[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Aug 8 22:43:14 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
9eff77de by Moritz Muehlenhoff at 2026-08-08T23:42:59+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9577,6 +9577,7 @@ CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) in the email module in Rosk
CVE-2026-58662 (Improper Validation of Specified Quantity in Input, Out-of-bounds Read ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/13mzvylr3r3nktxrh5k1h30ng1t1sw1d
CVE-2026-58389 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
[experimental] - thrift 0.24.0-1
@@ -9594,6 +9595,7 @@ CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when recon
CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings. Th ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/z2myopbovxngfvchdz8hddots9p5ffbt
CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary crafted ...)
NOT-FOR-US: proCertum SmartSign
@@ -9606,6 +9608,7 @@ CVE-2026-56537 (HCL Connections is vulnerable to information disclosure which co
CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/xjs36m6kjxpmrmzwck636msg3nvoqnmx
CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings. This is ...)
[experimental] - thrift 0.24.0-1
@@ -9615,6 +9618,7 @@ CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings. T
CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/xmkgd107k795hyrg5kf97mny30sgl5bo
CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources Without Li ...)
[experimental] - thrift 0.24.0-1
@@ -9693,6 +9697,7 @@ CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch vulnerabil
CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/2xoltfxgzf5jyhcwq6y07spts5cn6ppj
CVE-2026-48052 (Papra is a minimalistic document management and archiving platform. Pr ...)
NOT-FOR-US: Papra
@@ -9709,6 +9714,7 @@ CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib zip
NOTE: Fixed by: https://github.com/erlang/otp/commit/8a933c9c7835b06776d31d17b79b7336627d887a (OTP-29.0.4, OTP-28.5.0.4, OTP-27.3.4.15)
CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
- node-postcss 8.5.12+~cs9.3.32-1
+ [trixie] - node-postcss <no-dsa> (Minor issue)
NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-6g55-p6wh-862q
NOTE: https://github.com/postcss/postcss/commit/aaec7b78b3ce2792585b4b300ef1bd5dd5b3e8ad (8.5.12)
NOTE: https://github.com/postcss/postcss/commit/c64b7488d2731dfa16213739b42c34faf5a9eba3 (8.5.12)
@@ -9952,6 +9958,7 @@ CVE-2026-47701
NOT-FOR-US: OpenTelemetry Operator
CVE-2026-16566
- ansible <unfixed>
+ [trixie] - ansible <no-dsa> (Minor issue)
[bookworm] - ansible <not-affected> (Vulnerable code not present)
[bullseye] - ansible <not-affected> (Vulnerable code not present)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506113
@@ -11641,10 +11648,12 @@ CVE-2026-66038 (FFmpeg through 8.1.2, fixed in commit 8670835, contains an infor
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/e7cbfd1c507b57a806a5825b87d609963e862c8c
CVE-2026-66037 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains an uncontrolle ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23627
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/86708357d126af84c16f80d9c57335d1e8c845c5
CVE-2026-66036 (FFmpeg through 8.1.2, fixed in commit 5d7112c, contains a heap out-of- ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23783
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/5d7112c60e6f0f0742ce47d448e6da0718a70f4c
CVE-2026-62835 (Improper authorization in Azure Portal allows an unauthorized attacker ...)
@@ -12124,7 +12133,10 @@ CVE-2026-16743 (A flaw was found in accountsservice. The systemd-homed code path
NOTE: https://gitlab.freedesktop.org/accountsservice/accountsservice/-/merge_requests/182 (26.26.9)
CVE-2026-16730 (A flaw was found in dbus-broker. When the process file-descriptor limi ...)
- dbus-broker <unfixed> (bug #1142850)
+ [trixie] - dbus-broker <no-dsa> (Minor issue)
NOTE: https://github.com/bus1/dbus-broker/issues/435
+ NOTE: https://github.com/bus1/dbus-broker/commit/c4a3c886366f7bd566ec9a55b3855ade8290fa17
+ NOTE: https://github.com/bus1/dbus-broker/commit/aaa9fd6bbc2d5d7bfeca039f9c457b7f88a50dde
CVE-2026-16519 (A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Uti ...)
NOT-FOR-US: GeoVision
CVE-2026-15821 (The SureDash \u2013 Community, Courses & Member Dashboard plugin for W ...)
@@ -12189,18 +12201,22 @@ CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped
NOTE: https://bugs.launchpad.net/ironic-python-agent/+bug/2160050
CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulne ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23779
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/a7e38b617b32f996beaa371bbf04b39907d7a527
CVE-2026-65705 (FFmpeg versions 3.4 through 8.1.2 contain an out-of-bounds write vulne ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23780
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f186c50cf53aec20e9a29059cb22ca3f2d59201c
CVE-2026-65704 (FFmpeg through 8.1.2 contains an out-of-bounds write vulnerability tha ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23767
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/de771bd52774a52d45b0e2c82e56995a1ef40df7
CVE-2026-65703 (FFmpeg versions 2.7 through 8.1.2 contain an out-of-bounds write vulne ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23773
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/fd3ee52fab34d98a95b787d0b5ff45685766200c
CVE-2026-65694 (Microweber CMS through 2.0.20 contains a path traversal vulnerability ...)
@@ -13452,6 +13468,7 @@ CVE-2026-16544 (A flaw was found in AWX. The websocket event consumer performs R
NOT-FOR-US: Ansible Tower
CVE-2026-16473 (A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one e ...)
- sbc <unfixed> (bug #1142848)
+ [trixie] - sbc <no-dsa> (Minor issue)
[bookworm] - sbc <postponed> (Minor issue)
[bullseye] - sbc <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2503650
@@ -16545,6 +16562,7 @@ CVE-2026-1372 (The Tutor LMS Elementor Addons plugin for WordPress is vulnerable
NOT-FOR-US: WordPress plugin
CVE-2026-16493 (A flaw was found in ansible-core. The _extract_collection_from_git() f ...)
- ansible-core <unfixed>
+ [trixie] - ansible-core <no-dsa> (Minor issue)
- ansible 5.4.0-1
[bullseye] - ansible <postponed> (Needs only work when CVE-2026-11332 is fixed as well)
NOTE: ansible-core was split off from src:ansible with 4.6.0-1 in experimental/5.4.0-1 in sid
@@ -17693,6 +17711,7 @@ CVE-2026-64187 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4)
CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure session ids ...)
- libdancer2-perl <unfixed> (bug #1142718)
+ [trixie] - libdancer2-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41975698/
CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy Terms Word ...)
NOT-FOR-US: WordPress plugin
@@ -21952,10 +21971,11 @@ CVE-2026-62389
CVE-2026-62378 (RustFS Console is a web management console for the RustFS distributed ...)
NOT-FOR-US: RustFS
CVE-2026-62294 (Flameshot is powerful yet simple to use screenshot software. Prior to ...)
- - flameshot 14.0.0-1
+ - flameshot 14.0.0-1 (unimportant)
NOTE: https://github.com/flameshot-org/flameshot/security/advisories/GHSA-fqqf-4rj8-c392
NOTE: https://github.com/flameshot-org/flameshot/pull/4716
NOTE: Fixed by: https://github.com/flameshot-org/flameshot/commit/936716b8d8b7052be461c3d5e2f88492b6eb3b96 (v14.0.0)
+ NOTE: Neutralised by kernel tmp hardening
CVE-2026-62287
REJECTED
CVE-2026-62248
@@ -22375,6 +22395,7 @@ CVE-2026-15804 (The HCM developed by MetaGuru has a SQL Injection vulnerability.
NOT-FOR-US: MetaGuru
CVE-2026-15779 (A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ...)
- samba <unfixed>
+ [trixie] - samba <no-dsa> (Minor issue)
[bookworm] - samba <postponed> (Minor issue; pam_winbind mkhomedir chowns a pre-existing home dir, and mkhomedir is not enabled by default in Debian; can be fixed in next update)
[bullseye] - samba <postponed> (Minor issue; pam_winbind mkhomedir chowns a pre-existing home dir, and mkhomedir is not enabled by default in Debian; can be fixed in next update)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499991
@@ -24738,10 +24759,12 @@ CVE-2025-15665 (The Ultimate Before After Image Slider & Gallery WordPress plug
NOT-FOR-US: WordPress plugin
CVE-2026-58102 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow a heap out-o ...)
- libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
+ [trixie] - libcrypt-openssl-x509-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792355/
NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-x509/commit/757289bfce095455c104d4adfe9312e7b339620f (2.1.3)
CVE-2026-58101 (Crypt::OpenSSL::X509 versions before 2.1.3 for Perl allow denial of se ...)
- libcrypt-openssl-x509-perl 2.1.3-1 (bug #1142034)
+ [trixie] - libcrypt-openssl-x509-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41792358/
NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-x509/commit/4c1e2370556097c253ae27abe9e1097ea377fbd2 (2.1.3)
CVE-2026-63090 (ProFTPD before 1.3.9c and 1.3.10rc3 contains a heap-based buffer overf ...)
@@ -26270,6 +26293,7 @@ CVE-2026-15373 (A vulnerability was detected in Eleveo Call Recording Software 9
NOT-FOR-US: Eleveo Call Recording Software
CVE-2026-15146 (GNU Wget does not validate the IP address provided by an FTP PASV resp ...)
- wget 1.25.0-3 (bug #1142284)
+ [trixie] - wget <no-dsa> (Minor issue)
[bookworm] - wget <postponed> (Minor issue)
[bullseye] - wget <postponed> (Minor issue)
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/wget.git/commit/?id=4f85853f641863d5915786a8413e1a213726a62b
@@ -26472,6 +26496,7 @@ CVE-2026-39243 (decompress before 4.2.2 allows arbitrary hardlink creation durin
NOT-FOR-US: Node decompress module
CVE-2026-38076 (An integer overflow in the jbig2_arith_iaid_ctx_new() function of Arti ...)
- jbig2dec <unfixed> (bug #1142282)
+ [trixie] - jbig2dec <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/ArtifexSoftware/jbig2dec/commit/cc37d0931aa71582f7128736a068c92cd8712d9b
CVE-2026-33803 (An Improper Restriction of Communication Channel to Intended Endpoints ...)
NOT-FOR-US: Juniper
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9eff77de9ac4997c483051d676d749cf88897f7b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9eff77de9ac4997c483051d676d749cf88897f7b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260808/5d380869/attachment.htm>
More information about the debian-security-tracker-commits
mailing list