Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
d41c63a1 by Moritz Muehlenhoff at 2026-10-08T09:00:16+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -725,37 +725,65 @@ CVE-2026-16516 (wolfSSH does not validate that the ECDSA
curve identifier in a K
CVE-2026-14911 (Improper Neutralization of Input During Web Page Generation
(\u201cCro ...)
NOT-FOR-US: ASUS
CVE-2026-106589 (In sshd in OpenSSH through 10.6, in certain environments such
as QNX 6 ...)
- - openssh 1:10.6p1-1
+ - openssh <not-affected> (Doesn't affect OpenSSH on Linux)
+ - openssh-gssapi <not-affected> (Doesn't affect OpenSSH on Linux)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106588 (In sshd in OpenSSH through 10.6, use of the macOS 27 (or
later) SDK ha ...)
- openssh <not-affected> (Only affects OpenSSH on macOS)
+ - openssh-gssapi <not-affected> (Only affects OpenSSH on macOS)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106587 (In sshd in OpenSSH before 10.6, the value "none" for a
configuration o ...)
- openssh 1:10.6p1-1
+ [trixie] - openssh <no-dsa> (Minor issue)
+ - openssh-gssapi 1:10.6p1-1
+ [trixie] - openssh-gssapi <no-dsa> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106586 (In sshd in OpenSSH before 10.6, the restrict keyword (in
authorized_ke ...)
- openssh 1:10.6p1-1
+ [trixie] - openssh <no-dsa> (Minor issue)
+ - openssh-gssapi 1:10.6p1-1
+ [trixie] - openssh-gssapi <no-dsa> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106585 (In sshd and ssh in OpenSSH before 10.6, there is no check for
whether ...)
- openssh 1:10.6p1-1
+ [trixie] - openssh <no-dsa> (Minor issue)
+ - openssh-gssapi 1:10.6p1-1
+ [trixie] - openssh-gssapi <no-dsa> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106584 (In ssh-keygen in OpenSSH before 10.6, certificates could have
incorrec ...)
- - openssh 1:10.6p1-1
+ - openssh 1:10.6p1-1 (unimportant)
+ - openssh-gssapi 1:10.6p1-1 (unimportant)
NOTE: https://www.openssh.org/releasenotes.html#10.6
+ NOTE: Negligible security impact
CVE-2026-106583 (In ssh in OpenSSH before 10.6, a $ or \ character can occur
in a comma ...)
- openssh 1:10.6p1-1
+ [trixie] - openssh <no-dsa> (Minor issue)
+ - openssh-gssapi 1:10.6p1-1
+ [trixie] - openssh-gssapi <no-dsa> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106582 (In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary
coder can b ...)
- openssh 1:10.6p1-1
+ [trixie] - openssh <no-dsa> (Minor issue)
+ - openssh-gssapi 1:10.6p1-1
+ [trixie] - openssh-gssapi <no-dsa> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106555 (In sshd in OpenSSH before 10.6, GSSAPIAuthentication
authentication st ...)
- openssh 1:10.6p1-1
+ [trixie] - openssh <no-dsa> (Minor issue)
+ - openssh-gssapi 1:10.6p1-1
+ [trixie] - openssh-gssapi <no-dsa> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106553 (In sshd in OpenSSH before 10.6, credentials can incorrectly
persist af ...)
- openssh 1:10.6p1-1
+ [trixie] - openssh <no-dsa> (Minor issue)
+ - openssh-gssapi 1:10.6p1-1
+ [trixie] - openssh-gssapi <no-dsa> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106552 (In sftp in OpenSSH before 10.6, a server can trigger
directory travers ...)
- openssh 1:10.6p1-1
+ [trixie] - openssh <no-dsa> (Minor issue)
+ - openssh-gssapi 1:10.6p1-1
+ [trixie] - openssh-gssapi <no-dsa> (Minor issue)
NOTE: https://www.openssh.org/releasenotes.html#10.6
CVE-2026-106550 (Mozilla's Node-convict (version 6.2.2 and later) is
vulnerable to a De ...)
NOT-FOR-US: Node convict
@@ -3166,6 +3194,7 @@ CVE-2026-105783 (Joplin is an open source note-taking and
to-do application that
- joplin <itp> (bug #931306)
CVE-2026-105782 (Scrapy is a high-level web crawling and scraping framework
for Python. ...)
- python-scrapy 2.14.2-1
+ [trixie] - python-scrapy <no-dsa> (Minor issue)
NOTE:
https://github.com/scrapy/scrapy/security/advisories/GHSA-cwxj-rr6w-m6w7
NOTE: Fixed by:
https://github.com/scrapy/scrapy/commit/b6e5c58ae707a3d4bb491537b5519534050047e0
CVE-2026-105778 (A vulnerability has been found in Tenda AC5
02.03.01.111_multi. Affect ...)
@@ -9762,12 +9791,14 @@ CVE-2026-102771 (A security vulnerability has been
detected in Naichen ThinkCMF
NOT-FOR-US: Naichen ThinkCMF
CVE-2026-102621 (A vulnerability was identified in Freedesktop Poppler up to
26.08.0. A ...)
- poppler 26.07.0-3 (bug #1149698)
+ [trixie] - poppler <no-dsa> (Minor issue)
[bookworm] - poppler <postponed> (Minor issue)
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1763
NOTE:
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2325
NOTE:
https://gitlab.freedesktop.org/poppler/poppler/-/commit/323c91036d99926a8b90dc14329f7b40aece22f8
CVE-2026-102620 (A vulnerability was determined in Freedesktop Poppler
26.06.0/26.07.0/ ...)
- poppler 26.07.0-3 (bug #1149697)
+ [trixie] - poppler <no-dsa> (Minor issue)
[bookworm] - poppler <postponed> (Minor issue)
NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1762
NOTE:
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2326
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d41c63a1428561bf152d27a68df73a533aedd415
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d41c63a1428561bf152d27a68df73a533aedd415
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits