Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
f1cbdc23 by Moritz Muehlenhoff at 2026-10-05T16:11:45+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -88,6 +88,7 @@ CVE-2026-20519 (In Modem, there is a possible out of bounds 
write due to a missi
        NOT-FOR-US: MediaTek
 CVE-2026-19954 (Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois 
command ...)
        - libnet-whois-raw-perl <unfixed>
+       [trixie] - libnet-whois-raw-perl <no-dsa> (Minor issue)
        NOTE: https://github.com/regru/Net-Whois-Raw/issues/34
        NOTE: https://github.com/regru/Net-Whois-Raw/pull/35
        NOTE: Fixed by: 
https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch
@@ -412,6 +413,7 @@ CVE-2026-103065 (Improper Validation of Specified Quantity 
in Input vulnerabilit
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-94291
        - epiphany-browser 51.1-1
+       [trixie] - epiphany-browser <no-dsa> (Minor issue)
        [bookworm] - epiphany-browser <postponed> (Limited support)
        NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2952
        NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/2214
@@ -1357,6 +1359,7 @@ CVE-2026-103600 (Uncontrolled recursion in the ASN.1 
parser (Asn1InputStream, As
        NOT-FOR-US: Bouncycastle components not packaged in Debian
 CVE-2026-103552 (Stack Overflow vulnerability in Apache Directory LDAP API.    
Before b ...)
        - apache-directory-api <unfixed> (bug #1149877)
+       [trixie] - apache-directory-api <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/4
 CVE-2026-103426 (The Relevanssi Premium plugin for WordPress is vulnerable to 
Stored Cr ...)
        NOT-FOR-US: WordPress plugin
@@ -1371,6 +1374,7 @@ CVE-2026-102772 (The CMB2 plugin for WordPress is 
vulnerable to Stored Cross-Sit
        NOT-FOR-US: WordPress plugin
 CVE-2026-102731 (Memory allocation with excessive size value vulnerability in 
Apache Di ...)
        - apache-directory-api <unfixed> (bug #1149877)
+       [trixie] - apache-directory-api <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/3
 CVE-2026-102626 (An authenticated LimeSurvey Community Edition 7.4.0user with 
the globa ...)
        - limesurvey <itp> (bug #472802)
@@ -5691,24 +5695,26 @@ CVE-2026-103040 (LightLLM through 1.2.0 contains a 
remote code execution vulnera
        NOT-FOR-US: LightLLM
 CVE-2026-102938 (virtualenv is a tool for creating isolated virtual python 
environments ...)
        - python-virtualenv <unfixed> (bug #1149650)
+       [trixie] - python-virtualenv <no-dsa> (Minor issue)
        [bookworm] - python-virtualenv <postponed> (Minor issue)
        NOTE: 
https://github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g
        NOTE: https://github.com/pypa/virtualenv/pull/3247
        NOTE: Fixed by: 
https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140
 (21.7.11)
 CVE-2026-102937 (virtualenv is a tool for creating isolated virtual python 
environments ...)
-       - python-virtualenv <unfixed> (unimportant)
+       - python-virtualenv <not-affected> (Windows-specific)
        NOTE: 
https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q
        NOTE: https://github.com/pypa/virtualenv/pull/3250
        NOTE: Fixed by: 
https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6
 (21.7.12)
-       NOTE: Only impact activate.bat when running on Windows
 CVE-2026-102930 (virtualenv is a tool for creating isolated virtual python 
environments ...)
        - python-virtualenv <unfixed> (bug #1149650)
+       [trixie] - python-virtualenv <no-dsa> (Minor issue)
        [bookworm] - python-virtualenv <postponed> (Minor issue)
        NOTE: 
https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45
        NOTE: https://github.com/pypa/virtualenv/pull/3251
        NOTE: Fixed by: 
https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d
 (21.7.12)
 CVE-2026-102925 (virtualenv is a tool for creating isolated virtual python 
environments ...)
        - python-virtualenv <unfixed> (bug #1149650)
+       [trixie] - python-virtualenv <no-dsa> (Minor issue)
        [bookworm] - python-virtualenv <not-affected> (Vulnerable code 
introduced in 20.33.0)
        NOTE: 
https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2
        NOTE: https://github.com/pypa/virtualenv/pull/3252
@@ -6175,11 +6181,12 @@ CVE-2026-11796 (Asset Suite allows unauthenticated 
users to access PropertiesRel
 CVE-2026-10518 (GitLab has remediated an issue in GitLab EE affecting all 
versions fro ...)
        NOT-FOR-US: GitLab (used to be packaged in the Debian archive as 
src:gitlab, but never in a stable release)
 CVE-2026-102831 (JupyterLab is an extensible environment for interactive and 
reproducib ...)
