Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
e42dd985 by Moritz Muehlenhoff at 2026-09-28T20:44:43+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3289,6 +3289,7 @@ CVE-2026-XXXX [GHSA-mfwv-x733-9446]
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-mfwv-x733-9446
 CVE-2026-XXXX [GHSA-wfvq-qh87-gm4j]
        - incus 7.0.1-5
+       [trixie] - incus <postponed> (Wait until 6.x backport is available)
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-wfvq-qh87-gm4j
 CVE-2026-XXXX [GHSA-443p-7392-h4v2]
        - incus 7.0.1-5
@@ -5864,14 +5865,17 @@ CVE-2026-86247 (Race condition within a thread 
vulnerability in Apache Tomcat Na
        - tomcat-native 2.0.16-1
        NOTE: Fixed by: 
https://github.com/apache/tomcat-native/commit/fb688de41e837d98e76961e44584b37989e4f7d0
 (2.0.16)
        NOTE: Fixed by: 
https://github.com/apache/tomcat-native/commit/3dc73c118d2202c8dfc6053787cc6d61416ddce6
 (1.3.9)
+       NOTE: https://lists.apache.org/thread/obsson6zhvfg0wsp2bx602l61ltj87r1
 CVE-2026-86246 (Initialization of a resource with an insecure default 
vulnerability in ...)
        - tomcat-native 2.0.16-1
        NOTE: Fixed by: 
https://github.com/apache/tomcat-native/commit/f6bb04b28f234a35c21a2997963195ae1d86de69
 (2.0.16)
        NOTE: Fixed by: 
https://github.com/apache/tomcat-native/commit/77a87991079211805f41ddb2c51067bb807dcb40
 (1.3.9)
+       NOTE: https://www.openwall.com/lists/oss-security/2026/09/23/32
 CVE-2026-86243 (Buffer over-read vulnerability in Apache Tomcat Native during 
the TLS  ...)
        - tomcat-native 2.0.16-1
        NOTE: Fixed by: 
https://github.com/apache/tomcat-native/commit/9a7c804afc05fdc630520eb4012ce1c4ff787862
 (2.0.16)
        NOTE: Fixed by: 
https://github.com/apache/tomcat-native/commit/ce019af0db385dfd5bc7c7a759f71602559a0499
 (1.3.9)
+       NOTE: https://www.openwall.com/lists/oss-security/2026/09/23/31
 CVE-2026-94422
        {DSA-6510-1}
        - xdg-dbus-proxy 0.1.9-1 (bug #1148782)
@@ -6454,6 +6458,7 @@ CVE-2026-5924 (The Getwid \u2013 Gutenberg Blocks plugin 
for WordPress is vulner
        NOT-FOR-US: WordPress plugin
 CVE-2026-59991 (psd-tools is a Python package for working with Adobe Photoshop 
PSD fil ...)
        - psd-tools 1.17.4+dfsg.1-1
+       [trixie] - psd-tools <no-dsa> (Minor issue)
        NOTE: 
https://github.com/psd-tools/psd-tools/security/advisories/GHSA-8q6g-vjhf-jp8m
        NOTE: Fixed by: 
https://github.com/psd-tools/psd-tools/commit/a3d9a53ad51e667b5772a4f636ca6f2e16f4b271
 (v1.17.4)
 CVE-2026-58268 (SIPGO is a library for writing SIP services in the GO 
language. Prior  ...)
@@ -17553,6 +17558,7 @@ CVE-2026-91835 (A vulnerability was detected in 
OpenClaw ClawScan up to 0.1.6. T
        NOT-FOR-US: OpenClaw
 CVE-2026-91826 (Stack-based buffer overflow vulnerability in Samsung 
Opensource rLotti ...)
        - rlottie <unfixed>
+       [trixie] - rlottie <no-dsa> (Minor issue)
        NOTE: https://github.com/Samsung/rlottie/pull/607
        NOTE: Fixed by: 
https://github.com/Samsung/rlottie/commit/480a2ad0c5d2e45458c545b8213279e9e8b71e39
 CVE-2026-91825 (Affected versions of MISP fail to authorize a submitted 
sharing group  ...)
@@ -24014,8 +24020,10 @@ CVE-2026-68488 (A Time-of-check Time-of-use (TOCTOU) 
race condition leading to i
 CVE-2026-68487 (Path traversal in Plesk's Backup Manager causes arbitrary file 
write a ...)
        NOT-FOR-US: Plesk
 CVE-2026-68006 (An issue in Puma v.5.0.0 and before v.8.0.3 allows an attacker 
to exec ...)
-       - puma <unfixed>
-       TODO: check, unclear if https://github.com/czx1111/cve/issues/1 
properly reported upstream
+       - puma <unfixed> (unimportant)
+       NOTE: https://github.com/puma/puma/pull/4021
+       NOTE: 
https://github.com/puma/puma/commit/8fadfe019eb0435f5ad4a816115fd60034e0f1dc
+       NOTE: https://github.com/czx1111/cve/issues/1#issuecomment-5854677689
 CVE-2026-66674 (Unauthenticated Bypass Vulnerability in Simple Cloudflare 
Turnstile <= ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66632 (Unauthenticated Content Injection in Simple Cloudflare 
Turnstile <= 1. ...)
@@ -61191,9 +61199,7 @@ CVE-2026-19588 (Integer Overflow to Buffer Overflow 
vulnerability in Samsung Ope
        NOTE: https://github.com/Samsung/rlottie/pull/600
        NOTE: 
https://github.com/Samsung/rlottie/commit/27f2f23ece8a98f3e0a870e2c125faaac37e8904
 CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung 
Open Source ...)
-       - rlottie <unfixed> (bug #1144472)
-       [trixie] - rlottie <no-dsa> (Minor issue)
-       [bookworm] - rlottie <postponed> (Minor issue)
+       - rlottie 0.1+dfsg-4 (bug #1143931)
        NOTE: https://github.com/Samsung/rlottie/pull/599
        NOTE: 
https://github.com/Samsung/rlottie/commit/34465a9e93c38af9a5287ad28400bb932c1a2a92
 CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass 
(insecure direc ...)
@@ -70144,9 +70150,7 @@ CVE-2026-18774 (A flaw has been found in NousResearch 
hermes-agent up to 0.16.0.
 CVE-2026-18773 (A vulnerability was detected in NousResearch hermes-agent up 
to 2026.6 ...)
        NOT-FOR-US: NousResearch
 CVE-2026-18772 (Improperly controlled sequential memory allocation 
vulnerability in Sa ...)
-       - rlottie <unfixed> (bug #1143931)
-       [trixie] - rlottie <no-dsa> (Minor issue)
-       [bookworm] - rlottie <postponed> (Minor issue)
+       - rlottie 0.1+dfsg-4 (bug #1143931)
        NOTE: https://github.com/Samsung/rlottie/pull/596
 CVE-2026-18770 (A vulnerability has been found in vibesurf-ai VibeSurf up to 
cd6e519d5 ...)
        NOT-FOR-US: vibesurf-ai VibeSurf



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e42dd985445d1f642bb368624341b75b1509f014

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e42dd985445d1f642bb368624341b75b1509f014
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to