Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
86f97a07 by Moritz Muehlenhoff at 2026-10-06T15:51:20+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1320,6 +1320,7 @@ CVE-2026-12171 (auto-changelog before 2.6.1 merges 
configuration from inside the
        NOT-FOR-US: auto-changelog
 CVE-2026-105712 (gpgtar in GnuPG before 2.5.19 can allow file overwrite via 
crafted dat ...)
        - gnupg2 <unfixed> (bug #1150168)
+       [trixie] - gnupg2 <no-dsa> (Minor issue)
        NOTE: https://static.dev.gnupg.org/T8159.html
        NOTE: Fixed by: 
https://github.com/gpg/gnupg/commit/7a2692fe5e580ae3bbb2a47abc4baaf1af65aa88 
(gnupg-2.5.19)
        NOTE: 
https://lists.gnupg.org/pipermail/gnupg-announce/2026q2/000504.html
@@ -1905,6 +1906,7 @@ CVE-2026-103062 (Improper Neutralization of Input During 
Web Page Generation ('C
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66020 [virtio-gpu: disable blob scanouts on mapping cleanup]
        - qemu 1:11.1.2+ds-2
+       [trixie] - qemu <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/3ece85b53c124142c7d5cbb1165d4da125b7c369
        NOTE: Fixed by: 
https://gitlab.com/qemu-project/qemu/-/commit/8eebc546bbd54fdd7b6fa2ebb3b54036ab397564
 (v10.0.14)
 CVE-2026-97332 (The User Private Files  WordPress plugin before 2.2.0 does not 
properl ...)
@@ -3490,6 +3492,7 @@ CVE-2026-78242 (Insertion of sensitive information into 
log file vulnerability i
        NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-77387 (geopy is a geocoding library for Python. Prior to 2.5.0, 
geopy.Point a ...)
        - geopy <unfixed> (bug #1149676)
+       [trixie] - geopy <no-dsa> (Minor issue)
        NOTE: 
https://github.com/geopy/geopy/security/advisories/GHSA-mhvh-fq92-pfmr
        NOTE: https://github.com/geopy/geopy/issues/608
        NOTE: https://github.com/geopy/geopy/pull/610
@@ -3653,6 +3656,7 @@ CVE-2026-103757 (Budibase through 3.41.0 contains a 
server-side request forgery
        NOT-FOR-US: Budibase
 CVE-2026-103754 (A flaw was found in ansible-runner. The unstream_dir() 
function, which ...)
        - ansible-runner <unfixed> (bug #1149995)
+       [trixie] - ansible-runner <no-dsa> (Minor issue)
        NOTE: https://github.com/ansible/ansible-runner/pull/1550
 CVE-2026-103752 (Unauthenticated Privilege Escalation in Authorizer <= 3.15.3 
versions.)
        NOT-FOR-US: WordPress plugin or theme
@@ -9078,6 +9082,7 @@ CVE-2026-101280 (A vulnerability was detected in Trusted 
Domain Project OpenDMAR
        NOTE: 
https://xuyongzhe-vt.github.io/share/opendmarc-multi-record-downgrade.html
 CVE-2026-101279 (A security vulnerability has been detected in Trusted Domain 
Project O ...)
        - opendmarc <unfixed> (bug #1149876)
+       [trixie] - opendmarc <no-dsa> (Minor issue)
        NOTE: 
https://xuyongzhe-vt.github.io/share/dmarc-pct-integer-handling.html
 CVE-2026-101278 (A weakness has been identified in Trusted Domain Project 
OpenDMARC up  ...)
        - opendmarc <unfixed> (bug #1149876)
@@ -9497,10 +9502,12 @@ CVE-2026-12265 (Zohocorp ManageEngine DDI Central 
versions before 6201 are vulne
 CVE-2026-12264 (Zohocorp ManageEngine DDI Central versions before 6201 are 
vulnerable  ...)
        NOT-FOR-US: Zoho
 CVE-2026-102010 (A flaw was found in GCC. When an application calls the 
erase_if functi ...)
-       - gcc-15 <unfixed>
        - gcc-16 <unfixed>
+       - gcc-15 <unfixed>
        - gcc-14 <unfixed>
+       [trixie] - gcc-14 <no-dsa> (Minor issue)
        - gcc-12 <unfixed>
+       [trixie] - gcc-12 <ignored> (Minor issue, not fixed in upstream 12 
branch)
        NOTE: https://gcc.gnu.org/bugzilla/show_bug.cgi?id=127656
        NOTE: 
https://gcc.gnu.org/git/?p=gcc.git;a=commit;h=aaa8351f4d2e636f9680a1f0a8ebc2f0a60611e6
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478395
@@ -16113,6 +16120,7 @@ CVE-2026-94422 (An incorrect implementation of message 
filtering in xdg-dbus-pro
        NOTE: 
https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq
 CVE-2026-92709
        - rsyslog <unfixed> (bug #1148832)
+       [trixie] - rsyslog <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rsyslog/rsyslog/security/advisories/GHSA-xmp9-244p-5ggv
 CVE-2026-93403 [Stack-based Buffer Overflow in mmpstrucdata rsyslog plugin]
        - rsyslog 8.2606.0-4
@@ -16123,6 +16131,7 @@ CVE-2026-93403 [Stack-based Buffer Overflow in 
mmpstrucdata rsyslog plugin]
        NOTE: Fixed by: 
https://github.com/rsyslog/rsyslog/commit/bcda60a3692efdf0c8e44102528f5a0ebe0dec6d
 (v8.2606.0)
 CVE-2026-93402 [mdtls discards the peer-identity verification result]
        - rsyslog <unfixed> (bug #1148833)
+       [trixie] - rsyslog <no-dsa> (Minor issue)
        NOTE: 
https://github.com/rsyslog/rsyslog/security/advisories/GHSA-8v8w-f8wf-475j
        NOTE: https://github.com/rsyslog/rsyslog/pull/7617
        NOTE: Fixed by: 
https://github.com/rsyslog/rsyslog/commit/ef9f77d709640ceb3d5e78118081a291f9e373c5
@@ -129557,6 +129566,7 @@ CVE-2026-42488 (Some shadow paging errors paths will 
switch the page-tables with
 CVE-2025-10263 (Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, 
Neoverse V1 ...)
        {DSA-6424-1 DLA-4818-1 DLA-4671-1 DLA-4665-1 DLA-4664-1}
        - arm-trusted-firmware 2.12.16+dfsg-1
+       [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
        - linux 7.0.13-1
        [trixie] - linux 6.12.94-1
        - xen 4.20.3+127-gc42374a105-1
@@ -191203,6 +191213,7 @@ CVE-2026-1628 (Mattermost Desktop App versions 
<=5.13.3 fail to attach listeners
        NOT-FOR-US: Mattermost Desktop App
 CVE-2026-0995 (An issue has been identified in Arm C1-Pro before r1p2-50eac0, 
where,  ...)
        - arm-trusted-firmware 2.12.16+dfsg-1
+       [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
        NOTE: https://support.arm.com/documentation/111823
 CVE-2026-0689 (In ExtremeCloud IQ \u2013 Site Engine (XIQ\u2011SE) before 
26.2.10, a  ...)
        NOT-FOR-US: ExtremeCloud IQ
@@ -210090,6 +210101,7 @@ CVE-2025-13175 (Y Soft SafeQ 6 renders the Workflow 
Connector password field in
        NOT-FOR-US: Y Soft
 CVE-2025-0647 (In certain Arm CPUs, a CPP RCTX instruction executed on one 
Processing ...)
        - arm-trusted-firmware 2.12.16+dfsg-1
+       [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
        NOTE: https://support.arm.com/documentation/111546/latest/
 CVE-2025-71144 (In the Linux kernel, the following vulnerability has been 
resolved:  m ...)
        {DSA-6163-1 DSA-6126-1 DLA-4499-1}


=====================================
data/dsa-needed.txt
=====================================
@@ -82,6 +82,8 @@ kitty
 --
 libnet-idn-encode-perl (carnil)
 --
+librsvg (jmm)
+--
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more 6.12.y versions
@@ -90,6 +92,10 @@ lxd
 --
 mediawiki (jmm)
 --
+modsecurity
+--
+modsecurity-apache
+--
 nagios4
 --
 nats-server



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86f97a07711f157c334cd53543b9b04e680d7e4d

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86f97a07711f157c334cd53543b9b04e680d7e4d
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to