Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
f1cbdc23 by Moritz Muehlenhoff at 2026-10-05T16:11:45+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -88,6 +88,7 @@ CVE-2026-20519 (In Modem, there is a possible out of bounds
write due to a missi
NOT-FOR-US: MediaTek
CVE-2026-19954 (Net::Whois::Raw versions before 2.99044 for Perl ship a pwhois
command ...)
- libnet-whois-raw-perl <unfixed>
+ [trixie] - libnet-whois-raw-perl <no-dsa> (Minor issue)
NOTE: https://github.com/regru/Net-Whois-Raw/issues/34
NOTE: https://github.com/regru/Net-Whois-Raw/pull/35
NOTE: Fixed by:
https://security.metacpan.org/patches/N/Net-Whois-Raw/2.99043/CVE-2026-19954-r1.patch
@@ -412,6 +413,7 @@ CVE-2026-103065 (Improper Validation of Specified Quantity
in Input vulnerabilit
NOT-FOR-US: WordPress plugin or theme
CVE-2026-94291
- epiphany-browser 51.1-1
+ [trixie] - epiphany-browser <no-dsa> (Minor issue)
[bookworm] - epiphany-browser <postponed> (Limited support)
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2952
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/2214
@@ -1357,6 +1359,7 @@ CVE-2026-103600 (Uncontrolled recursion in the ASN.1
parser (Asn1InputStream, As
NOT-FOR-US: Bouncycastle components not packaged in Debian
CVE-2026-103552 (Stack Overflow vulnerability in Apache Directory LDAP API.
Before b ...)
- apache-directory-api <unfixed> (bug #1149877)
+ [trixie] - apache-directory-api <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/4
CVE-2026-103426 (The Relevanssi Premium plugin for WordPress is vulnerable to
Stored Cr ...)
NOT-FOR-US: WordPress plugin
@@ -1371,6 +1374,7 @@ CVE-2026-102772 (The CMB2 plugin for WordPress is
vulnerable to Stored Cross-Sit
NOT-FOR-US: WordPress plugin
CVE-2026-102731 (Memory allocation with excessive size value vulnerability in
Apache Di ...)
- apache-directory-api <unfixed> (bug #1149877)
+ [trixie] - apache-directory-api <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/02/3
CVE-2026-102626 (An authenticated LimeSurvey Community Edition 7.4.0user with
the globa ...)
- limesurvey <itp> (bug #472802)
@@ -5691,24 +5695,26 @@ CVE-2026-103040 (LightLLM through 1.2.0 contains a
remote code execution vulnera
NOT-FOR-US: LightLLM
CVE-2026-102938 (virtualenv is a tool for creating isolated virtual python
environments ...)
- python-virtualenv <unfixed> (bug #1149650)
+ [trixie] - python-virtualenv <no-dsa> (Minor issue)
[bookworm] - python-virtualenv <postponed> (Minor issue)
NOTE:
https://github.com/pypa/virtualenv/security/advisories/GHSA-9h9j-4vrj-gf7g
NOTE: https://github.com/pypa/virtualenv/pull/3247
NOTE: Fixed by:
https://github.com/pypa/virtualenv/commit/a30f995461043acb6cacbf3a890951563ccf7140
(21.7.11)
CVE-2026-102937 (virtualenv is a tool for creating isolated virtual python
environments ...)
- - python-virtualenv <unfixed> (unimportant)
+ - python-virtualenv <not-affected> (Windows-specific)
NOTE:
https://github.com/pypa/virtualenv/security/advisories/GHSA-x78j-v8h9-3j2q
NOTE: https://github.com/pypa/virtualenv/pull/3250
NOTE: Fixed by:
https://github.com/pypa/virtualenv/commit/d721ff140ce4afdc2a9b76751e4584e25d9fbea6
(21.7.12)
- NOTE: Only impact activate.bat when running on Windows
CVE-2026-102930 (virtualenv is a tool for creating isolated virtual python
environments ...)
- python-virtualenv <unfixed> (bug #1149650)
+ [trixie] - python-virtualenv <no-dsa> (Minor issue)
[bookworm] - python-virtualenv <postponed> (Minor issue)
NOTE:
https://github.com/pypa/virtualenv/security/advisories/GHSA-94p9-xgh2-xp45
NOTE: https://github.com/pypa/virtualenv/pull/3251
NOTE: Fixed by:
https://github.com/pypa/virtualenv/commit/a01ed3e2f239d6ab1fce62c5c7664ccf268fff6d
(21.7.12)
CVE-2026-102925 (virtualenv is a tool for creating isolated virtual python
environments ...)
- python-virtualenv <unfixed> (bug #1149650)
+ [trixie] - python-virtualenv <no-dsa> (Minor issue)
[bookworm] - python-virtualenv <not-affected> (Vulnerable code
introduced in 20.33.0)
NOTE:
https://github.com/pypa/virtualenv/security/advisories/GHSA-p58f-9548-mpm2
NOTE: https://github.com/pypa/virtualenv/pull/3252
@@ -6175,11 +6181,12 @@ CVE-2026-11796 (Asset Suite allows unauthenticated
users to access PropertiesRel
CVE-2026-10518 (GitLab has remediated an issue in GitLab EE affecting all
versions fro ...)
