Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a5f56d95 by Moritz Muehlenhoff at 2026-10-08T22:41:10+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -668,15 +668,19 @@ CVE-2026-107174 (A flaw was found in source-to-image. 
When unpacking archive fil
        NOT-FOR-US: source-to-image in OpenShift
 CVE-2026-107170 (A flaw was found in m17n-lib. A partial failure during 
library initial ...)
        - m17n-lib <unfixed>
+       [trixie] - m17n-lib <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547411
 CVE-2026-107169 (A flaw was found in m17n-lib. An attacker could provide 
specially craf ...)
        - m17n-lib <unfixed>
+       [trixie] - m17n-lib <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547410
 CVE-2026-107168 (A flaw was found in m17n-lib. By providing crafted input 
containing an ...)
        - m17n-lib <unfixed>
+       [trixie] - m17n-lib <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547409
 CVE-2026-107167 (A flaw was found in m17n-lib. A user providing specially 
crafted text  ...)
        - m17n-lib <unfixed>
+       [trixie] - m17n-lib <no-dsa> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547408
 CVE-2026-107166 (A weakness has been identified in Open5GS up to 2.7.7. This 
vulnerabil ...)
        - open5gs <itp> (bug #1094791)
@@ -1258,6 +1262,7 @@ CVE-2026-106455 (Backstage is an open framework for 
building developer portals.
        NOT-FOR-US: Backstage
 CVE-2026-106454 (Twisted is an event-based framework for internet 
applications, support ...)
        - twisted 26.4.0-5 (bug #1150248)
+       [trixie] - twisted <no-dsa> (Minor issue)
        NOTE: 
https://github.com/twisted/twisted/security/advisories/GHSA-8pqf-f4m5-798g
        NOTE: https://github.com/twisted/twisted/pull/12788
        NOTE: Fixed by: 
https://github.com/twisted/twisted/commit/2f8a3c29246f4eb324690e06a9767a11dc4aec9f
@@ -1342,34 +1347,36 @@ CVE-2026-105268 (The Gitea API routes for issue 
attachments (`/api/v1/repos/{own
 CVE-2026-105267 (The Gitea web route for deleting tags (`POST 
/{owner}/{repo}/tags/dele ...)
        NOT-FOR-US: Gitea (used to be packaged in the Debian archive as 
src:gitea, but never in a stable release)
 CVE-2026-105244 (Improper Encoding or Escaping of Output vulnerability in the 
RemoteSys ...)
-       - log4net <undetermined>
+       - log4net <not-affected> (Vulnerable code introduced later)
        NOTE: https://github.com/apache/logging-log4net/pull/315
        NOTE: Fixed by: 
https://github.com/apache/logging-log4net/commit/77717061b20d4346b6c0ce6b54643d85fb348bc7
 (rc/3.5.0-rc1)
        NOTE: https://lists.apache.org/thread/q7649hhdodthoqw8jsjgtnb4m8qfy6d6
-       TODO: check, might not affect our old version and upstream claims 
1.2.12 onwards
 CVE-2026-105243 (Insufficient Logging vulnerability in the EventLogAppender of 
Apache l ...)
        - log4net <unfixed> (bug #1150239)
+       [trixie] - log4net <no-dsa> (Minor issue)
        NOTE: https://github.com/apache/logging-log4net/pull/315
        NOTE: Fixed by: 
https://github.com/apache/logging-log4net/commit/28fbfb25678c48a8cc5bc9b94ead0dddfc39ffed
 (rc/3.5.0-rc1)
        NOTE: https://lists.apache.org/thread/jr6fj5skv1vnjbc9jmt8bp151p8ow1rp
 CVE-2026-105242 (Improper Handling of Exceptional Conditions vulnerability in 
the aspne ...)
-       - log4net <undetermined>
+       - log4net <not-affected> (Vulnerable code introduced later)
        NOTE: https://github.com/apache/logging-log4net/pull/316
        NOTE: Fixed by: 
https://github.com/apache/logging-log4net/commit/145203420c579a703008b4b723b6a080757f4964
 (rc/3.5.0-rc1)
        NOTE: https://lists.apache.org/thread/zg6dbqm4ztm7j3c21nfsqj0yxm5yrpdx
-       TODO: check, might not affect our old version, upstream claims 12.11 
onwards
 CVE-2026-105241 (Improper Handling of Unicode Encoding vulnerability in the 
SmtpPickupD ...)
