Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d9feb674 by Moritz Muehlenhoff at 2026-09-28T16:58:19+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -179,6 +179,7 @@ CVE-2026-62439
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/gimp/-/commit/4427b9f31552060aafa5b03caee6ffdd6c257c8b
(GIMP_3_2_6)
CVE-2026-95622
- modemmanager <unfixed>
+ [trixie] - modemmanager <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2540006
CVE-2026-91182
NOT-FOR-US: Red Hat open-cluster-management
@@ -588,18 +589,22 @@ CVE-2026-100703 (Kyverno 1.16.0 through 1.19.0 registers
the globalcontext.Lib C
NOT-FOR-US: Kyverno
CVE-2026-100702 (Nodemailer before 10.0.2 fails to properly flatten deeply
nested array ...)
- node-nodemailer 10.0.10+~8.0.1-1
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE:
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8vvx-rff5-p5rq
NOTE: Fixed by:
https://github.com/nodemailer/nodemailer/commit/ebe084940aef88278afc6016b78c6d1c3821bb66
(v10.0.2)
CVE-2026-100701 (Nodemailer versions 5.0.0 through 10.0.1 use a process-global
DNS cach ...)
- node-nodemailer 10.0.10+~8.0.1-1
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE:
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-6vj9-mwq6-2f5v
NOTE: Fixed by:
https://github.com/nodemailer/nodemailer/commit/a6512dbcb3c6e7f2f70d3acccc5752defe3c61fe
(v10.0.2)
CVE-2026-100700 (nodemailer before 10.0.6 contains a denial of service
vulnerability in ...)
- node-nodemailer 10.0.10+~8.0.1-1
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE:
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-v53p-9fqp-m79j
NOTE: Fixed by:
https://github.com/nodemailer/nodemailer/commit/437d7fc47403df176bc39271641541b7a9bce102
(v10.0.6)
CVE-2026-100699 (Nodemailer is a Node.js email-sending library. In versions >=
9.1.0 an ...)
- node-nodemailer 10.0.10+~8.0.1-1
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE:
https://github.com/nodemailer/nodemailer/security/advisories/GHSA-g57g-f23g-4646
NOTE: Fixed by:
https://github.com/nodemailer/nodemailer/commit/2f36eb1aa1dd33e312411dc9b888548e14db54ee
(v10.0.9)
CVE-2026-100698 (Adminer 5.5.1 through 6.0.1 improperly parses the login
'server' strin ...)
@@ -3357,12 +3362,15 @@ CVE-2026-96750 (MongoDB Compass can interpolate a
database name without escaping
NOT-FOR-US: mongodb-js (not same as node-mongodb)
CVE-2026-96749 (An integer overflow in the BSON document encoding component of
the Mon ...)
- pymongo <unfixed> (bug #1148967)
+ [trixie] - pymongo <no-dsa> (Minor issue)
NOTE:
https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-v4x9-3549-crwv
CVE-2026-96748 (PyMongo's connection string parsing decodes percent-encoded
characters ...)
- pymongo <unfixed> (bug #1148967)
+ [trixie] - pymongo <no-dsa> (Minor issue)
NOTE:
https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-vp6j-j7w5-5xjj
CVE-2026-96747 (The client-side field level encryption support in the MongoDB
Python D ...)
- pymongo <unfixed> (bug #1148967)
+ [trixie] - pymongo <no-dsa> (Minor issue)
NOTE:
https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-qx36-8mw2-4r3x
CVE-2026-96746 (An out-of-bounds write in the connection-monitoring logic of
the Mongo ...)
- mongo-c-driver 2.5.5-1
@@ -5183,24 +5191,24 @@ CVE-2026-88839 (BusyBox passwd/group tokenize()
references a stale endpoint poin
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531353
CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as
plaintext durin ...)
- busybox <unfixed>
+ [trixie] - busybox <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
- TODO: check
CVE-2026-88835 (BusyBox dpkg read_package_field() steps past a NUL terminator
on malfo ...)
- busybox <unfixed> (unimportant)
NOTE: ttps://bugzilla.redhat.com/show_bug.cgi?id=2531349
NOTE: Crash in CLI tool, no security impact
CVE-2026-88832 (BusyBox romfs volume ID parsing uses unbounded strlen on
attacker-cont ...)
- busybox <unfixed>
+ [trixie] - busybox <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531345
- TODO: check
CVE-2026-88831 (BusyBox httpd IP deny rules with invalid CIDR prefix lengths
fail open ...)
- busybox <unfixed>
+ [trixie] - busybox <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531346
- TODO: check
CVE-2026-88830 (A unit confusion in BusyBox TLS Montgomery reduction buffer
allocation ...)
- busybox <unfixed>
+ [trixie] - busybox <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531344
- TODO: check
CVE-2026-87978 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does
not ver ...)
NOT-FOR-US: WordPress plugin
CVE-2026-87900 (Argument injection in WP Toolkit for cPanel 6.11.2-10794 and
earlier a ...)
@@ -5347,7 +5355,9 @@ CVE-2026-80338 (The CMB2 WordPress plugin before 2.13.0
does not perform any cap
NOT-FOR-US: WordPress plugin
CVE-2026-79616 (Out-of-bounds read while parsing untrusted SVG path strings in
Qt Quic ...)
- qt6-declarative 6.11.2+dfsg-3
+ [trixie] - qt6-declarative <no-dsa> (Minor issue)
- qtdeclarative-opensource-src <unfixed>
+ [trixie] - qtdeclarative-opensource-src <no-dsa> (Minor issue)
NOTE: https://codereview.qt-project.org/c/qt/qtdeclarative/+/754718
NOTE:
https://github.com/qt/qtdeclarative/commit/0aba8c7674dbbbaaa142775247249e297a339c85
CVE-2026-79310 (webpy web.py 0.76 is vulnerable to server-side template
injection (SST ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -73,6 +73,8 @@ jupyterlab
--
kitty
--
+libnet-idn-encode-perl
+--
libwebsockets (jmm)
--
linux (carnil)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9feb674a08acf9ce85346e66ef32574015bed5a
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9feb674a08acf9ce85346e66ef32574015bed5a
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits