Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c039764e by Moritz Muehlenhoff at 2026-09-29T18:25:40+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1054,33 +1054,43 @@ CVE-2026-97164 (Joomla Extension - svenbluege.de - 
Authenticated arbitrary path
        NOT-FOR-US: Joomla
 CVE-2026-94419 (Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not 
return a  ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/11500 (v5.9.4-stable)
 CVE-2026-94418 (Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs 
the certi ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/11500 (v5.9.4-stable)
 CVE-2026-94417 (When an application enables both OCSP and CRL revocation 
checking on o ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/11500 (v5.9.4-stable)
 CVE-2026-93304 (A (D)TLS 1.2 client can accept a ChangeCipherSpec message 
before it ha ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/11458 (v5.9.4-stable)
 CVE-2026-93302 (MatchTrustedPeer ignores the public key used, leading to 
forged CA clo ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/wolfSSL/wolfssl/commit/22bcd51d553eaac1de37bee91fdac80cc47961e1
 (v5.9.4-stable)
 CVE-2026-89136 (When using RPK (Raw Public Key), the client side of a TLS 1.2, 
1.3 and ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/11009 (v5.9.4-stable)
 CVE-2026-89135 (A failed X509_verify_cert call permanently plants an 
unverified attack ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/11009 (v5.9.4-stable)
 CVE-2026-89134 (A certificate with no dNSName SAN but another SAN type present 
(e.g. r ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10837 (v5.9.4-stable)
 CVE-2026-89133 (wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509 
certifi ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10687 (v5.9.4-stable)
 CVE-2026-89102 (In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side 
impleme ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/11027 (v5.9.4-stable)
 CVE-2026-88778 (Predictable exact value from previous values vulnerability in 
Citrix N ...)
        NOT-FOR-US: NetScaler
@@ -1100,6 +1110,7 @@ CVE-2026-88771 (Improper input validation vulnerability 
in Citrix NetScaler ADC
        NOT-FOR-US: NetScaler
 CVE-2026-15442 (In all builds that make use of (D)TLS, including default 
builds, there ...)
        - wolfssl <unfixed>
+       [trixie] - wolfssl <no-dsa> (Minor issue)
        NOTE: https://github.com/wolfSSL/wolfssl/pull/10863 (v5.9.4-stable)
 CVE-2026-101061 (utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain 
server-s ...)
        NOT-FOR-US: utcp
@@ -2029,6 +2040,7 @@ CVE-2026-100368 (CliInvoke is a .NET library for invoking 
command-line programs,
        NOT-FOR-US: CliInvoke
 CVE-2026-100310 (GNU libextractor before 1.16 loads plugins from an untrusted 
search pa ...)
        - libextractor 1:1.17-1
+       [trixie] - libextractor <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/25/25
        NOTE: https://github.com/Haitam-lazaar/libextractor-privesc
        NOTE: Fixed by: 
https://git.gnunet.org/gnunet/libextractor/commit/6edfa653c048800e24a17f7e8cc2bb42659b8d01.html
@@ -5591,6 +5603,7 @@ CVE-2026-96889 (A flaw was found in librsvg. When 
processing an SVG document con
        NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0305.html
        NOTE: https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/librsvg/-/commit/8a1b0cd319e9af2d1e9cf878081dd77f227a0504
 (2.63.1)
+       NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/librsvg/-/commit/1606574427408baca8203ef723281509a229f9e2
 (2.60.3)
 CVE-2026-96884 (A security flaw has been discovered in MantisZip up to 0.4.5. 
Affected ...)
        NOT-FOR-US: MantisZip
 CVE-2026-96882 (A vulnerability was identified in TaleLin lin-cms-spring-boot 
up to 0. ...)
@@ -6216,6 +6229,7 @@ CVE-2026-79616 (Out-of-bounds read while parsing 
untrusted SVG path strings in Q
        NOTE: 
https://github.com/qt/qtdeclarative/commit/0aba8c7674dbbbaaa142775247249e297a339c85
 CVE-2026-79310 (webpy web.py 0.76 is vulnerable to server-side template 
injection (SST ...)
        - web2py <unfixed>
+       [trixie] - web2py <no-dsa> (Minor issue)
        NOTE: 
https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79310.md
 CVE-2026-79306 (CyberPanel v1.9.1 contains a path traversal vulnerability in 
the compr ...)
        NOT-FOR-US: CyberPanel
@@ -8107,12 +8121,15 @@ CVE-2026-79314 (A horizontal privilege escalation 
vulnerability exists in x-ui 0
        NOT-FOR-US: x-ui
 CVE-2026-79313 (webpy web.py 0.76 is vulnerable to Insufficient Session 
Expiration. Th ...)
        - webpy <unfixed>
+       [trixie] - webpy <no-dsa> (Minor issue)
        NOTE: 
https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79313.md
 CVE-2026-79312 (webpy web.py 0.76 is vulnerable to Session Fixation. The 
component Ses ...)
        - webpy <unfixed>
+       [trixie] - webpy <no-dsa> (Minor issue)
        NOTE: 
https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79312.md
 CVE-2026-79311 (webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS) 
via rend ...)
        - webpy <unfixed>
+       [trixie] - webpy <no-dsa> (Minor issue)
        NOTE: 
https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79311.md
 CVE-2026-77637 (Cloudreve is a self-hosted file management and sharing system. 
Prior t ...)
        NOT-FOR-US: Cloudreve
@@ -10018,6 +10035,7 @@ CVE-2026-93657 (hickory-resolver versions before 0.26.2 
fail to propagate bogus
        NOTE: 
https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274ea4a9fdd238
 CVE-2026-93653 (A denial of service flaw was found in Poppler's Splash 
backend. A craf ...)
        - poppler <unfixed> (bug #1148398)
+       [trixie] - poppler <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537005
 CVE-2026-93652 (Integer overflow in \xb5D3TN v0.15.0 TCPCLv3 handshake causes 
heap ove ...)
        NOT-FOR-US: ud3tn
@@ -10864,21 +10882,25 @@ CVE-2026-93331 (A vulnerability was identified in 
GPAC 26.08-DEV. This vulnerabi
        - gpac <removed>
 CVE-2026-93314 (A vulnerability was determined in Freedesktop Poppler 26.07.0. 
This af ...)
        - poppler <unfixed> (bug #1148266)
+       [trixie] - poppler <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1761
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2315
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/ed2a5538cf0a8d3ff908191eda9b73f91a5f952a
 (poppler-26.08.0)
 CVE-2026-93313 (A vulnerability was found in Freedesktop Poppler 26.07.0. The 
impacted ...)
        - poppler <unfixed> (bug #1148266)
+       [trixie] - poppler <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1760
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2322
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/eb87cf711563894649bd0c365baa479401dc6d51
 CVE-2026-93312 (A flaw has been found in Freedesktop Poppler 26.07.0. Impacted 
is the  ...)
        - poppler <unfixed> (bug #1148266)
+       [trixie] - poppler <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314
        NOTE: Fixed by: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067
 (poppler-26.08.0)
 CVE-2026-93311 (A vulnerability was detected in Freedesktop Poppler 26.07.0. 
This issu ...)
        - poppler <unfixed> (bug #1148267)
+       [trixie] - poppler <no-dsa> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1758
 CVE-2026-93310 (A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10. 
This af ...)
        NOT-FOR-US: O-RAN-SC SMO OAM
@@ -19706,6 +19728,7 @@ CVE-2026-91770 (IceHRM before 36.0.0 fails to validate 
employee ownership on sev
        NOT-FOR-US: IceHRM
 CVE-2026-91752 (GNU libextractor before 1.15 contains a stack-based buffer 
overflow vu ...)
        - libextractor 1:1.17-1
+       [trixie] - libextractor <no-dsa> (Minor issue)
        NOTE: https://github.com/Haitam-lazaar/libextractor-ole2-rce
        NOTE: 
https://git.gnunet.org/gnunet/libextractor/commit/04004eb19033e093938138b09befdf31e71e8522.html
 CVE-2026-91751 (Flextype CMS through 1.0.0-alpha.3 fails to properly validate 
id and n ...)
@@ -21720,9 +21743,10 @@ CVE-2026-90651 (Socket Firewall 
(socketdev/socket-registry-firewall) in registry
        NOT-FOR-US: Socket Firewall (socketdev/socket-registry-firewall)
 CVE-2026-90648 (wasm2c in WebAssembly wabt through 1.0.41 allows sandbox 
escape in som ...)
        - wabt <unfixed>
+       [trixie] - wabt <no-dsa> (Minor issue)
        NOTE: https://github.com/trustsig-eu/wasm2c-tableflip
        NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=1827704
-       TODO: check upstream details
+       NOTE: https://github.com/WebAssembly/wabt/issues/2831
 CVE-2026-90647 (ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through 
2.37 on W ...)
        NOT-FOR-US: ASE/Kalkitech ASE2000 V2 Communication Test Set
 CVE-2026-90499 (A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT. 
This af ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c039764ea38137f2e7b3c9969166be9b3d8036ae

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c039764ea38137f2e7b3c9969166be9b3d8036ae
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to