[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 10 16:02:43 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
6d4052dd by Moritz Muehlenhoff at 2026-08-10T14:22:40+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -9,6 +9,7 @@ CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant in
 	NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
 CVE-2026-19389 (Multiple integer overflow and underflow vulnerabilities were found in  ...)
 	- gst-plugins-ugly1.0 1.28.6-1
+	[trixie] - gst-plugins-ugly1.0 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12233
 	NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12243
 	NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a598edfef83878f714ea53925ae802f49c3b31a6 (1.28.6)
@@ -1037,6 +1038,7 @@ CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and detects violations of a
 	NOT-FOR-US: PHP_CodeSniffer
 CVE-2026-67422 (pymdown-extensions is a collection of extensions for the Python Markdo ...)
 	- pymdown-extensions 11.0.1-1
+	[trixie] - pymdown-extensions <no-dsa> (Minor issue)
 	NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-gm37-52c6-37mw
 	NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/c68498598d7b13011bb4571350b6e3612a4ce44b (11.0.1)
 CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows an auth ...)
@@ -1083,6 +1085,7 @@ CVE-2026-62830 (Missing authorization in Azure SRE Agent allows an authorized at
 	NOT-FOR-US: Microsoft
 CVE-2026-61632 (PyMdown Extensions is a set of extensions for the Python-Markdown mark ...)
 	- pymdown-extensions 11.0.1-1
+	[trixie] - pymdown-extensions <no-dsa> (Minor issue)
 	NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-9xwg-3r6f-jcx2
 CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt ...)
 	NOT-FOR-US: Contiki-NG
@@ -1257,6 +1260,7 @@ CVE-2026-19054 (A vulnerability was detected in Lspace-io lspace-server up to 79
 	NOT-FOR-US: Lspace-io lspace-server
 CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser reads web ad ...)
 	- epiphany-browser <unfixed> (bug #1143966)
+	[trixie] - epiphany-browser <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897
 	NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/commit/13dd600719d7aac532ed6c84ea0d12dd372d4ac4
 CVE-2026-18367 (A privilege escalation vulnerability allows local users to execute arb ...)
@@ -1381,6 +1385,7 @@ CVE-2024-39024 (In Packetfence 13.2.0, the WebGui interface setting allows authe
 	TODO: check
 CVE-2026-18938 (A flaw was found in p11-kit. A local attacker, or one with equivalent  ...)
 	- p11-kit <unfixed>
+	[trixie] - p11-kit <no-dsa> (Minor issue)
 	NOTE: https://github.com/p11-glue/p11-kit/pull/777
 	NOTE: Fixed by: https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc (0.26.5)
 CVE-2026-64638 (WordPress is vulnerable to a pre-auth reflected XSS vulnerability on t ...)
@@ -5059,6 +5064,7 @@ CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMap
 	NOTE: Fixed by: https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423 (v3.1.3)
 CVE-2026-54787 (sigstore-go is a Go library for Sigstore signing and verification. Pri ...)
 	- sigstore-go 1.2.1-1
+	[trixie] - sigstore-go <no-dsa> (Minor issue)
 	NOTE: https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm
 	NOTE: https://github.com/sigstore/sigstore-go/pull/642
 	NOTE: https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f (v1.2.1)
@@ -10261,9 +10267,11 @@ CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter of
 CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
 	- unzip <unfixed> (bug #1142906)
 CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
-	- unzip <unfixed> (bug #1142905)
+	- unzip <unfixed> (bug #1142905; unimportant)
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-XXXX [heap OOB read in EF_IZUNIX3 extra field handler]
-	- unzip <unfixed> (bug #1142904)
+	- unzip <unfixed> (bug #1142904; unimportant)
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control vulnerabilit ...)
@@ -10360,6 +10368,7 @@ CVE-2026-49478
 	NOTE: Fixed by: https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1 (v1.8.6)
 CVE-2026-48702
 	- rekor 1.5.2-1
+	[trixie] - rekor <no-dsa> (Minor issue)
 	NOTE: https://github.com/sigstore/rekor/pull/2831
 	NOTE: Fixed by: https://github.com/sigstore/rekor/commit/759b98e2a7c39ea9779b6a51299c5f0f987f8802 (v1.5.2)
 CVE-2026-50540 (Kata Containers is an open source project focusing on a standard imple ...)
@@ -12615,6 +12624,7 @@ CVE-2026-6454 (The Firelight Lightbox plugin for WordPress is vulnerable to Stor
 	NOT-FOR-US: WordPress plugin
 CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXT ...)
 	- zaqar 22.0.0-3 (bug #1142858)
+	[trixie] - zaqar <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/7
 	NOTE: https://launchpad.net/bugs/2161254
 CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped user  ...)
@@ -12893,6 +12903,7 @@ CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary file
 	NOT-FOR-US: Meshery
 CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains  ...)
 	- pytorch-vision <unfixed> (bug #1142689)
+	[trixie] - pytorch-vision <no-dsa> (Minor issue)
 	NOTE: https://github.com/pytorch/vision/issues/9551
 	NOTE: https://github.com/pytorch/vision/pull/9520
 	NOTE: Fixed by: https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed
@@ -13218,6 +13229,7 @@ CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image downl
 	NOT-FOR-US: Joomla
 CVE-2026-64611 (A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ...)
 	- libcupsfilters <unfixed> (bug #1142686)
+	[trixie] - libcupsfilters <no-dsa> (Minor issue)
 	[bookworm] - libcupsfilters <postponed> (Minor issue)
 	[bullseye] - libcupsfilters <postponed> (Minor issue)
 	NOTE: https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4
@@ -21824,6 +21836,7 @@ CVE-2026-46341 (The Apify MCP server enables AI agents to extract data from webs
 	NOT-FOR-US: Apify MCP server
 CVE-2026-46338 (PyMdown Extensions is a set of extensions for the Python-Markdown mark ...)
 	- pymdown-extensions 11.0.1-1
+	[trixie] - pymdown-extensions <no-dsa> (Minor issue)
 	NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-62q4-447f-wv8h
 	NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/63b7835776d703d6c339cf2110d9888f676efc0c (10.21.3)
 CVE-2026-46336 (Manyfold is an open source, self-hosted web application for managing a ...)
@@ -23010,14 +23023,17 @@ CVE-2026-59888 (jackson-databind contains the general-purpose data-binding funct
 	NOTE: Fixed by: https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d (jackson-databind-2.18.8)
 CVE-2026-59886 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ ...)
 	- pyasn1 0.6.4-1 (bug #1142388)
+	[trixie] - pyasn1 <no-dsa> (Minor issue)
 	NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r
 	NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886 (v0.6.4)
 CVE-2026-59885 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, ...)
 	- pyasn1 0.6.4-1 (bug #1142388)
+	[trixie] - pyasn1 <no-dsa> (Minor issue)
 	NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj
 	NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9 (v0.6.4)
 CVE-2026-59884 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER  ...)
 	- pyasn1 0.6.4-1 (bug #1142388)
+	[trixie] - pyasn1 <no-dsa> (Minor issue)
 	NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j
 	NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 (v0.6.4)
 CVE-2026-59841 (A improper restriction of communication channel to intended endpoints  ...)
@@ -24248,10 +24264,12 @@ CVE-2026-49783 (Improperly implemented security check for standard in Windows Se
 	NOT-FOR-US: Microsoft
 CVE-2026-49477 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
 	- soupsieve 2.8.4-1
+	[trixie] - soupsieve <no-dsa> (Minor issue)
 	NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37
 	NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3 (2.8.4)
 CVE-2026-49476 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
 	- soupsieve 2.8.4-1
+	[trixie] - soupsieve <no-dsa> (Minor issue)
 	NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x
 	NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39 (2.8.4)
 CVE-2026-49459 (DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...)
@@ -41403,9 +41421,11 @@ CVE-2026-56221 (Cap-go before 12.128.2 contains multiple SQL injection vulnerabi
 	NOT-FOR-US: Cap-go
 CVE-2026-55655 (A flaw was found in OpenSSH. A local unprivileged attacker on a Linux  ...)
 	- openssh <unfixed> (bug #1143936)
+	[trixie] - openssh <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462250
 CVE-2026-55654 (A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds  ...)
 	- openssh <unfixed> (bug #1143924)
+	[trixie] - openssh <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462493
 CVE-2026-55653 (A flaw was found in OpenSSH. A malicious SSH server can exploit a doub ...)
 	- openssh <not-affected> (Only an issue with FIPS patch which is not in Debian/upstream)


=====================================
data/dsa-needed.txt
=====================================
@@ -49,6 +49,10 @@ firebird4.0
 --
 gimp
 --
+gst-plugins-bad1.0
+--
+ironic
+--
 jackson-databind
 --
 jetty9
@@ -144,6 +148,8 @@ tomcat11
 unbound
   Michael Tokarev is working on rebasing to 1.25.2 (possibly 1.26.0)
 --
+unzip
+--
 util-linux (carnil)
   Maintainer is preparing updates
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d4052ddcfd70277a9a16cadf6d41420c341e5c9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d4052ddcfd70277a9a16cadf6d41420c341e5c9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/e884f2ee/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list