[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 8 20:14:04 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
825c809d by security tracker role at 2026-08-08T19:13:57+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,55 @@
+CVE-2026-71958 (D-Link DWR-M961 devices with hardware version C1 and software version ...)
+ TODO: check
+CVE-2026-71957 (D-Link DWR-M961 devices with hardware version C1 and software version ...)
+ TODO: check
+CVE-2026-71956 (D-Link DWR-M961 devices with hardware version C1 and software version ...)
+ TODO: check
+CVE-2026-71955 (D-Link DWR-M961 devices with hardware version C1 and software version ...)
+ TODO: check
+CVE-2026-71954 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71953 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71952 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71951 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71950 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71949 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71948 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71947 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71946 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71945 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-71944 (D-Link DWR-M961 devices with hardware version C1 and firmware version ...)
+ TODO: check
+CVE-2026-67620 (Flowise through 3.1.4 contains a server-side request forgery vulnerabi ...)
+ TODO: check
+CVE-2026-19288 (A vulnerability has been found in astralisone rive-mcp-server-core up ...)
+ TODO: check
+CVE-2026-19287 (A flaw has been found in abrinsmead mindpilot-mcp 0.5.0. Affected by t ...)
+ TODO: check
+CVE-2026-19285 (A vulnerability was detected in aaronsb memory-graph up to 5cfd2382778 ...)
+ TODO: check
+CVE-2026-19284 (A security vulnerability has been detected in MauricioMilano coder-api ...)
+ TODO: check
+CVE-2026-19282 (A weakness has been identified in andreahaku llm_memory_mcp up to f11d ...)
+ TODO: check
+CVE-2026-19281 (A security flaw has been discovered in adolfosalasgomez3011 slidev-bui ...)
+ TODO: check
+CVE-2026-19279 (A vulnerability was identified in MIMICLab mcp-pdf-vision 1.1.0. The i ...)
+ TODO: check
+CVE-2026-19270 (A security flaw has been discovered in Hulupeep mcp-ui-probe up to 0.2 ...)
+ TODO: check
+CVE-2026-19268 (A vulnerability was identified in abdullah1854 MCPGateway up to 549f49 ...)
+ TODO: check
+CVE-2026-19266 (A vulnerability was determined in Kirachon context-engine up to 1.9.0. ...)
+ TODO: check
CVE-2026-XXXX [RUSTSEC-2026-0235]
- rust-rkyv 0.8.17-1
[trixie] - rust-rkyv <no-dsa> (Minor issue)
@@ -12,10 +64,10 @@ CVE-2026-XXXX [RUSTSEC-2026-0234]
[trixie] - rust-rkyv <no-dsa> (Minor issue)
[bookworm] - rust-rkyv <not-affected> (Vulnerable code not present, only affects 0.8.x)
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0234.html
-CVE-2026-68082 [libceph: fix two unsafe bare decodes in decode_lockers()]
+CVE-2026-68082 (In the Linux kernel, the following vulnerability has been resolved: l ...)
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/a109a556115271ca7896dcda7b4b7e45e156c227 (7.2-rc5)
-CVE-2026-68081 [KVM: nVMX: Put vmcs12 pages if nested VM-Enter fails due to invalid guest state]
+CVE-2026-68081 (In the Linux kernel, the following vulnerability has been resolved: K ...)
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/2f2312c422fd2695da772cecb30c69994b795964 (7.2-rc4)
CVE-2026-9031 (An input validation vulnerability exists in the HTTP-WRITEOEM handler ...)
@@ -1547,6 +1599,7 @@ CVE-2026-68480 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.7-1
NOTE: https://people.csail.mit.edu/mengjia/data/2026.USENIX.TONTOU.pdf
CVE-2026-52682 [A crafted DNS packet can cause increased memory and CPU consumption]
+ {DSA-6421-1 DSA-6420-1 DSA-6419-1}
- pdns 5.1.4-1
[bookworm] - pdns <end-of-life> (See #1119290)
[bullseye] - pdns <end-of-life> (see DLA 4471)
@@ -2937,7 +2990,7 @@ CVE-2026-11421 (The ERP: Complete HR, Accounting & CRM Suite with WooCommerce CR
NOT-FOR-US: WordPress plugin
CVE-2025-15677 (The GeoDirectory WordPress plugin before 2.8.110 does not sanitise an ...)
NOT-FOR-US: WordPress plugin
-CVE-2026-42170
+CVE-2026-42170 (A heap-based buffer overflow vulnerability exists in the GIMP DDS (Dir ...)
- gimp 3.2.4-1
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16161
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2758
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/825c809dbb9ac0e7e4cf6b7b80383e6f709008ad
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/825c809dbb9ac0e7e4cf6b7b80383e6f709008ad
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/036fa338/attachment.htm>
More information about the debian-security-tracker-commits
mailing list