b540
(v1.0-rc0)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/fe9e30899ffceef25cf345ec83f76546afca19dd
(master)
@@ -3459,6 +3471,7 @@ CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0)
contains an uncontrolled me
CVE-2026-88378 (QuickJS commit 04be24600 contains a heap out-of-bounds write
condition ...)
- quickjs-ng <unfixed>
- quickjs <unfixed>
+ [trixie] - quickjs <no-dsa> (Minor issue)
NOTE: https://github.com/bellard/quickjs/issues/549
NOTE: https://github.com/bellard/quickjs/pull/553
CVE-2026-88377 (Bento4 1.6.0.0 contains an integer underflow vulnerability in
the avcC ...)
@@ -3503,9 +3516,8 @@ CVE-2026-88362 (MuJS e892c9fdb contains an incorrect
numeric conversion vulnerab
CVE-2026-88361 (SumatraPDF 3.6.1 contains an integer overflow vulnerability in
EngineM ...)
NOT-FOR-US: SumatraPDF
CVE-2026-88360 (libvips 8.19.0 contains a memory access vulnerability when
processing ...)
- - vips <unfixed> (bug #1149056; unimportant)
+ NOTE: Bogus CVE assignment for vips, was also filed at #1149056
NOTE: https://github.com/libvips/libvips/issues/5187
- NOTE: Not considered a security issue by upstream
CVE-2026-88359 (libfyaml 0.9.6 contains a stack exhaustion vulnerability in
fy_atom_it ...)
- libfyaml <unfixed> (bug #1149055)
[trixie] - libfyaml <no-dsa> (Minor issue)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6674333c11ec2c955ecc6232678ecacf97bc5438
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6674333c11ec2c955ecc6232678ecacf97bc5438
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits