Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
d41c63a1 by Moritz Muehlenhoff at 2026-10-08T09:00:16+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -725,37 +725,65 @@ CVE-2026-16516 (wolfSSH does not validate that the ECDSA 
curve identifier in a K
 CVE-2026-14911 (Improper Neutralization of Input During Web Page Generation 
(\u201cCro ...)
        NOT-FOR-US: ASUS
 CVE-2026-106589 (In sshd in OpenSSH through 10.6, in certain environments such 
as QNX 6 ...)
-       - openssh 1:10.6p1-1
+       - openssh <not-affected> (Doesn't affect OpenSSH on Linux)
+       - openssh-gssapi <not-affected> (Doesn't affect OpenSSH on Linux)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106588 (In sshd in OpenSSH through 10.6, use of the macOS 27 (or 
later) SDK ha ...)
        - openssh <not-affected> (Only affects OpenSSH on macOS)
+       - openssh-gssapi <not-affected> (Only affects OpenSSH on macOS)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106587 (In sshd in OpenSSH before 10.6, the value "none" for a 
configuration o ...)
        - openssh 1:10.6p1-1
+       [trixie] - openssh <no-dsa> (Minor issue)
+       - openssh-gssapi 1:10.6p1-1
+       [trixie] - openssh-gssapi <no-dsa> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106586 (In sshd in OpenSSH before 10.6, the restrict keyword (in 
authorized_ke ...)
        - openssh 1:10.6p1-1
+       [trixie] - openssh <no-dsa> (Minor issue)
+       - openssh-gssapi 1:10.6p1-1
+       [trixie] - openssh-gssapi <no-dsa> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106585 (In sshd and ssh in OpenSSH before 10.6, there is no check for 
whether  ...)
        - openssh 1:10.6p1-1
+       [trixie] - openssh <no-dsa> (Minor issue)
+       - openssh-gssapi 1:10.6p1-1
+       [trixie] - openssh-gssapi <no-dsa> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106584 (In ssh-keygen in OpenSSH before 10.6, certificates could have 
incorrec ...)
-       - openssh 1:10.6p1-1
+       - openssh 1:10.6p1-1 (unimportant)
+       - openssh-gssapi 1:10.6p1-1 (unimportant)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
+       NOTE: Negligible security impact
 CVE-2026-106583 (In ssh in OpenSSH before 10.6, a $ or \ character can occur 
in a comma ...)
        - openssh 1:10.6p1-1
+       [trixie] - openssh <no-dsa> (Minor issue)
+       - openssh-gssapi 1:10.6p1-1
+       [trixie] - openssh-gssapi <no-dsa> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106582 (In sshd and ssh in OpenSSH before 10.6, an LZ77 dictionary 
coder can b ...)
        - openssh 1:10.6p1-1
+       [trixie] - openssh <no-dsa> (Minor issue)
+       - openssh-gssapi 1:10.6p1-1
+       [trixie] - openssh-gssapi <no-dsa> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106555 (In sshd in OpenSSH before 10.6, GSSAPIAuthentication 
authentication st ...)
        - openssh 1:10.6p1-1
+       [trixie] - openssh <no-dsa> (Minor issue)
+       - openssh-gssapi 1:10.6p1-1
+       [trixie] - openssh-gssapi <no-dsa> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106553 (In sshd in OpenSSH before 10.6, credentials can incorrectly 
persist af ...)
        - openssh 1:10.6p1-1
+       [trixie] - openssh <no-dsa> (Minor issue)
+       - openssh-gssapi 1:10.6p1-1
+       [trixie] - openssh-gssapi <no-dsa> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106552 (In sftp in OpenSSH before 10.6, a server can trigger 
directory travers ...)
        - openssh 1:10.6p1-1
+       [trixie] - openssh <no-dsa> (Minor issue)
+       - openssh-gssapi 1:10.6p1-1
+       [trixie] - openssh-gssapi <no-dsa> (Minor issue)
        NOTE: https://www.openssh.org/releasenotes.html#10.6
 CVE-2026-106550 (Mozilla's Node-convict (version 6.2.2 and later) is 
vulnerable to a De ...)
        NOT-FOR-US: Node convict
@@ -3166,6 +3194,7 @@ CVE-2026-105783 (Joplin is an open source note-taking and 
to-do application that
        - joplin <itp> (bug #931306)
 CVE-2026-105782 (Scrapy is a high-level web crawling and scraping framework 
for Python. ...)
        - python-scrapy 2.14.2-1
+       [trixie] - python-scrapy <no-dsa> (Minor issue)
        NOTE: 
https://github.com/scrapy/scrapy/security/advisories/GHSA-cwxj-rr6w-m6w7
        NOTE: Fixed by: 
https://github.com/scrapy/scrapy/commit/b6e5c58ae707a3d4bb491537b5519534050047e0
 CVE-2026-105778 (A vulnerability has been found in Tenda AC5 
02.03.01.111_multi. Affect ...)
@@ -9762,12 +9791,14 @@ CVE-2026-102771 (A security vulnerability has been 
detected in Naichen ThinkCMF
        NOT-FOR-US: Naichen ThinkCMF
 CVE-2026-102621 (A vulnerability was identified in Freedesktop Poppler up to 
26.08.0. A ...)
        - poppler 26.07.0-3 (bug #1149698)
+       [trixie] - poppler <no-dsa> (Minor issue)
        [bookworm] - poppler <postponed> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1763
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2325
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/commit/323c91036d99926a8b90dc14329f7b40aece22f8
 CVE-2026-102620 (A vulnerability was determined in Freedesktop Poppler 
26.06.0/26.07.0/ ...)
        - poppler 26.07.0-3 (bug #1149697)
+       [trixie] - poppler <no-dsa> (Minor issue)
        [bookworm] - poppler <postponed> (Minor issue)
        NOTE: https://gitlab.freedesktop.org/poppler/poppler/-/work_items/1762
        NOTE: 
https://gitlab.freedesktop.org/poppler/poppler/-/merge_requests/2326



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d41c63a1428561bf152d27a68df73a533aedd415

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d41c63a1428561bf152d27a68df73a533aedd415
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to