Moritz Muehlenhoff pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
bd36d426 by Moritz Muehlenhoff at 2026-10-09T15:14:38+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -516,39 +516,48 @@ CVE-2026-107698 (FFmpeg before 7.1.4 and 8.0.x before
8.0.2 contains a server-si
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b05562b9b399057b6537fae337d0eeabcff6ef5c
(n5.1.9)
CVE-2026-107697 (FFmpeg before 8.1.3 contains a protection mechanism failure
in the HLS ...)
- ffmpeg 7:9.0.2-1
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream
branch)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/23602df9cd1b485c45ba6f533d3b85569de3f323
(master)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/01044d04536eec6e2f5f48ef404cf45d15feb461
(n9.0)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/191715f0232cee64402c3e7733f28ff4061224b6
(n8.1.3)
CVE-2026-107696 (FFmpeg through 9.0.2 contains an infinite loop vulnerability
in ff_rts ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream
branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24902
CVE-2026-107695 (FFmpeg before 8.1.3 contains an infinite loop vulnerability
in the HLS ...)
- ffmpeg 7:9.0.2-1
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream
branch)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c364ab176f722bdabc886845e770c9eacbc1e3e5
(master)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/0e6eef35517af086419c5157980e926a81070c2a
(n9.0)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a4ddaba8bb7811b1a3afaad59fe6555e720d4754
(n8.1.3)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23618
CVE-2026-107678 (FFmpeg through 9.0.2 contains a stack exhaustion
vulnerability in av_e ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream
branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24593
CVE-2026-107677 (FFmpeg through 9.0.2 contains a denial of service
vulnerability in the ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream
branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24592
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/ed27bfcbbbc0872c0195eaf4dd2c0c93b9f1778e
(master)
CVE-2026-107676 (FFmpeg through 9.0.2 contains an uninitialized memory
disclosure vulne ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream
branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24590
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2c2f6e96e31795ae95a8f8323a493ffbc493111f
(master)
CVE-2026-107675 (FFmpeg through 9.0.2 contains a missing host key verification
vulnerab ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <ignored> (Minor issue and breaking change, won't be
backported to release branches)
+ [bookworm] - ffmpeg <ignored> (Minor issue and breaking change, won't
be backported to release branches)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24384
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/2b822b7fb6ed195546bc9fd9bdb794e98222bdce
(master)
CVE-2026-107660 (FFmpeg before 8.1.3 and 9.x before 9.0.2 contains an improper
certific ...)
- - ffmpeg 7:9.0.2-1
+ - ffmpeg 7:9.0.2-1 (unimportant)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24383
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/57a2e704b4a6eda5d061b45aacde6b19c026bfc0
(master)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d377212904a19fc740d721cbda0ba58fa3805a29
(n9.0.2)
NOTE: Fixed by:
https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/0cd2a70eacd510c2efed48b9fc177c7cb2bc549f
(n8.1.3)
+ NOTE: mbedtls not enabled in Debian builds
CVE-2026-107651 (A flaw was found in Eye of GNOME (eog). A heap-based buffer
overflow e ...)
- eog <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2547986
@@ -2000,9 +2009,11 @@ CVE-2025-64391 (This vulnerability in Veeam Agent for
Microsoft Windows allows a
NOT-FOR-US: Veeam
CVE-2026-92415 (\u2014 Use of Externally-Controlled Input to Select Classes or
Code vu ...)
- jackrabbit <unfixed> (bug #1150343)
+ [trixie] - jackrabbit <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/07/28
CVE-2026-92414 (: Session Fixation / Session Reuse across Users vulnerability
in Apach ...)
- jackrabbit <unfixed> (bug #1150343)
+ [trixie] - jackrabbit <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/10/07/27
CVE-2026-98374 (In the Linux kernel, the following vulnerability has been
resolved: t ...)
- linux 7.2.9-1
@@ -21123,7 +21134,8 @@ CVE-2026-95619 (A flaw was found in libstdc++. An
integer overflow can occur whe
[trixie] - gcc-14 <no-dsa> (Minor issue)
- gcc-12 <unfixed>
[trixie] - gcc-12 <no-dsa> (Minor issue)
- NOTE:
https://github.com/gcc-mirror/gcc/commit/59d235ffa5a69231eb42e5290d52dc8c90d28b7a
+ NOTE:
https://github.com/gcc-mirror/gcc/commit/59d235ffa5a69231eb42e5290d52dc8c90d28b7a
(master)
+ NOTE:
https://github.com/gcc-mirror/gcc/commit/200183d4ab5d57575f3dfebc6af3baf649910b9e
(releases/gcc-14)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537811
CVE-2026-95511
REJECTED
=====================================
data/dsa-needed.txt
=====================================
@@ -100,7 +100,9 @@ modsecurity
--
modsecurity-apache
--
-nagios4
+mutt (jmm)
+--
+nagios4 (jmm)
Maintainer provided an update for review in
<[email protected]>
--
nats-server
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd36d42621b5fad95773b4561704b2b23257167c
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bd36d42621b5fad95773b4561704b2b23257167c
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits