[Git][security-tracker-team/security-tracker][master] 2 commits: auto-nfu: Add two more products covered by the Nvidia CNA rule

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Dec 10 08:42:20 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ee9c3184 by Salvatore Bonaccorso at 2025-12-10T09:41:23+01:00
auto-nfu: Add two more products covered by the Nvidia CNA rule

- - - - -
08a20c11 by Salvatore Bonaccorso at 2025-12-10T09:41:53+01:00
Process two more NFUs

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -885,9 +885,9 @@ CVE-2025-34397 (MailEnable versions prior to 10.54 contain a reflected cross-sit
 CVE-2025-34396 (MailEnable versions prior to 10.54 contain an unsafe DLL loading vulne ...)
 	NOT-FOR-US: MailEnable
 CVE-2025-33214 (NVIDIA NVTabular for Linux contains a vulnerability in the Workflow co ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2025-33213 (NVIDIA Merlin Transformers4Rec for Linux contains a vulnerability in t ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2025-2296 (EDK2 contains a vulnerability in BIOS where an attacker may cause \u20 ...)
 	- edk2 2025.02-1
 	NOTE: https://github.com/tianocore/edk2/security/advisories/GHSA-6pp6-cm5h-86g5


=====================================
data/packages/nfu.yaml
=====================================
@@ -440,6 +440,7 @@
       - product: Isaac Lab
       - product: Megatron LM
       - product: Megatron-LM
+      - product: Merlin Transformers4Rec
       - product: NVApp
       - product: NVDebug tool
       - product: NVIDIA Apex
@@ -450,6 +451,7 @@
       - product: NVIDIA NeMo Curator
       - product: NVIDIA NeMo Framework
       - product: NVIDIA WebDataset
+      - product: NVTabular
       - product: NeMo Agent ToolKit
       - product: NeMo Framework
       - product: Nsight Graphics



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ffa3ddb0d8f69d628c6c51f03589e6c312ec640d...08a20c118a2bd19270a10e9dba3fb6f4d12cb264

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ffa3ddb0d8f69d628c6c51f03589e6c312ec640d...08a20c118a2bd19270a10e9dba3fb6f4d12cb264
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251210/d7d0023e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list