[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 10 16:02:43 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
6d4052dd by Moritz Muehlenhoff at 2026-08-10T14:22:40+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,6 +9,7 @@ CVE-2026-72522 (libexpat before 2.8.3 has an out-of-bounds read and resultant in
NOTE: https://bugzilla.mozilla.org/show_bug.cgi?id=2053153
CVE-2026-19389 (Multiple integer overflow and underflow vulnerabilities were found in ...)
- gst-plugins-ugly1.0 1.28.6-1
+ [trixie] - gst-plugins-ugly1.0 <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12233
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/12243
NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/a598edfef83878f714ea53925ae802f49c3b31a6 (1.28.6)
@@ -1037,6 +1038,7 @@ CVE-2026-67434 (PHP_CodeSniffer tokenizes PHP files and detects violations of a
NOT-FOR-US: PHP_CodeSniffer
CVE-2026-67422 (pymdown-extensions is a collection of extensions for the Python Markdo ...)
- pymdown-extensions 11.0.1-1
+ [trixie] - pymdown-extensions <no-dsa> (Minor issue)
NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-gm37-52c6-37mw
NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/c68498598d7b13011bb4571350b6e3612a4ce44b (11.0.1)
CVE-2026-65668 (Improper access control in Microsoft Purview eDiscovery allows an auth ...)
@@ -1083,6 +1085,7 @@ CVE-2026-62830 (Missing authorization in Azure SRE Agent allows an authorized at
NOT-FOR-US: Microsoft
CVE-2026-61632 (PyMdown Extensions is a set of extensions for the Python-Markdown mark ...)
- pymdown-extensions 11.0.1-1
+ [trixie] - pymdown-extensions <no-dsa> (Minor issue)
NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-9xwg-3r6f-jcx2
CVE-2026-5857 (Contiki-NG's MQTT client parse_publish_vhdr() in os/net/app-layer/mqtt ...)
NOT-FOR-US: Contiki-NG
@@ -1257,6 +1260,7 @@ CVE-2026-19054 (A vulnerability was detected in Lspace-io lspace-server up to 79
NOT-FOR-US: Lspace-io lspace-server
CVE-2026-18487 (A flaw was found in Epiphany. An issue in how the browser reads web ad ...)
- epiphany-browser <unfixed> (bug #1143966)
+ [trixie] - epiphany-browser <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/work_items/2897
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/commit/13dd600719d7aac532ed6c84ea0d12dd372d4ac4
CVE-2026-18367 (A privilege escalation vulnerability allows local users to execute arb ...)
@@ -1381,6 +1385,7 @@ CVE-2024-39024 (In Packetfence 13.2.0, the WebGui interface setting allows authe
TODO: check
CVE-2026-18938 (A flaw was found in p11-kit. A local attacker, or one with equivalent ...)
- p11-kit <unfixed>
+ [trixie] - p11-kit <no-dsa> (Minor issue)
NOTE: https://github.com/p11-glue/p11-kit/pull/777
NOTE: Fixed by: https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc (0.26.5)
CVE-2026-64638 (WordPress is vulnerable to a pre-auth reflected XSS vulnerability on t ...)
@@ -5059,6 +5064,7 @@ CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMap
NOTE: Fixed by: https://github.com/pion/stun/commit/fa9f074a33a8059c76c960b1fbee39f308002423 (v3.1.3)
CVE-2026-54787 (sigstore-go is a Go library for Sigstore signing and verification. Pri ...)
- sigstore-go 1.2.1-1
+ [trixie] - sigstore-go <no-dsa> (Minor issue)
NOTE: https://github.com/sigstore/sigstore-go/security/advisories/GHSA-wqqc-jjcq-vfxm
NOTE: https://github.com/sigstore/sigstore-go/pull/642
NOTE: https://github.com/sigstore/sigstore-go/commit/4594ab4c779d08be1f4419803a8249188f35ed5f (v1.2.1)
@@ -10261,9 +10267,11 @@ CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter of
CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
- unzip <unfixed> (bug #1142906)
CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
- - unzip <unfixed> (bug #1142905)
+ - unzip <unfixed> (bug #1142905; unimportant)
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-XXXX [heap OOB read in EF_IZUNIX3 extra field handler]
- - unzip <unfixed> (bug #1142904)
+ - unzip <unfixed> (bug #1142904; unimportant)
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin before 5.7.3 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control vulnerabilit ...)
@@ -10360,6 +10368,7 @@ CVE-2026-49478
NOTE: Fixed by: https://github.com/sigstore/fulcio/commit/378c654f48c3bafdced04ead7010aab2cb4c6ca1 (v1.8.6)
CVE-2026-48702
- rekor 1.5.2-1
+ [trixie] - rekor <no-dsa> (Minor issue)
NOTE: https://github.com/sigstore/rekor/pull/2831
NOTE: Fixed by: https://github.com/sigstore/rekor/commit/759b98e2a7c39ea9779b6a51299c5f0f987f8802 (v1.5.2)
CVE-2026-50540 (Kata Containers is an open source project focusing on a standard imple ...)
@@ -12615,6 +12624,7 @@ CVE-2026-6454 (The Firelight Lightbox plugin for WordPress is vulnerable to Stor
NOT-FOR-US: WordPress plugin
CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXT ...)
- zaqar 22.0.0-3 (bug #1142858)
+ [trixie] - zaqar <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/7
NOTE: https://launchpad.net/bugs/2161254
CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped user ...)
@@ -12893,6 +12903,7 @@ CVE-2026-65919 (Meshery before 1.0.57 contains an unauthenticated arbitrary file
NOT-FOR-US: Meshery
CVE-2026-65918 (PyTorch torchvision through 0.28.0, fixed in commit 4e05dc2, contains ...)
- pytorch-vision <unfixed> (bug #1142689)
+ [trixie] - pytorch-vision <no-dsa> (Minor issue)
NOTE: https://github.com/pytorch/vision/issues/9551
NOTE: https://github.com/pytorch/vision/pull/9520
NOTE: Fixed by: https://github.com/pytorch/vision/commit/4e05dc22f5f050a9528cc0ea09ceca6cdaf8f4ed
@@ -13218,6 +13229,7 @@ CVE-2026-64799 (Joomla Extension - regularlabs.com - SSRF via remote image downl
NOT-FOR-US: Joomla
CVE-2026-64611 (A flaw was found in libcupsfilters. The cfIEEE1284NormalizeMakeModel() ...)
- libcupsfilters <unfixed> (bug #1142686)
+ [trixie] - libcupsfilters <no-dsa> (Minor issue)
[bookworm] - libcupsfilters <postponed> (Minor issue)
[bullseye] - libcupsfilters <postponed> (Minor issue)
NOTE: https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-rcq7-rv5g-j3r4
@@ -21824,6 +21836,7 @@ CVE-2026-46341 (The Apify MCP server enables AI agents to extract data from webs
NOT-FOR-US: Apify MCP server
CVE-2026-46338 (PyMdown Extensions is a set of extensions for the Python-Markdown mark ...)
- pymdown-extensions 11.0.1-1
+ [trixie] - pymdown-extensions <no-dsa> (Minor issue)
NOTE: https://github.com/facelessuser/pymdown-extensions/security/advisories/GHSA-62q4-447f-wv8h
NOTE: Fixed by: https://github.com/facelessuser/pymdown-extensions/commit/63b7835776d703d6c339cf2110d9888f676efc0c (10.21.3)
CVE-2026-46336 (Manyfold is an open source, self-hosted web application for managing a ...)
@@ -23010,14 +23023,17 @@ CVE-2026-59888 (jackson-databind contains the general-purpose data-binding funct
NOTE: Fixed by: https://github.com/FasterXML/jackson-databind/commit/c7c678360624da5bc7eed2152789fa522880db9d (jackson-databind-2.18.8)
CVE-2026-59886 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the univ ...)
- pyasn1 0.6.4-1 (bug #1142388)
+ [trixie] - pyasn1 <no-dsa> (Minor issue)
NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-hm4w-wwcw-mr6r
NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/e60c691cb91addb8fcefa2f537e85ede6fb1e886 (v0.6.4)
CVE-2026-59885 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER, ...)
- pyasn1 0.6.4-1 (bug #1142388)
+ [trixie] - pyasn1 <no-dsa> (Minor issue)
NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-8ppf-4f7h-5ppj
NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/45bdb19eb7df4b3780fe9c912c63e99bffc39dd9 (v0.6.4)
CVE-2026-59884 (pyasn1 is a generic ASN.1 library for Python. Prior to 0.6.4, the BER ...)
- pyasn1 0.6.4-1 (bug #1142388)
+ [trixie] - pyasn1 <no-dsa> (Minor issue)
NOTE: https://github.com/pyasn1/pyasn1/security/advisories/GHSA-m4p7-r5rc-7g4j
NOTE: Fixed by: https://github.com/pyasn1/pyasn1/commit/628e36ecbb5277a3f01572ce418ef54271b165a5 (v0.6.4)
CVE-2026-59841 (A improper restriction of communication channel to intended endpoints ...)
@@ -24248,10 +24264,12 @@ CVE-2026-49783 (Improperly implemented security check for standard in Windows Se
NOT-FOR-US: Microsoft
CVE-2026-49477 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
- soupsieve 2.8.4-1
+ [trixie] - soupsieve <no-dsa> (Minor issue)
NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-836r-79rf-4m37
NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/eb4397618709186c109400448c6043b728217dc3 (2.8.4)
CVE-2026-49476 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
- soupsieve 2.8.4-1
+ [trixie] - soupsieve <no-dsa> (Minor issue)
NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-2wc2-fm75-p42x
NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/28108ab805818c832d9568142a99844fd95a0d39 (2.8.4)
CVE-2026-49459 (DOMPurify is a DOM-only cross-site scripting sanitizer for HTML, MathM ...)
@@ -41403,9 +41421,11 @@ CVE-2026-56221 (Cap-go before 12.128.2 contains multiple SQL injection vulnerabi
NOT-FOR-US: Cap-go
CVE-2026-55655 (A flaw was found in OpenSSH. A local unprivileged attacker on a Linux ...)
- openssh <unfixed> (bug #1143936)
+ [trixie] - openssh <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462250
CVE-2026-55654 (A flaw was found in OpenSSH. This vulnerability, a heap out-of-bounds ...)
- openssh <unfixed> (bug #1143924)
+ [trixie] - openssh <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462493
CVE-2026-55653 (A flaw was found in OpenSSH. A malicious SSH server can exploit a doub ...)
- openssh <not-affected> (Only an issue with FIPS patch which is not in Debian/upstream)
=====================================
data/dsa-needed.txt
=====================================
@@ -49,6 +49,10 @@ firebird4.0
--
gimp
--
+gst-plugins-bad1.0
+--
+ironic
+--
jackson-databind
--
jetty9
@@ -144,6 +148,8 @@ tomcat11
unbound
Michael Tokarev is working on rebasing to 1.25.2 (possibly 1.26.0)
--
+unzip
+--
util-linux (carnil)
Maintainer is preparing updates
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d4052ddcfd70277a9a16cadf6d41420c341e5c9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/6d4052ddcfd70277a9a16cadf6d41420c341e5c9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/e884f2ee/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list