Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a25bff00 by Moritz Muehlenhoff at 2026-09-29T08:49:28+02:00
trixie triage

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -3830,13 +3830,11 @@ CVE-2026-XXXX [GHSA-443p-7392-h4v2]
        NOTE: 
https://github.com/lxc/incus/security/advisories/GHSA-443p-7392-h4v2
 CVE-2026-85526 [GHSA-h85r-gjgx-g2rv]
        - incus 7.0.1-5
-       [trixie] - incus 6.0.4-2+deb13u11
        - lxd <removed>
        [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-h85r-gjgx-g2rv
 CVE-2026-85185 [GHSA-27q7-qwhm-c34p]
        - incus 7.0.1-5
-       [trixie] - incus 6.0.4-2+deb13u11
        - lxd <removed>
        [bookworm] - lxd <end-of-life> (EOL in bookworm LTS)
        NOTE: 
https://github.com/canonical/lxd/security/advisories/GHSA-27q7-qwhm-c34p
@@ -17979,6 +17977,7 @@ CVE-2026-91993 (Jpom through 2.11.12 fails to validate 
workspace ownership when
        NOT-FOR-US: Jpom
 CVE-2026-91992 (Tornado before 6.5.7 contains a credential leak vulnerability 
in CurlA ...)
        - python-tornado <unfixed> (bug #1148323)
+       [trixie] - python-tornado <no-dsa> (Minor issue)
        NOTE: 
https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f
 CVE-2026-91991 (Tornado before 6.5.8 contains an incomplete fix for cookie 
attribute i ...)
        - python-tornado <unfixed> (bug #1148323)
@@ -17987,6 +17986,7 @@ CVE-2026-91991 (Tornado before 6.5.8 contains an 
incomplete fix for cookie attri
        NOTE: CVE exists because of an incomplete fix for CVE-2026-35536
 CVE-2026-91990 (Tornado before 6.5.8 contains a memory amplification 
vulnerability in  ...)
        - python-tornado <unfixed> (bug #1148323)
+       [trixie] - python-tornado <no-dsa> (Minor issue)
        NOTE: 
https://github.com/tornadoweb/tornado/security/advisories/GHSA-8423-8fgw-73vq
 CVE-2026-91989 (atomic-agents-stack before 1.1.0 contains a path traversal 
vulnerabili ...)
        NOT-FOR-US: atomic-agents-stack


=====================================
data/DSA/list
=====================================
@@ -1697,7 +1697,7 @@
        [bookworm] - lxd 5.0.2-5+deb12u1
        [trixie] - lxd 5.0.2+git20231211.1364ae4-9+deb13u1
 [17 Oct 2025] DSA-6027-1 incus - security update
-       {CVE-2025-54286 CVE-2025-54287 CVE-2025-54288 CVE-2025-54289 
CVE-2025-54290 CVE-2025-54291 CVE-2025-54293}
+       {CVE-2025-54286 CVE-2025-54287 CVE-2025-54288 CVE-2025-54289 
CVE-2025-54290 CVE-2025-54291 CVE-2025-54293 CVE-2026-85526 CVE-2026-85185}
        [trixie] - incus 6.0.4-2+deb13u1
 [16 Oct 2025] DSA-6026-1 chromium - security update
        {CVE-2025-11756}


=====================================
data/dsa-needed.txt
=====================================
@@ -185,6 +185,8 @@ vips
 weechat
   Upstream recommends to use branch from 
https://github.com/weechat/weechat/commits/4.6/, cf #1142597
 --
+wireshark
+--
 xz-utils
 --
 zlib (carnil)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a25bff001e6fbe3a6af2d555e213d92bb21d0604

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a25bff001e6fbe3a6af2d555e213d92bb21d0604
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to