Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a5f56d95 by Moritz Muehlenhoff at 2026-10-08T22:41:10+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -668,15 +668,19 @@ CVE-2026-107174 (A flaw was found in source-to-image.
When unpacking archive fil
NOT-FOR-US: source-to-image in OpenShift
CVE-2026-107170 (A flaw was found in m17n-lib. A partial failure during
library initial ...)
- m17n-lib <unfixed>
+ [trixie] - m17n-lib <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547411
CVE-2026-107169 (A flaw was found in m17n-lib. An attacker could provide
specially craf ...)
- m17n-lib <unfixed>
+ [trixie] - m17n-lib <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547410
CVE-2026-107168 (A flaw was found in m17n-lib. By providing crafted input
containing an ...)
- m17n-lib <unfixed>
+ [trixie] - m17n-lib <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547409
CVE-2026-107167 (A flaw was found in m17n-lib. A user providing specially
crafted text ...)
- m17n-lib <unfixed>
+ [trixie] - m17n-lib <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547408
CVE-2026-107166 (A weakness has been identified in Open5GS up to 2.7.7. This
vulnerabil ...)
- open5gs <itp> (bug #1094791)
@@ -1258,6 +1262,7 @@ CVE-2026-106455 (Backstage is an open framework for
building developer portals.
NOT-FOR-US: Backstage
CVE-2026-106454 (Twisted is an event-based framework for internet
applications, support ...)
- twisted 26.4.0-5 (bug #1150248)
+ [trixie] - twisted <no-dsa> (Minor issue)
NOTE:
https://github.com/twisted/twisted/security/advisories/GHSA-8pqf-f4m5-798g
NOTE: https://github.com/twisted/twisted/pull/12788
NOTE: Fixed by:
https://github.com/twisted/twisted/commit/2f8a3c29246f4eb324690e06a9767a11dc4aec9f
@@ -1342,34 +1347,36 @@ CVE-2026-105268 (The Gitea API routes for issue
attachments (`/api/v1/repos/{own
CVE-2026-105267 (The Gitea web route for deleting tags (`POST
/{owner}/{repo}/tags/dele ...)
NOT-FOR-US: Gitea (used to be packaged in the Debian archive as
src:gitea, but never in a stable release)
CVE-2026-105244 (Improper Encoding or Escaping of Output vulnerability in the
RemoteSys ...)
- - log4net <undetermined>
+ - log4net <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/apache/logging-log4net/pull/315
NOTE: Fixed by:
https://github.com/apache/logging-log4net/commit/77717061b20d4346b6c0ce6b54643d85fb348bc7
(rc/3.5.0-rc1)
NOTE: https://lists.apache.org/thread/q7649hhdodthoqw8jsjgtnb4m8qfy6d6
- TODO: check, might not affect our old version and upstream claims
1.2.12 onwards
CVE-2026-105243 (Insufficient Logging vulnerability in the EventLogAppender of
Apache l ...)
- log4net <unfixed> (bug #1150239)
+ [trixie] - log4net <no-dsa> (Minor issue)
NOTE: https://github.com/apache/logging-log4net/pull/315
NOTE: Fixed by:
https://github.com/apache/logging-log4net/commit/28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed
(rc/3.5.0-rc1)
NOTE: https://lists.apache.org/thread/jr6fj5skv1vnjbc9jmt8bp151p8ow1rp
CVE-2026-105242 (Improper Handling of Exceptional Conditions vulnerability in
the aspne ...)
- - log4net <undetermined>
+ - log4net <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/apache/logging-log4net/pull/316
NOTE: Fixed by:
https://github.com/apache/logging-log4net/commit/145203420c579a703008b4b723b6a080757f4964
(rc/3.5.0-rc1)
NOTE: https://lists.apache.org/thread/zg6dbqm4ztm7j3c21nfsqj0yxm5yrpdx
- TODO: check, might not affect our old version, upstream claims 12.11
onwards
CVE-2026-105241 (Improper Handling of Unicode Encoding vulnerability in the
SmtpPickupD ...)
