Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8cf51689 by Moritz Muehlenhoff at 2026-10-02T16:48:49+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -602,6 +602,7 @@ CVE-2026-104018 (An improper privilege management 
vulnerability (CWE-269) exists
        NOT-FOR-US: WindRiver
 CVE-2026-103923 (KaTeX is a fast, easy-to-use JavaScript library for TeX math 
rendering ...)
        - node-katex <unfixed> (bug #1149653)
+       [trixie] - node-katex <no-dsa> (Minor issue)
        NOTE: 
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7
        NOTE: https://github.com/KaTeX/KaTeX/pull/4260
        NOTE: Fixed by: 
https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4 
(v0.18.2)
@@ -629,14 +630,17 @@ CVE-2026-103687 (A vulnerability has been found in 
rhukster dom-sanitizer up to
 CVE-2026-103686 (A flaw has been found in rhukster dom-sanitizer up to 1.0.15. 
Impacted ...)
        NOT-FOR-US: DOMSanitizer
 CVE-2026-103680 (A flaw was found in tnef. A heap-based buffer overflow can 
occur in th ...)
-       - tnef <unfixed>
+       - tnef <unfixed> (unimportant)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2544478
+       NOTE: Crash in CLI tool, no security impact (mitigated by toolchain 
hardening)
 CVE-2026-103679 (A flaw was found in tnef. A remote attacker could exploit 
this vulnera ...)
-       - tnef <unfixed>
+       - tnef <unfixed> (unimportant)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2544477
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-103678 (A flaw was found in tnef. An attacker can exploit this 
vulnerability b ...)
-       - tnef <unfixed>
+       - tnef <unfixed> (unimportant)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2544476
+       NOTE: Crash in CLI tool, no security impact
 CVE-2026-103664 (MISP contains a reflected cross-site scripting (XSS) 
vulnerability in  ...)
        - misp <itp> (bug #1144317)
 CVE-2026-103662 (MISP contains a reflected cross-site scripting (XSS) 
vulnerability in  ...)
@@ -1559,6 +1563,7 @@ CVE-2026-96338 (Subscriber Cross Site Scripting (XSS) in 
Profile Builder <= 4.0.
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-95616 (An integer overflow in WSS4J's DER bounds check lets an 
oversized allo ...)
        - wss4j <unfixed>
+       [trixie] - wss4j <no-dsa> (Minor issue)
        NOTE: 
https://lists.apache.org/thread.html/sdf0fsphkg4qbj7nh2brjgwvcmd67hct
 CVE-2026-95587 (Unauthenticated Broken Access Control in Hostinger Migrator <= 
1.0 ver ...)
        NOT-FOR-US: WordPress plugin or theme
@@ -1644,6 +1649,7 @@ CVE-2026-93460 (A stored cross-site scripting 
vulnerability via appended strings
        NOT-FOR-US: baserCMS
 CVE-2026-92899 (Apache WSS4J remembers the Nonce of each UsernameToken it 
accepts, so  ...)
        - wss4j <unfixed>
+       [trixie] - wss4j <no-dsa> (Minor issue)
        NOTE: 
https://lists.apache.org/thread.html/nrzngsz1xm2lztq3t873663xx9wnrwm7
 CVE-2026-92873 (Pgpool-II contains an incorrect implementation of an 
authentication al ...)
        - pgpool2 4.7.3-1 (bug #1149670)
@@ -1670,19 +1676,23 @@ CVE-2026-92712 (The ReactPress \u2013 Create React App 
for WordPress plugin for
        NOT-FOR-US: WordPress plugin
 CVE-2026-92121 (In the WSS4J streaming (StAX) code, a signature reference 
using the WS ...)
        - wss4j <unfixed>
+       [trixie] - wss4j <no-dsa> (Minor issue)
        NOTE: 
https://lists.apache.org/thread.html/oop9p4hpl5o9byosb1qg3z7q1sgnn4pc
 CVE-2026-91860 (A prototype pollution vulnerability exists in the deep merge 
helpers o ...)
        NOT-FOR-US: Vaadin
 CVE-2026-89238 (WSS4J EncryptedHeader child confusion could promote an 
attacker-contro ...)
        - wss4j <unfixed>
+       [trixie] - wss4j <no-dsa> (Minor issue)
        NOTE: 
https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w
 CVE-2026-88920 (An authentication bypass in the DOM security processor in 
Apache WSS4J ...)
        - wss4j <unfixed>
+       [trixie] - wss4j <no-dsa> (Minor issue)
        NOTE: 
https://lists.apache.org/thread.html/grt43m3bgbzz0mk0cnho3rcybb1j01z9
 CVE-2026-88037 (The Bold Page Builder plugin for WordPress is vulnerable to 
Stored Cro ...)
        NOT-FOR-US: WordPress plugin
 CVE-2026-87830 (In the StAX streaming WS-SecurityPolicy validator, certain 
relative or ...)
        - wss4j <unfixed>
+       [trixie] - wss4j <no-dsa> (Minor issue)
        NOTE: 
https://lists.apache.org/thread.html/lwlozb1x20d16f9dnyvoygc9rrhzq2vn
 CVE-2026-87004 (Tugtainer is a self-hosted app for automating updates of 
Docker contai ...)
        NOT-FOR-US: Tugtainer
@@ -1690,6 +1700,7 @@ CVE-2026-86778 (Observable response discrepancy 
vulnerability in Maksisoft Techn
        NOT-FOR-US: Maksisoft Gym
 CVE-2026-85532 (Apache WSS4J accepted attacker-controlled derived-key lengths 
and offs ...)
        - wss4j <unfixed>
+       [trixie] - wss4j <no-dsa> (Minor issue)
        NOTE: 
https://lists.apache.org/thread.html/7jllcpbf4nbzhdp2vchz5yplnl5w6vd6
 CVE-2026-82307 (Improper neutralization of special elements used in an SQL 
command ('S ...)
        NOT-FOR-US: SOPLOG
@@ -4132,6 +4143,7 @@ CVE-2024-31026 (An issue in Greek Universities Network 
(GUnet) Open eClass Platf
        NOT-FOR-US: Greek Universities Network (GUnet) Open eClass Platform
 CVE-2026-XXXX [GHSA-5rfj-p5qw-w48g: Unauthenticated remote DoS via 
attacker-controlled reverse-DNS hostname in auto-hosts parsing]
        - sshuttle 2.0.0-1
+       [trixie] - sshuttle <no-dsa> (Minor issue)
        NOTE: 
https://github.com/sshuttle/sshuttle/security/advisories/GHSA-5rfj-p5qw-w48g
        NOTE: Fixed by: 
https://github.com/sshuttle/sshuttle/commit/baea31a6769baeb52e8837ad6cc582017d74676c
 (v2.0.0)
 CVE-2026-102331 (Buffer overflow in ANGLE in Google Chrome on on Android prior 
to 154.0 ...)
@@ -4285,6 +4297,7 @@ CVE-2026-96428 (SQL Injection in the 
/WebAgenda/SMBAjaxAutoComplete.do API endpo
        NOT-FOR-US: Flowring Agentflow
 CVE-2026-95520 (A heap-based buffer overflow flaw was found in rpm. Parsing a 
symlink  ...)
        - rpm <unfixed>
+       [trixie] - rpm <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537809
 CVE-2026-19395
        NOT-FOR-US: Qt for MCUs
@@ -5404,14 +5417,17 @@ CVE-2026-XXXX [groff issues]
        NOTE: https://savannah.gnu.org/bugs/?68688 (private)
 CVE-2026-16271 [hw/display/qxl: validate primary surface stride against width]
        - qemu 1:11.1.2+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/f39ebe53c3f319132cfb60030de12c8547426ace
 (v11.1.2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/e6d0120e039a961392eea2c566a4b110884a1b60
 (v10.0.14)
 CVE-2026-77913 [hw/display/vga: fix text-mode OOB write after a graphics 
surface switch]
        - qemu 1:11.1.2+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/f3c6a0a6dcae7b6beef21a9ee332c1c6e8035c8a
 (v11.1.2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/931861685366c372e1c12faf8e10786409ee4d12
 (v10.0.14)
 CVE-2026-84788 [io/channel-socket: do not treat a zero length write as an 
error]
        - qemu 1:11.1.2+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/98b79943b28d417327e36281dca180dd2b95c75d
 (v11.1.2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/756836f32a394b3cd29dff540a7dd907600dc589
 (v11.1.2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/a1bc6e49b357458eecd94e05ca9eea00336c4dce
 (v11.1.2)
@@ -5424,14 +5440,17 @@ CVE-2026-84788 [io/channel-socket: do not treat a zero 
length write as an error]
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/316989d81e9bb4d253c8e726d462c7bb7031d04c
 (v10.0.14)
 CVE-2026-66900 [hw/net/virtio-net: strip trailing padding when caching RSC 
segment]
        - qemu 1:11.1.2+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/ec2fdc85829a5090ebaea2f4094b9616a4ea6309
 (v11.1.2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/cc48e48a3a3a836ce712305bbeeb9515900dd4ef
 (v10.0.14)
 CVE-2026-66899 [virtio-balloon: fix free-page BH teardown on unrealize]
        - qemu 1:11.1.2+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/f731c7d2d4cc511abba74607bea4184c207a069e
 (v11.1.2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/be1244c42390de95fa5201a722f3db1302ccef2d
 (v10.0.14)
 CVE-2026-17588 [hw/usb/hcd-xhci: Set reentrancy guard in timer functions]
        - qemu 1:11.1.2+ds-1
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/ed582623e2372fdf862a804d122766052aba81c7
 (v11.1.2)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/1622c9abec17d5cba63383d4d4cb1419cedf8158
 (v10.0.14)
 CVE-2026-46675 [Use-after-free of zlib input in `png_read_end` after 
incomplete zTXt, iTXt or iCCP decompression]
@@ -11821,6 +11840,7 @@ CVE-2026-92284 (Caddy is an extensible server platform 
that uses TLS by default.
        TODO: check references, refers to GHSA-j8px-rmrx-76h9 which is for 
CVE-2026-77281
 CVE-2026-92164 (Streamlink is a CLI utility which pipes video streams from 
various ser ...)
        - streamlink 8.6.0-1
+       [trixie] - streamlink <no-dsa> (Minor issue)
        NOTE: 
https://github.com/streamlink/streamlink/security/advisories/GHSA-vf2x-4v53-pm7v
        NOTE: 
https://github.com/streamlink/streamlink/commit/4b99c64dde21ea70c24d9ffdbd15849b05f465c6
 (8.6.0)
 CVE-2026-92001 (Improper restriction of recursive entity references in DTDs 
('XML enti ...)
@@ -15109,6 +15129,7 @@ CVE-2026-82187 (The Web to Print Online Designer 
WordPress plugin before 2.15.0
        NOT-FOR-US: WordPress plugin
 CVE-2026-92382 (An out-of-bounds write flaw was found in usbredir. Starting an 
isochro ...)
        - usbredir <unfixed> (bug #1148831)
+       [trixie] - usbredir <postponed> (Revisit when fixed upstream)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2535972
        TODO: check details once Red Hat opens up bugzilla entry
 CVE-2026-94113 (Frappe ERPNext versions before 15.121.0 and 16.x before 
16.34.0 contai ...)
@@ -31456,6 +31477,7 @@ CVE-2026-88021 (Consul and Consul Enterprise are 
vulnerable to an authorization
        - consul <removed>
 CVE-2026-88018 (rclone is a command-line program to sync files and directories 
to and  ...)
        - rclone <unfixed> (bug #1147404)
+       [trixie] - rclone <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-xwwr-4h3p-r22c
        NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/90595f34f27f569be6b27c57fe5ab65057d323bd
 (1.75.1)
 CVE-2026-88017 (rclone is a command-line program to sync files and directories 
to and  ...)
@@ -116786,6 +116808,7 @@ CVE-2026-54503 (plone.app.textfield provides a 
zope.schema-style field type call
        NOT-FOR-US: Plone
 CVE-2026-55830 (RestrictedPython is a tool that helps to define a subset of 
the Python ...)
        - restrictedpython 8.4-1
+       [trixie] - restrictedpython <no-dsa> (Minor issue)
        NOTE: 
https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-ffg3-p8fm-mjx2
        NOTE: Fixed by: 
https://github.com/zopefoundation/RestrictedPython/commit/3737596ec9f28c34a073cc845bd2f4c0a80cb671
 (8.3)
 CVE-2026-55099 (icalendar is an RFC 5545 compatible parser and generator of 
iCalendar  ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -165,6 +165,8 @@ sabnzbdplus
 --
 shaarli
 --
+social-auth-core
+--
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8cf51689ec9b5231027c01e1e0970b3047f83876

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8cf51689ec9b5231027c01e1e0970b3047f83876
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to