Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d9feb674 by Moritz Muehlenhoff at 2026-09-28T16:58:19+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -179,6 +179,7 @@ CVE-2026-62439
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/gimp/-/commit/4427b9f31552060aafa5b03caee6ffdd6c257c8b
 (GIMP_3_2_6)
 CVE-2026-95622
        - modemmanager <unfixed>
+       [trixie] - modemmanager <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2540006
 CVE-2026-91182
        NOT-FOR-US: Red Hat open-cluster-management
@@ -588,18 +589,22 @@ CVE-2026-100703 (Kyverno 1.16.0 through 1.19.0 registers 
the globalcontext.Lib C
        NOT-FOR-US: Kyverno
 CVE-2026-100702 (Nodemailer before 10.0.2 fails to properly flatten deeply 
nested array ...)
        - node-nodemailer 10.0.10+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8vvx-rff5-p5rq
        NOTE: Fixed by: 
https://github.com/nodemailer/nodemailer/commit/ebe084940aef88278afc6016b78c6d1c3821bb66
 (v10.0.2)
 CVE-2026-100701 (Nodemailer versions 5.0.0 through 10.0.1 use a process-global 
DNS cach ...)
        - node-nodemailer 10.0.10+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-6vj9-mwq6-2f5v
        NOTE: Fixed by: 
https://github.com/nodemailer/nodemailer/commit/a6512dbcb3c6e7f2f70d3acccc5752defe3c61fe
 (v10.0.2)
 CVE-2026-100700 (nodemailer before 10.0.6 contains a denial of service 
vulnerability in ...)
        - node-nodemailer 10.0.10+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j
        NOTE: Fixed by: 
https://github.com/nodemailer/nodemailer/commit/437d7fc47403df176bc39271641541b7a9bce102
 (v10.0.6)
 CVE-2026-100699 (Nodemailer is a Node.js email-sending library. In versions >= 
9.1.0 an ...)
        - node-nodemailer 10.0.10+~8.0.1-1
+       [trixie] - node-nodemailer <no-dsa> (Minor issue)
        NOTE: 
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-g57g-f23g-4646
        NOTE: Fixed by: 
https://github.com/nodemailer/nodemailer/commit/2f36eb1aa1dd33e312411dc9b888548e14db54ee
 (v10.0.9)
 CVE-2026-100698 (Adminer 5.5.1 through 6.0.1 improperly parses the login 
'server' strin ...)
@@ -3357,12 +3362,15 @@ CVE-2026-96750 (MongoDB Compass can interpolate a 
database name without escaping
        NOT-FOR-US: mongodb-js (not same as node-mongodb)
 CVE-2026-96749 (An integer overflow in the BSON document encoding component of 
the Mon ...)
        - pymongo <unfixed> (bug #1148967)
+       [trixie] - pymongo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-v4x9-3549-crwv
 CVE-2026-96748 (PyMongo's connection string parsing decodes percent-encoded 
characters ...)
        - pymongo <unfixed> (bug #1148967)
+       [trixie] - pymongo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-vp6j-j7w5-5xjj
 CVE-2026-96747 (The client-side field level encryption support in the MongoDB 
Python D ...)
        - pymongo <unfixed> (bug #1148967)
+       [trixie] - pymongo <no-dsa> (Minor issue)
        NOTE: 
https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-qx36-8mw2-4r3x
 CVE-2026-96746 (An out-of-bounds write in the connection-monitoring logic of 
the Mongo ...)
        - mongo-c-driver 2.5.5-1
@@ -5183,24 +5191,24 @@ CVE-2026-88839 (BusyBox passwd/group tokenize() 
references a stale endpoint poin
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531353
 CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as 
plaintext durin ...)
        - busybox <unfixed>
+       [trixie] - busybox <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
-       TODO: check
 CVE-2026-88835 (BusyBox dpkg read_package_field() steps past a NUL terminator 
on malfo ...)
        - busybox <unfixed> (unimportant)
        NOTE: ttps://bugzilla.redhat.com/show_bug.cgi?id=2531349
        NOTE: Crash in CLI tool, no security impact
 CVE-2026-88832 (BusyBox romfs volume ID parsing uses unbounded strlen on 
attacker-cont ...)
        - busybox <unfixed>
+       [trixie] - busybox <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531345
-       TODO: check
 CVE-2026-88831 (BusyBox httpd IP deny rules with invalid CIDR prefix lengths 
fail open ...)
        - busybox <unfixed>
+       [trixie] - busybox <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531346
-       TODO: check
 CVE-2026-88830 (A unit confusion in BusyBox TLS Montgomery reduction buffer 
allocation ...)
        - busybox <unfixed>
+       [trixie] - busybox <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531344
-       TODO: check
 CVE-2026-87978 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does 
not ver ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-87900 (Argument injection in WP Toolkit for cPanel 6.11.2-10794 and 
earlier a ...)
@@ -5347,7 +5355,9 @@ CVE-2026-80338 (The CMB2 WordPress plugin before 2.13.0 
does not perform any cap
        NOT-FOR-US: WordPress plugin
 CVE-2026-79616 (Out-of-bounds read while parsing untrusted SVG path strings in 
Qt Quic ...)
        - qt6-declarative 6.11.2+dfsg-3
+       [trixie] - qt6-declarative <no-dsa> (Minor issue)
        - qtdeclarative-opensource-src <unfixed>
+       [trixie] - qtdeclarative-opensource-src <no-dsa> (Minor issue)
        NOTE: https://codereview.qt-project.org/c/qt/qtdeclarative/+/754718
        NOTE: 
https://github.com/qt/qtdeclarative/commit/0aba8c7674dbbbaaa142775247249e297a339c85
 CVE-2026-79310 (webpy web.py 0.76 is vulnerable to server-side template 
injection (SST ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -73,6 +73,8 @@ jupyterlab
 --
 kitty
 --
+libnet-idn-encode-perl
+--
 libwebsockets (jmm)
 --
 linux (carnil)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9feb674a08acf9ce85346e66ef32574015bed5a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9feb674a08acf9ce85346e66ef32574015bed5a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to