- log4net <unfixed> (bug #1150239)
+ [trixie] - log4net <no-dsa> (Minor issue)
NOTE: https://github.com/apache/logging-log4net/pull/315
NOTE: Fixed by:
https://github.com/apache/logging-log4net/commit/4d2e10f0908199604b4326f9df6d0b43b871e333
(rc/3.5.0-rc1)
NOTE: https://lists.apache.org/thread/hg8dgh3oy8bp3dhb8nsygk9kw2o401ws
CVE-2026-105240 (Improper Neutralization of Null Byte or NUL Character
vulnerability in ...)
- log4net <unfixed> (bug #1150239)
+ [trixie] - log4net <no-dsa> (Minor issue)
NOTE: https://github.com/apache/logging-log4net/pull/315
NOTE: Fixed by:
https://github.com/apache/logging-log4net/commit/6046fe9d7f353b49fe995361c071ec2eea8f7ef6
(rc/3.5.0-rc1)
NOTE: https://lists.apache.org/thread/gyw2d4ppy82t1vlpdknkfd1nmzp21z17
CVE-2026-105239 (Improper Neutralization of Null Byte or NUL Character
vulnerability in ...)
- log4net <unfixed> (bug #1150239)
+ [trixie] - log4net <no-dsa> (Minor issue)
NOTE: https://github.com/apache/logging-log4net/pull/315
NOTE: Fixed by:
https://github.com/apache/logging-log4net/commit/dc5855a0720c91590fd7a81d729ea01fdd69e000
(rc/3.5.0-rc1)
NOTE: https://lists.apache.org/thread/9fx1qo5hc0tg8ym0t6p9gt1zpb2qlxpq
@@ -6983,6 +6990,7 @@ CVE-2026-102997 (pypdf is a free and open-source
pure-python PDF library. Prior
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/d9d38cf99b115deb562d3b68f36c33027bc04f79
(6.18.1)
CVE-2026-102996 (pypdf is a free and open-source pure-python PDF library.
Prior to 6.18 ...)
- pypdf 6.19.0-1
+ [trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <not-affected> (Per-glyph /Widths map introduced in
pypdf 4.0.0)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9cg-prrw-2r8q
@@ -6990,6 +6998,7 @@ CVE-2026-102996 (pypdf is a free and open-source
pure-python PDF library. Prior
NOTE: Fixed by:
https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5
(6.18.1)
CVE-2026-102995 (pypdf is a free and open-source pure-python PDF library.
Prior to 6.18 ...)
- pypdf 6.19.0-1
+ [trixie] - pypdf <no-dsa> (Minor issue)
- pypdf2 <removed>
[bookworm] - pypdf2 <postponed> (Minor issue, DoS)
NOTE:
https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3h-c4fm-7vvf
@@ -84554,12 +84563,14 @@ CVE-2026-70369 (Koha's reports/acquisitions_stats.pl
builds its per-cell statist
CVE-2026-70368 (A stack-based out-of-bounds read vulnerability exists in the
"s_vlog" ...)
- stunnel 3:5.80-1
- stunnel4 <removed>
+ [trixie] - stunnel4 <no-dsa> (Minor issue)
[bookworm] - stunnel4 <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462029
NOTE: https://www.stunnel.org/CVE-2026-70368.html
CVE-2026-70367 (A Server-Side Request Forgery (SSRF) bypass vulnerability
exists in \u ...)
- stunnel 3:5.80-1
- stunnel4 <removed>
+ [trixie] - stunnel4 <no-dsa> (Minor issue)
[bookworm] - stunnel4 <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462083
NOTE: https://www.stunnel.org/CVE-2026-70367.html
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5f56d9572ddbcbf983f994d60ff5a29b5809648
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5f56d9572ddbcbf983f994d60ff5a29b5809648
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits