Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
9e986430 by Moritz Muehlenhoff at 2026-10-05T22:33:36+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1626,6 +1626,7 @@ CVE-2026-104853 (Nx is a monorepo solution for TypeScript 
and polyglot codebases
        NOT-FOR-US: Nx
 CVE-2026-104851 (fsspec is a specification and Python implementation framework 
for file ...)
        - fsspec <unfixed> (bug #1149800)
+       [trixie] - fsspec <no-dsa> (Minor issue)
        NOTE: 
https://github.com/fsspec/filesystem_spec/security/advisories/GHSA-27vj-qcqg-25rc
        NOTE: Introduced with: 
https://github.com/fsspec/filesystem_spec/commit/0fb8d56b684ee74ad9ad4587fd560bde1b116450
 (0.9.0)
        NOTE: Fixed by: 
https://github.com/fsspec/filesystem_spec/commit/86438783f93b1398ef245b92f0e6063b445b611c
 (2026.6.0)
@@ -1968,12 +1969,15 @@ CVE-2026-102977
        NOTE: 
https://gerrit.wikimedia.org/r/c/mediawiki/extensions/AbuseFilter/+/1347830 
(master)
 CVE-2026-XXXX [MFA auth receipt and TOTP are not invalidated after use, 
allowing replay attacks]
        - keystone 2:30.0.0~rc1-2 (bug #1149305)
+       [trixie] - keystone <no-dsa> (Minor issue)
        NOTE: https://bugs.launchpad.net/keystone/+bug/2157347
 CVE-2026-XXXX [POST /v3/users/{id}/password does not verify MFA when MFA rules 
are configured, allowing account lockout with stolen password alone]
        - keystone 2:30.0.0~rc1-2 (bug #1149304)
+       [trixie] - keystone <no-dsa> (Minor issue)
        NOTE: https://bugs.launchpad.net/keystone/+bug/2158970
 CVE-2026-XXXX [Delegated tokens (like ec2credential, application_credential, 
...) can GET/PATCH/DELETE any credential including TOTP seeds]
        - keystone <unfixed> (bug #1149303)
+       [trixie] - keystone <no-dsa> (Minor issue)
        NOTE: https://bugs.launchpad.net/keystone/+bug/2159643
 CVE-2026-97318 (The Giveaways and Contests by RafflePress  WordPress plugin 
before 1.1 ...)
        NOT-FOR-US: WordPress plugin
@@ -3100,6 +3104,7 @@ CVE-2026-102995 (pypdf is a free and open-source 
pure-python PDF library. Prior
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/319d0b823ce2c311a2435e9fd93c13994d32bb51 
(6.18.1)
 CVE-2026-102994 (pypdf is a free and open-source pure-python PDF library. 
Prior to 6.18 ...)
        - pypdf 6.19.0-1
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <postponed> (Minor issue, DoS)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-5jq2-8x83-x246
@@ -3107,6 +3112,7 @@ CVE-2026-102994 (pypdf is a free and open-source 
pure-python PDF library. Prior
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/82501d2993c6387833c4949d205caeb188f8bb9e 
(6.18.0)
 CVE-2026-102993 (pypdf is a free and open-source pure-python PDF library. 
Prior to 6.17 ...)
        - pypdf 6.19.0-1
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <not-affected> (Page label support introduced in 
pypdf 3.2.0)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-qv6h-rv94-w285
@@ -6490,6 +6496,7 @@ CVE-2026-98164 (In the Linux kernel, the following 
vulnerability has been resolv
        NOTE: 
https://git.kernel.org/linus/0f38453cdb2e17566ccb7c0f3dabd5bd21caca26 (7.2-rc6)
 CVE-2026-97711 (Serialize JavaScript serializes JavaScript values to a 
superset of JSO ...)
        - node-serialize-javascript 7.1.2+~5.0.4-1
+       [trixie] - node-serialize-javascript <no-dsa> (Minor issue)
        NOTE: 
https://github.com/yahoo/serialize-javascript/security/advisories/GHSA-gfhx-hw2g-v5hg
        NOTE: Fixed by: 
https://github.com/yahoo/serialize-javascript/commit/2bdbaaff9cb8a4639135eb24cfcd383d3fefb534
 (v7.1.2)
 CVE-2026-97395 (Apache Polaris allows an authenticated principal with 
permission to cr ...)
@@ -6842,6 +6849,7 @@ CVE-2026-102616 (A vulnerability was detected in 
risesoft-y9 WorkFlow-Engine up
        NOT-FOR-US: risesoft-y9 WorkFlow-Engine
 CVE-2026-102601 (Flysystem is an open source file storage library for PHP. 
Prior to 3.3 ...)
        - php-league-flysystem <unfixed> (bug #1149886)
+       [trixie] - php-league-flysystem <no-dsa> (Minor issue)
        NOTE: 
https://github.com/thephpleague/flysystem/security/advisories/GHSA-cxf4-7mrp-vvpr
        NOTE: Fixed by: 
https://github.com/thephpleague/flysystem/commit/ef4a9a557d769b5d472c403125716706a0d9cc77
 (3.35.3)
 CVE-2026-102600 (Socket.IO enables bidirectional and low-latency communication 
for ever ...)
@@ -7797,6 +7805,7 @@ CVE-2026-102281 (Nest is a framework for building 
scalable Node.js server-side a
        NOT-FOR-US: Nest
 CVE-2026-102279 (Laravel is a web application framework. Prior to 12.69.0 and 
13.30.0,  ...)
        - php-laravel-framework <unfixed> (bug #1150001)
+       [trixie] - php-laravel-framework <no-dsa> (Minor issue)
        NOTE: 
https://github.com/laravel/framework/security/advisories/GHSA-jh5r-qr3c-85q8
        NOTE: https://github.com/laravel/framework/pull/61381
        NOTE: Fixed by: 
https://github.com/laravel/framework/commit/b495ca2ec4e15a977e8700328bf13e8a79f29d12
 (v12.69.0)
@@ -7938,12 +7947,14 @@ CVE-2026-101354 (A security flaw has been discovered in 
FAST FAC1203R 20200116_2
        NOT-FOR-US: FAST FAC1203R
 CVE-2026-101281 (A flaw has been found in Trusted Domain Project OpenDMARC up 
to 1.4.2. ...)
        - opendmarc <unfixed> (bug #1149876)
+       [trixie] - opendmarc <no-dsa> (Minor issue)
        NOTE: https://github.com/trusteddomainproject/OpenDMARC/issues/262
        NOTE: https://github.com/trusteddomainproject/OpenDMARC/pull/328
        NOTE: Fixed by: 
https://github.com/trusteddomainproject/OpenDMARC/commit/a9a87bdedbf886f5f1e7a6ddce465cb4626d337d
        NOTE: 
https://xuyongzhe-vt.github.io/share/opendmarc-spf-postmaster-macro.html
 CVE-2026-101280 (A vulnerability was detected in Trusted Domain Project 
OpenDMARC up to ...)
        - opendmarc <unfixed> (bug #1149876)
+       [trixie] - opendmarc <no-dsa> (Minor issue)
        NOTE: 
https://xuyongzhe-vt.github.io/share/opendmarc-multi-record-downgrade.html
 CVE-2026-101279 (A security vulnerability has been detected in Trusted Domain 
Project O ...)
        - opendmarc <unfixed> (bug #1149876)
@@ -10448,6 +10459,7 @@ CVE-2026-52622 (An issue in Wellav Technologies Co., 
Ltd Wellav WES Emergency Br
        NOT-FOR-US: Wellav
 CVE-2026-51773 (An issue in the VMware datastore driver of OpenStack 
glance_store. Whe ...)
        - glance <unfixed> (bug #1149967)
+       [trixie] - glance <ignored> (Minor issue)
        NOTE: https://bugs.launchpad.net/glance/+bug/2167929
 CVE-2026-51772 (A Server-Side Request Forgery (SSRF) vulnerability exists in 
the Image ...)
        NOTE: Duplicate of already assigned CVE-2026-71198
@@ -32901,6 +32913,7 @@ CVE-2026-8301 (Improper neutralization of special 
elements used in an OS command
        NOT-FOR-US: Pardus Boot Repair
 CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access 
to the  ...)
        - multipath-tools <unfixed> (bug #1147523)
+       [trixie] - multipath-tools <no-dsa> (Minor issue)
        [bookworm] - multipath-tools <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470013
        NOTE: 
https://github.com/opensvc/multipath-tools/security/advisories/GHSA-hmcm-9cq4-r2xm
@@ -33228,6 +33241,7 @@ CVE-2026-19486 (A Server-Side Request Forgery (SSRF) 
vulnerability in Google Clo
        NOT-FOR-US: Google Cloud Gemini Enterprise Agent Platform App Builder
 CVE-2026-18495 (A flaw was found in libtiff. A heap-buffer overflow 
vulnerability exis ...)
        - tiff 4.7.1-1
+       [trixie] - tiff <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531414
        NOTE: https://gitlab.com/libtiff/libtiff/-/merge_requests/729
        NOTE: Fixed by: 
https://gitlab.com/libtiff/libtiff/-/commit/67fd283d276f09db54dc39b9ef7b979d4b45c4b1
 (v4.7.1rc1)


=====================================
data/dsa-needed.txt
=====================================
@@ -59,6 +59,8 @@ freerdp3 (jmm)
 gegl (jmm)
   move to 0.4.72
 --
+gnocchi
+--
 graphicsmagick
 --
 gst-plugins-good1.0



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e986430dede03d69c5c6c6952968ec2b1078e41

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9e986430dede03d69c5c6c6952968ec2b1078e41
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to