Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c6905245 by Moritz Muehlenhoff at 2026-10-01T22:31:30+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -838,6 +838,7 @@ CVE-2026-102991 (Mako is a template library written in 
Python. Prior to 1.4.2, o
        NOTE: Fxied by: 
https://github.com/sqlalchemy/mako/commit/000ed85e4e48771eff460bf4fc721fb43de80e08
 (rel_1_4_2)
 CVE-2026-102990 (basic-ftp is an FTP client for Node.js. Prior to 6.2.1, 
Client.list()  ...)
        - node-proxy-agents <unfixed>
+       [trixie] - node-proxy-agents <no-dsa> (Minor issue)
        NOTE: 
https://github.com/patrickjuchli/basic-ftp/security/advisories/GHSA-c475-qrg2-pj4r
        NOTE: Fixed by: 
https://github.com/patrickjuchli/basic-ftp/commit/d0d9e07c56e519587bb50532ac6eadbb0cb0cfe9
 (v6.2.1)
 CVE-2026-102150 (A function in the Kiteworks Advanced Forms component was 
reachable wit ...)
@@ -964,6 +965,7 @@ CVE-2026-102089 (Kiteworks Email Protection Gateway before 
version 9.5.0 is vuln
        NOT-FOR-US: Kiteworks
 CVE-2026-101887 (BlueALSA (bluez-alsa/bluealsad) contains a division-by-zero 
vulnerabil ...)
        - bluez-alsa <unfixed>
+       [trixie] - bluez-alsa <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/arkq/bluez-alsa/commit/1a84465dd860d1be9dcf62339c6273e9e0632dd2
 CVE-2026-101885 (ZeroClaw versions before 0.8.5 built with plugins-wasm 
feature contain ...)
        NOT-FOR-US: ZeroClaw
@@ -3095,9 +3097,11 @@ CVE-2026-103437 (Improper neutralization of 
Script-Related HTML tags in a web pa
        NOT-FOR-US: MediaWiki extensions/skins not packaged in Debian
 CVE-2026-103436 (apcupsd through 3.14.14 discloses uninitialized stack memory 
in getups ...)
        - apcupsd <unfixed>
+       [trixie] - apcupsd <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493140
 CVE-2026-103432 (apcupsd through 3.14.14 has an sscanf stack-based buffer 
overflow in g ...)
        - apcupsd <unfixed>
+       [trixie] - apcupsd <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2493140
 CVE-2026-103399 (A flaw was found in SoupServer (libsoup). When an HTTP/1.x 
client send ...)
        - libsoup3 3.8.0-1
@@ -3128,6 +3132,7 @@ CVE-2026-103243 (LightLLM through 1.2.0 fails to validate 
image_url and audio_ur
        NOT-FOR-US: LightLLM
 CVE-2026-103242 (A heap-based buffer overflow flaw was found in rpm. 
RPMTAG_FILESIGNATU ...)
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2543866
 CVE-2026-103241 (A flaw has been found in vllm-project vLLM up to 0.26.0. This 
vulnerab ...)
        - vllm <itp> (bug #1095237)
@@ -3367,6 +3372,7 @@ CVE-2026-94204 (The central cloud storage backend for the 
entire dashcam platfor
        NOT-FOR-US: Viidure
 CVE-2026-93853 (Unverified ownership in Barman snapshot backup deletion allows 
a princ ...)
        - barman 3.20.1-1
+       [trixie] - barman <no-dsa> (Minor issue)
        NOTE: 
https://www.enterprisedb.com/docs/security/advisories/cve202693853/
 CVE-2026-93580 (The InPost PL WordPress plugin before 1.9.8 does not verify 
the authen ...)
        NOT-FOR-US: WordPress plugin
@@ -9741,6 +9747,7 @@ CVE-2026-88359 (libfyaml 0.9.6 contains a stack 
exhaustion vulnerability in fy_a
        NOTE: Fixed by: 
https://github.com/pantoniou/libfyaml/commit/12d903a5c9163d15edf2ef9d7311bd0d1505d902
 (v1.0.0-beta1)
 CVE-2026-88358 (simdjson 4.6.1 contains a one-byte out-of-bounds read 
vulnerability in ...)
        - simdjson <unfixed> (bug #1149053)
+       [trixie] - simdjson <no-dsa> (Minor issue)
        NOTE: https://github.com/simdjson/simdjson/issues/2815
        NOTE: https://github.com/simdjson/simdjson/pull/2817
        NOTE: Fixed by: 
https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577
@@ -11723,7 +11730,9 @@ CVE-2026-79304 (CyberPanel 1.9.1 contains a path 
traversal vulnerability in the
        NOT-FOR-US: CyberPanel
 CVE-2026-78253 (Uncontrolled recursion in QXmlStreamReader::readElementText() 
in Qt Gr ...)
        - qt6-base 6.11.2+dfsg-5
+       [trixie] - qt6-base <no-dsa> (Minor issue)
        - qtbase-opensource-src <unfixed>
+       [trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
        NOTE: https://codereview.qt-project.org/c/qt/qtbase/+/754345
        NOTE: 
https://github.com/qt/qtbase/commit/50cc08f278c6961d00b5b8bae408d4ccc2fbca4d 
(dev)
        NOTE: 
https://github.com/qt/qtbase/commit/f91c48650443262db9be37d5239ebe0db18e9555 
(v6.11.2)
@@ -31659,6 +31668,8 @@ CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 
8.x before 8.3.6 fail to a
 CVE-2026-86776 (KeePass versions 2.35 through 2.61.1 fail to validate KDBX 
header fiel ...)
        NOTE: Bogus CVE for keepass2:
        NOTE: Quoting from https://keepass.info/help/kb/sec_issues.html:
+       NOTE: When reading a KDBX file, KeePass may allocate about 2 GB of RAM 
(temporarily).
+       NOTE: We do not consider this to be a problem. Especially, it is not a 
security issue.
 CVE-2026-86775 (knowns (npm package) versions <= 0.29.1 contain a path 
traversal vulne ...)
        NOT-FOR-US: knowns-dev/knowns
 CVE-2026-86774 (Snipe-IT versions before 8.7.0 contain a broken access control 
vulnera ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -20,6 +20,9 @@ activemq
 amd64-microcode (carnil)
   Coordinating with maintainer DSA/bookworm-pu and sync with mitgations in 
src:linux
 --
+apache2
+  move to 2.4.69 after a grace period to wait for regressions
+--
 bouncycastle
   possibly move to 1.85 for trixie
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6905245284be7e526ebef8b1975d184e29649ab

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6905245284be7e526ebef8b1975d184e29649ab
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to