Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c6905245 by Moritz Muehlenhoff at 2026-10-01T22:31:30+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -838,6 +838,7 @@ CVE-2026-102991 (Mako is a template library written in
Python. Prior to 1.4.2, o
NOTE: Fxied by:
https://github.com/sqlalchemy/mako/commit/000ed85e4e48771eff460bf4fc721fb43de80e08
(rel_1_4_2)
CVE-2026-102990 (basic-ftp is an FTP client for Node.js. Prior to 6.2.1,
Client.list() ...)
- node-proxy-agents <unfixed>
+ [trixie] - node-proxy-agents <no-dsa> (Minor issue)
NOTE:
https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r
NOTE: Fixed by:
https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9
(v6.2.1)
CVE-2026-102150 (A function in the Kiteworks Advanced Forms component was
reachable wit ...)
@@ -964,6 +965,7 @@ CVE-2026-102089 (Kiteworks Email Protection Gateway before
version 9.5.0 is vuln
NOT-FOR-US: Kiteworks
CVE-2026-101887 (BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero
vulnerabil ...)
- bluez-alsa <unfixed>
+ [trixie] - bluez-alsa <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/arkq/bluez-alsa/commit/1a84465dd860d1be9dcf62339c6273e9e0632dd2
CVE-2026-101885 (ZeroClaw versions before 0.8.5 built with plugins-wasm
feature contain ...)
NOT-FOR-US: ZeroClaw
@@ -3095,9 +3097,11 @@ CVE-2026-103437 (Improper neutralization of
Script-Related HTML tags in a web pa
NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
CVE-2026-103436 (apcupsd through 3.14.14 discloses uninitialized stack memory
in getups ...)
- apcupsd <unfixed>
+ [trixie] - apcupsd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493140
CVE-2026-103432 (apcupsd through 3.14.14 has an sscanf stack-based buffer
overflow in g ...)
- apcupsd <unfixed>
+ [trixie] - apcupsd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493140
CVE-2026-103399 (A flaw was found in SoupServer (libsoup). When an HTTP/1.x
client send ...)
- libsoup3 3.8.0-1
@@ -3128,6 +3132,7 @@ CVE-2026-103243 (LightLLM through 1.2.0 fails to validate
image_url and audio_ur
NOT-FOR-US: LightLLM
CVE-2026-103242 (A heap-based buffer overflow flaw was found in rpm.
RPMTAG_FILESIGNATU ...)
- rpm <unfixed>
+ [trixie] - rpm <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543866
CVE-2026-103241 (A flaw has been found in vllm-project vLLM up to 0.26.0. This
vulnerab ...)
- vllm <itp> (bug #1095237)
@@ -3367,6 +3372,7 @@ CVE-2026-94204 (The central cloud storage backend for the
entire dashcam platfor
NOT-FOR-US: Viidure
CVE-2026-93853 (Unverified ownership in Barman snapshot backup deletion allows
a princ ...)
- barman 3.20.1-1
+ [trixie] - barman <no-dsa> (Minor issue)
NOTE:
https://www.enterprisedb.com/docs/security/advisories/cve202693853/
CVE-2026-93580 (The InPost PL WordPress plugin before 1.9.8 does not verify
the authen ...)
NOT-FOR-US: WordPress plugin
@@ -9741,6 +9747,7 @@ CVE-2026-88359 (libfyaml 0.9.6 contains a stack
exhaustion vulnerability in fy_a
NOTE: Fixed by:
https://github.com/pantoniou/libfyaml/commit/12d903a5c9163d15edf2ef9d7311bd0d1505d902
(v1.0.0-beta1)
CVE-2026-88358 (simdjson 4.6.1 contains a one-byte out-of-bounds read
vulnerability in ...)
- simdjson <unfixed> (bug #1149053)
+ [trixie] - simdjson <no-dsa> (Minor issue)
NOTE: https://github.com/simdjson/simdjson/issues/2815
NOTE: https://github.com/simdjson/simdjson/pull/2817
NOTE: Fixed by:
https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577
@@ -11723,7 +11730,9 @@ CVE-2026-79304 (CyberPanel 1.9.1 contains a path
traversal vulnerability in the
NOT-FOR-US: CyberPanel
CVE-2026-78253 (Uncontrolled recursion in QXmlStreamReader::readElementText()
in Qt Gr ...)
- qt6-base 6.11.2+dfsg-5
+ [trixie] - qt6-base <no-dsa> (Minor issue)
- qtbase-opensource-src <unfixed>
+ [trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
NOTE: https://codereview.qt-project.org/c/qt/qtbase/+/754345
NOTE:
https://github.com/qt/qtbase/commit/50cc08f278c6961d00b5b8bae408d4ccc2fbca4d
(dev)
NOTE:
https://github.com/qt/qtbase/commit/f91c48650443262db9be37d5239ebe0db18e9555
(v6.11.2)
@@ -31659,6 +31668,8 @@ CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and
8.x before 8.3.6 fail to a
CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX
header fiel ...)
NOTE: Bogus CVE for keepass2:
NOTE: Quoting from https://keepass.info/help/kb/sec_issues.html:
+ NOTE: When reading a KDBX file, KeePass may allocate about 2 GB of RAM
(temporarily).
+ NOTE: We do not consider this to be a problem. Especially, it is not a
security issue.
CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path
traversal vulne ...)
NOT-FOR-US: knowns-dev/knowns
CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control
vulnera ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -20,6 +20,9 @@ activemq
amd64-microcode (carnil)
Coordinating with maintainer DSA/bookworm-pu and sync with mitgations in
src:linux
--
+apache2
+ move to 2.4.69 after a grace period to wait for regressions
+--
bouncycastle
possibly move to 1.85 for trixie
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6905245284be7e526ebef8b1975d184e29649ab
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6905245284be7e526ebef8b1975d184e29649ab
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits