Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
fedfa495 by Moritz Muehlenhoff at 2026-10-01T20:26:25+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3265,27 +3265,35 @@ CVE-2026-102305 (UI misrepresentation in SignIn in 
Google Chrome on on iOS prior
        - chromium 154.0.8037.92-1
 CVE-2026-94053 (Authentication bypass via LDAP injection in component 
sshd-ldap in Apa ...)
        - libmina-sshd-java <unfixed>
+       [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/39
 CVE-2026-94052 (A missing check in LdapPasswordAuthenticator in component 
sshd-ldap in ...)
        - libmina-sshd-java <unfixed>
+       [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/38
 CVE-2026-94029 (Server-side memory exhaustion in Apache MINA SSHD 1.0.0 to 
2.19.0 and  ...)
        - libmina-sshd-java <unfixed>
+       [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/37
 CVE-2026-94002 (Possible memory exhaustion in SFTP clients (DefaultSftpClient) 
in comp ...)
        - libmina-sshd-java <unfixed>
+       [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/36
 CVE-2026-93996 (Uncontrolled resource consumption in component ssd-scp in 
Apache MINA  ...)
        - libmina-sshd-java <unfixed>
+       [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/35
 CVE-2026-93995 (Improper input validation in sshd-git in Apache MINA SSHD, 
versions up ...)
        - libmina-sshd-java <unfixed>
+       [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/34
 CVE-2026-93994 (Apache MINA SSHD is a Java library for client-side and 
server-side SSH ...)
        - libmina-sshd-java <unfixed>
+       [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/33
 CVE-2026-77185 (Authentication bypass in sshd-core in Apache MINA SSHD 
versions 2.0.0  ...)
        - libmina-sshd-java <unfixed>
+       [trixie] - libmina-sshd-java <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/09/29/32
 CVE-2026-98164 (In the Linux kernel, the following vulnerability has been 
resolved:  K ...)
        - linux 7.1.13-1
@@ -9424,11 +9432,13 @@ CVE-2026-97404 (In OpenStack Zaqar before 22.0.2, WSGI 
transport mishandles the
 CVE-2026-88816 (DBI versions before 1.654 for Perl incorrectly treat numeric 
values as ...)
        {DLA-4798-1}
        - libdbi-perl 1.654-1 (bug #1149042)
+       [trixie] - libdbi-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/43915934/
        NOTE: Fixed by: 
https://github.com/perl5-dbi/dbi/commit/70962570212dc60a5428098cf2a0462ad5945851
 (1.654)
 CVE-2026-88815 (DBI versions before 1.654 for Perl incorrectly treat numeric 
values as ...)
        {DLA-4798-1}
        - libdbi-perl 1.654-1 (bug #1149042)
+       [trixie] - libdbi-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/43915930/
        NOTE: Fixed by: 
https://github.com/perl5-dbi/dbi/commit/e5ad87e5602da995d28b4d65df222368b58d6702
 (1.654)
 CVE-2026-97521 (In the Linux kernel, the following vulnerability has been 
resolved:  g ...)
@@ -11611,21 +11621,27 @@ CVE-2026-93402 [mdtls discards the peer-identity 
verification result]
        NOTE: Fixed by: 
https://github.com/rsyslog/rsyslog/commit/7847bd5392cb018646afc8f267aedfb5d51df1f9
 CVE-2026-XXXX [GHSA-v8qw-hwjv-44hw: AV1/libaom path allows allocation before 
libheif rejects mismatched coded dimensions]
        - libheif <unfixed>
+       [trixie] - libheif <no-dsa> (Minor issue)
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-v8qw-hwjv-44hw
 CVE-2026-XXXX [GHSA-qfj5-c4pq-q998: Out-of-bounds heap read in 
unc_encoder_rgb_pixel_interleave when an alpha plane is attached to an image 
whose chroma format carries no alpha]
        - libheif <unfixed>
+       [trixie] - libheif <no-dsa> (Minor issue)
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-qfj5-c4pq-q998
 CVE-2026-XXXX [GHSA-qwpf-5wf7-r996: Heap-use-after-free and double free in 
ImageItem::encode_to_bitstream_and_boxes (shallow copy of 
ImageDescription::m_tai_timestamp)]
        - libheif <unfixed>
+       [trixie] - libheif <no-dsa> (Minor issue)
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-qwpf-5wf7-r996
 CVE-2026-XXXX [GHSA-9c75-9g8r-4728: JPEG 2000 pclr zero-column allocation 
amplification bypasses max_total_memory]
        - libheif <unfixed>
+       [trixie] - libheif <no-dsa> (Minor issue)
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-9c75-9g8r-4728
 CVE-2026-XXXX [GHSA-r7gr-2xm2-23wf: Heap out-of-bounds read in libheif alpha 
compositing via mismatched per-channel bit depths (uncompressed codec)]
        - libheif <unfixed>
+       [trixie] - libheif <no-dsa> (Minor issue)
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-r7gr-2xm2-23wf
 CVE-2026-XXXX [GHSA-7pwf-qh74-p35w: Caller-configured security limits not 
enforced for MINI-box parsing]
        - libheif <unfixed>
+       [trixie] - libheif <no-dsa> (Minor issue)
        NOTE: 
https://github.com/strukturag/libheif/security/advisories/GHSA-7pwf-qh74-p35w
 CVE-2026-XXXX [GHSA-xq87-9rrm-6wqw]
        - freerdp3 3.32.0+dfsg-1
@@ -15112,13 +15128,20 @@ CVE-2026-92249 (The Qi Addons For Elementor plugin 
for WordPress is vulnerable t
        NOT-FOR-US: WordPress plugin
 CVE-2026-91149 (A flaw was found in Cockpit. An unauthenticated remote 
attacker can ex ...)
        - cockpit 368-1
+       [trixie] - cockpit <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479422
+       NOTE: 
https://github.com/cockpit-project/cockpit/commit/e12c37897d5a8efb41c65ca95064930e256d562e
 (368)
 CVE-2026-91147 (A flaw was found in `cockpit-ws`. This vulnerability allows a 
remote,  ...)
        - cockpit 368-1
+       [trixie] - cockpit <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479230
+       NOTE: 
https://github.com/cockpit-project/cockpit/commit/78afe1d587afb6b380e1b8999a0955ad09c31902
 (368)
 CVE-2026-91142 (A flaw was found in Cockpit. An integer overflow vulnerability 
in the  ...)
        - cockpit 368-1
+       [trixie] - cockpit <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479459
+       NOTE: 
https://github.com/cockpit-project/cockpit/commit/5efa4af065321873f6eb8988f3b0b50e981689ba
 (368)
+       NOTE: 
https://github.com/cockpit-project/cockpit/commit/6e76c96272a4ebcb085c948e5cc9189eeee561af
 (368)
 CVE-2026-91127 (File Viewer is a browser-native viewer for Office, PDF, CAD, 
archive,  ...)
        NOT-FOR-US: File Viewer
 CVE-2026-90981 (The Newsletter \u2013 Send awesome emails from WordPress 
plugin for Wo ...)
@@ -29385,6 +29408,7 @@ CVE-2026-80926 (In the Linux kernel, the following 
vulnerability has been resolv
 CVE-2026-78030 (DBI versions before 1.653 for Perl load arbitrary modules via 
unvalida ...)
        {DLA-4798-1}
        - libdbi-perl 1.653-1
+       [trixie] - libdbi-perl <no-dsa> (Minor issue)
        NOTE: https://lists.security.metacpan.org/cve-announce/msg/43677746/
        NOTE: 
https://github.com/perl5-dbi/dbi/security/advisories/GHSA-wqmw-wqwx-3fr7
        NOTE: Fixed by: 
https://github.com/perl5-dbi/dbi/commit/315c6ce703b8b3cbe9188062d9ec80730293554a
 (1.653)
@@ -30200,6 +30224,7 @@ CVE-2026-88860 (Capgo fails to clean up channel 
permission overrides when a user
        NOT-FOR-US: Cap-go
 CVE-2026-88859 (A flaw was found in Evolution. A remote attacker can exploit 
this vuln ...)
        - evolution <unfixed> (bug #1147400)
+       [trixie] - evolution <no-dsa> (Minor issue)
        NOTE: https://gitlab.gnome.org/GNOME/evolution/-/work_items/3388
        NOTE: Fixed by: 
https://gitlab.gnome.org/GNOME/evolution/-/commit/a6f37ef58f9889e361022d46e70b8a53b6f9fd97
 (3.62.0)
 CVE-2026-88790 (A security vulnerability has been detected in proma-ai Proma 
up to 0.1 ...)
@@ -31014,9 +31039,8 @@ CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 
contain an argument injection v
 CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to 
authori ...)
        NOT-FOR-US: AlchemyCMS
 CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX 
header fiel ...)
-       - keepass2 <unfixed>
-       NOTE: https://github.com/KSecur1ty/KDBX-Header-Size-Mirage-POC
-       TODO: check upstream details
+       NOTE: Bogus CVE for keepass2:
+       NOTE: Quoting from https://keepass.info/help/kb/sec_issues.html:
 CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path 
traversal vulne ...)
        NOT-FOR-US: knowns-dev/knowns
 CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control 
vulnera ...)
@@ -153857,6 +153881,7 @@ CVE-2026-34994
        REJECTED
 CVE-2026-32148 (Insufficient Verification of Data Authenticity vulnerability 
in hexpm  ...)
        - erlang-hex 2.4.2-2
+       [trixie] - erlang-hex <no-dsa> (Minor issue)
        NOTE: 
https://github.com/hexpm/hex/security/advisories/GHSA-hmv9-4mfr-m92v
        NOTE: https://cna.erlef.org/cves/CVE-2026-32148.html
        NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-32148



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fedfa495b7de93bb1040f1e8d1b8cc1fb81393a1

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fedfa495b7de93bb1040f1e8d1b8cc1fb81393a1
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to