Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8adb2750 by Moritz Muehlenhoff at 2026-10-04T23:32:28+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -2262,7 +2262,7 @@ CVE-2026-12241 (The Advanced Woo Labels \u2013 Product 
Labels & Badges for WooCo
 CVE-2026-103641 (A flaw was found in GEGL. The Radiance HDR loader reads past 
the end o ...)
        - gegl <unfixed>
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2544420
-       TODO: check status upstream
+       NOTE: 
https://gitlab.gnome.org/GNOME/gegl/-/commit/75214d1e6893d5a6b418a62ae6953a121c371a32
 CVE-2026-103592 (simple-php-router through 5.4.1.7 contains an IP restriction 
bypass vu ...)
        NOT-FOR-US: simple-php-router
 CVE-2026-103591 (DeepWiki-Open through commit d92819a contains an 
unauthenticated arbit ...)
@@ -2307,15 +2307,18 @@ CVE-2026-103532 (A vulnerability has been found in 
immich-app Immich up to 2.7.5
        NOT-FOR-US: immich-app Immich
 CVE-2026-103531 (A flaw has been found in OpenSC up to 0.27.1. The impacted 
element is  ...)
        - opensc <unfixed> (bug #1149970)
+       [trixie] - opensc <no-dsa> (Minor issue)
        NOTE: https://github.com/OpenSC/OpenSC/pull/3812
        NOTE: Fixed by: 
https://github.com/OpenSC/OpenSC/commit/ad730304052937c32b4eb489a06835ac6123632c
 CVE-2026-103530 (A vulnerability was detected in decolua 9Router up to 0.5.55. 
The affe ...)
        NOT-FOR-US: decolua 9Router
 CVE-2026-103387 (A weakness has been identified in garycourt uri-js up to 
4.4.1. This a ...)
        - node-uri-js <unfixed> (bug #1149972)
+       [trixie] - node-uri-js <no-dsa> (Minor issue)
        NOTE: https://github.com/garycourt/uri-js/issues/103
 CVE-2026-103001 (PyJWT is a Python implementation of JSON Web Token standards. 
From 2.1 ...)
        - pyjwt 2.14.0-1
+       [trixie] - pyjwt <not-affected> (Vulnerable code not present)
        [bookworm] - pyjwt <not-affected> (Vulnerable code introduced in 2.11.0)
        NOTE: 
https://github.com/jpadilla/pyjwt/security/advisories/GHSA-gvp8-978c-rx2q
        NOTE: https://github.com/jpadilla/pyjwt/issues/679


=====================================
data/dsa-needed.txt
=====================================
@@ -158,7 +158,7 @@ runc
 rust-wasmtime
   for CVE-2026-34987 CVE-2026-34971, rest would also be fine to ignore
 --
-sabnzbdplus
+sabnzbdplus (jmm)
   Maintainer is proposing an update for review in 
https://bugs.debian.org/1147154#17
 --
 shaarli



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8adb275017fd6e9c8efa590fdd10fac8d1e5062a

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8adb275017fd6e9c8efa590fdd10fac8d1e5062a
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to