Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
c1ae5f0d by Moritz Muehlenhoff at 2026-10-07T23:14:11+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -550,6 +550,7 @@ CVE-2026-94205 (Gitea Actions decided whether a fork pull 
request run needed app
        NOT-FOR-US: Gitea (used to be packaged in the Debian archive as 
src:gitea, but never in a stable release)
 CVE-2026-94114 (Symbolic name not mapping to correct object vulnerability in 
Apache Co ...)
        - bcel <unfixed> (bug #1150215)
+       [trixie] - bcel <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/07/12
        NOTE: 
https://github.com/apache/commons-bcel/commit/14890bf2b9014df25f9b4de86f29b5e917e5656b
 (commons-bcel-6.13.0-RC1)
        NOTE: https://lists.apache.org/thread/d87nxx7nb5bombqggxhxo9lz16nwtsf9
@@ -932,6 +933,7 @@ CVE-2026-105239 (Improper Neutralization of Null Byte or 
NUL Character vulnerabi
        NOTE: https://lists.apache.org/thread/9fx1qo5hc0tg8ym0t6p9gt1zpb2qlxpq
 CVE-2026-105111 (Improper neutralization of input during web page generation 
('cross-si ...)
        - bcel <unfixed> (bug #1150227)
+       [trixie] - bcel <no-dsa> (Minor issue)
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/07/13
        NOTE: Fixed by: 
https://github.com/apache/commons-bcel/commit/fb72c225cbc6ec3d94060ed6edb269f07428d504
 (commons-bcel-6.13.0-RC1)
        NOTE: https://lists.apache.org/thread/co1wfk2lyrmpnfhn49o370pvfl978rw6
@@ -1214,7 +1216,9 @@ CVE-2026-82924 (Improper Control of Interaction Frequency 
vulnerability in Pusul
        NOT-FOR-US: Expert Mail
 CVE-2026-82531 (Smarty before 4.5.8 and 5.x before 5.8.5 contains a code 
injection vul ...)
        - smarty4 <unfixed> (bug #1150192)
+       [trixie] - smarty4 <no-dsa> (Minor issue)
        - smarty3 <unfixed>
+       [trixie] - smarty3 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/smarty-php/smarty/security/advisories/GHSA-3w63-v7pm-cq9x
        NOTE: Fixed by: 
https://github.com/smarty-php/smarty/commit/1cba51cb813563eb61d963c83d28cd59f26b858d
 (v4.5.8)
 CVE-2026-82162 (Dell Command | Configure (DCC), versions prior to 5.2.3.35, 
contain an ...)
@@ -1227,14 +1231,17 @@ CVE-2026-76105 (Dell Container Storage Modules, 
versions prior to 1.18.0 contain
        NOT-FOR-US: Dell / EMC
 CVE-2026-75820 (GNU Aspell contains an integer truncation vulnerability in the 
Writabl ...)
        - aspell <unfixed>
+       [trixie] - aspell <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/10/CVE-2026-75818
        NOTE: Fixed by: 
https://github.com/GNUAspell/aspell/commit/782ce94e4dc71eaec4ee1bd945eb3b9c47c5387d
 CVE-2026-75819 (GNU Aspell contains an out-of-bounds read vulnerability in 
ReadOnlyDic ...)
        - aspell <unfixed>
+       [trixie] - aspell <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/10/CVE-2026-75818
        NOTE: Fixed by: 
https://github.com/GNUAspell/aspell/commit/941953b25031bc9104e83f58e138a664b8dedc3f
 CVE-2026-75818 (GNU Aspell prezip-bin contains a heap-based buffer overflow 
vulnerabil ...)
        - aspell <unfixed>
+       [trixie] - aspell <no-dsa> (Minor issue)
        NOTE: https://cert.pl/en/posts/2026/10/CVE-2026-75818
        NOTE: Fixed by: 
https://github.com/GNUAspell/aspell/commit/15b188437f9e0192d4ac4472ad66a4e2f62a782f
 CVE-2026-71168 (Dell System Update, versions prior to 2.3.0.0, contains an 
Improper Li ...)
@@ -2061,6 +2068,7 @@ CVE-2026-106033 (A DOM-based Cross-Site Scripting (XSS) 
vulnerability exists in
        - ansible-ui <itp> (bug #1119346)
 CVE-2026-106026 (tftp-hpa 5.4 before 6.0 contains an out-of-bounds read 
vulnerability i ...)
        - tftp-hpa 7.1-1
+       [trixie] - tftp-hpa <no-dsa> (Minor issue)
        NOTE: 
https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=6735086fb6475c3e1f1daf9829836b3d06f14291
 (tftp-hpa-6.0)
 CVE-2026-106016 (Mitigation bypass in the File Handling component. This 
vulnerability w ...)
        - firefox <unfixed>
@@ -2144,12 +2152,15 @@ CVE-2026-105840 (lrzsz before 0.13.0 contains a path 
traversal vulnerability in
        NOTE: https://ohse.de/uwe/software/lrzsz/NEWS-0.13.0.html
 CVE-2026-105839 (libmikmod before 3.3.14 contains an integer overflow in the 
Oktalyzer  ...)
        - libmikmod 3.3.14-1
+       [trixie] - libmikmod <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/sezero/mikmod/commit/097b69281fad6ba38a553569e6f55dbfdd71dc2a
 (libmikmod-3.3.14)
 CVE-2026-105838 (libmikmod before 3.3.14 contains a heap out-of-bounds read 
vulnerabili ...)
        - libmikmod 3.3.14-1
+       [trixie] - libmikmod <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/sezero/mikmod/commit/e7c6c9e88fbe3e8af4668a2e116bb8de341383f8
 (libmikmod-3.3.14)
 CVE-2026-105837 (libmikmod before 3.3.14 contains an integer overflow 
vulnerability in  ...)
        - libmikmod 3.3.14-1
+       [trixie] - libmikmod <no-dsa> (Minor issue)
        NOTE: Fixed by: 
https://github.com/sezero/mikmod/commit/a125eabbd086f311496ae46d08aaebcad0a1c426
 (libmikmod-3.3.14)
 CVE-2026-105836 (QloApps through 1.7.0 contains an authorization bypass 
vulnerability i ...)
        NOT-FOR-US: QloApps
@@ -11832,6 +11843,7 @@ CVE-2026-102010 (A flaw was found in GCC. When an 
application calls the erase_if
        - gcc-14 <unfixed> (bug #1150196)
        [trixie] - gcc-14 <no-dsa> (Minor issue)
        - gcc-13 <unfixed> (bug #1150197)
+       [trixie] - gcc-13 <no-dsa> (Minor issue)
        - gcc-12 <unfixed> (bug #1150198)
        [trixie] - gcc-12 <ignored> (Minor issue, not fixed in upstream 12 
branch)
        [bookworm] - gcc-12 <ignored> (Minor issue, not fixed in upstream 12 
branch)
@@ -19551,7 +19563,9 @@ CVE-2026-95619 (A flaw was found in libstdc++. An 
integer overflow can occur whe
        - gcc-15 <unfixed>
        - gcc-16 <unfixed>
        - gcc-14 <unfixed>
+       [trixie] - gcc-14 <no-dsa> (Minor issue)
        - gcc-12 <unfixed>
+       [trixie] - gcc-12 <no-dsa> (Minor issue)
        NOTE: 
https://github.com/gcc-mirror/gcc/commit/59d235ffa5a69231eb42e5290d52dc8c90d28b7a
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537811
 CVE-2026-95511
@@ -583386,6 +583400,7 @@ CVE-2022-23961 (In Thruk Monitoring through 2.46.3, 
the login field of the login
 CVE-2022-23960 (Certain Arm Cortex and Neoverse processors through 2022-03-08 
do not p ...)
        {DSA-5173-1 DLA-3065-1}
        - arm-trusted-firmware 2.12.16+dfsg-1
+       [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
        - linux 5.16.14-1
        [bullseye] - linux 5.10.106-1
        [buster] - linux 4.19.235-1
@@ -801908,6 +801923,7 @@ CVE-2018-19441 (An issue was discovered in Neato 
Botvac Connected 2.2.0. The Gen
        NOT-FOR-US: Neato Botvac Connected
 CVE-2018-19440 (ARM Trusted Firmware-A allows information disclosure.)
        - arm-trusted-firmware 2.12.16+dfsg-1
+       [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
        NOTE: https://github.com/ARM-software/arm-trusted-firmware/pull/1710
        NOTE: 
https://trustedfirmware-a.readthedocs.io/en/latest/security_advisories/security-advisory-tfv-8.html
 CVE-2018-19439 (XSS exists in the Administration Console in Oracle Secure 
Global Deskt ...)
@@ -845750,6 +845766,7 @@ CVE-2018-3640 (Systems with microprocessors utilizing 
speculative execution and
 CVE-2018-3639 (Systems with microprocessors utilizing speculative execution 
and specu ...)
        {DSA-4273-2 DSA-4273-1 DSA-4210-1 DLA-1731-1 DLA-1715-1 DLA-1529-1 
DLA-1446-1 DLA-1423-1}
        - arm-trusted-firmware 2.12.16+dfsg-1
+       [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
        - intel-microcode 3.20180703.1
        - linux 4.16.12-1
        [stretch] - linux 4.9.107-1
@@ -863178,6 +863195,7 @@ CVE-2017-15032 (ImageMagick version 7.0.7-2 contains 
a memory leak in ReadYCBCRI
        NOTE: 
https://github.com/ImageMagick/ImageMagick/commit/241988ca28139ad970c1d9717c419f41e360ddb0
 CVE-2017-15031 (In all versions of ARM Trusted Firmware up to and including 
v1.4, not  ...)
        - arm-trusted-firmware 2.12.16+dfsg-1
+       [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
 CVE-2017-15030 (Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected 
by: Cross ...)
        NOT-FOR-US: Open-Xchange GmbH OX App Suite
 CVE-2017-15029 (Open-Xchange GmbH OX App Suite 7.8.4 and earlier is affected 
by: SSRF.)
@@ -891821,6 +891839,7 @@ CVE-2017-5716
 CVE-2017-5715 (Systems with microprocessors utilizing speculative execution 
and indir ...)
        {DSA-4213-1 DSA-4201-1 DSA-4188-1 DSA-4187-1 DLA-2743-1 DLA-2148-1 
DLA-1497-1 DLA-1422-1 DLA-1369-1}
        - arm-trusted-firmware 2.12.16+dfsg-1
+       [trixie] - arm-trusted-firmware <no-dsa> (Minor issue)
        - linux 4.15.11-1
        - intel-microcode 3.20180425.1
        [stretch] - intel-microcode 3.20180425.1~deb9u1


=====================================
data/dsa-needed.txt
=====================================
@@ -70,6 +70,8 @@ gst-plugins-good1.0 (jmm)
 hplip
   security patches first need to be isolated
 --
+imagemagick
+--
 jackson-databind
 --
 jetty9



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c1ae5f0dbf59e0bd8b60363bd5584ef5b28c8387

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c1ae5f0dbf59e0bd8b60363bd5584ef5b28c8387
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to