Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c039764e by Moritz Muehlenhoff at 2026-09-29T18:25:40+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1054,33 +1054,43 @@ CVE-2026-97164 (Joomla Extension - svenbluege.de -
Authenticated arbitrary path
NOT-FOR-US: Joomla
CVE-2026-94419 (Without NO_SESSION_CACHE_REF, wolfSSL_get_session() does not
return a ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/11500 (v5.9.4-stable)
CVE-2026-94418 (Under WOLFSSL_SMALL_CERT_VERIFY, ProcessPeerCertParse() runs
the certi ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/11500 (v5.9.4-stable)
CVE-2026-94417 (When an application enables both OCSP and CRL revocation
checking on o ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/11500 (v5.9.4-stable)
CVE-2026-93304 (A (D)TLS 1.2 client can accept a ChangeCipherSpec message
before it ha ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/11458 (v5.9.4-stable)
CVE-2026-93302 (MatchTrustedPeer ignores the public key used, leading to
forged CA clo ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/wolfSSL/wolfssl/commit/22bcd51d553eaac1de37bee91fdac80cc47961e1
(v5.9.4-stable)
CVE-2026-89136 (When using RPK (Raw Public Key), the client side of a TLS 1.2,
1.3 and ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/11009 (v5.9.4-stable)
CVE-2026-89135 (A failed X509_verify_cert call permanently plants an
unverified attack ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/11009 (v5.9.4-stable)
CVE-2026-89134 (A certificate with no dNSName SAN but another SAN type present
(e.g. r ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10837 (v5.9.4-stable)
CVE-2026-89133 (wolfSSL versions 5.9.2 and earlier contain a flaw in the X.509
certifi ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10687 (v5.9.4-stable)
CVE-2026-89102 (In wolfSSL versions 5.7.2 through 5.9.2 there is a client-side
impleme ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/11027 (v5.9.4-stable)
CVE-2026-88778 (Predictable exact value from previous values vulnerability in
Citrix N ...)
NOT-FOR-US: NetScaler
@@ -1100,6 +1110,7 @@ CVE-2026-88771 (Improper input validation vulnerability
in Citrix NetScaler ADC
NOT-FOR-US: NetScaler
CVE-2026-15442 (In all builds that make use of (D)TLS, including default
builds, there ...)
- wolfssl <unfixed>
+ [trixie] - wolfssl <no-dsa> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10863 (v5.9.4-stable)
CVE-2026-101061 (utcp-gql before 1.1.1 and utcp-websocket before 1.1.1 contain
server-s ...)
NOT-FOR-US: utcp
@@ -2029,6 +2040,7 @@ CVE-2026-100368 (CliInvoke is a .NET library for invoking
command-line programs,
NOT-FOR-US: CliInvoke
CVE-2026-100310 (GNU libextractor before 1.16 loads plugins from an untrusted
search pa ...)
- libextractor 1:1.17-1
+ [trixie] - libextractor <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/25/25
NOTE: https://github.com/Haitam-lazaar/libextractor-privesc
NOTE: Fixed by:
https://git.gnunet.org/gnunet/libextractor/commit/6edfa653c048800e24a17f7e8cc2bb42659b8d01.html
@@ -5591,6 +5603,7 @@ CVE-2026-96889 (A flaw was found in librsvg. When
processing an SVG document con
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0305.html
NOTE: https://gitlab.gnome.org/GNOME/librsvg/-/work_items/1241
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/librsvg/-/commit/8a1b0cd319e9af2d1e9cf878081dd77f227a0504
(2.63.1)
+ NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/librsvg/-/commit/1606574427408baca8203ef723281509a229f9e2
(2.60.3)
CVE-2026-96884 (A security flaw has been discovered in MantisZip up to 0.4.5.
Affected ...)
NOT-FOR-US: MantisZip
CVE-2026-96882 (A vulnerability was identified in TaleLin lin-cms-spring-boot
up to 0. ...)
@@ -6216,6 +6229,7 @@ CVE-2026-79616 (Out-of-bounds read while parsing
untrusted SVG path strings in Q
NOTE:
https://github.com/qt/qtdeclarative/commit/0aba8c7674dbbbaaa142775247249e297a339c85
CVE-2026-79310 (webpy web.py 0.76 is vulnerable to server-side template
injection (SST ...)
- web2py <unfixed>
+ [trixie] - web2py <no-dsa> (Minor issue)
NOTE:
https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79310.md
CVE-2026-79306 (CyberPanel v1.9.1 contains a path traversal vulnerability in
the compr ...)
NOT-FOR-US: CyberPanel
@@ -8107,12 +8121,15 @@ CVE-2026-79314 (A horizontal privilege escalation
vulnerability exists in x-ui 0
NOT-FOR-US: x-ui
CVE-2026-79313 (webpy web.py 0.76 is vulnerable to Insufficient Session
Expiration. Th ...)
- webpy <unfixed>
+ [trixie] - webpy <no-dsa> (Minor issue)
NOTE:
https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79313.md
CVE-2026-79312 (webpy web.py 0.76 is vulnerable to Session Fixation. The
component Ses ...)
- webpy <unfixed>
+ [trixie] - webpy <no-dsa> (Minor issue)
NOTE:
https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79312.md
CVE-2026-79311 (webpy web.py 0.76 is vulnerable to Cross Site Scripting (XSS)
via rend ...)
- webpy <unfixed>
+ [trixie] - webpy <no-dsa> (Minor issue)
NOTE:
https://github.com/lichoin/TraceLoom/blob/main/CVEs/CVE-2026-79311.md
CVE-2026-77637 (Cloudreve is a self-hosted file management and sharing system.
Prior t ...)
NOT-FOR-US: Cloudreve
@@ -10018,6 +10035,7 @@ CVE-2026-93657 (hickory-resolver versions before 0.26.2
fail to propagate bogus
NOTE:
https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274ea4a9fdd238
CVE-2026-93653 (A denial of service flaw was found in Poppler's Splash
backend. A craf ...)
- poppler <unfixed> (bug #1148398)
+ [trixie] - poppler <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537005
CVE-2026-93652 (Integer overflow in \xb5D3TN v0.15.0 TCPCLv3 handshake causes
heap ove ...)
NOT-FOR-US: ud3tn
@@ -10864,21 +10882,25 @@ CVE-2026-93331 (A vulnerability was identified in
GPAC 26.08-DEV. This vulnerabi
- gpac <removed>
CVE-2026-93314 (A vulnerability was determined in Freedesktop Poppler 26.07.0.
This af ...)
- poppler <unfixed> (bug #1148266)
+ [trixie] - poppler <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1761
NOTE:
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2315
NOTE: Fixed by:
https://gitlab.freedesktop.org/poppler/poppler/-/commit/ed2a5538cf0a8d3ff908191eda9b73f91a5f952a
(poppler-26.08.0)
CVE-2026-93313 (A vulnerability was found in Freedesktop Poppler 26.07.0. The
impacted ...)
- poppler <unfixed> (bug #1148266)
+ [trixie] - poppler <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1760
NOTE:
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2322
NOTE: Fixed by:
https://gitlab.freedesktop.org/poppler/poppler/-/commit/eb87cf711563894649bd0c365baa479401dc6d51
CVE-2026-93312 (A flaw has been found in Freedesktop Poppler 26.07.0. Impacted
is the ...)
- poppler <unfixed> (bug #1148266)
+ [trixie] - poppler <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1759
NOTE:
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2314
NOTE: Fixed by:
https://gitlab.freedesktop.org/poppler/poppler/-/commit/5e49250f13b0390edeb3f90eb4c02c9941f97067
(poppler-26.08.0)
CVE-2026-93311 (A vulnerability was detected in Freedesktop Poppler 26.07.0.
This issu ...)
- poppler <unfixed> (bug #1148267)
+ [trixie] - poppler <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1758
CVE-2026-93310 (A vulnerability was identified in O-RAN-SC SMO OAM 2025-06-10.
This af ...)
NOT-FOR-US: O-RAN-SC SMO OAM
@@ -19706,6 +19728,7 @@ CVE-2026-91770 (IceHRM before 36.0.0 fails to validate
employee ownership on sev
NOT-FOR-US: IceHRM
CVE-2026-91752 (GNU libextractor before 1.15 contains a stack-based buffer
overflow vu ...)
- libextractor 1:1.17-1
+ [trixie] - libextractor <no-dsa> (Minor issue)
NOTE: https://github.com/Haitam-lazaar/libextractor-ole2-rce
NOTE:
https://git.gnunet.org/gnunet/libextractor/commit/04004eb19033e093938138b09befdf31e71e8522.html
CVE-2026-91751 (Flextype CMS through 1.0.0-alpha.3 fails to properly validate
id and n ...)
@@ -21720,9 +21743,10 @@ CVE-2026-90651 (Socket Firewall
(socketdev/socket-registry-firewall) in registry
NOT-FOR-US: Socket Firewall (socketdev/socket-registry-firewall)
CVE-2026-90648 (wasm2c in WebAssembly wabt through 1.0.41 allows sandbox
escape in som ...)
- wabt <unfixed>
+ [trixie] - wabt <no-dsa> (Minor issue)
NOTE: https://github.com/trustsig-eu/wasm2c-tableflip
NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=1827704
- TODO: check upstream details
+ NOTE: https://github.com/WebAssembly/wabt/issues/2831
CVE-2026-90647 (ASE/Kalkitech ASE2000 V2 Communication Test Set 2.35 through
2.37 on W ...)
NOT-FOR-US: ASE/Kalkitech ASE2000 V2 Communication Test Set
CVE-2026-90499 (A security flaw has been discovered in lenve vhr 1.0-SNAPSHOT.
This af ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c039764ea38137f2e7b3c9969166be9b3d8036ae
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c039764ea38137f2e7b3c9969166be9b3d8036ae
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits