Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
fedfa495 by Moritz Muehlenhoff at 2026-10-01T20:26:25+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3265,27 +3265,35 @@ CVE-2026-102305 (UI misrepresentation in SignIn in
Google Chrome on on iOS prior
- chromium 154.0.8037.92-1
CVE-2026-94053 (Authentication bypass via LDAP injection in component
sshd-ldap in Apa ...)
- libmina-sshd-java <unfixed>
+ [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/39
CVE-2026-94052 (A missing check in LdapPasswordAuthenticator in component
sshd-ldap in ...)
- libmina-sshd-java <unfixed>
+ [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/38
CVE-2026-94029 (Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to
2.19.0 and ...)
- libmina-sshd-java <unfixed>
+ [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/37
CVE-2026-94002 (Possible memory exhaustion in SFTP clients (DefaultSftpClient)
in comp ...)
- libmina-sshd-java <unfixed>
+ [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/36
CVE-2026-93996 (Uncontrolled resource consumption in component ssd-scp in
Apache MINA ...)
- libmina-sshd-java <unfixed>
+ [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/35
CVE-2026-93995 (Improper input validation in sshd-git in Apache MINA SSHD,
versions up ...)
- libmina-sshd-java <unfixed>
+ [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/34
CVE-2026-93994 (Apache MINA SSHD is a Java library for client-side and
server-side SSH ...)
- libmina-sshd-java <unfixed>
+ [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/33
CVE-2026-77185 (Authentication bypass in sshd-core in Apache MINA SSHD
versions 2.0.0 ...)
- libmina-sshd-java <unfixed>
+ [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/32
CVE-2026-98164 (In the Linux kernel, the following vulnerability has been
resolved: K ...)
- linux 7.1.13-1
@@ -9424,11 +9432,13 @@ CVE-2026-97404 (In OpenStack Zaqar before 22.0.2, WSGI
transport mishandles the
CVE-2026-88816 (DBI versions before 1.654 for Perl incorrectly treat numeric
values as ...)
{DLA-4798-1}
- libdbi-perl 1.654-1 (bug #1149042)
+ [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43915934/
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/70962570212dc60a5428098cf2a0462ad5945851
(1.654)
CVE-2026-88815 (DBI versions before 1.654 for Perl incorrectly treat numeric
values as ...)
{DLA-4798-1}
- libdbi-perl 1.654-1 (bug #1149042)
+ [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43915930/
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d6702
(1.654)
CVE-2026-97521 (In the Linux kernel, the following vulnerability has been
resolved: g ...)
@@ -11611,21 +11621,27 @@ CVE-2026-93402 [mdtls discards the peer-identity
verification result]
NOTE: Fixed by:
https://github.com/rsyslog/rsyslog/commit/7847bd5392cb018646afc8f267aedfb5d51df1f9
CVE-2026-XXXX [GHSA-v8qw-hwjv-44hw: AV1/libaom path allows allocation before
libheif rejects mismatched coded dimensions]
- libheif <unfixed>
+ [trixie] - libheif <no-dsa> (Minor issue)
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-v8qw-hwjv-44hw
CVE-2026-XXXX [GHSA-qfj5-c4pq-q998: Out-of-bounds heap read in
unc_encoder_rgb_pixel_interleave when an alpha plane is attached to an image
whose chroma format carries no alpha]
- libheif <unfixed>
+ [trixie] - libheif <no-dsa> (Minor issue)
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-qfj5-c4pq-q998
CVE-2026-XXXX [GHSA-qwpf-5wf7-r996: Heap-use-after-free and double free in
ImageItem::encode_to_bitstream_and_boxes (shallow copy of
ImageDescription::m_tai_timestamp)]
- libheif <unfixed>
+ [trixie] - libheif <no-dsa> (Minor issue)
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-qwpf-5wf7-r996
CVE-2026-XXXX [GHSA-9c75-9g8r-4728: JPEG 2000 pclr zero-column allocation
amplification bypasses max_total_memory]
- libheif <unfixed>
+ [trixie] - libheif <no-dsa> (Minor issue)
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-9c75-9g8r-4728
CVE-2026-XXXX [GHSA-r7gr-2xm2-23wf: Heap out-of-bounds read in libheif alpha
compositing via mismatched per-channel bit depths (uncompressed codec)]
- libheif <unfixed>
+ [trixie] - libheif <no-dsa> (Minor issue)
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-r7gr-2xm2-23wf
CVE-2026-XXXX [GHSA-7pwf-qh74-p35w: Caller-configured security limits not
enforced for MINI-box parsing]
- libheif <unfixed>
+ [trixie] - libheif <no-dsa> (Minor issue)
NOTE:
https://github.com/strukturag/libheif/security/advisories/GHSA-7pwf-qh74-p35w
CVE-2026-XXXX [GHSA-xq87-9rrm-6wqw]
- freerdp3 3.32.0+dfsg-1
@@ -15112,13 +15128,20 @@ CVE-2026-92249 (The Qi Addons For Elementor plugin
for WordPress is vulnerable t
NOT-FOR-US: WordPress plugin
CVE-2026-91149 (A flaw was found in Cockpit. An unauthenticated remote
attacker can ex ...)
- cockpit 368-1
+ [trixie] - cockpit <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479422
+ NOTE:
https://github.com/cockpit-project/cockpit/commit/e12c37897d5a8efb41c65ca95064930e256d562e
(368)
CVE-2026-91147 (A flaw was found in `cockpit-ws`. This vulnerability allows a
remote, ...)
- cockpit 368-1
+ [trixie] - cockpit <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479230
+ NOTE:
https://github.com/cockpit-project/cockpit/commit/78afe1d587afb6b380e1b8999a0955ad09c31902
(368)
CVE-2026-91142 (A flaw was found in Cockpit. An integer overflow vulnerability
in the ...)
- cockpit 368-1
+ [trixie] - cockpit <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479459
+ NOTE:
https://github.com/cockpit-project/cockpit/commit/5efa4af065321873f6eb8988f3b0b50e981689ba
(368)
+ NOTE:
https://github.com/cockpit-project/cockpit/commit/6e76c96272a4ebcb085c948e5cc9189eeee561af
(368)
CVE-2026-91127 (File Viewer is a browser-native viewer for Office, PDF, CAD,
archive, ...)
NOT-FOR-US: File Viewer
CVE-2026-90981 (The Newsletter \u2013 Send awesome emails from WordPress
plugin for Wo ...)
@@ -29385,6 +29408,7 @@ CVE-2026-80926 (In the Linux kernel, the following
vulnerability has been resolv
CVE-2026-78030 (DBI versions before 1.653 for Perl load arbitrary modules via
unvalida ...)
{DLA-4798-1}
- libdbi-perl 1.653-1
+ [trixie] - libdbi-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43677746/
NOTE:
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-wqmw-wqwx-3fr7
NOTE: Fixed by:
https://github.com/perl5-dbi/dbi/commit/315c6ce703b8b3cbe9188062d9ec80730293554a
(1.653)
@@ -30200,6 +30224,7 @@ CVE-2026-88860 (Capgo fails to clean up channel
permission overrides when a user
NOT-FOR-US: Cap-go
CVE-2026-88859 (A flaw was found in Evolution. A remote attacker can exploit
this vuln ...)
- evolution <unfixed> (bug #1147400)
+ [trixie] - evolution <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/evolution/-/work_items/3388
NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/evolution/-/commit/a6f37ef58f9889e361022d46e70b8a53b6f9fd97
(3.62.0)
CVE-2026-88790 (A security vulnerability has been detected in proma-ai Proma
up to 0.1 ...)
@@ -31014,9 +31039,8 @@ CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2
contain an argument injection v
CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to
authori ...)
NOT-FOR-US: AlchemyCMS
CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX
header fiel ...)
- - keepass2 <unfixed>
- NOTE: https://github.com/KSecur1ty/KDBX-Header-Size-Mirage-POC
- TODO: check upstream details
+ NOTE: Bogus CVE for keepass2:
+ NOTE: Quoting from https://keepass.info/help/kb/sec_issues.html:
CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path
traversal vulne ...)
NOT-FOR-US: knowns-dev/knowns
CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control
vulnera ...)
@@ -153857,6 +153881,7 @@ CVE-2026-34994
REJECTED
CVE-2026-32148 (Insufficient Verification of Data Authenticity vulnerability
in hexpm ...)
- erlang-hex 2.4.2-2
+ [trixie] - erlang-hex <no-dsa> (Minor issue)
NOTE:
https://github.com/hexpm/hex/security/advisories/GHSA-hmv9-4mfr-m92v
NOTE: https://cna.erlef.org/cves/CVE-2026-32148.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-32148
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fedfa495b7de93bb1040f1e8d1b8cc1fb81393a1
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fedfa495b7de93bb1040f1e8d1b8cc1fb81393a1
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits