Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8b3b5857 by Moritz Muehlenhoff at 2026-09-30T08:50:15+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -68,34 +68,42 @@ CVE-2026-102305
- chromium <unfixed>
CVE-2026-94053
- mina2 <unfixed>
+ [trixie] - mina2 <no-dsa> (Minor issue)
- mina <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/39
CVE-2026-94052
- mina2 <unfixed>
+ [trixie] - mina2 <no-dsa> (Minor issue)
- mina <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/38
CVE-2026-94029
- mina2 <unfixed>
+ [trixie] - mina2 <no-dsa> (Minor issue)
- mina <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/37
CVE-2026-94002
- mina2 <unfixed>
+ [trixie] - mina2 <no-dsa> (Minor issue)
- mina <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/36
CVE-2026-93996
- mina2 <unfixed>
+ [trixie] - mina2 <no-dsa> (Minor issue)
- mina <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/35
CVE-2026-93995
- mina2 <unfixed>
+ [trixie] - mina2 <no-dsa> (Minor issue)
- mina <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/34
CVE-2026-93994
- mina2 <unfixed>
+ [trixie] - mina2 <no-dsa> (Minor issue)
- mina <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/33
CVE-2026-77185
- mina2 <unfixed>
+ [trixie] - mina2 <no-dsa> (Minor issue)
- mina <removed>
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/32
CVE-2026-98164 (In the Linux kernel, the following vulnerability has been
resolved: K ...)
@@ -277,13 +285,16 @@ CVE-2026-19547 (Ghostscript for Windows is vulnerable to
local privilege escalat
NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=709522
CVE-2026-15390 (Das U-Bootwith CONFIG_IP_DEFRAG=y parameter fails to clear IP
reassemb ...)
- u-boot <unfixed>
+ [trixie] - u-boot <no-dsa> (Minor issue)
NOTE: Fixed by:
https://source.denx.de/u-boot/u-boot/-/commit/b1aec609bb5e0d08c25c888c91935287ab4ee5fa
(v2026.07)
CVE-2026-12345 (The cleanup of tempfile.TemporaryDirectory is vulnerable to a
race con ...)
- python3.15 <unfixed>
- python3.14 <unfixed>
- python3.13 <unfixed>
+ [trixie] - python3.13 <no-dsa> (Minor issue)
- python3.11 <removed>
- pypy3 <unfixed>
+ [trixie] - pypy3 <no-dsa> (Minor issue)
NOTE: https://github.com/python/cpython/issues/157579
NOTE: https://github.com/python/cpython/pull/157580
CVE-2026-11796 (Asset Suite allows unauthenticated users to access
PropertiesReloadSer ...)
@@ -453,13 +464,17 @@ CVE-2026-102566 (CTranslate2 before 4.8.1 contains a
heap-based buffer overflow
NOT-FOR-US: CTranslate2
CVE-2026-102560 (A flaw was found in libsoup. When the permessage-deflate
WebSocket ext ...)
- libsoup3 <unfixed>
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543296
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/libsoup/-/commit/dbd0417ea3a569135e9a9344b7812076b7b178f1
(3.7.3)
CVE-2026-102559 (A flaw was found in libsoup. When constructing a masked
WebSocket clie ...)
- libsoup3 <unfixed>
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543285
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/554
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/libsoup/-/commit/d7f074f8c8c90216f2476522836287c6f80fc53e
(3.7.3)
@@ -500,8 +515,9 @@ CVE-2026-102495 (Apache XmlSchema doesn't limit how deeply
schema imports and in
CVE-2026-102491 (A vulnerability was identified in mahonelau kykms up to
8f130c2d85842d ...)
NOT-FOR-US: mahonelau kykms
CVE-2026-102474 (A flaw was found in dash. The printf builtin reserves four
bytes befor ...)
- - dash <unfixed>
- NOTE: ttps://bugzilla.redhat.com/show_bug.cgi?id=2543004
+ - dash <unfixed> (unimportant)
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543004
+ NOTE: Negligible security impact
CVE-2026-102473 (A flaw was found in dash. When built without libc fnmatch,
the interna ...)
- dash <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543005
@@ -1070,6 +1086,7 @@ CVE-2026-102422 (shell-quote's `quote()` function emits a
`{ comment }` token as
NOTE: Fixed by:
https://github.com/ljharb/shell-quote/commit/6002b2ed90c6b83095eb272b6b0adaf3a172b0bc
(v1.11.0)
CVE-2026-102414 (pbkdf2 through 3.1.6 re-hashes passwords longer than the
digest's bloc ...)
- node-pbkdf2 <unfixed>
+ [trixie] - node-pbkdf2 <no-dsa> (Minor issue)
NOTE:
https://github.com/browserify/pbkdf2/security/advisories/GHSA-477h-4r7f-fvrx
NOTE: https://github.com/browserify/pbkdf2/issues/82
NOTE: Fixed by:
https://github.com/browserify/pbkdf2/commit/493d8d8ff437f680338bf7397398fda884ad462e
(v3.1.7)
=====================================
data/dsa-needed.txt
=====================================
@@ -106,6 +106,8 @@ ntfs-3g (carnil)
--
node-dompurify
--
+node-shell-quote
+--
nsd
--
openexr
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b3b58576e7a1f7506d310880c775dc3a868b4d7
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8b3b58576e7a1f7506d310880c775dc3a868b4d7
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits