[Git][security-tracker-team/security-tracker][master] Add Debian bug references for reported issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 4 19:08:36 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bb05ff4b by Salvatore Bonaccorso at 2026-08-04T20:07:52+02:00
Add Debian bug references for reported issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -17,7 +17,7 @@ CVE-2026-69248 (cryptography is a package designed to expose cryptographic primi
 	NOTE: https://github.com/pyca/cryptography/pull/14888
 	NOTE: Fixed by: https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2 (49.0.0)
 CVE-2026-69247 (cryptography is a package designed to expose cryptographic primitives  ...)
-	- python-cryptography <unfixed>
+	- python-cryptography <unfixed> (bug #1143596)
 	[trixie] - python-cryptography <not-affected> (Vulnerable code introduced later)
 	[bookworm] - python-cryptography <not-affected> (Vulnerable code introduced later)
 	[bullseye] - python-cryptography <not-affected> (Vulnerable code introduced later)
@@ -26,23 +26,23 @@ CVE-2026-69247 (cryptography is a package designed to expose cryptographic primi
 	NOTE: Fixed by: https://github.com/pyca/cryptography/commit/53fccd93413a8d7f07d6d8999681f27b75cffa3f (50.0.0)
 CVE-2026-69246 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Gu ...)
 	[experimental] - guzzle 8.0.1-1
-	- guzzle <unfixed>
+	- guzzle <unfixed> (bug #1143595)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-v5mv-p594-2x33
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4 (8.0.1)
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf (7.15.2)
 CVE-2026-69245 (Guzzle is an extensible PHP HTTP client. Prior to 7.15.2 and 8.0.1, Se ...)
 	[experimental] - guzzle 8.0.1-1
-	- guzzle <unfixed>
+	- guzzle <unfixed> (bug #1143595)
 	NOTE: https://github.com/guzzle/guzzle/security/advisories/GHSA-f7vp-7xgx-4w4r
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/3aeea0406aab88cbbd86531313d7cebf8ae149a4 (8.0.1)
 	NOTE: Fixed by: https://github.com/guzzle/guzzle/commit/744101956d78b7c1384d0cbf379db13e859167bf (7.15.2)
 CVE-2026-69244 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
-	- python-aiohttp <unfixed>
+	- python-aiohttp <unfixed> (bug #1143597)
 	NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-cq5v-8q36-5273
 	NOTE: https://github.com/aio-libs/aiohttp/pull/13223
 	NOTE: Fixed by: https://github.com/aio-libs/aiohttp/commit/49f65d54150397892f7bcc4aae887767d51c322d (v3.14.3)
 CVE-2026-69243 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
-	- python-aiohttp <unfixed>
+	- python-aiohttp <unfixed> (bug #1143597)
 	NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mfx4-hv73-q22v
 	NOTE: https://github.com/aio-libs/aiohttp/pull/13017
 	NOTE: Fixed by: https://github.com/aio-libs/aiohttp/commit/6ae358f0983c3f4d6f67692b2f8e65dc8e091c98 (v3.14.2)
@@ -62,7 +62,7 @@ CVE-2026-69192 (ip-address is a library for parsing and manipulating IPv4 and IP
 	NOTE: https://github.com/beaugunderson/ip-address/security/advisories/GHSA-mwp4-54f8-5fhr
 	NOTE: Fixed by: https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e (v10.3.1)
 CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication for ever ...)
-	- node-socket.io-parser <unfixed>
+	- node-socket.io-parser <unfixed> (bug #1143598)
 	NOTE: https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
 	NOTE: Fixed by: https://github.com/socketio/socket.io/commit/7c6ef571a00656718e9e05e3b948fd1758b2a7b4 (socket.io-parser at 4.2.7)
 	NOTE: Fixed by: https://github.com/socketio/socket.io/commit/ced94ffa3ac020a8f3c14eb98a3bf34acb14d291 (socket.io-parser at 3.4.5)
@@ -74,7 +74,7 @@ CVE-2026-68980 (Apache NiFi 2.0.0 through 2.10.0 support creating, reading, and
 CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context update R ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function  ...)
-	- sssd <unfixed>
+	- sssd <unfixed> (bug #1143600)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509761
 CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers  ...)
 	NOT-FOR-US: NASA cFS
@@ -350,7 +350,7 @@ CVE-2026-69151 (Angular is a development platform for building mobile and deskto
 CVE-2026-69149 (Angular is a development platform for building mobile and desktop web  ...)
 	- angular.js <unfixed>
 CVE-2026-69097 (GitPython before 3.1.53 fails to properly escape section names in git  ...)
-	- python-git <unfixed>
+	- python-git <unfixed> (bug #1143602)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2
 CVE-2026-69096 (OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots co ...)
 	NOT-FOR-US: OpenWrt luci-app-dockerman
@@ -391,13 +391,13 @@ CVE-2026-69075 (FlowIntel is affected by a stored cross-site scripting vulnerabi
 CVE-2026-68945 (Angular is a development platform for building mobile and desktop web  ...)
 	- angular.js <unfixed>
 CVE-2026-68930 (Russh is a Rust SSH client & server library. Prior to 0.62.5, russh di ...)
-	- rust-russh <unfixed>
+	- rust-russh <unfixed> (bug #1143601)
 	NOTE: https://github.com/Eugeny/russh/security/advisories/GHSA-m65r-rprj-r5rg
 	NOTE: Fixed by: https://github.com/Eugeny/russh/commit/7c5659f8cf6f6f2f9989d12dba0ebf49dc50a171 (v0.62.5)
 CVE-2026-68869
 	REJECTED
 CVE-2026-68742 (A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function i ...)
-	- sssd <unfixed>
+	- sssd <unfixed> (bug #1143600)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509762
 	TODO: check upstream status
 CVE-2026-68587 (SiYuan versions before v3.7.3 contain an information disclosure vulner ...)
@@ -431,7 +431,7 @@ CVE-2026-61524 (WebsiteBaker CMS before 2.13.10 contains an unrestricted file up
 CVE-2026-61523 (WebsiteBaker CMS before 2.13.10 contains a code injection vulnerabilit ...)
 	NOT-FOR-US: WebsiteBaker CMS
 CVE-2026-61372 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
-	- apache-jena <unfixed>
+	- apache-jena <unfixed> (bug #1143599)
 	NOTE: https://lists.apache.org/thread/h206tpxtbzts7m254og6ffqljjdjkm84
 CVE-2026-60011 (Sharp and Toshiba Tec MFPs (multifunction printers) fail to properly a ...)
 	NOT-FOR-US: Sharp and Toshiba Tec MFPs
@@ -484,7 +484,7 @@ CVE-2026-21548 (In nr modem, there is a possible improper input validation. This
 CVE-2026-18718 (Ghidra contains an arbitrary code execution vulnerability in the Swift ...)
 	- ghidra <itp> (bug #923851)
 CVE-2026-18651 (A flaw was found in 389 Directory Server. During SASL PLAIN authentica ...)
-	- 389-ds-base <unfixed>
+	- 389-ds-base <unfixed> (bug #1143603)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2510617
 CVE-2026-18642 (Deserialization of untrusted data vulnerability in TUBITAK BILGEM Soft ...)
 	NOT-FOR-US: eta-otp-lock



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb05ff4bde2fed78036e44db1680894fad55a408

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb05ff4bde2fed78036e44db1680894fad55a408
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260804/1e570c84/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list