Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f71c28dd by Moritz Muehlenhoff at 2026-09-29T14:52:21+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -783,6 +783,7 @@ CVE-2026-100750 (Joomla Extension - regularlabs.com - LFI /
SSRF in Modules Anyw
NOT-FOR-US: Joomla
CVE-2026-85644 (XS::Parse::Infix versions from 0.40 through 0.49 for Perl
treat a numb ...)
- libxs-parse-keyword-perl <unfixed> (bug #1149243)
+ [trixie] - libxs-parse-keyword-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43916020/
NOTE:
https://metacpan.org/release/PEVANS/XS-Parse-Keyword-0.50/diff/PEVANS/XS-Parse-Keyword-0.49/src/infix.c
CVE-2026-91006 (Apache Karaf's instance-management service
(InstanceServiceImpl) build ...)
@@ -6204,33 +6205,37 @@ CVE-2026-77602 (OpenC3 COSMOS provides the
functionality needed to send commands
CVE-2026-77601 (OpenC3 COSMOS provides the functionality needed to send
commands to an ...)
NOT-FOR-US: OpenC3 COSMOS
CVE-2026-77423 (JLine is a Java library for handling console input. From 3.0.0
until 3 ...)
- - jline3 <unfixed>
+ - jline3 <unfixed> (unimportant)
- jline2 <not-affected> (Less pager was introduced in 3.x)
- jline <not-affected> (Less pager was introduced in 3.x)
NOTE:
https://github.com/jline/jline3/security/advisories/GHSA-2v9w-34q6-wpqx
NOTE: https://github.com/jline/jline3/pull/2018
NOTE:
https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
(jline-3.30.15)
+ NOTE: Negligible security impact
CVE-2026-77422 (JLine is a Java library for handling console input. From 3.0.0
until 3 ...)
- - jline3 <unfixed>
+ - jline3 <unfixed> (unimportant)
- jline2 <not-affected> (Grep command was introduced in 3.x)
- jline <not-affected> (Grep command was introduced in 3.x)
NOTE:
https://github.com/jline/jline3/security/advisories/GHSA-r2xf-8xr9-62gw
NOTE: https://github.com/jline/jline3/pull/2018
NOTE:
https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
(jline-3.30.15)
+ NOTE: Negligible security impact
CVE-2026-77421 (JLine is a Java library for handling console input. From 3.0.0
until 3 ...)
- - jline3 <unfixed>
+ - jline3 <unfixed> (unimportant)
- jline2 <not-affected> (Nano editor was introduced in 3.x)
- jline <not-affected> (Nano editor was introduced in 3.x)
NOTE:
https://github.com/jline/jline3/security/advisories/GHSA-ph9c-7hw9-vhhw
NOTE: https://github.com/jline/jline3/pull/2018
NOTE:
https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
(jline-3.30.15)
+ NOTE: Negligible security impact
CVE-2026-77420 (JLine is a Java library for handling console input. From 3.0.0
until 3 ...)
- - jline3 <unfixed>
+ - jline3 <unfixed> (unimportant)
- jline2 <not-affected> (HISTORY_IGNORE was introduced in 3.x)
- jline <not-affected> (HISTORY_IGNORE was introduced in 3.x)
NOTE:
https://github.com/jline/jline3/security/advisories/GHSA-5q95-hrpc-m3w3
NOTE: https://github.com/jline/jline3/pull/2018
NOTE:
https://github.com/jline/jline3/commit/341ee69ccc57b7733c1b40d6993219b64b3206ae
(jline-3.30.15)
+ NOTE: Negligible security impact
CVE-2026-77394 (OpenC3 COSMOS provides the functionality needed to send
commands to an ...)
NOT-FOR-US: OpenC3 COSMOS
CVE-2026-77285 (OpenBao is an open source identity-based secrets management
system. Pr ...)
@@ -6425,6 +6430,7 @@ CVE-2026-61834 (scim-patch is a library for applying SCIM
patch operations. Prio
NOT-FOR-US: scim-patch
CVE-2026-61814 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn's
AsyncParser ...)
- jawn <unfixed>
+ [trixie] - jawn <no-dsa> (Minor issue)
NOTE:
https://github.com/typelevel/jawn/security/advisories/GHSA-w4cm-gvhj-cgw6
NOTE: Fixed by:
https://github.com/typelevel/jawn/commit/cddcd5e3387c356b05953f7b2af103d309687e4b
(v1.7.0)
CVE-2026-61695 (Wire provides gRPC and protocol buffers for Android, Kotlin,
Swift, an ...)
@@ -6437,6 +6443,7 @@ CVE-2026-5695 (Arbitrary file upload vulnerability due to
a lack of proper valid
NOT-FOR-US: Microweber CMS
CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse
methods ...)
- jawn <unfixed>
+ [trixie] - jawn <no-dsa> (Minor issue)
NOTE:
https://github.com/typelevel/jawn/security/advisories/GHSA-cc4v-rvgp-2pf3
NOTE: Fixed by:
https://github.com/typelevel/jawn/commit/191cb3a44e77f1afab439ee636bf66bdf3c54a04
(v1.7.0)
NOTE: Fixed by:
https://github.com/typelevel/jawn/commit/6219666641f9408498f85868f835e17bd8a72fed
(v1.7.0)
@@ -9509,6 +9516,7 @@ CVE-2026-11608 (The WP Customer Reviews plugin for
WordPress is vulnerable to Re
NOT-FOR-US: WordPress plugin
CVE-2026-82560 (Pod::Text versions before 6.1.1 for Perl allow CPU and memory
exhausti ...)
- perl <unfixed> (bug #1148455)
+ [trixie] - perl <no-dsa> (Minor issue)
- podlators-perl <removed>
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43682367/
NOTE: Fixed by:
https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f
(release/v6.1.1)
=====================================
data/dsa-needed.txt
=====================================
@@ -73,6 +73,8 @@ kitty
--
libnet-idn-encode-perl
--
+libpng1.6 (jmm)
+--
libwebsockets (jmm)
--
linux (carnil)
@@ -169,7 +171,7 @@ tomcat10
--
tomcat11
--
-tor
+tor (jmm)
--
valkey (aron)
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f71c28dd57bc1049d6223af3406a2103d4f2e8ed
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f71c28dd57bc1049d6223af3406a2103d4f2e8ed
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits