[Git][security-tracker-team/security-tracker][master] automatic NOT-FOR-US entries update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 3 08:13:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0c37430c by security tracker role at 2026-08-03T07:13:16+00:00
automatic NOT-FOR-US entries update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -49,83 +49,83 @@ CVE-2026-58060 (In Bouncy Castle for Java before 1.85, HSS public-key level coun
 CVE-2026-58059 (In Bouncy Castle for Java before 1.85, Quadratic-time escaping when st ...)
 	TODO: check
 CVE-2026-4793 (An incorrect default permissions vulnerability in Synology Assistant b ...)
-	TODO: check
+	NOT-FOR-US: Synology
 CVE-2026-3245 (A deserialization vulnerability in PRISMAproduction Version 6.5 or ear ...)
-	TODO: check
+	NOT-FOR-US: Canon
 CVE-2026-20498 (In geniezone, there is a possible escalation of privilege due to a mis ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20497 (In geniezone, there is a possible out of bounds write due to a missing ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20496 (In geniezone, there is a possible out of bounds read due to a missing  ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20495 (In Bluetooth driver, there is a possible permission bypass due to a mi ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20494 (In wifi, there is a possible out of bounds read due to a missing bound ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20493 (In wifi, there is a possible out of bounds write due to a missing boun ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20492 (In Audio HAL, there is a possible system becoming unresponsive due to  ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20491 (In med, there is a possible out of bounds write due to an incorrect bo ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20490 (In ccci, there is a possible out of bounds read due to a missing bound ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20489 (In display, there is a possible information disclosure due to an integ ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20488 (In display, there is a possible information disclosure due to a missin ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20486 (In imgsensor, there is a possible application crash due to incorrect e ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20485 (In HFRP, there is a possible out of bounds write due to a missing boun ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20484 (In TFA, there is a possible information disclosure due to a missing pe ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20483 (In Telephony, there is a possible escalation of privilege due to a mis ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20482 (In wlan STA FW, there is a possible system becoming unresponsive due t ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20481 (In geniezone, there is a possible out of bounds write due to a missing ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20480 (In Audio HAL, there is a possible out of bounds write due to a heap bu ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20479 (In Modem, there is a possible out of bounds read due to a missing boun ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20478 (In Audio HAL, there is a possible out of bounds write due to a heap bu ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20477 (In display, there is a possible out of bounds write due to a missing b ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20476 (In ccci, there is a possible out of bounds read due to a missing bound ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20475 (In display, there is a possible out of bounds write due to a missing b ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20474 (In display, there is a possible escalation of privilege due to a race  ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20473 (In display, there is a possible memory corruption due to use after fre ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20472 (In TFA, there is a possible out of bounds write due to a missing bound ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20471 (In DA, there is a possible out of bounds write due to a missing bounds ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20470 (In Telephony, there is a possible information disclosure due to a miss ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20469 (In trusted_mem, there is a possible escalation of privilege due to imp ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20468 (In apusys, there is a possible escalation of privilege due to a confus ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20467 (In apusys, there is a possible escalation of privilege due to a missin ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20466 (In sec boot, there is a possible escalation of privilege due to a heap ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20465 (In wlan AP driver, there is a possible out of bounds write due to a mi ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-20464 (In hevc decoder, there is a possible out of bounds write due to an int ...)
-	TODO: check
+	NOT-FOR-US: MediaTek
 CVE-2026-18589 (A vulnerability was found in Wavlink WL-NU516U1 708c073-mt7628. This i ...)
-	TODO: check
+	NOT-FOR-US: Wavlink
 CVE-2026-18588 (A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7628. T ...)
-	TODO: check
+	NOT-FOR-US: Wavlink
 CVE-2026-18587 (A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impact ...)
-	TODO: check
+	NOT-FOR-US: Wavlink
 CVE-2026-18585 (A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600 ...)
 	TODO: check
 CVE-2026-18584 (A security vulnerability has been detected in GL.iNet E5800, E750, X20 ...)
@@ -139,63 +139,63 @@ CVE-2026-18581 (A vulnerability was determined in ggml-org llama.cpp e15efe0. Af
 CVE-2026-18577 (An incomplete patch for CVE-2026-18556 allows for authentication bypas ...)
 	TODO: check
 CVE-2026-16572 (The LogMyTrip WordPress plugin through 1.9 does not sanitize and escap ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16565 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16564 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16563 (The Academy LMS WordPress plugin before 3.8.3 does not verify course e ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16539 (The sm page duplicator WordPress plugin through 1.0.0 does not sanitis ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16534 (The Import and export users and customers WordPress plugin before 2.4. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16532 (The Link Library WordPress plugin before 7.9.3 does not properly sanit ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16300 (The ChamaWP  WordPress plugin before 1.0.13 does not properly validate ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16297 (The Clearfy Cache  WordPress plugin before 2.4.3 does not restrict the ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16289 (The ProfileGrid  WordPress plugin before 6.0.0.0 does not perform auth ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16276 (The Classified Listing  WordPress plugin before 5.4.4 does not perform ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16274 (The Classified Listing  WordPress plugin before 5.4.4 does not perform ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16250 (The Personal QR Message WordPress plugin through 1.0 does not restrict ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16060 (The Insert or Embed Articulate Content into WordPress plugin through 4 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-16057 (The Contest Gallery  WordPress plugin before 30.0.7 does not perform p ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15931 (The Simple Membership WordPress plugin before 4.7.8 does not sanitise  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15930 (The Simple Membership WordPress plugin before 4.7.8 does not verify wh ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15383 (The Blog Floating Button WordPress plugin through 1.4.20 does not sani ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15260 (The GEO my WP WordPress plugin before 4.5.5.3 does not perform any own ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15254 (The Simply Schedule Appointments WordPress plugin before 1.6.12.11 doe ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15231 (The Tag, Category, and Taxonomy Manager  WordPress plugin before 3.51. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-15055 (In Bouncy Castle for Java before 1.85, PKCS#8 / PBES2 decryptors honou ...)
 	TODO: check
 CVE-2026-14682 (In Bouncy Castle for Java before 1.85, Possible OOM from unbounded up- ...)
 	TODO: check
 CVE-2026-14557 (The SoftMarket \u2014 Digital Marketplace WordPress plugin through 1.0 ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-13586 (In Bouncy Castle for Java before 1.85, PKCS#12 MAC and bag-decryption  ...)
 	TODO: check
 CVE-2026-13506 (In Bouncy Castle for Java before 1.85, Lazy ASN.1 sequence forcing res ...)
 	TODO: check
 CVE-2026-13340 (The SVG Support WordPress plugin before 2.5.17 does not apply its SVG  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12965 (The Super Store Finder WordPress plugin through 7.8 does not sanitize  ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12872 (The Webinfos WordPress plugin through 1.2 does not validate the type o ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-12860 (In Bouncy Castle for Java before 1.85, RSA PKCS#1 verification skips l ...)
 	TODO: check
 CVE-2026-12852 (In Bouncy Castle for Java before 1.85, MLS wire decoder allocates atta ...)
@@ -211,9 +211,9 @@ CVE-2026-12802 (In Bouncy Castle for Java before 1.85, CMS AuthEnvelopedData fai
 CVE-2026-12185 (In Bouncy Castle for Java before 1.85, BKS/UBER keystore allocates fro ...)
 	TODO: check
 CVE-2025-15673 (The Import and export users and customers WordPress plugin before 2.4. ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2025-15672 (The ChamaWP  WordPress plugin before 1.0.13 does not properly validate ...)
-	TODO: check
+	NOT-FOR-US: WordPress plugin
 CVE-2026-9856 (A vulnerability in huggingface/transformers versions <=5.8.0.dev0 allo ...)
 	NOT-FOR-US: huggingface/transformers
 CVE-2026-68583 (luci-app-adblock-fast before 1.2.4-4 contains a stored cross-site scri ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c37430c597340db95e4680f0ea9c44d8f64a8d8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0c37430c597340db95e4680f0ea9c44d8f64a8d8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/ef66d6d4/attachment.htm>


More information about the debian-security-tracker-commits mailing list