Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
7c605498 by Moritz Muehlenhoff at 2026-09-29T09:49:02+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -322,19 +322,24 @@ CVE-2026-95104 (Stack-based buffer overflow vulnerability
exists in BUFFALO Wi-F
NOT-FOR-US: BUFFALO
CVE-2026-94287 (A denial of service via unsigned underflow in libXpm's write
path in l ...)
- libxpm <unfixed>
+ [trixie] - libxpm <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxpm/-/merge_requests/32
NOTE: Fixed by:
https://gitlab.freedesktop.org/xorg/lib/libxpm/-/commit/6e42eb9e105ae17318f3ba5656d94cd3f80eeaa3
CVE-2026-94286 (An out-of-bounds read in libXtst's RECORD reply parser in
libXtst befo ...)
- libxtst <unfixed>
+ [trixie] - libxtst <no-dsa> (Minor issue)
NOTE:
https://gitlab.freedesktop.org/xorg/lib/libxtst/-/merge_requests/10
CVE-2026-94285 (An out-of-bounds read in libX11's byte-oriented codeset parser
in libX ...)
- libx11 <unfixed>
+ [trixie] - libx11 <no-dsa> (Minor issue)
NOTE:
https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310
CVE-2026-94284 (An out-of-bounds read vulnerability in libX11's XIM
trigger-key regist ...)
- libx11 <unfixed>
+ [trixie] - libx11 <no-dsa> (Minor issue)
NOTE:
https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310
CVE-2026-94283 (An out-of-bounds read vulnerability in libX11's XIM (X Input
Method) a ...)
- libx11 <unfixed>
+ [trixie] - libx11 <no-dsa> (Minor issue)
NOTE:
https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/310
CVE-2026-94194 (Inconsistent Interpretation of HTTP Requests ('HTTP
Request/Response S ...)
NOT-FOR-US: elixir-mint Mint
@@ -963,8 +968,9 @@ CVE-2026-95622
CVE-2026-91182
NOT-FOR-US: Red Hat open-cluster-management
CVE-2026-88841
- - busybox <unfixed>
+ - busybox <unfixed> (unimportant)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539987
+ NOTE: Negligible security impact
CVE-2026-84475
NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-84684
@@ -6619,16 +6625,19 @@ CVE-2026-XXXX [GHSA-r6xj-6488-p8mv:
NTFS-3G-SA_2026-06-1_05]
NOTE:
https://github.com/tuxera/ntfs-3g/security/advisories/GHSA-r6xj-6488-p8mv
CVE-2026-86247 (Race condition within a thread vulnerability in Apache Tomcat
Native a ...)
- tomcat-native 2.0.16-1
+ [trixie] - tomcat-native <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/apache/tomcat-native/commit/fb688de41e837d98e76961e44584b37989e4f7d0
(2.0.16)
NOTE: Fixed by:
https://github.com/apache/tomcat-native/commit/3dc73c118d2202c8dfc6053787cc6d61416ddce6
(1.3.9)
NOTE: https://lists.apache.org/thread/obsson6zhvfg0wsp2bx602l61ltj87r1
CVE-2026-86246 (Initialization of a resource with an insecure default
vulnerability in ...)
- tomcat-native 2.0.16-1
+ [trixie] - tomcat-native <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/apache/tomcat-native/commit/f6bb04b28f234a35c21a2997963195ae1d86de69
(2.0.16)
NOTE: Fixed by:
https://github.com/apache/tomcat-native/commit/77a87991079211805f41ddb2c51067bb807dcb40
(1.3.9)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/23/32
CVE-2026-86243 (Buffer over-read vulnerability in Apache Tomcat Native during
the TLS ...)
- tomcat-native 2.0.16-1
+ [trixie] - tomcat-native <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/apache/tomcat-native/commit/9a7c804afc05fdc630520eb4012ce1c4ff787862
(2.0.16)
NOTE: Fixed by:
https://github.com/apache/tomcat-native/commit/ce019af0db385dfd5bc7c7a759f71602559a0499
(1.3.9)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/23/31
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c605498521605a9c21fde89a39140fb51c0ec00
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c605498521605a9c21fde89a39140fb51c0ec00
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits