[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Aug 8 16:23:59 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d9332741 by Moritz Muehlenhoff at 2026-08-08T17:23:46+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -476,6 +476,7 @@ CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting vulnerabili
 	NOT-FOR-US: CTI-Transmute
 CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
 	- node-re2 1.26.1+~cs1.7.0-1 (bug #1143901)
+	[trixie] - node-re2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-j4r3-hg7j-8chg
 	NOTE: https://github.com/uhop/node-re2/issues/272
 	NOTE: Fixed by: https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4 (1.26.1)
@@ -524,6 +525,7 @@ CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite Checkpoint are the Post
 	NOT-FOR-US: LangGraph Checkpoint
 CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
 	- node-re2 1.26.1+~cs1.7.0-1 (bug #1143901)
+	[trixie] - node-re2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-8hcv-x26h-mcgp
 CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
 	- traefik <itp> (bug #983289)
@@ -3077,12 +3079,15 @@ CVE-2026-48121 (@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js
 	NOT-FOR-US: langchain/langgraph-checkpoint-mongodb
 CVE-2026-47781 (PDM is a Python package and dependency manager. In versions up to and  ...)
 	- pdm 2.27.0-1
+	[trixie] - pdm <no-dsa> (Minor issue)
 	NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf
 CVE-2026-47764 (pdm is a Python package and dependency manager supporting the latest P ...)
 	- pdm 2.27.0-1
+	[trixie] - pdm <no-dsa> (Minor issue)
 	NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-78v8-vpjp-cjqh
 CVE-2026-47763 (pdm is a Python package and dependency manager supporting the latest P ...)
 	- pdm 2.27.0-1
+	[trixie] - pdm <no-dsa> (Minor issue)
 	NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-ghq2-5c67-fprm
 CVE-2026-47623 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker cou ...)
 	NOT-FOR-US: NVIDIA
@@ -3315,6 +3320,7 @@ CVE-2026-69192 (ip-address is a library for parsing and manipulating IPv4 and IP
 	NOTE: Fixed by: https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e (v10.3.1)
 CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication for ever ...)
 	- node-socket.io-parser <unfixed> (bug #1143598)
+	[trixie] - node-socket.io-parser <no-dsa> (Minor issue)
 	[bookworm] - node-socket.io-parser <postponed> (minor issue; DoS)
 	[bullseye] - node-socket.io-parser <postponed> (minor issue; DoS)
 	NOTE: https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
@@ -3596,6 +3602,7 @@ CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive authenticatio
 	NOT-FOR-US: PaperCut
 CVE-2026-69153 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
 	- node-postcss 8.5.23+~cs10.2.23-1
+	[trixie] - node-postcss <no-dsa> (Minor issue)
 	NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
 	NOTE: Fixed by: https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8 (8.5.23)
 CVE-2026-69152 (The brace-expansion library generates arbitrary strings containing a c ...)
@@ -3612,6 +3619,7 @@ CVE-2026-69149 (Angular is a development platform for building mobile and deskto
 	- angular.js <unfixed>
 CVE-2026-69097 (GitPython before 3.1.53 fails to properly escape section names in git  ...)
 	- python-git <unfixed> (bug #1143602)
+	[trixie] - python-git <no-dsa> (Minor issue)
 	NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2
 CVE-2026-69096 (OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots co ...)
 	NOT-FOR-US: OpenWrt luci-app-dockerman
@@ -4932,6 +4940,7 @@ CVE-2026-18358 (A flaw was found in gnome-remote-desktop as shipped in Red Hat E
 	TODO: does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug
 CVE-2026-18321 (Buffer overflow in NTPsec's Zyfer refclock allows local attacker to cr ...)
 	- ntpsec <unfixed>
+	[trixie] - ntpsec <no-dsa> (Minor issue)
 	[bookworm] - ntpsec <postponed> (minor issue; DoS)
 	[bullseye] - ntpsec <postponed> (minor issue; DoS)
 	NOTE: https://gitlab.com/NTPsec/ntpsec/-/work_items/890
@@ -8631,6 +8640,7 @@ CVE-2026-16462 (In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly s
 	NOT-FOR-US: PROCON-WEB SCADA
 CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...)
 	- sg3-utils <unfixed> (bug #1143004)
+	[trixie] - sg3-utils <no-dsa> (Minor issue)
 	[bookworm] - sg3-utils <postponed> (Minor issue)
 	[bullseye] - sg3-utils <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502845
@@ -20636,6 +20646,7 @@ CVE-2026-9585 (An unauthenticated reflected cross-site scripting (XSS) vulnerabi
 	NOT-FOR-US: Sangoma Switchvox SMB Edition
 CVE-2026-9537 (Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a  ...)
 	- libmojo-jwt-perl 1.02-1
+	[trixie] - libmojo-jwt-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41907805/
 	NOTE: Fixed by: https://github.com/jberger/Mojo-JWT/commit/b8aefb846613e44b5b12bc170898ffd5b05094a2 (1.02)
 CVE-2026-9202 (IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers ...)
@@ -26171,6 +26182,7 @@ CVE-2026-15104 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wi
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15028 (A flaw was found in libarchive. This vulnerability allows a remote att ...)
 	- libarchive 3.8.9-1 (bug #1142833)
+	[trixie] - libarchive <no-dsa> (Minor issue)
 	NOTE: https://github.com/libarchive/libarchive/issues/3251
 	NOTE: https://github.com/libarchive/libarchive/pull/3253
 	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/f93abd161ec37326c566f4f0efcd44fe7a66dd95
@@ -27065,6 +27077,7 @@ CVE-2026-55470 (HAPI FHIR is a complete implementation of the HL7 FHIR standard
 	NOT-FOR-US: HAPI FHIR
 CVE-2026-55404 (yt-dlp and youtube-dl are command-line audio/video downloaders. Prior  ...)
 	- yt-dlp 2026.07.04-1
+	[trixie] - yt-dlp <no-dsa> (Minor issue)
 	NOTE: https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32
 	NOTE: Fixed by: https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789 (2026.07.04)
 CVE-2026-55206 (py7zr is a Python-based library and utility to support 7zip archive co ...)
@@ -27818,14 +27831,17 @@ CVE-2026-3144 (IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credential
 	NOT-FOR-US: IBM
 CVE-2026-29009 (U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in  ...)
 	- u-boot <unfixed> (bug #1142070)
+	[trixie] - u-boot <no-dsa> (Minor issue)
 	NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
 	NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
 CVE-2026-29008 (U-Boot through 2026.04-rc3 contains an integer underflow vulnerability ...)
 	- u-boot <unfixed> (bug #1142070)
+	[trixie] - u-boot <no-dsa> (Minor issue)
 	NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
 	NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
 CVE-2026-29007 (U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerabilit ...)
 	- u-boot <unfixed> (bug #1142070)
+	[trixie] - u-boot <no-dsa> (Minor issue)
 	NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
 	NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
 CVE-2026-24700 (An OS command injection vulnerability exists in the start_lltd() funct ...)
@@ -63109,13 +63125,14 @@ CVE-2026-39531 (Improper Neutralization of Special Elements used in an SQL Comma
 CVE-2026-39461 (libcasper(3) communicates with helper processes via UNIX domain socket ...)
 	NOT-FOR-US: FreeBSD
 CVE-2026-36189 (Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrust ...)
-	- uncrustify <unfixed> (bug #1142851)
+	- uncrustify <unfixed> (bug #1142851; unimportant)
 	NOTE: https://github.com/uncrustify/uncrustify/issues/4636
 	NOTE: https://github.com/uncrustify/uncrustify/pull/4641
 	NOTE: https://github.com/uncrustify/uncrustify/pull/4650
 	NOTE: tokenizer related code moved to subfolder in:
 	NOTE: https://github.com/uncrustify/uncrustify/commit/35f4eb550fd0cb419d0d48575c51b1d19def18fa (uncrustify-0.79.0)
 	NOTE: Fixed by: https://github.com/uncrustify/uncrustify/commit/04e7614fd25d283508d6d68d85006d9b420c0f1a (uncrustify-0.83.0)
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-34930 (An origin validation vulnerability in the Apex One/SEP agent could all ...)
 	NOT-FOR-US: Trend Micro
 CVE-2026-34929 (An origin validation vulnerability in the Apex One/SEP agent could all ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -85,9 +85,9 @@ node-dompurify
 --
 openexr
 --
-openjdk-17
+openjdk-21 (jmm)
 --
-openjdk-21
+openjdk-25 (jmm)
 --
 pacemaker
 --
@@ -135,12 +135,16 @@ rust-wasmtime
 --
 shaarli
 --
+srt
+--
 starlette
 --
 tomcat10
 --
 tomcat11
 --
+unbound
+--
 util-linux (carnil)
   Maintainer is preparing updates
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9332741d0696bebfc1256dbdf55f5f26289bbee

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9332741d0696bebfc1256dbdf55f5f26289bbee
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/2d7f2910/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list