[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Aug 8 16:23:59 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d9332741 by Moritz Muehlenhoff at 2026-08-08T17:23:46+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -476,6 +476,7 @@ CVE-2026-71502 (CTI-Transmute contains a stored cross-site scripting vulnerabili
NOT-FOR-US: CTI-Transmute
CVE-2026-71498 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
- node-re2 1.26.1+~cs1.7.0-1 (bug #1143901)
+ [trixie] - node-re2 <no-dsa> (Minor issue)
NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-j4r3-hg7j-8chg
NOTE: https://github.com/uhop/node-re2/issues/272
NOTE: Fixed by: https://github.com/uhop/node-re2/commit/9d72042a6a0da5bc523908b04808ea0e23867cc4 (1.26.1)
@@ -524,6 +525,7 @@ CVE-2026-71433 (LangGraph Checkpoint Postgres and SQLite Checkpoint are the Post
NOT-FOR-US: LangGraph Checkpoint
CVE-2026-71430 (node-re2 provides RE2 regular expression bindings for Node.js. Prior t ...)
- node-re2 1.26.1+~cs1.7.0-1 (bug #1143901)
+ [trixie] - node-re2 <no-dsa> (Minor issue)
NOTE: https://github.com/uhop/node-re2/security/advisories/GHSA-8hcv-x26h-mcgp
CVE-2026-71327 (Traefik is an open source HTTP reverse proxy and load balancer. From 3 ...)
- traefik <itp> (bug #983289)
@@ -3077,12 +3079,15 @@ CVE-2026-48121 (@langchain/langgraph-checkpoint-mongodb provides a LangGraph.js
NOT-FOR-US: langchain/langgraph-checkpoint-mongodb
CVE-2026-47781 (PDM is a Python package and dependency manager. In versions up to and ...)
- pdm 2.27.0-1
+ [trixie] - pdm <no-dsa> (Minor issue)
NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-qq6c-99pv-prvf
CVE-2026-47764 (pdm is a Python package and dependency manager supporting the latest P ...)
- pdm 2.27.0-1
+ [trixie] - pdm <no-dsa> (Minor issue)
NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-78v8-vpjp-cjqh
CVE-2026-47763 (pdm is a Python package and dependency manager supporting the latest P ...)
- pdm 2.27.0-1
+ [trixie] - pdm <no-dsa> (Minor issue)
NOTE: https://github.com/pdm-project/pdm/security/advisories/GHSA-ghq2-5c67-fprm
CVE-2026-47623 (NVIDIA Dynamo for Linux contains a vulnerability where an attacker cou ...)
NOT-FOR-US: NVIDIA
@@ -3315,6 +3320,7 @@ CVE-2026-69192 (ip-address is a library for parsing and manipulating IPv4 and IP
NOTE: Fixed by: https://github.com/beaugunderson/ip-address/commit/56368cb3d66c73ba0ee9b6b834fd31b22c2fd71e (v10.3.1)
CVE-2026-69185 (Socket.IO enables bidirectional and low-latency communication for ever ...)
- node-socket.io-parser <unfixed> (bug #1143598)
+ [trixie] - node-socket.io-parser <no-dsa> (Minor issue)
[bookworm] - node-socket.io-parser <postponed> (minor issue; DoS)
[bullseye] - node-socket.io-parser <postponed> (minor issue; DoS)
NOTE: https://github.com/socketio/socket.io/security/advisories/GHSA-2m8v-j782-fhvr
@@ -3596,6 +3602,7 @@ CVE-2026-8793 (PaperCut NG/MF does not properly restrict excessive authenticatio
NOT-FOR-US: PaperCut
CVE-2026-69153 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
- node-postcss 8.5.23+~cs10.2.23-1
+ [trixie] - node-postcss <no-dsa> (Minor issue)
NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-fxqj-rqcc-2cmp
NOTE: Fixed by: https://github.com/postcss/postcss/commit/7beca139e70f9075c6b19700fcb00dd8033e5da8 (8.5.23)
CVE-2026-69152 (The brace-expansion library generates arbitrary strings containing a c ...)
@@ -3612,6 +3619,7 @@ CVE-2026-69149 (Angular is a development platform for building mobile and deskto
- angular.js <unfixed>
CVE-2026-69097 (GitPython before 3.1.53 fails to properly escape section names in git ...)
- python-git <unfixed> (bug #1143602)
+ [trixie] - python-git <no-dsa> (Minor issue)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-3rp5-jjmw-4wv2
CVE-2026-69096 (OpenWrt luci-app-dockerman (LuCI master and openwrt-25.12 snapshots co ...)
NOT-FOR-US: OpenWrt luci-app-dockerman
@@ -4932,6 +4940,7 @@ CVE-2026-18358 (A flaw was found in gnome-remote-desktop as shipped in Red Hat E
TODO: does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug
CVE-2026-18321 (Buffer overflow in NTPsec's Zyfer refclock allows local attacker to cr ...)
- ntpsec <unfixed>
+ [trixie] - ntpsec <no-dsa> (Minor issue)
[bookworm] - ntpsec <postponed> (minor issue; DoS)
[bullseye] - ntpsec <postponed> (minor issue; DoS)
NOTE: https://gitlab.com/NTPsec/ntpsec/-/work_items/890
@@ -8631,6 +8640,7 @@ CVE-2026-16462 (In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly s
NOT-FOR-US: PROCON-WEB SCADA
CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...)
