Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
9e986430 by Moritz Muehlenhoff at 2026-10-05T22:33:36+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1626,6 +1626,7 @@ CVE-2026-104853 (Nx is a monorepo solution for TypeScript
and polyglot codebases
NOT-FOR-US: Nx
CVE-2026-104851 (fsspec is a specification and Python implementation framework
for file ...)
- fsspec <unfixed> (bug #1149800)
+ [trixie] - fsspec <no-dsa> (Minor issue)
NOTE:
https://github.com/fsspec/filesystem_spec/security/advisories/GHSA-27vj-qcqg-25rc
NOTE: Introduced with:
https://github.com/fsspec/filesystem_spec/commit/0fb8d56b684ee74ad9ad4587fd560bde1b116450
(0.9.0)
NOTE: Fixed by:
https://github.com/fsspec/filesystem_spec/commit/86438783f93b1398ef245b92f0e6063b445b611c
(2026.6.0)
@@ -1968,12 +1969,15 @@ CVE-2026-102977
NOTE:
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1347830
(master)
CVE-2026-XXXX [MFA auth receipt and TOTP are not invalidated after use,
allowing replay attacks]
- keystone 2:30.0.0~rc1-2 (bug #1149305)
+ [trixie] - keystone <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/keystone/+bug/2157347
CVE-2026-XXXX [POST /v3/users/{id}/password does not verify MFA when MFA rules
are configured, allowing account lockout with stolen password alone]
- keystone 2:30.0.0~rc1-2 (bug #1149304)
+ [trixie] - keystone <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/keystone/+bug/2158970
CVE-2026-XXXX [Delegated tokens (like ec2credential, application_credential,
...) can GET/PATCH/DELETE any credential including TOTP seeds]
- keystone <unfixed> (bug #1149303)
+ [trixie] - keystone <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/keystone/+bug/2159643
CVE-2026-97318 (The Giveaways and Contests by RafflePress WordPress plugin
before 1.1 ...)
NOT-FOR-US: WordPress plugin
@@ -3100,6 +3104,7 @@ CVE-2026-102995 (pypdf is a free and open-source
pure-python PDF library. Prior
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/319d0b823ce2c311a2435e9fd93c13994d32bb51
(6.18.1)
CVE-2026-102994 (pypdf is a free and open-source pure-python PDF library.
Prior to 6.18 ...)
- pypdf 6.19.0-1
+ [trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <postponed> (Minor issue, DoS)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-5jq2-8x83-x246
@@ -3107,6 +3112,7 @@ CVE-2026-102994 (pypdf is a free and open-source
pure-python PDF library. Prior
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/82501d2993c6387833c4949d205caeb188f8bb9e
(6.18.0)
CVE-2026-102993 (pypdf is a free and open-source pure-python PDF library.
Prior to 6.17 ...)
- pypdf 6.19.0-1
+ [trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <not-affected> (Page label support introduced in
pypdf 3.2.0)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285
@@ -6490,6 +6496,7 @@ CVE-2026-98164 (In the Linux kernel, the following
vulnerability has been resolv
NOTE:
https://git.kernel.org/linus/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26 (7.2-rc6)
CVE-2026-97711 (Serialize JavaScript serializes JavaScript values to a
superset of JSO ...)
- node-serialize-javascript 7.1.2+~5.0.4-1
+ [trixie] - node-serialize-javascript <no-dsa> (Minor issue)
NOTE:
https://github.com/yahoo/serialize-javascript/security/advisories/GHSA-gfhx-hw2g-v5hg
NOTE: Fixed by:
https://github.com/yahoo/serialize-javascript/commit/2bdbaaff9cb8a4639135eb24cfcd383d3fefb534
(v7.1.2)
CVE-2026-97395 (Apache Polaris allows an authenticated principal with
permission to cr ...)
@@ -6842,6 +6849,7 @@ CVE-2026-102616 (A vulnerability was detected in
risesoft-y9 WorkFlow-Engine up
NOT-FOR-US: risesoft-y9 WorkFlow-Engine
CVE-2026-102601 (Flysystem is an open source file storage library for PHP.
Prior to 3.3 ...)
- php-league-flysystem <unfixed> (bug #1149886)
+ [trixie] - php-league-flysystem <no-dsa> (Minor issue)
NOTE:
https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr
NOTE: Fixed by:
https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77
(3.35.3)
CVE-2026-102600 (Socket.IO enables bidirectional and low-latency communication
for ever ...)
@@ -7797,6 +7805,7 @@ CVE-2026-102281 (Nest is a framework for building
scalable Node.js server-side a
NOT-FOR-US: Nest
CVE-2026-102279 (Laravel is a web application framework. Prior to 12.69.0 and
13.30.0, ...)
- php-laravel-framework <unfixed> (bug #1150001)
+ [trixie] - php-laravel-framework <no-dsa> (Minor issue)
NOTE:
https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8
NOTE: https://github.com/laravel/framework/pull/61381
NOTE: Fixed by:
https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12
(v12.69.0)
@@ -7938,12 +7947,14 @@ CVE-2026-101354 (A security flaw has been discovered in
FAST FAC1203R 20200116_2
NOT-FOR-US: FAST FAC1203R
CVE-2026-101281 (A flaw has been found in Trusted Domain Project OpenDMARC up
to 1.4.2. ...)
- opendmarc <unfixed> (bug #1149876)
+ [trixie] - opendmarc <no-dsa> (Minor issue)
NOTE: https://github.com/trusteddomainproject/OpenDMARC/issues/262
NOTE: https://github.com/trusteddomainproject/OpenDMARC/pull/328
NOTE: Fixed by:
https://github.com/trusteddomainproject/OpenDMARC/commit/a9a87bdedbf886f5f1e7a6ddce465cb4626d337d
NOTE:
https://xuyongzhe-vt.github.io/share/opendmarc-spf-postmaster-macro.html
CVE-2026-101280 (A vulnerability was detected in Trusted Domain Project
OpenDMARC up to ...)
- opendmarc <unfixed> (bug #1149876)
+ [trixie] - opendmarc <no-dsa> (Minor issue)
NOTE:
https://xuyongzhe-vt.github.io/share/opendmarc-multi-record-downgrade.html
CVE-2026-101279 (A security vulnerability has been detected in Trusted Domain
Project O ...)
- opendmarc <unfixed> (bug #1149876)
@@ -10448,6 +10459,7 @@ CVE-2026-52622 (An issue in Wellav Technologies Co.,
Ltd Wellav WES Emergency Br
NOT-FOR-US: Wellav
CVE-2026-51773 (An issue in the VMware datastore driver of OpenStack
glance_store. Whe ...)
- glance <unfixed> (bug #1149967)
+ [trixie] - glance <ignored> (Minor issue)
NOTE: https://bugs.launchpad.net/glance/+bug/2167929
CVE-2026-51772 (A Server-Side Request Forgery (SSRF) vulnerability exists in
the Image ...)
NOTE: Duplicate of already assigned CVE-2026-71198
@@ -32901,6 +32913,7 @@ CVE-2026-8301 (Improper neutralization of special
elements used in an OS command
NOT-FOR-US: Pardus Boot Repair
CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access
to the ...)
- multipath-tools <unfixed> (bug #1147523)
+ [trixie] - multipath-tools <no-dsa> (Minor issue)
[bookworm] - multipath-tools <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470013
NOTE:
https://github.com/opensvc/multipath-tools/security/advisories/GHSA-hmcm-9cq4-r2xm
@@ -33228,6 +33241,7 @@ CVE-2026-19486 (A Server-Side Request Forgery (SSRF)
vulnerability in Google Clo
NOT-FOR-US: Google Cloud Gemini Enterprise Agent Platform App Builder
CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow
vulnerability exis ...)
- tiff 4.7.1-1
+ [trixie] - tiff <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531414
NOTE: https://gitlab.com/libtiff/libtiff/-/merge_requests/729
NOTE: Fixed by:
https://gitlab.com/libtiff/libtiff/-/commit/67fd283d276f09db54dc39b9ef7b979d4b45c4b1
(v4.7.1rc1)
=====================================
data/dsa-needed.txt
=====================================
@@ -59,6 +59,8 @@ freerdp3 (jmm)
gegl (jmm)
move to 0.4.72
--
+gnocchi
+--
graphicsmagick
--
gst-plugins-good1.0
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e986430dede03d69c5c6c6952968ec2b1078e41
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e986430dede03d69c5c6c6952968ec2b1078e41
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits