Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
c1ae5f0d by Moritz Muehlenhoff at 2026-10-07T23:14:11+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -550,6 +550,7 @@ CVE-2026-94205 (Gitea Actions decided whether a fork pull
request run needed app
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as
src:gitea, but never in a stable release)
CVE-2026-94114 (Symbolic name not mapping to correct object vulnerability in
Apache Co ...)
- bcel <unfixed> (bug #1150215)
+ [trixie] - bcel <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/07/12
NOTE:
https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e917e5656b
(commons-bcel-6.13.0-RC1)
NOTE: https://lists.apache.org/thread/d87nxx7nb5bombqggxhxo9lz16nwtsf9
@@ -932,6 +933,7 @@ CVE-2026-105239 (Improper Neutralization of Null Byte or
NUL Character vulnerabi
NOTE: https://lists.apache.org/thread/9fx1qo5hc0tg8ym0t6p9gt1zpb2qlxpq
CVE-2026-105111 (Improper neutralization of input during web page generation
('cross-si ...)
- bcel <unfixed> (bug #1150227)
+ [trixie] - bcel <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/07/13
NOTE: Fixed by:
https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504
(commons-bcel-6.13.0-RC1)
NOTE: https://lists.apache.org/thread/co1wfk2lyrmpnfhn49o370pvfl978rw6
@@ -1214,7 +1216,9 @@ CVE-2026-82924 (Improper Control of Interaction Frequency
vulnerability in Pusul
NOT-FOR-US: Expert Mail
CVE-2026-82531 (Smarty before 4.5.8 and 5.x before 5.8.5 contains a code
injection vul ...)
- smarty4 <unfixed> (bug #1150192)
+ [trixie] - smarty4 <no-dsa> (Minor issue)
- smarty3 <unfixed>
+ [trixie] - smarty3 <no-dsa> (Minor issue)
NOTE:
https://github.com/smarty-php/smarty/security/advisories/GHSA-3w63-v7pm-cq9x
NOTE: Fixed by:
https://github.com/smarty-php/smarty/commit/1cba51cb813563eb61d963c83d28cd59f26b858d
(v4.5.8)
CVE-2026-82162 (Dell Command | Configure (DCC), versions prior to 5.2.3.35,
contain an ...)
@@ -1227,14 +1231,17 @@ CVE-2026-76105 (Dell Container Storage Modules,
versions prior to 1.18.0 contain
NOT-FOR-US: Dell / EMC
CVE-2026-75820 (GNU Aspell contains an integer truncation vulnerability in the
Writabl ...)
- aspell <unfixed>
+ [trixie] - aspell <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/10/CVE-2026-75818
NOTE: Fixed by:
https://github.com/GNUAspell/aspell/commit/782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d
CVE-2026-75819 (GNU Aspell contains an out-of-bounds read vulnerability in
ReadOnlyDic ...)
- aspell <unfixed>
+ [trixie] - aspell <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/10/CVE-2026-75818
NOTE: Fixed by:
https://github.com/GNUAspell/aspell/commit/941953b25031bc9104e83f58e138a664b8dedc3f
CVE-2026-75818 (GNU Aspell prezip-bin contains a heap-based buffer overflow
vulnerabil ...)
- aspell <unfixed>
+ [trixie] - aspell <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/10/CVE-2026-75818
NOTE: Fixed by:
https://github.com/GNUAspell/aspell/commit/15b188437f9e0192d4ac4472ad66a4e2f62a782f
CVE-2026-71168 (Dell System Update, versions prior to 2.3.0.0, contains an
Improper Li ...)
@@ -2061,6 +2068,7 @@ CVE-2026-106033 (A DOM-based Cross-Site Scripting (XSS)
vulnerability exists in
- ansible-ui <itp> (bug #1119346)
CVE-2026-106026 (tftp-hpa 5.4 before 6.0 contains an out-of-bounds read
vulnerability i ...)
- tftp-hpa 7.1-1
+ [trixie] - tftp-hpa <no-dsa> (Minor issue)
NOTE:
https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=6735086fb6475c3e1f1daf9829836b3d06f14291
(tftp-hpa-6.0)
CVE-2026-106016 (Mitigation bypass in the File Handling component. This
vulnerability w ...)
- firefox <unfixed>
@@ -2144,12 +2152,15 @@ CVE-2026-105840 (lrzsz before 0.13.0 contains a path
traversal vulnerability in
NOTE: https://ohse.de/uwe/software/lrzsz/NEWS-0.13.0.html
CVE-2026-105839 (libmikmod before 3.3.14 contains an integer overflow in the
Oktalyzer ...)
- libmikmod 3.3.14-1
+ [trixie] - libmikmod <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/sezero/mikmod/commit/097b69281fad6ba38a553569e6f55dbfdd71dc2a
(libmikmod-3.3.14)
CVE-2026-105838 (libmikmod before 3.3.14 contains a heap out-of-bounds read
vulnerabili ...)
- libmikmod 3.3.14-1
+ [trixie] - libmikmod <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/sezero/mikmod/commit/e7c6c9e88fbe3e8af4668a2e116bb8de341383f8
(libmikmod-3.3.14)
CVE-2026-105837 (libmikmod before 3.3.14 contains an integer overflow
vulnerability in ...)
- libmikmod 3.3.14-1
+ [trixie] - libmikmod <no-dsa> (Minor issue)
NOTE: Fixed by:
https://github.com/sezero/mikmod/commit/a125eabbd086f311496ae46d08aaebcad0a1c426
(libmikmod-3.3.14)
CVE-2026-105836 (QloApps through 1.7.0 contains an authorization bypass
vulnerability i ...)
NOT-FOR-US: QloApps
@@ -11832,6 +11843,7 @@ CVE-2026-102010 (A flaw was found in GCC. When an
application calls the erase_if
- gcc-14 <unfixed> (bug #1150196)
[trixie] - gcc-14 <no-dsa> (Minor issue)
- gcc-13 <unfixed> (bug #1150197)
+ [trixie] - gcc-13 <no-dsa> (Minor issue)
- gcc-12 <unfixed> (bug #1150198)
[trixie] - gcc-12 <ignored> (Minor issue, not fixed in upstream 12
branch)
[bookworm] - gcc-12 <ignored> (Minor issue, not fixed in upstream 12
branch)
@@ -19551,7 +19563,9 @@ CVE-2026-95619 (A flaw was found in libstdc++. An
integer overflow can occur whe
- gcc-15 <unfixed>
- gcc-16 <unfixed>
- gcc-14 <unfixed>
+ [trixie] - gcc-14 <no-dsa> (Minor issue)
- gcc-12 <unfixed>
+ [trixie] - gcc-12 <no-dsa> (Minor issue)
NOTE:
https://github.com/gcc-mirror/gcc/commit/59d235ffa5a69231eb42e5290d52dc8c90d28b7a
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537811
CVE-2026-95511
@@ -583386,6 +583400,7 @@ CVE-2022-23961 (In Thruk Monitoring through 2.46.3,
the login field of the login
CVE-2022-23960 (Certain Arm Cortex and Neoverse processors through 2022-03-08
do not p ...)
{DSA-5173-1 DLA-3065-1}
- arm-trusted-firmware 2.12.16+dfsg-1
+ [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
- linux 5.16.14-1
[bullseye] - linux 5.10.106-1
[buster] - linux 4.19.235-1
@@ -801908,6 +801923,7 @@ CVE-2018-19441 (An issue was discovered in Neato
Botvac Connected 2.2.0. The Gen
NOT-FOR-US: Neato Botvac Connected
CVE-2018-19440 (ARM Trusted Firmware-A allows information disclosure.)
- arm-trusted-firmware 2.12.16+dfsg-1
+ [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
NOTE: https://github.com/ARM-software/arm-trusted-firmware/pull/1710
NOTE:
https://trustedfirmware-a.readthedocs.io/en/latest/security_advisories/security-advisory-tfv-8.html
CVE-2018-19439 (XSS exists in the Administration Console in Oracle Secure
Global Deskt ...)
@@ -845750,6 +845766,7 @@ CVE-2018-3640 (Systems with microprocessors utilizing
speculative execution and
CVE-2018-3639 (Systems with microprocessors utilizing speculative execution
and specu ...)
{DSA-4273-2 DSA-4273-1 DSA-4210-1 DLA-1731-1 DLA-1715-1 DLA-1529-1
DLA-1446-1 DLA-1423-1}
- arm-trusted-firmware 2.12.16+dfsg-1
+ [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
- intel-microcode 3.20180703.1
- linux 4.16.12-1
[stretch] - linux 4.9.107-1
@@ -863178,6 +863195,7 @@ CVE-2017-15032 (ImageMagick version 7.0.7-2 contains
a memory leak in ReadYCBCRI
NOTE:
https://github.com/ImageMagick/ImageMagick/commit/241988ca28139ad970c1d9717c419f41e360ddb0
CVE-2017-15031 (In all versions of ARM Trusted Firmware up to and including
v1.4, not ...)
- arm-trusted-firmware 2.12.16+dfsg-1
+ [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
CVE-2017-15030 (Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected
by: Cross ...)
NOT-FOR-US: Open-Xchange GmbH OX App Suite
CVE-2017-15029 (Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected
by: SSRF.)
@@ -891821,6 +891839,7 @@ CVE-2017-5716
CVE-2017-5715 (Systems with microprocessors utilizing speculative execution
and indir ...)
{DSA-4213-1 DSA-4201-1 DSA-4188-1 DSA-4187-1 DLA-2743-1 DLA-2148-1
DLA-1497-1 DLA-1422-1 DLA-1369-1}
- arm-trusted-firmware 2.12.16+dfsg-1
+ [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
- linux 4.15.11-1
- intel-microcode 3.20180425.1
[stretch] - intel-microcode 3.20180425.1~deb9u1
=====================================
data/dsa-needed.txt
=====================================
@@ -70,6 +70,8 @@ gst-plugins-good1.0 (jmm)
hplip
security patches first need to be isolated
--
+imagemagick
+--
jackson-databind
--
jetty9
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c1ae5f0dbf59e0bd8b60363bd5584ef5b28c8387
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c1ae5f0dbf59e0bd8b60363bd5584ef5b28c8387
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits