Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8cf51689 by Moritz Muehlenhoff at 2026-10-02T16:48:49+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -602,6 +602,7 @@ CVE-2026-104018 (An improper privilege management
vulnerability (CWE-269) exists
NOT-FOR-US: WindRiver
CVE-2026-103923 (KaTeX is a fast, easy-to-use JavaScript library for TeX math
rendering ...)
- node-katex <unfixed> (bug #1149653)
+ [trixie] - node-katex <no-dsa> (Minor issue)
NOTE:
https://github.com/KaTeX/KaTeX/security/advisories/GHSA-238p-pmpm-9mq7
NOTE: https://github.com/KaTeX/KaTeX/pull/4260
NOTE: Fixed by:
https://github.com/KaTeX/KaTeX/commit/0adf7e77db6915d991803b29699f82b1ccf8d4f4
(v0.18.2)
@@ -629,14 +630,17 @@ CVE-2026-103687 (A vulnerability has been found in
rhukster dom-sanitizer up to
CVE-2026-103686 (A flaw has been found in rhukster dom-sanitizer up to 1.0.15.
Impacted ...)
NOT-FOR-US: DOMSanitizer
CVE-2026-103680 (A flaw was found in tnef. A heap-based buffer overflow can
occur in th ...)
- - tnef <unfixed>
+ - tnef <unfixed> (unimportant)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2544478
+ NOTE: Crash in CLI tool, no security impact (mitigated by toolchain
hardening)
CVE-2026-103679 (A flaw was found in tnef. A remote attacker could exploit
this vulnera ...)
- - tnef <unfixed>
+ - tnef <unfixed> (unimportant)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2544477
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-103678 (A flaw was found in tnef. An attacker can exploit this
vulnerability b ...)
- - tnef <unfixed>
+ - tnef <unfixed> (unimportant)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2544476
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-103664 (MISP contains a reflected cross-site scripting (XSS)
vulnerability in ...)
- misp <itp> (bug #1144317)
CVE-2026-103662 (MISP contains a reflected cross-site scripting (XSS)
vulnerability in ...)
@@ -1559,6 +1563,7 @@ CVE-2026-96338 (Subscriber Cross Site Scripting (XSS) in
Profile Builder <= 4.0.
NOT-FOR-US: WordPress plugin or theme
CVE-2026-95616 (An integer overflow in WSS4J's DER bounds check lets an
oversized allo ...)
- wss4j <unfixed>
+ [trixie] - wss4j <no-dsa> (Minor issue)
NOTE:
https://lists.apache.org/thread.html/sdf0fsphkg4qbj7nh2brjgwvcmd67hct
CVE-2026-95587 (Unauthenticated Broken Access Control in Hostinger Migrator <=
1.0 ver ...)
NOT-FOR-US: WordPress plugin or theme
@@ -1644,6 +1649,7 @@ CVE-2026-93460 (A stored cross-site scripting
vulnerability via appended strings
NOT-FOR-US: baserCMS
CVE-2026-92899 (Apache WSS4J remembers the Nonce of each UsernameToken it
accepts, so ...)
- wss4j <unfixed>
+ [trixie] - wss4j <no-dsa> (Minor issue)
NOTE:
https://lists.apache.org/thread.html/nrzngsz1xm2lztq3t873663xx9wnrwm7
CVE-2026-92873 (Pgpool-II contains an incorrect implementation of an
authentication al ...)
- pgpool2 4.7.3-1 (bug #1149670)
@@ -1670,19 +1676,23 @@ CVE-2026-92712 (The ReactPress \u2013 Create React App
for WordPress plugin for
NOT-FOR-US: WordPress plugin
CVE-2026-92121 (In the WSS4J streaming (StAX) code, a signature reference
using the WS ...)
- wss4j <unfixed>
+ [trixie] - wss4j <no-dsa> (Minor issue)
NOTE:
https://lists.apache.org/thread.html/oop9p4hpl5o9byosb1qg3z7q1sgnn4pc
CVE-2026-91860 (A prototype pollution vulnerability exists in the deep merge
helpers o ...)
NOT-FOR-US: Vaadin
CVE-2026-89238 (WSS4J EncryptedHeader child confusion could promote an
attacker-contro ...)
- wss4j <unfixed>
+ [trixie] - wss4j <no-dsa> (Minor issue)
NOTE:
https://lists.apache.org/thread.html/1lv4hpl8kon1ns5txjnhn2m2sh9rl22w
CVE-2026-88920 (An authentication bypass in the DOM security processor in
Apache WSS4J ...)
- wss4j <unfixed>
+ [trixie] - wss4j <no-dsa> (Minor issue)
NOTE:
https://lists.apache.org/thread.html/grt43m3bgbzz0mk0cnho3rcybb1j01z9
CVE-2026-88037 (The Bold Page Builder plugin for WordPress is vulnerable to
Stored Cro ...)
NOT-FOR-US: WordPress plugin
CVE-2026-87830 (In the StAX streaming WS-SecurityPolicy validator, certain
relative or ...)
- wss4j <unfixed>
+ [trixie] - wss4j <no-dsa> (Minor issue)
NOTE:
https://lists.apache.org/thread.html/lwlozb1x20d16f9dnyvoygc9rrhzq2vn
CVE-2026-87004 (Tugtainer is a self-hosted app for automating updates of
Docker contai ...)
NOT-FOR-US: Tugtainer
@@ -1690,6 +1700,7 @@ CVE-2026-86778 (Observable response discrepancy
vulnerability in Maksisoft Techn
NOT-FOR-US: Maksisoft Gym
CVE-2026-85532 (Apache WSS4J accepted attacker-controlled derived-key lengths
and offs ...)
- wss4j <unfixed>
+ [trixie] - wss4j <no-dsa> (Minor issue)
NOTE:
https://lists.apache.org/thread.html/7jllcpbf4nbzhdp2vchz5yplnl5w6vd6
CVE-2026-82307 (Improper neutralization of special elements used in an SQL
command ('S ...)
NOT-FOR-US: SOPLOG
@@ -4132,6 +4143,7 @@ CVE-2024-31026 (An issue in Greek Universities Network
(GUnet) Open eClass Platf
NOT-FOR-US: Greek Universities Network (GUnet) Open eClass Platform
CVE-2026-XXXX [GHSA-5rfj-p5qw-w48g: Unauthenticated remote DoS via
attacker-controlled reverse-DNS hostname in auto-hosts parsing]
- sshuttle 2.0.0-1
+ [trixie] - sshuttle <no-dsa> (Minor issue)
NOTE:
https://github.com/sshuttle/sshuttle/security/advisories/GHSA-5rfj-p5qw-w48g
NOTE: Fixed by:
https://github.com/sshuttle/sshuttle/commit/baea31a6769baeb52e8837ad6cc582017d74676c
(v2.0.0)
CVE-2026-102331 (Buffer overflow in ANGLE in Google Chrome on on Android prior
to 154.0 ...)
@@ -4285,6 +4297,7 @@ CVE-2026-96428 (SQL Injection in the
/WebAgenda/SMBAjaxAutoComplete.do API endpo
NOT-FOR-US: Flowring Agentflow
CVE-2026-95520 (A heap-based buffer overflow flaw was found in rpm. Parsing a
symlink ...)
- rpm <unfixed>
+ [trixie] - rpm <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537809
CVE-2026-19395
NOT-FOR-US: Qt for MCUs
@@ -5404,14 +5417,17 @@ CVE-2026-XXXX [groff issues]
NOTE: https://savannah.gnu.org/bugs/?68688 (private)
CVE-2026-16271 [hw/display/qxl: validate primary surface stride against width]
- qemu 1:11.1.2+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/f39ebe53c3f319132cfb60030de12c8547426ace
(v11.1.2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/e6d0120e039a961392eea2c566a4b110884a1b60
(v10.0.14)
CVE-2026-77913 [hw/display/vga: fix text-mode OOB write after a graphics
surface switch]
- qemu 1:11.1.2+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/f3c6a0a6dcae7b6beef21a9ee332c1c6e8035c8a
(v11.1.2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/931861685366c372e1c12faf8e10786409ee4d12
(v10.0.14)
CVE-2026-84788 [io/channel-socket: do not treat a zero length write as an
error]
- qemu 1:11.1.2+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/98b79943b28d417327e36281dca180dd2b95c75d
(v11.1.2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/756836f32a394b3cd29dff540a7dd907600dc589
(v11.1.2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/a1bc6e49b357458eecd94e05ca9eea00336c4dce
(v11.1.2)
@@ -5424,14 +5440,17 @@ CVE-2026-84788 [io/channel-socket: do not treat a zero
length write as an error]
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/316989d81e9bb4d253c8e726d462c7bb7031d04c
(v10.0.14)
CVE-2026-66900 [hw/net/virtio-net: strip trailing padding when caching RSC
segment]
- qemu 1:11.1.2+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/ec2fdc85829a5090ebaea2f4094b9616a4ea6309
(v11.1.2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/cc48e48a3a3a836ce712305bbeeb9515900dd4ef
(v10.0.14)
CVE-2026-66899 [virtio-balloon: fix free-page BH teardown on unrealize]
- qemu 1:11.1.2+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/f731c7d2d4cc511abba74607bea4184c207a069e
(v11.1.2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/be1244c42390de95fa5201a722f3db1302ccef2d
(v10.0.14)
CVE-2026-17588 [hw/usb/hcd-xhci: Set reentrancy guard in timer functions]
- qemu 1:11.1.2+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/ed582623e2372fdf862a804d122766052aba81c7
(v11.1.2)
NOTE: Fixed by:
https://gitlab.com/qemu-project/qemu/-/commit/1622c9abec17d5cba63383d4d4cb1419cedf8158
(v10.0.14)
CVE-2026-46675 [Use-after-free of zlib input in `png_read_end` after
incomplete zTXt, iTXt or iCCP decompression]
@@ -11821,6 +11840,7 @@ CVE-2026-92284 (Caddy is an extensible server platform
that uses TLS by default.
TODO: check references, refers to GHSA-j8px-rmrx-76h9 which is for
CVE-2026-77281
CVE-2026-92164 (Streamlink is a CLI utility which pipes video streams from
various ser ...)
- streamlink 8.6.0-1
+ [trixie] - streamlink <no-dsa> (Minor issue)
NOTE:
https://github.com/streamlink/streamlink/security/advisories/GHSA-vf2x-4v53-pm7v
NOTE:
https://github.com/streamlink/streamlink/commit/4b99c64dde21ea70c24d9ffdbd15849b05f465c6
(8.6.0)
CVE-2026-92001 (Improper restriction of recursive entity references in DTDs
('XML enti ...)
@@ -15109,6 +15129,7 @@ CVE-2026-82187 (The Web to Print Online Designer
WordPress plugin before 2.15.0
NOT-FOR-US: WordPress plugin
CVE-2026-92382 (An out-of-bounds write flaw was found in usbredir. Starting an
isochro ...)
- usbredir <unfixed> (bug #1148831)
+ [trixie] - usbredir <postponed> (Revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2535972
TODO: check details once Red Hat opens up bugzilla entry
CVE-2026-94113 (Frappe ERPNext versions before 15.121.0 and 16.x before
16.34.0 contai ...)
@@ -31456,6 +31477,7 @@ CVE-2026-88021 (Consul and Consul Enterprise are
vulnerable to an authorization
- consul <removed>
CVE-2026-88018 (rclone is a command-line program to sync files and directories
to and ...)
- rclone <unfixed> (bug #1147404)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE:
https://github.com/rclone/rclone/security/advisories/GHSA-xwwr-4h3p-r22c
NOTE: Fixed by:
https://github.com/rclone/rclone/commit/90595f34f27f569be6b27c57fe5ab65057d323bd
(1.75.1)
CVE-2026-88017 (rclone is a command-line program to sync files and directories
to and ...)
@@ -116786,6 +116808,7 @@ CVE-2026-54503 (plone.app.textfield provides a
zope.schema-style field type call
NOT-FOR-US: Plone
CVE-2026-55830 (RestrictedPython is a tool that helps to define a subset of
the Python ...)
- restrictedpython 8.4-1
+ [trixie] - restrictedpython <no-dsa> (Minor issue)
NOTE:
https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-ffg3-p8fm-mjx2
NOTE: Fixed by:
https://github.com/zopefoundation/RestrictedPython/commit/3737596ec9f28c34a073cc845bd2f4c0a80cb671
(8.3)
CVE-2026-55099 (icalendar is an RFC 5545 compatible parser and generator of
iCalendar ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -165,6 +165,8 @@ sabnzbdplus
--
shaarli
--
+social-auth-core
+--
sogo
Regression update for #1144734, new batch of issues from 5.12.10 release
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8cf51689ec9b5231027c01e1e0970b3047f83876
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8cf51689ec9b5231027c01e1e0970b3047f83876
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits