[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Aug 10 18:05:41 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
da2bd0df by Moritz Muehlenhoff at 2026-08-10T17:05:08+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1825,6 +1825,7 @@ CVE-2026-12570 (A vulnerability in keras-team/keras versions <= 3.15.0 allows fo
 	[bullseye] - keras <end-of-life> (EOL in bullseye LTS)
 CVE-2026-12372 (A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk ...)
 	- nltk <unfixed>
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513003
 CVE-2026-70395 (Improper Neutralization of Special Elements in Data Query Logic vulner ...)
 	NOT-FOR-US: ash-project ash
@@ -5129,6 +5130,7 @@ CVE-2026-69098 (kotaemon through 0.12.0 contains an insecure deserialization vul
 	NOT-FOR-US: kotaemon
 CVE-2026-68743 (A flaw was found in SSSD. The extract_authtok_v1() function in the PAM ...)
 	- sssd <unfixed> (bug #1143947)
+	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509760
 CVE-2026-68494 (The fix released in jackson-core 2.18.6 and 2.21.1 for CVE-2026-18401  ...)
 	- jackson-core <not-affected> (Incomplete fix for CVE-2026-18401 not applied)
@@ -5461,6 +5463,7 @@ CVE-2026-68979 (Apache NiFI 1.10.0 through 2.10.0 provide a Parameter Context up
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-68744 (A flaw was found in SSSD. The sss_nss_protocol_fill_initgr() function  ...)
 	- sssd <unfixed> (bug #1143600)
+	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509761
 CVE-2026-67978 (An issue in the SBN UDP interface of NASA cFS v7.0.1 allows attackers  ...)
 	NOT-FOR-US: NASA cFS
@@ -5794,8 +5797,8 @@ CVE-2026-68869
 	REJECTED
 CVE-2026-68742 (A flaw was found in SSSD. The sss_nss_protocol_parse_addr() function i ...)
 	- sssd <unfixed> (bug #1143600)
+	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509762
-	TODO: check upstream status
 CVE-2026-68587 (SiYuan versions before v3.7.3 contain an information disclosure vulner ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-68586 (SiYuan before v3.7.3 fails to apply publish-access filters to the getB ...)
@@ -9779,6 +9782,7 @@ CVE-2026-67215 (cJSON through 1.7.19 is vulnerable to uncontrolled recursion lea
 	NOTE: https://joshua.hu/cjson-json-parser-cve-vulnerabilities
 CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in the custom ...)
 	- node-postcss 8.5.15+~cs9.3.39-1
+	[trixie] - node-postcss <no-dsa> (Minor issue)
 	- node-mocha 9.1.4+ds1+~cs28.2.8-1
 	[bullseye] - node-mocha <postponed> (Minor issue, only test framework)
 	NOTE: node-postcss bundles nanoid
@@ -9786,6 +9790,7 @@ CVE-2026-67214 (nanoid (Nano ID) before 5.1.16 contains an infinite loop in the
 	NOTE: Fixed by: https://github.com/ai/nanoid/commit/6de05d794f62eeac3f527c74c34c6af0c1d32e49 (5.1.16)
 CVE-2026-67213 (nanoid (Nano ID) before 5.1.6 contains an infinite loop in the customA ...)
 	- node-postcss 8.5.8+~cs9.3.30-1
+	[trixie] - node-postcss <no-dsa> (Minor issue)
 	- node-mocha 9.1.4+ds1+~cs28.2.8-1
 	[bullseye] - node-mocha <postponed> (Minor issue, only test framework)
 	NOTE: node-postcss bundles nanoid
@@ -13785,6 +13790,7 @@ CVE-2026-66374 (Knot Resolver before 6.4.1 allows remote code execution via a he
 	[bullseye] - knot-resolver <not-affected> (Vulnerable code not present, quic support added in 6.2)
 	NOTE: https://openwall.com/lists/oss-security/2026/07/23/6
 	NOTE: https://github.com/venglin/knot-doq
+	NOTE: https://lists.nic.cz/hyperkitty/list/knot-resolver-announce@lists.nic.cz/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
 CVE-2026-9765 (Note: The CVE and blog post don't exist because we determined this is  ...)
 	NOT-FOR-US: Grafana
 CVE-2026-8789 (The Easy Appointments plugin for WordPress is vulnerable to unauthoriz ...)
@@ -14135,6 +14141,7 @@ CVE-2026-64208 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/2b50aceafe6606ea52ed42aadd1b4d44a188aade (7.1-rc5)
 CVE-2026-63317 (Arbitrary Class Instantiation via XML Feature Generator Descriptor and ...)
 	- apache-opennlp <unfixed> (bug #1142855)
+	[trixie] - apache-opennlp <no-dsa> (Minor issue)
 	[bookworm] - apache-opennlp <postponed> (minor issue)
 	[bullseye] - apache-opennlp <postponed> (minor issue)
 	NOTE: https://lists.apache.org/thread/myr446n8t3gv8gq8wbpxm41olx16d8yj
@@ -14500,10 +14507,6 @@ CVE-2024-58354 (cal.com (calcom repository, later renamed cal.diy) is affected b
 	NOT-FOR-US: Cal.com (calcom/cal.diy)
 CVE-2024-58353 (Cal.com (repository calcom/cal.diy) in versions <= 4.7.15 is vulnerabl ...)
 	NOT-FOR-US: Cal.com (calcom/cal.diy)
-CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
-	- knot-resolver 6.4.1-1
-	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
-	NOTE: https://lists.nic.cz/hyperkitty/list/knot-resolver-announce@lists.nic.cz/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
 CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious bootc cont ...)
 	- ironic-python-agent 11.5.0-4 (bug #1142854)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
@@ -15564,6 +15567,7 @@ CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId creation
 	NOT-FOR-US: Cal.com OSS
 CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth authori ...)
 	- librest <unfixed> (bug #1142715)
+	[trixie] - librest <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2504432
 	NOTE: https://gitlab.gnome.org/GNOME/librest/-/issues/25
 CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
@@ -19469,6 +19473,7 @@ CVE-2026-64612 (A flaw was found in libcupsfilters and cups-filters. The PNG ima
 	NOTE: https://github.com/OpenPrinting/libcupsfilters/commit/e8888af31419 (2.2.0)
 CVE-2026-64194 (Net::DNS versions through 1.55 for Perl allow Denial of Service via de ...)
 	- libnet-dns-perl 1.56-1 (bug #1142503)
+	[trixie] - libnet-dns-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41989541/
 	NOTE: https://rt.cpan.org/Ticket/Display.html?id=179946
 CVE-2026-64193 (Net::DNS versions through 1.55 for Perl allow remote execution injecti ...)
@@ -19665,6 +19670,7 @@ CVE-2026-40187 (In egroupware version 26.0 and earlier, an authenticated adminis
 	- egroupware <removed>
 CVE-2026-39879 (Due to a missing sanitization call in [`afsql_dd_run_query`](https://g ...)
 	- syslog-ng <unfixed> (bug #1143061)
+	[trixie] - syslog-ng <no-dsa> (Minor issue)
 	[bookworm] - syslog-ng <postponed> (Minor issue)
 	[bullseye] - syslog-ng <postponed> (Minor issue)
 	NOTE: https://github.com/syslog-ng/syslog-ng/security/advisories/GHSA-qwf9-6222-m24m
@@ -23043,6 +23049,7 @@ CVE-2026-45162 (Pimcore is an Open Source Data & Experience Management Platform.
 	NOT-FOR-US: Pimcore
 CVE-2026-44722 (pyzipper is a replacement for Python's zipfile that can read and write ...)
 	- python-pyzipper <unfixed> (bug #1142473)
+	[trixie] - python-pyzipper <no-dsa> (Minor issue)
 	NOTE: https://github.com/danifus/pyzipper/security/advisories/GHSA-crqm-m339-7m2p
 	NOTE: Fixed by; https://github.com/danifus/pyzipper/commit/93ce88e7dfd1635443197dab3fb8d477cff579ae (v0.4.0)
 CVE-2026-22104 (Improper access control in Hashtopolis server web-interface chunk acti ...)
@@ -26207,6 +26214,7 @@ CVE-2026-47767 (Symfony is a PHP framework for web and console applications and
 	NOTE: https://github.com/symfony/symfony/commit/3228c3806ee511008bea19a95084d460b17e5d25 (v5.4.52, v6.4.40, v7.4.12, v8.0.12)
 CVE-2026-47737 (Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until ...)
 	- puma 8.0.2-1
+	[trixie] - puma <no-dsa> (Minor issue)
 	NOTE: https://github.com/puma/puma/security/advisories/GHSA-2vqw-3mp8-cgmx
 	NOTE: https://github.com/puma/puma/pull/3944
 	NOTE: https://github.com/puma/puma/pull/3947
@@ -26214,6 +26222,7 @@ CVE-2026-47737 (Puma is a Ruby/Rack web server built for parallelism. From 5.5.0
 	NOTE: https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58 (v7.2.1)
 CVE-2026-47736 (Puma is a Ruby/Rack web server built for parallelism. From 5.5.0 until ...)
 	- puma 8.0.2-1
+	[trixie] - puma <no-dsa> (Minor issue)
 	NOTE: https://github.com/puma/puma/security/advisories/GHSA-qpgp-93vx-g8v8
 	NOTE: https://github.com/puma/puma/commit/439c6136d9c2275721b7864db3ee78af7c80889f (v8.0.2)
 	NOTE: https://github.com/puma/puma/commit/ebe9db3929ab8299d19c8f5b41e8ef4f4b22fa58 (v7.2.1)
@@ -26664,6 +26673,7 @@ CVE-2026-42491
 	NOTE: https://xenbits.xen.org/xsa/advisory-498.html
 CVE-2026-15747 (Mojolicious versions from 4.59 before 9.48 for Perl expose a stable re ...)
 	- libmojolicious-perl 9.48+dfsg-1
+	[trixie] - libmojolicious-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/41816171/
 	NOTE: Fixed by: https://github.com/mojolicious/mojo/commit/01921fbbbbeca2d1397e082d4a647f9b84c24e27 (v9.48)
 CVE-2026-15392 (DBD::File versions before 1.651 for Perl do not ensure the table file  ...)
@@ -26987,12 +26997,10 @@ CVE-2026-61462 (mcp-gitlab contains a path traversal vulnerability in the job_id
 CVE-2026-60121 (Vitec Flamingo 4.12.2 contains an unauthenticated OS command injection ...)
 	NOT-FOR-US: Vitec Flamingo
 CVE-2026-60103 (Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerabili ...)
-	- blender <unfixed> (bug #1143049)
-	[trixie] - blender <no-dsa> (Minor issue)
-	[bookworm] - blender <postponed> (Minor issue, OOB read)
-	[bullseye] - blender <postponed> (Minor issue, OOB read)
+	- blender <unfixed> (bug #1143049; unimportant)
 	NOTE: https://projects.blender.org/blender/blender/pulls/161273
 	NOTE: Fixed by: https://projects.blender.org/blender/blender/commit/968972a918b5ed2d534295b639c54449d7de11cd
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-59523 (Missing Authorization vulnerability in NSquared Simply Schedule Appoin ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-59521 (Deserialization of Untrusted Data vulnerability in ShapedPlugin LLC Re ...)
@@ -27932,6 +27940,7 @@ CVE-2026-4661 (The WP CTA \u2013 Sticky CTA Builder, Generate Leads, Promote Sal
 	NOT-FOR-US: WordPress plugin
 CVE-2026-49844 (Improper encoding of non-finite floating-point values during MapMessag ...)
 	- apache-log4j2 <unfixed> (bug #1141960)
+	[trixie] - apache-log4j2 <no-dsa> (Minor issue)
 	NOTE: https://logging.apache.org/security.html#CVE-2026-49844
 	NOTE: https://github.com/apache/logging-log4j2/pull/4163
 	NOTE: Fixed by: https://github.com/apache/logging-log4j2/commit/19edb23e162d6c728a8c2221a240037d389ed300 (2.x branch)
@@ -264265,6 +264274,7 @@ CVE-2024-52046 (The ObjectSerializationDecoder in Apache MINA uses Java\u2019s n
 	[bookworm] - mina <no-dsa> (Minor issue)
 	[bullseye] - mina <postponed> (Minor issue; need specific conditions)
 	- mina2 2.2.9-1 (bug #1091530)
+	[trixie] - mina2 <no-dsa> (Minor issue)
 	[bookworm] - mina2 <no-dsa> (Minor issue)
 	[bullseye] - mina2 <postponed> (Minor issue; need specific conditions)
 	NOTE: https://lists.apache.org/thread/4wxktgjpggdbto15d515wdctohb0qmv8



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da2bd0df13d9e2cca7613b647069548ca9395084

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/da2bd0df13d9e2cca7613b647069548ca9395084
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/33c744e1/attachment.htm>


More information about the debian-security-tracker-commits mailing list