[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 3 08:30:56 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
22062b2a by Salvatore Bonaccorso at 2026-08-03T09:26:02+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-9593 (A vulnerability in the iDTM FDI allows an attacker with elevated privi ...)
-	TODO: check
+	NOT-FOR-US: iDTM FDI
 CVE-2026-8763 (In Bouncy Castle for Java before 1.85, Name Constraints bypass via tra ...)
 	TODO: check
 CVE-2026-6695 (A flaw was found in GIMP. A remote attacker could exploit this by tric ...)
@@ -7,7 +7,7 @@ CVE-2026-6695 (A flaw was found in GIMP. A remote attacker could exploit this by
 CVE-2026-6694 (A flaw was found in GIMP's file-png plugin. A remote attacker can expl ...)
 	TODO: check
 CVE-2026-65875 (BaserCMS provided by baserCMS Users Community contains a CSV file inje ...)
-	TODO: check
+	NOT-FOR-US: BaserCMS
 CVE-2026-59652 (In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy ...)
 	TODO: check
 CVE-2026-59651 (In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy ver ...)
@@ -127,17 +127,17 @@ CVE-2026-18588 (A vulnerability has been found in Wavlink WL-NU516U1 708c073-mt7
 CVE-2026-18587 (A flaw has been found in Wavlink WL-NU516U1 708c073-mt7628. The impact ...)
 	NOT-FOR-US: Wavlink
 CVE-2026-18585 (A vulnerability was detected in GL.iNet MT3000, MT6000, BE9300, BE3600 ...)
-	TODO: check
+	NOT-FOR-US: GL.iNet
 CVE-2026-18584 (A security vulnerability has been detected in GL.iNet E5800, E750, X20 ...)
-	TODO: check
+	NOT-FOR-US: GL.iNet
 CVE-2026-18583 (A weakness has been identified in mz-automation libiec61850 up to 1.6. ...)
-	TODO: check
+	NOT-FOR-US: mz-automation libiec61850
 CVE-2026-18582 (A security flaw has been discovered in mz-automation libiec61850 up to ...)
-	TODO: check
+	NOT-FOR-US: mz-automation libiec61850
 CVE-2026-18581 (A vulnerability was determined in ggml-org llama.cpp e15efe0. Affected ...)
 	TODO: check
 CVE-2026-18577 (An incomplete patch for CVE-2026-18556 allows for authentication bypas ...)
-	TODO: check
+	NOT-FOR-US: N-central
 CVE-2026-16572 (The LogMyTrip WordPress plugin through 1.9 does not sanitize and escap ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16565 (The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution  Wo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22062b2ad5968b2b5283e83058821bdceba8da67

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22062b2ad5968b2b5283e83058821bdceba8da67
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/f5b9182e/attachment.htm>


More information about the debian-security-tracker-commits mailing list