[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Aug 9 21:44:28 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d60cd7fe by Moritz Muehlenhoff at 2026-08-09T22:44:13+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -624,6 +624,7 @@ CVE-2026-19082 (Imager versions from 0.45_02 before 1.034 for Perl may expose ad
NOTE: Fixed by: https://github.com/tonycoz/imager/commit/24bde0427a113264d53f45a9c29ae756d84c82fe (v1.034)
CVE-2026-19079 (A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerability was ...)
- policycoreutils <unfixed> (bug #1143965)
+ [trixie] - policycoreutils <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/SELinuxProject/selinux/commit/a556538c2d5d2583273e025b45c02651fef47679
CVE-2026-18497 (A heap-buffer-overflow vulnerability exists in the nothings stb TrueTy ...)
TODO: check
@@ -3765,6 +3766,7 @@ CVE-2026-41447 (FirmaCheck for Windows before 1.3.16 contains a DLL hijacking vu
NOT-FOR-US: FirmaCheck for Windows
CVE-2026-18739 (A flaw was found in popt, a command-line option parsing library. An of ...)
- popt <unfixed>
+ [trixie] - popt <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2510737
CVE-2026-18738 (Shlink versions 5.0.0 through 5.1.5 contain a CSV formula injection vu ...)
NOT-FOR-US: Shlink
@@ -8600,6 +8602,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed>
+ [trixie] - pypy3 <no-dsa> (Minor issue)
[bookworm] - pypy3 <postponed> (Minor issue)
[bullseye] - pypy3 <postponed> (Minor issue)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/7YMZ6DDZVR26TJJBVO3RDNBAVGHNYAKR/
@@ -10216,6 +10219,7 @@ CVE-2026-61475
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6c2f9592dec667796dacdffd7adbd065948fe212 (v10.0.12)
CVE-2026-16043
- qemu 1:11.0.3+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4001
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/2a5bc4de0f544a3739c32a99b11a9e78e71472c2 (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/b0411a1747ac9b205633011f62ac85436f354f35 (v10.0.12)
@@ -17316,6 +17320,7 @@ CVE-2026-64619 (FileCodeBox before 2.4 contains a rate-limit bypass vulnerabilit
NOT-FOR-US: FileCodeBox
CVE-2026-63771 (Adminer before 5.4.3 contains a cookie injection vulnerability that al ...)
- adminer 5.4.3+dfsg-1
+ [trixie] - adminer <no-dsa> (Minor issue)
NOTE: https://github.com/vrana/adminer/issues/1298
NOTE: https://github.com/vrana/adminer/security/advisories/GHSA-c533-9qwm-8w5h
CVE-2026-63770 (Glance through 0.8.5 contains an IP address spoofing vulnerability in ...)
@@ -17883,6 +17888,7 @@ CVE-2026-12341 (This vulnerability impacts all versions of IdentityIQ and allows
NOT-FOR-US: SailPoint Technologies
CVE-2026-12080 (A flaw was found in the QEMU Guest Agent (qga). A local unprivileged u ...)
- qemu <unfixed>
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3929
CVE-2026-64207 (In the Linux kernel, the following vulnerability has been resolved: n ...)
- linux 7.1.4-1
@@ -20538,6 +20544,7 @@ CVE-2026-53368 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/019f9dda7f66e55eb94cd32e1d3fff5835f73fbc (7.1-rc1)
CVE-2026-9323 (The urwid web display backend (urwid/display/web.py) generates web ses ...)
- urwid <unfixed>
+ [trixie] - urwid <no-dsa> (Minor issue)
NOTE: https://github.com/urwid/urwid/security/advisories/GHSA-rjwp-g85x-gmjv
NOTE: https://github.com/urwid/urwid/pull/1128
NOTE: Fixed by: https://github.com/urwid/urwid/commit/24acd12f0d0598036d0d577f2ee63e4a27b4a3d9 (4.0.2)
@@ -21428,6 +21435,7 @@ CVE-2026-60060 (Improper Handling of Length Parameter Inconsistency (CWE-130) vu
NOT-FOR-US: Tera Term
CVE-2026-5674 (A flaw was found in PipeWire, a multimedia server. This vulnerability ...)
- pipewire <unfixed> (bug #1142416)
+ [trixie] - pipewire <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2455341
CVE-2026-59867 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.32.5, ...)
NOT-FOR-US: Kiota
@@ -22855,6 +22863,7 @@ CVE-2026-59199 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow publ
NOTE: Fixed by: https://github.com/python-pillow/Pillow/commit/ceefc348eb3c3844c7f9796ef2cc3a7dd5fbba7b (12.3.0)
CVE-2026-59198 (Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pillow's ...)
- pillow 12.3.0-1 (bug #1142274)
+ [trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue)
[bullseye] - pillow <postponed> (Minor issue)
NOTE: https://github.com/python-pillow/Pillow/security/advisories/GHSA-fj7v-r99m-22gq
@@ -22862,6 +22871,7 @@ CVE-2026-59198 (Pillow is a Python imaging library. From 5.2.0 until 12.3.0, Pil
NOTE: Fixed by: https://github.com/python-pillow/Pillow/commit/eada3cbd7fb9963ee90673fb7b5270124a0d5f4b (12.3.0)
CVE-2026-59197 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow's public r ...)
- pillow 12.3.0-1 (bug #1142274)
+ [trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue)
[bullseye] - pillow <postponed> (Minor issue)
NOTE: https://github.com/python-pillow/Pillow/security/advisories/GHSA-xj96-63gp-2gmr
@@ -23379,6 +23389,7 @@ CVE-2026-54107 (Concurrent execution using shared resource with improper synchro
NOT-FOR-US: Microsoft
CVE-2026-54058 (Pillow is a Python imaging library. Prior to 12.3.0, when Pillow loads ...)
- pillow 12.3.0-1 (bug #1142274)
+ [trixie] - pillow <no-dsa> (Minor issue)
[bookworm] - pillow <postponed> (Minor issue)
[bullseye] - pillow <postponed> (Minor issue)
NOTE: https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93
@@ -27378,6 +27389,7 @@ CVE-2026-58525 (Improper access control in Microsoft Edge (Chromium-based) allow
NOT-FOR-US: Microsoft
CVE-2026-58501 (Zeep is a Python SOAP client. From 4.0.0 before 4.3.3, Settings.forbid ...)
- python-zeep <unfixed> (bug #1141819)
+ [trixie] - python-zeep <no-dsa> (Minor issue)
NOTE: https://github.com/mvantellingen/python-zeep/security/advisories/GHSA-4cc2-g9w2-fhf6
NOTE: https://github.com/mvantellingen/python-zeep/commit/83eb07bc6c84d841329d4f88856fecdba86f753e (4.3.3)
CVE-2026-58494 (Wasmtime is a runtime for WebAssembly. Prior to 24.0.11, 36.0.12, 45.0 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d60cd7fed89e56795174f0625abe6df437b0ad48
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d60cd7fed89e56795174f0625abe6df437b0ad48
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/979a42c2/attachment.htm>
More information about the debian-security-tracker-commits
mailing list