Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8115c3cb by Moritz Muehlenhoff at 2026-10-10T00:30:25+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1342,11 +1342,13 @@ CVE-2026-106596 (Missing Authorization vulnerability in 
Visual Composer Visual C
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-106438 (An incorrect calculation in Decimal128 string parsing in the 
MongoDB C ...)
        - mongo-c-driver 2.5.6-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6419
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/54a7e9f372bd8e1953298b60393b07b042360a87
 (2.5.6)
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/12930599bad296e8a42042677478279fd9e903f7
 (1.30.13)
 CVE-2026-106437 (The BSON buffer-reservation API in the MongoDB C Driver can 
record a l ...)
        - mongo-c-driver 2.5.6-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6423
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/6c593a59a9dce87e42298b85779ca02a9357dd74
 (2.5.6)
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/b7f1f5742351741c068020196fd88f196551aad2
 (1.30.13)
@@ -1375,6 +1377,7 @@ CVE-2026-106432 (The BSON encoder in the MongoDB PHP 
Driver converts a string le
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-php-driver/commit/79036dd7a4c946cfef2d0105f8102f26d685b260
 (2.5.4, 2.1.11, 1.21.11)
 CVE-2026-106431 (An off-by-one error in the BSON bulk document writer in the 
MongoDB C  ...)
        - mongo-c-driver 2.5.6-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6418
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/bddaffdabdb449d8ee5e8b28f9a82afd03cd42aa
 (2.5.6)
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/70d96b8f28974e02cc966a00953dc3d8c308b8ff
 (1.30.13)
@@ -1392,6 +1395,7 @@ CVE-2026-106429 (An integer underflow in the KMS 
endpoint-parsing logic of Mongo
        NOTE: Fixed by: 
https://github.com/mongodb/libmongocrypt/commit/03d09f07bb32f9387aec823444cd7bb6d41cddad
 (1.20.5)
 CVE-2026-106428 (An out-of-bounds read in SCRAM authentication response 
parsing in the  ...)
        - mongo-c-driver 2.4.0-1
+       [trixie] - mongo-c-driver <no-dsa> (Minor issue)
        NOTE: https://jira.mongodb.org/browse/CDRIVER-6370
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/9655909e15c83149c0fc68e53f38e696bbd23569
 (2.4.0)
        NOTE: Fixed by: 
https://github.com/mongodb/mongo-c-driver/commit/57054353fdf79383341de21540a2adab196eb6a4
 (1.30.13)
@@ -1568,6 +1572,7 @@ CVE-2026-97032 (HTTP/2 servers could end up crashing due 
to inadvertently modify
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-golang-x-net 1:0.60.0-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
@@ -1580,6 +1585,7 @@ CVE-2026-78659 (When "Trailer" headers are sent by a 
client, the HTTP server int
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-golang-x-net 1:0.60.0-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
@@ -1592,6 +1598,7 @@ CVE-2026-97031 (Multiple ECH outer extension references 
are not permitted under
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81855
@@ -1602,6 +1609,7 @@ CVE-2026-94444 (Previously, a user operating inside of a 
malicious Go project th
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81833
@@ -1612,6 +1620,7 @@ CVE-2026-94447 (Previously, a user operating inside of a 
malicious Go project th
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81834
@@ -1622,6 +1631,7 @@ CVE-2026-94448 (When a JavaScript template literal 
contains consecutive expressi
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81821
@@ -1632,6 +1642,7 @@ CVE-2026-97030 (A trusted template author may have 
previously written a valid te
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81823
@@ -1642,6 +1653,7 @@ CVE-2026-94440 (Parsing a multipart form can bypass 
memory limits and read an ar
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81741
@@ -1652,6 +1664,7 @@ CVE-2026-56866 (When http.Transport sends an HTTP/1 
CONNECT request with a non-e
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81740
@@ -1662,6 +1675,7 @@ CVE-2026-94439 (When an HTTP server handler sends a 2xx 
response to an HTTP/1 CO
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81744
@@ -1672,6 +1686,7 @@ CVE-2026-78669 (A malicious HTTP/2 peer can cause 
excessive CPU consumption in t
        - golang-1.26 <unfixed>
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-golang-x-net 1:0.60.0-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
@@ -1684,6 +1699,7 @@ CVE-2026-78660 (Historically, we have been rather lax 
about malformed framing-re
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-golang-x-net 1:0.60.0-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
@@ -1703,6 +1719,7 @@ CVE-2026-78667 (When parsing a Range header containing a 
large number of small r
        - golang-1.26 1.26.9-1
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9
        NOTE: https://github.com/golang/go/issues/81858
@@ -1713,6 +1730,7 @@ CVE-2026-78663 (The HTTP/2 server can refund 
connection-level flow control twice
        - golang-1.26 <unfixed>
        - golang-1.25 <removed>
        - golang-1.24 <removed>
+       [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
        - golang-golang-x-net 1:0.60.0-1
        NOTE: https://www.openwall.com/lists/oss-security/2026/10/08/9


=====================================
data/dsa-needed.txt
=====================================
@@ -199,6 +199,8 @@ vips
 weechat
   Upstream recommends to use branch from 
https://github.com/weechat/weechat/commits/4.6/, cf #1142597
 --
+wordpress
+--
 xorg-server (carnil)
 --
 zlib (carnil)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8115c3cbfce736a791981092cbc56fe2e8a88ee4

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8115c3cbfce736a791981092cbc56fe2e8a88ee4
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to