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as
src:gitlab, but never in a stable release)
CVE-2026-102831 (JupyterLab is an extensible environment for interactive and
reproducib ...)
- - jupyterlab <unfixed>
+ - jupyterlab <not-affected> (Vulnerable code introduced later)
- jupyter-notebook <unfixed>
NOTE:
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-6966-vjj6-99xv
NOTE: Fixed by:
https://github.com/jupyterlab/jupyterlab/commit/7f9f29e29e0c83fb17b0f11da57d06b3c6a40d96
(v4.5.11)
- TODO: check, might be introduced later in both products
+ NOTE: Introduced by:
https://github.com/jupyterlab/jupyterlab/commit/e5bc7eaaa7315e2d56bfd482efe4302e6a894c33
(v4.5.0a)
+ TODO: check, might be introduced later
CVE-2026-102830 (JupyterLab is an extensible environment for interactive and
reproducib ...)
- jupyterlab <unfixed> (bug #1149998)
NOTE:
https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-3jqq-pw4j-pqcj
@@ -7043,6 +7050,8 @@ CVE-2026-100831 (Use-after-free in the DOM: UI Events &
Focus Handling component
- firefox 157.0-1
- firefox-esr 153.4.0esr-1
- thunderbird 1:153.4.0esr-1
+ [trixie] - thunderbird <not-affected> (Vulnerable code not present,
doesn't affect ESR140)
+ [bookworm] - thunderbird <not-affected> (Vulnerable code not present,
doesn't affect ESR140)
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-97/#CVE-2026-100831
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-100/#CVE-2026-100831
NOTE:
https://www.mozilla.org/en-US/security/advisories/mfsa2026-103/#CVE-2026-100831
@@ -8463,6 +8472,7 @@ CVE-2026-XXXX [Infinite loops and heap OOB read when
parsing malformed ASF heade
[bookworm] - libmms <postponed> (Minor issue; client-side DoS when
connecting to a malicious MMS server)
CVE-2026-XXXX [unbounded list indices from a Word document reach a wild
pointer dereference in wvAssembleSimplePAP]
- wv <unfixed> (bug #1148725)
+ [trixie] - wv <no-dsa> (Minor issue)
CVE-2026-XXXX [GHSA-h547-rmjf-5m2m: Table permission bypass using trailing
newlines in table names]
- datasette 0.65.5+ds-1 (bug #1148576)
NOTE:
https://github.com/simonw/datasette/security/advisories/GHSA-h547-rmjf-5m2m
@@ -38588,8 +38598,8 @@ CVE-2026-20293 (A vulnerability in the Unified
Extensible Firmware Interface (UE
NOT-FOR-US: Cisco
CVE-2026-19614 (The API is prone to XML external entity (XXE) injection. By
default, X ...)
- libnanoxml2-java <unfixed>
+ [trixie] - libnanoxml2-java <no-dsa> (Minor issue)
NOTE:
https://www.thalesgroup.com/en/search/cybersecurity/cybersecurity-services/cve-2026-19614
- TODO: check details as reference not accessible
CVE-2026-19203 (A client may issue specially crafted HTTP/1.1 chunked requests
to a Je ...)
- jetty12 12.0.39-1
- jetty9 <unfixed>
@@ -239667,13 +239677,7 @@ CVE-2025-34500 (Deck Mate 2's firmware update
mechanism accepts packages without
CVE-2025-34293 (GN4 Publishing System versions prior to 2.6 contain an
insecure direct ...)
NOT-FOR-US: GN4 Publishing System
CVE-2025-12194 (Uncontrolled Resource Consumption vulnerability in Legion of
the Bounc ...)
- - bouncycastle <unfixed> (bug #1118945)
- [trixie] - bouncycastle <no-dsa> (Minor issue)
- [bookworm] - bouncycastle <no-dsa> (Minor issue)
- [bullseye] - bouncycastle <ignored> (Minor issue)
- NOTE: Fixed by:
https://github.com/bcgit/bc-lts-java/commit/f2776feac0c30230f7a5ac34eb24f5019caf0324
(r2rv73dot8)
- NOTE: Followup:
https://github.com/bcgit/bc-lts-java/commit/2c9be6c64152ce48c6afc784c042a514be71ec71
(r2rv73dot8)
- NOTE:
https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902025%E2%80%9012194
+ NOT-FOR-US: Bouncycastle components not packaged in Debian
CVE-2025-12095 (The Simple Registration for WooCommerce plugin for WordPress
is vulner ...)
NOT-FOR-US: WordPress plugin
CVE-2025-12034 (The Fast Velocity Minify plugin for WordPress is vulnerable to
Stored ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1cbdc2385bb3f517761ec4e8f13f87c9c1238ce
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1cbdc2385bb3f517761ec4e8f13f87c9c1238ce
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits