[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Aug 9 22:30:42 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cdfc55dd by Moritz Muehlenhoff at 2026-08-09T23:29:40+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -417,12 +417,14 @@ CVE-2026-9169 (DLL Search Order Hijacking in LUCID Vision Labs Arena SDK 1.0.80.
 	NOT-FOR-US: LUCID Vision Labs Arena SDK
 CVE-2026-71870 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
 	- pypdf <unfixed> (bug #1143902)
+	[trixie] - pypdf <no-dsa> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fp3f-mc75-235c
 	NOTE: https://github.com/py-pdf/pypdf/pull/3944
 	NOTE: Fixed by: https://github.com/py-pdf/pypdf/commit/afba8080e19d29a3c256a742b340995e695b35aa (6.15.0)
 CVE-2026-71852 (pypdf is a free and open-source pure-python PDF library. Prior to 6.15 ...)
 	- pypdf <unfixed> (bug #1143902)
+	[trixie] - pypdf <no-dsa> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-fwg2-594c-jp42
 	NOTE: https://github.com/py-pdf/pypdf/pull/3946
@@ -4879,6 +4881,7 @@ CVE-2026-55825 (Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, a
 CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAdd ...)
 	- golang-github-pion-stun-v3 <unfixed>
 	- golang-github-pion-stun <unfixed>
+	[trixie] - golang-github-pion-stun <no-dsa> (Minor issue)
 	NOTE: https://github.com/pion/stun/security/advisories/GHSA-34rh-wp3j-6cxc
 	NOTE: https://github.com/pion/stun/pull/278
 	NOTE: Fixed by: https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423 (v3.1.3)
@@ -8646,10 +8649,12 @@ CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulne
 	NOTE: https://github.com/theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-
 CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulnerabili ...)
 	- rust-tiny-http <unfixed> (bug #1142989)
+	[trixie] - rust-tiny-http <no-dsa> (Minor issue)
 	NOTE: https://github.com/theopaid/CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http-/tree/master
 	NOTE: https://github.com/tiny-http/tiny-http/issues/288
 CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling vulnerabil ...)
 	- rust-tiny-http <unfixed> (bug #1142989)
+	[trixie] - rust-tiny-http <no-dsa> (Minor issue)
 	NOTE: https://github.com/theopaid/CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-/tree/master
 	NOTE: https://github.com/tiny-http/tiny-http/issues/287
 CVE-2026-66751 (Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vuln ...)
@@ -10164,6 +10169,7 @@ CVE-2026-64531 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/28/8
 CVE-2026-49478
 	- golang-github-sigstore-fulcio 1.8.7-1
+	[trixie] - golang-github-sigstore-fulcio <no-dsa> (Minor issue)
 	NOTE: https://github.com/sigstore/fulcio/pull/2354
 	NOTE: Fixed by: https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1 (v1.8.6)
 CVE-2026-48702
@@ -13289,8 +13295,10 @@ CVE-2026-15348 (The Premium Packages \u2013 Sell Digital Products Securely plugi
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15037 (Improper output neutralization (XML injection) in QDom comment, CDATA, ...)
 	- qt6-base <unfixed>
+	[trixie] - qt6-base <no-dsa> (Minor issue)
 	[bookworm] - qt6-base <postponed> (Minor issue)
 	- qtbase-opensource-src <unfixed>
+	[trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
 	[bookworm] - qtbase-opensource-src <postponed> (Minor issue)
 	[bullseye] - qtbase-opensource-src <postponed> (Minor issue)
 	NOTE: https://codereview.qt-project.org/c/qt/qtbase/+/748323
@@ -20726,6 +20734,7 @@ CVE-2026-57980 (Authentication bypass using an alternate path or channel in Micr
 	NOT-FOR-US: Microsoft
 CVE-2026-56741 (JLine is a Java library for handling console input. Prior to 3.30.14,  ...)
 	- jline3 <unfixed> (bug #1143458)
+	[trixie] - jline3 <no-dsa> (Minor issue)
 	- jline2 <undetermined>
 	- jline <undetermined>
 	NOTE: https://github.com/jline/jline3/security/advisories/GHSA-2r2c-cx56-8933
@@ -20733,6 +20742,7 @@ CVE-2026-56741 (JLine is a Java library for handling console input. Prior to 3.3
 	NOTE: Fixed by: https://github.com/jline/jline3/commit/3ea9cad8699714dc072fade29d36be0d1e23d708 (jline-3.30.14)
 CVE-2026-56740 (JLine is a Java library for handling console input. Prior to 3.30.14,  ...)
 	- jline3 <unfixed> (bug #1143458)
+	[trixie] - jline3 <no-dsa> (Minor issue)
 	- jline2 <undetermined>
 	- jline <undetermined>
 	NOTE: https://github.com/jline/jline3/security/advisories/GHSA-47qp-hqvx-6r3f
@@ -20861,6 +20871,7 @@ CVE-2026-49852 (joserfc is a Python library that provides an implementation of s
 	NOTE: Fixed by: https://github.com/authlib/joserfc/commit/86d00910b2b2d2d07503fee9b572906daefab7f1 (1.6.8)
 CVE-2026-49834 (sigstore-go is a Go library for Sigstore signing and verification. Pri ...)
 	- sigstore-go 1.2.1-1
+	[trixie] - sigstore-go <no-dsa> (Minor issue)
 	NOTE: https://github.com/sigstore/sigstore-go/security/advisories/GHSA-9vcr-p3rj-q5q6
 	NOTE: https://github.com/sigstore/sigstore-go/pull/633
 	NOTE: Fixed by: https://github.com/sigstore/sigstore-go/commit/dbb07e62623edd5b175fb9dd5a41dcb85a159207 (v1.2.0)
@@ -20897,6 +20908,7 @@ CVE-2026-45785 (OpenMcdf is a fully .NET / C# library to manipulate Compound Fil
 	NOT-FOR-US: OpenMcdf
 CVE-2026-45784 (rust-openssl provides OpenSSL bindings for the Rust programming langua ...)
 	- rust-openssl <unfixed> (bug #1142474)
+	[trixie] - rust-openssl <no-dsa> (Minor issue)
 	[bookworm] - rust-openssl <not-affected> (Vulnerable CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are absent too)
 	[bullseye] - rust-openssl <not-affected> (Vulnerable CipherCtxRef::cipher_update_inplace() introduced in 0.10.50; the Cipher::aes_*_wrap_pad() constructors and CipherCtxFlags::FLAG_WRAP_ALLOW are absent too)
 	NOTE: https://github.com/rust-openssl/rust-openssl/security/advisories/GHSA-phqj-4mhp-q6mq
@@ -24248,6 +24260,7 @@ CVE-2026-48252 (Adobe Experience Manager is affected by a Missing Authentication
 	NOT-FOR-US: Adobe
 CVE-2026-48125 (UAParser.js is a JavaScript library to detect browsers, operating syst ...)
 	- node-ua-parser-js <unfixed>
+	[trixie] - node-ua-parser-js <no-dsa> (Minor issue)
 	[bookworm] - node-ua-parser-js <postponed> (minor issue)
 	[bullseye] - node-ua-parser-js <postponed> (minor issue)
 	NOTE: https://github.com/faisalman/ua-parser-js/security/advisories/GHSA-9h5v-pfqq-x599



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cdfc55dd2f3feed37233008320317d0c3fbe811c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cdfc55dd2f3feed37233008320317d0c3fbe811c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/b4955e77/attachment.htm>


More information about the debian-security-tracker-commits mailing list