- sg3-utils <unfixed> (bug #1143004)
+ [trixie] - sg3-utils <no-dsa> (Minor issue)
[bookworm] - sg3-utils <postponed> (Minor issue)
[bullseye] - sg3-utils <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502845
@@ -20636,6 +20646,7 @@ CVE-2026-9585 (An unauthenticated reflected cross-site scripting (XSS) vulnerabi
NOT-FOR-US: Sangoma Switchvox SMB Edition
CVE-2026-9537 (Mojo::JWT versions before 1.02 for Perl verify HMAC signatures with a ...)
- libmojo-jwt-perl 1.02-1
+ [trixie] - libmojo-jwt-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41907805/
NOTE: Fixed by: https://github.com/jberger/Mojo-JWT/commit/b8aefb846613e44b5b12bc170898ffd5b05094a2 (1.02)
CVE-2026-9202 (IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers ...)
@@ -26171,6 +26182,7 @@ CVE-2026-15104 (The BetterDocs \u2013 AI Documentation, Knowledge Base, Docs, Wi
NOT-FOR-US: WordPress plugin
CVE-2026-15028 (A flaw was found in libarchive. This vulnerability allows a remote att ...)
- libarchive 3.8.9-1 (bug #1142833)
+ [trixie] - libarchive <no-dsa> (Minor issue)
NOTE: https://github.com/libarchive/libarchive/issues/3251
NOTE: https://github.com/libarchive/libarchive/pull/3253
NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/f93abd161ec37326c566f4f0efcd44fe7a66dd95
@@ -27065,6 +27077,7 @@ CVE-2026-55470 (HAPI FHIR is a complete implementation of the HL7 FHIR standard
NOT-FOR-US: HAPI FHIR
CVE-2026-55404 (yt-dlp and youtube-dl are command-line audio/video downloaders. Prior ...)
- yt-dlp 2026.07.04-1
+ [trixie] - yt-dlp <no-dsa> (Minor issue)
NOTE: https://github.com/yt-dlp/yt-dlp/security/advisories/GHSA-6v4j-43gg-vj32
NOTE: Fixed by: https://github.com/yt-dlp/yt-dlp/commit/b6590aaa1e3808155d69c9a79a797ae484163789 (2026.07.04)
CVE-2026-55206 (py7zr is a Python-based library and utility to support 7zip archive co ...)
@@ -27818,14 +27831,17 @@ CVE-2026-3144 (IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credential
NOT-FOR-US: IBM
CVE-2026-29009 (U-Boot before 2026.07-rc2 contains a buffer overflow vulnerability in ...)
- u-boot <unfixed> (bug #1142070)
+ [trixie] - u-boot <no-dsa> (Minor issue)
NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
CVE-2026-29008 (U-Boot through 2026.04-rc3 contains an integer underflow vulnerability ...)
- u-boot <unfixed> (bug #1142070)
+ [trixie] - u-boot <no-dsa> (Minor issue)
NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
CVE-2026-29007 (U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerabilit ...)
- u-boot <unfixed> (bug #1142070)
+ [trixie] - u-boot <no-dsa> (Minor issue)
NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
CVE-2026-24700 (An OS command injection vulnerability exists in the start_lltd() funct ...)
@@ -63109,13 +63125,14 @@ CVE-2026-39531 (Improper Neutralization of Special Elements used in an SQL Comma
CVE-2026-39461 (libcasper(3) communicates with helper processes via UNIX domain socket ...)
NOT-FOR-US: FreeBSD
CVE-2026-36189 (Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrust ...)
- - uncrustify <unfixed> (bug #1142851)
+ - uncrustify <unfixed> (bug #1142851; unimportant)
NOTE: https://github.com/uncrustify/uncrustify/issues/4636
NOTE: https://github.com/uncrustify/uncrustify/pull/4641
NOTE: https://github.com/uncrustify/uncrustify/pull/4650
NOTE: tokenizer related code moved to subfolder in:
NOTE: https://github.com/uncrustify/uncrustify/commit/35f4eb550fd0cb419d0d48575c51b1d19def18fa (uncrustify-0.79.0)
NOTE: Fixed by: https://github.com/uncrustify/uncrustify/commit/04e7614fd25d283508d6d68d85006d9b420c0f1a (uncrustify-0.83.0)
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-34930 (An origin validation vulnerability in the Apex One/SEP agent could all ...)
NOT-FOR-US: Trend Micro
CVE-2026-34929 (An origin validation vulnerability in the Apex One/SEP agent could all ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -85,9 +85,9 @@ node-dompurify
--
openexr
--
-openjdk-17
+openjdk-21 (jmm)
--
-openjdk-21
+openjdk-25 (jmm)
--
pacemaker
--
@@ -135,12 +135,16 @@ rust-wasmtime
--
shaarli
--
+srt
+--
starlette
--
tomcat10
--
tomcat11
--
+unbound
+--
util-linux (carnil)
Maintainer is preparing updates
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9332741d0696bebfc1256dbdf55f5f26289bbee
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9332741d0696bebfc1256dbdf55f5f26289bbee
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/2d7f2910/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list