-       - jupyterlab <unfixed>
+       - jupyterlab <not-affected> (Vulnerable code introduced later)
        - jupyter-notebook <unfixed>
        NOTE: 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-6966-vjj6-99xv
        NOTE: Fixed by: 
https://github.com/jupyterlab/jupyterlab/commit/7f9f29e29e0c83fb17b0f11da57d06b3c6a40d96
 (v4.5.11)
-       TODO: check, might be introduced later in both products
+       NOTE: Introduced by: 
https://github.com/jupyterlab/jupyterlab/commit/e5bc7eaaa7315e2d56bfd482efe4302e6a894c33
 (v4.5.0a)
+       TODO: check, might be introduced later
 CVE-2026-102830 (JupyterLab is an extensible environment for interactive and 
reproducib ...)
        - jupyterlab <unfixed> (bug #1149998)
        NOTE: 
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3jqq-pw4j-pqcj
@@ -7043,6 +7050,8 @@ CVE-2026-100831 (Use-after-free in the DOM: UI Events & 
Focus Handling component
        - firefox 157.0-1
        - firefox-esr 153.4.0esr-1
        - thunderbird 1:153.4.0esr-1
+       [trixie] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
+       [bookworm] - thunderbird <not-affected> (Vulnerable code not present, 
doesn't affect ESR140)
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/#CVE-2026-100831
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/#CVE-2026-100831
        NOTE: 
https://www.mozilla.org/en-US/security/advisories/mfsa2026-103/#CVE-2026-100831
@@ -8463,6 +8472,7 @@ CVE-2026-XXXX [Infinite loops and heap OOB read when 
parsing malformed ASF heade
        [bookworm] - libmms <postponed> (Minor issue; client-side DoS when 
connecting to a malicious MMS server)
 CVE-2026-XXXX [unbounded list indices from a Word document reach a wild 
pointer dereference in wvAssembleSimplePAP]
        - wv <unfixed> (bug #1148725)
+       [trixie] - wv <no-dsa> (Minor issue)
 CVE-2026-XXXX [GHSA-h547-rmjf-5m2m: Table permission bypass using trailing 
newlines in table names]
        - datasette 0.65.5+ds-1 (bug #1148576)
        NOTE: 
https://github.com/simonw/datasette/security/advisories/GHSA-h547-rmjf-5m2m
@@ -38588,8 +38598,8 @@ CVE-2026-20293 (A vulnerability in the Unified 
Extensible Firmware Interface (UE
        NOT-FOR-US: Cisco
 CVE-2026-19614 (The API is prone to XML external entity (XXE) injection. By 
default, X ...)
        - libnanoxml2-java <unfixed>
+       [trixie] - libnanoxml2-java <no-dsa> (Minor issue)
        NOTE: 
https://www.thalesgroup.com/en/search/cybersecurity/cybersecurity-services/cve-2026-19614
-       TODO: check details as reference not accessible
 CVE-2026-19203 (A client may issue specially crafted HTTP/1.1 chunked requests 
to a Je ...)
        - jetty12 12.0.39-1
        - jetty9 <unfixed>
@@ -239667,13 +239677,7 @@ CVE-2025-34500 (Deck Mate 2's firmware update 
mechanism accepts packages without
 CVE-2025-34293 (GN4 Publishing System versions prior to 2.6 contain an 
insecure direct ...)
        NOT-FOR-US: GN4 Publishing System
 CVE-2025-12194 (Uncontrolled Resource Consumption vulnerability in Legion of 
the Bounc ...)
-       - bouncycastle <unfixed> (bug #1118945)
-       [trixie] - bouncycastle <no-dsa> (Minor issue)
-       [bookworm] - bouncycastle <no-dsa> (Minor issue)
-       [bullseye] - bouncycastle <ignored> (Minor issue)
-       NOTE: Fixed by: 
https://github.com/bcgit/bc-lts-java/commit/f2776feac0c30230f7a5ac34eb24f5019caf0324
 (r2rv73dot8)
-       NOTE: Followup: 
https://github.com/bcgit/bc-lts-java/commit/2c9be6c64152ce48c6afc784c042a514be71ec71
 (r2rv73dot8)
-       NOTE: 
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9012194
+       NOT-FOR-US: Bouncycastle components not packaged in Debian
 CVE-2025-12095 (The Simple Registration for WooCommerce plugin for WordPress 
is vulner ...)
        NOT-FOR-US: WordPress plugin
 CVE-2025-12034 (The Fast Velocity Minify plugin for WordPress is vulnerable to 
Stored  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1cbdc2385bb3f517761ec4e8f13f87c9c1238ce

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1cbdc2385bb3f517761ec4e8f13f87c9c1238ce
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to