[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 10 09:42:47 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
be665477 by Moritz Muehlenhoff at 2026-08-10T10:07:55+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -3698,6 +3698,7 @@ CVE-2026-15307 (An issue was discovered in Django 5.2 before 5.2.17 and 6.0 befo
 	NOTE: Fixed by: https://github.com/django/django/commit/115ffd0463a765ab1cc93de18e94b5459b8a300e (5.2.17)
 CVE-2026-XXXX [RUSTSEC-2026-0204]
 	- rust-crossbeam-epoch 0.9.20-1
+	[trixie] - rust-crossbeam-epoch <no-dsa> (Minor issue)
 	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0204.html
 	NOTE: https://github.com/crossbeam-rs/crossbeam/pull/1276
 CVE-2026-8508 (An improper authentication vulnerability in the "social_login.cgi" CGI ...)
@@ -8978,11 +8979,13 @@ CVE-2026-51251
 	REJECTED
 CVE-2026-50738 (A use-after-free condition exists in pglogical's worker signaling code ...)
 	- pglogical 2.4.8-1
+	[trixie] - pglogical <no-dsa> (Minor issue)
 	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
 	NOTE: https://www.enterprisedb.com/docs/security/advisories/cve202650735/
 	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/ed330e94cbceb51681eee7516708e142458eb005 (REL2_4_8)
 CVE-2026-50737 (When applying replicated changes for a row that is missing one or more ...)
 	- pglogical 2.4.8-1
+	[trixie] - pglogical <no-dsa> (Minor issue)
 	[bookworm] - pglogical <postponed> (minor issue; need privilegied user)
 	[bullseye] - pglogical <postponed> (minor issue; need privilegied user)
 	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
@@ -8990,6 +8993,7 @@ CVE-2026-50737 (When applying replicated changes for a row that is missing one o
 	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/62deadc86ce62c91cf988ce49373a98fafa77899 (REL2_4_8)
 CVE-2026-50736 (The pglogical queue mechanism, used to convey out-of-band commands suc ...)
 	- pglogical 2.4.8-1
+	[trixie] - pglogical <no-dsa> (Minor issue)
 	[bookworm] - pglogical <postponed> (minor issue; need privilegied user)
 	[bullseye] - pglogical <postponed> (minor issue; need privilegied user)
 	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
@@ -8997,6 +9001,7 @@ CVE-2026-50736 (The pglogical queue mechanism, used to convey out-of-band comman
 	NOTE: Fixed by: https://github.com/2ndQuadrant/pglogical/commit/62deadc86ce62c91cf988ce49373a98fafa77899 (REL2_4_8)
 CVE-2026-50735 (pglogical's apply worker does not sufficiently validate the length of  ...)
 	- pglogical 2.4.8-1
+	[trixie] - pglogical <no-dsa> (Minor issue)
 	[bookworm] - pglogical <postponed> (minor issue; need privilegied user)
 	[bullseye] - pglogical <postponed> (minor issue; need privilegied user)
 	NOTE: https://github.com/2ndQuadrant/pglogical/releases/tag/REL2_4_8
@@ -10387,11 +10392,13 @@ CVE-2026-17457 (A vulnerability has been found in mf-yang openclaw-cn up to 0.2.
 	NOT-FOR-US: mf-yang openclaw-cn
 CVE-2026-63319
 	- qemu 1:11.0.3+ds-1
+	[trixie] - qemu <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3995
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/1e54185745ba896af2beb5259b61ba6473e9881e (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6970b91d905f72ba952c4d224ab8d6192ef9b39d (v10.0.12)
 CVE-2026-61475
 	- qemu 1:11.0.3+ds-1
+	[trixie] - qemu <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3935
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/24767bcf0fdcd19415cb07c06f637ea29a5cebbb (v11.0.3)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6c2f9592dec667796dacdffd7adbd065948fe212 (v10.0.12)
@@ -13767,26 +13774,32 @@ CVE-2026-65011 (Graylog2 Server before commit 46a2eeb contains a missing per-ent
 	- graylog2 <itp> (bug #652273)
 CVE-2026-64835 (FFmpeg versions 4.4 through 8.1.2 contain an out-of-bounds memory acce ...)
 	- ffmpeg <unfixed>
+	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23659
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1836ef96846937a6cc2443698a693104f5c0b21e
 CVE-2026-64834 (FFmpeg versions 0.6.3 through 8.1.2 contain an infinite loop vulnerabi ...)
 	- ffmpeg <unfixed>
+	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23663
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/11d5f475be95d22d5f0692220cc772b116abc632
 CVE-2026-64833 (FFmpeg versions 0.7.1 through 8.1.2 contain an out-of-bounds read vuln ...)
 	- ffmpeg <unfixed>
+	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23661
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/6f80e2765492700622596af720534cef33dd31b4
 CVE-2026-64832 (FFmpeg versions 4.4 through 8.1.2 contain a double-free vulnerability  ...)
 	- ffmpeg <unfixed>
+	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23664
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/4c6217477fc64305055b37d9d1d0d76d30e37f97
 CVE-2026-64831 (FFmpeg versions 8.0 through 8.1.2 contains a stack buffer overflow vul ...)
 	- ffmpeg <unfixed>
+	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23665
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/92737390dc133daadce47dd7d2ec8ef3d9ebcbed
 CVE-2026-64830 (FFmpeg versions 2.1 through 8.1.2 contains a heap buffer overflow vuln ...)
 	- ffmpeg <unfixed>
+	[trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/23657
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/dbd495f066a85ba96b17433f4306582aa37c3951
 CVE-2026-64828 (Froiden TableTrack through 1.3.10 contains a stored cross-site scripti ...)
@@ -16762,8 +16775,10 @@ CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to 150.0
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in QText ...)
 	- qt6-5compat 6.10.2-4 (bug #1142690)
+	[trixie] - qt6-5compat <no-dsa> (Minor issue)
 	[bookworm] - qt6-5compat <postponed> (Minor issue)
 	- qtbase-opensource-src 5.15.19+dfsg-4 (bug #1142691)
+	[trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
 	[bookworm] - qtbase-opensource-src <postponed> (Minor issue)
 	[bullseye] - qtbase-opensource-src <postponed> (Minor issue)
 	NOTE: https://codereview.qt-project.org/c/qt/qt5compat/+/723911
@@ -26466,6 +26481,7 @@ CVE-2026-59190 (grav-plugin-admin is an HTML user interface that provides a way
 	NOT-FOR-US: grav-plugin-admin
 CVE-2026-59180 (Apprise is an open source library which allows you to send a notificat ...)
 	- apprise 1.11.0-1
+	[trixie] - apprise <no-dsa> (Minor issue)
 	NOTE: https://github.com/caronc/apprise/security/advisories/GHSA-856c-92hv-3vxx
 	NOTE: https://github.com/caronc/apprise/pull/1610
 	NOTE: Fixed by: https://github.com/caronc/apprise/commit/68c0aef218055e4586cf4605fd6b56358f5f462d (v1.11.0)
@@ -27553,6 +27569,7 @@ CVE-2026-59819 (LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenA
 	NOT-FOR-US: LiteLLM
 CVE-2026-59818 (etcd is a distributed key-value store for the data of a distributed sy ...)
 	- etcd <unfixed> (bug #1141963)
+	[trixie] - etcd <no-dsa> (Minor issue)
 	[bookworm] - etcd <not-affected> (Split HTTP/gRPC listener onlyGRPC CRL path introduced in 3.5.0; absent in 3.4.x)
 	[bullseye] - etcd <not-affected> (Split HTTP/gRPC listener onlyGRPC CRL path introduced in 3.5.0; absent in 3.3.x)
 	NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-3wh4-j44w-pg92
@@ -35674,6 +35691,7 @@ CVE-2026-10593 (The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-48002
 	- qemu 1:11.0.3+ds-1
+	[trixie] - qemu <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/00589953cc263ed8098fa9c0a007a9b04d470f85 (v11.0.2)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/52155a6affd077f7e50fd0aca99a391d6e9e7066 (v11.0.2)
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/738927b263c7dcd14edff148826b28990b18ae46 (v11.0.3)
@@ -262828,6 +262846,7 @@ CVE-2024-XXXX [RUSTSEC-2024-0429]
 	[bookworm] - rust-glib <not-affected> (Only affects >= 0.15)
 	[bullseye] - rust-glib <not-affected> (Only affects >= 0.15)
 	- rust-glib-0.18 <unfixed> (bug #1143114)
+	[trixie] - rust-glib-0.18 <no-dsa> (Minor issue)
 	NOTE: https://rustsec.org/advisories/RUSTSEC-2024-0429.html
 	NOTE: https://github.com/gtk-rs/gtk-rs-core/pull/1343
 	NOTE: https://github.com/gtk-rs/gtk-rs-core/commit/b5a4071e439bef2b5eea76c3aa25e5ae84839e34


=====================================
data/dsa-needed.txt
=====================================
@@ -23,6 +23,9 @@ amd64-microcode (carnil)
 apr-util (carnil)
   Bastien Roucaries proposed a debdiff for review
 --
+bouncycastle
+  possibly move to 1.85 for trixie
+--
 cacti
   probably best to move to 1.2.31
 --
@@ -73,6 +76,8 @@ nats-server
 --
 netty
 --
+neutron (jmm)
+--
 nginx (aron)
   Maintainer is working on updates
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be6654771457a842d17121dfc9756d3c0f70fb75

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/be6654771457a842d17121dfc9756d3c0f70fb75
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/7ac3da25/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list