[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 10 08:08:25 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0d44026c by Moritz Muehlenhoff at 2026-08-10T09:02:22+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7731,21 +7731,27 @@ CVE-2026-16553 (GitLab has remediated an issue in GitLab EE affecting all versio
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-16531 (An unauthenticated remote attacker can exploit a path traversal vulner ...)
- pcp <unfixed> (bug #1143154)
+ [trixie] - pcp <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506037
CVE-2026-16530 (A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service. ...)
- pcp <unfixed> (bug #1143154)
+ [trixie] - pcp <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506033
CVE-2026-16529 (A signed integer overflow in the PCP __pmGetPDU() function can be expl ...)
- pcp <unfixed> (bug #1143154)
+ [trixie] - pcp <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506032
CVE-2026-16527 (An unauthenticated remote attacker can bypass access controls by sendi ...)
- pcp <unfixed> (bug #1143154)
+ [trixie] - pcp <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506031
CVE-2026-16526 (A flaw in the PCP linux_sockets module exposes an unsecured internal c ...)
- pcp <unfixed> (bug #1143154)
+ [trixie] - pcp <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506026
CVE-2026-16524 (A command injection flaw in PCP's linux_sockets PMDA allows malicious ...)
- pcp <unfixed> (bug #1143154)
+ [trixie] - pcp <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506023
CVE-2026-16339
REJECTED
@@ -9916,6 +9922,7 @@ CVE-2026-49158 (Improper Handling of Highly Compressed Data (Data Amplification)
CVE-2026-48586 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/p008svsjf9p6bj47wyyf5dgglq5z7xoq
CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
[experimental] - thrift 0.24.0-1
@@ -9951,10 +9958,12 @@ CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and modi
CVE-2026-45112 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/hl9kmf1z2o3lxvspoj3g9ykl8lj9mdxc
CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby
CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erlang OT ...)
- erlang 1:29.0.4+dfsg-1 (bug #1142985)
@@ -9965,6 +9974,7 @@ CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erl
CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
[experimental] - thrift 0.24.0-1
- thrift <unfixed>
+ [trixie] - thrift <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/vwsbcwqdpwdtp8qkjo11ol6rodbfm21f
CVE-2026-40000 (The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)
NOT-FOR-US: ZTE
@@ -11916,6 +11926,9 @@ CVE-2025-71408 (NLTK (Natural Language Toolkit) before version 3.9.3 contains an
NOTE: Fixed by: https://github.com/nltk/nltk/commit/e373c8c3d10e236672ef65c38ca7d24612941553 (3.9.3)
CVE-2026-66374 (Knot Resolver before 6.4.1 allows remote code execution via a heap-bas ...)
- knot-resolver 6.4.1-1
+ [trixie] - knot-resolver <not-affected> (Vulnerable code not present, quic support added in 6.2)
+ [bookworm] - knot-resolver <not-affected> (Vulnerable code not present, quic support added in 6.2)
+ [bullseye] - knot-resolver <not-affected> (Vulnerable code not present, quic support added in 6.2)
NOTE: https://openwall.com/lists/oss-security/2026/07/23/6
NOTE: https://github.com/venglin/knot-doq
CVE-2026-9765 (Note: The CVE and blog post don't exist because we determined this is ...)
@@ -17472,11 +17485,13 @@ CVE-2026-15927 (A flaw was found in Red Hat Quay's repository-level mirror confi
NOT-FOR-US: Quay
CVE-2026-15812 (A vulnerability was found in the internal Access Control List (ACL) su ...)
- kronosnet <unfixed> (bug #1142847)
+ [trixie] - kronosnet <no-dsa> (Minor issue)
[bookworm] - kronosnet <postponed> (Minor issue)
[bullseye] - kronosnet <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500851
CVE-2026-15811 (A vulnerability was found in kronosnet's (version <=1.34) cryptographi ...)
- kronosnet <unfixed> (bug #1142847)
+ [trixie] - kronosnet <no-dsa> (Minor issue)
[bookworm] - kronosnet <postponed> (Minor issue)
[bullseye] - kronosnet <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500849
@@ -17882,6 +17897,7 @@ CVE-2026-16242 (A flaw was found in the Konnectivity proxy-server configuration
NOT-FOR-US: Konnectivity proxy-server
CVE-2026-15813 (A vulnerability was found in the network packet de-fragmentation engin ...)
- kronosnet <unfixed> (bug #1142847)
+ [trixie] - kronosnet <no-dsa> (Minor issue)
[bookworm] - kronosnet <postponed> (Minor issue)
[bullseye] - kronosnet <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500854
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d44026c89b0b4f8b809374dbd70ed059998331e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0d44026c89b0b4f8b809374dbd70ed059998331e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/0db968d2/attachment.htm>
More information about the debian-security-tracker-commits
mailing list