        - log4net <unfixed> (bug #1150239)
+       [trixie] - log4net <no-dsa> (Minor issue)
        NOTE: https://github.com/apache/logging-log4net/pull/315
        NOTE: Fixed by: 
https://github.com/apache/logging-log4net/commit/4d2e10f0908199604b4326f9df6d0b43b871e333
 (rc/3.5.0-rc1)
        NOTE: https://lists.apache.org/thread/hg8dgh3oy8bp3dhb8nsygk9kw2o401ws
 CVE-2026-105240 (Improper Neutralization of Null Byte or NUL Character 
vulnerability in ...)
        - log4net <unfixed> (bug #1150239)
+       [trixie] - log4net <no-dsa> (Minor issue)
        NOTE: https://github.com/apache/logging-log4net/pull/315
        NOTE: Fixed by: 
https://github.com/apache/logging-log4net/commit/6046fe9d7f353b49fe995361c071ec2eea8f7ef6
 (rc/3.5.0-rc1)
        NOTE: https://lists.apache.org/thread/gyw2d4ppy82t1vlpdknkfd1nmzp21z17
 CVE-2026-105239 (Improper Neutralization of Null Byte or NUL Character 
vulnerability in ...)
        - log4net <unfixed> (bug #1150239)
+       [trixie] - log4net <no-dsa> (Minor issue)
        NOTE: https://github.com/apache/logging-log4net/pull/315
        NOTE: Fixed by: 
https://github.com/apache/logging-log4net/commit/dc5855a0720c91590fd7a81d729ea01fdd69e000
 (rc/3.5.0-rc1)
        NOTE: https://lists.apache.org/thread/9fx1qo5hc0tg8ym0t6p9gt1zpb2qlxpq
@@ -6983,6 +6990,7 @@ CVE-2026-102997 (pypdf is a free and open-source 
pure-python PDF library. Prior
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/d9d38cf99b115deb562d3b68f36c33027bc04f79 
(6.18.1)
 CVE-2026-102996 (pypdf is a free and open-source pure-python PDF library. 
Prior to 6.18 ...)
        - pypdf 6.19.0-1
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <not-affected> (Per-glyph /Widths map introduced in 
pypdf 4.0.0)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-g9cg-prrw-2r8q
@@ -6990,6 +6998,7 @@ CVE-2026-102996 (pypdf is a free and open-source 
pure-python PDF library. Prior
        NOTE: Fixed by: 
https://github.com/py-pdf/pypdf/commit/0fb26eb8cdd01c44b3b2c9fe8329751be2f7cfd5 
(6.18.1)
 CVE-2026-102995 (pypdf is a free and open-source pure-python PDF library. 
Prior to 6.18 ...)
        - pypdf 6.19.0-1
+       [trixie] - pypdf <no-dsa> (Minor issue)
        - pypdf2 <removed>
        [bookworm] - pypdf2 <postponed> (Minor issue, DoS)
        NOTE: 
https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3h-c4fm-7vvf
@@ -84554,12 +84563,14 @@ CVE-2026-70369 (Koha's reports/acquisitions_stats.pl 
builds its per-cell statist
 CVE-2026-70368 (A stack-based out-of-bounds read vulnerability exists in the 
"s_vlog"  ...)
        - stunnel 3:5.80-1
        - stunnel4 <removed>
+       [trixie] - stunnel4 <no-dsa> (Minor issue)
        [bookworm] - stunnel4 <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462029
        NOTE: https://www.stunnel.org/CVE-2026-70368.html
 CVE-2026-70367 (A Server-Side Request Forgery (SSRF) bypass vulnerability 
exists in \u ...)
        - stunnel 3:5.80-1
        - stunnel4 <removed>
+       [trixie] - stunnel4 <no-dsa> (Minor issue)
        [bookworm] - stunnel4 <postponed> (Minor issue)
        NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462083
        NOTE: https://www.stunnel.org/CVE-2026-70367.html



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5f56d9572ddbcbf983f994d60ff5a29b5809648

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5f56d9572ddbcbf983f994d60ff5a29b5809648
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to