[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Aug 11 13:15:17 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eee6a607 by Moritz Muehlenhoff at 2026-08-11T14:15:07+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -58,6 +58,7 @@ CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3 contains
NOT-FOR-US: WordPress plugin
CVE-2026-73030 (unearth through 0.18.2, fixed in commit 6c78164, contains a path trave ...)
- unearth <unfixed>
+ [trixie] - unearth <no-dsa> (Minor issue)
NOTE: https://github.com/frostming/unearth/issues/180
NOTE: https://github.com/frostming/unearth/pull/181
NOTE: Fixed by: https://github.com/frostming/unearth/commit/6c78164e7bfa28b8b3d6f247b87e560692e3c8ba
@@ -508,15 +509,18 @@ CVE-2026-72564 (An improper authorization vulnerability in fosrl/pangolin throug
NOT-FOR-US: fosrl/pangolin
CVE-2026-71969 (OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer u ...)
- optee-os <unfixed>
+ [trixie] - optee-os <no-dsa> (Minor issue)
NOTE: https://github.com/OP-TEE/optee_os/pull/7898
NOTE: https://github.com/OP-TEE/optee_os/pull/7808
NOTE: Fixed by: https://github.com/OP-TEE/optee_os/commit/7b8b494e0a324cefec8ed386b7de413b44f1aaf3
CVE-2026-71968 (OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-afte ...)
- optee-os <unfixed>
+ [trixie] - optee-os <no-dsa> (Minor issue)
NOTE: https://github.com/OP-TEE/optee_os/pull/7900
NOTE: Fixed by: https://github.com/OP-TEE/optee_os/commit/8794043c4065c26a2b8b1313794ba5ba5f06d296
CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null poi ...)
- optee-os <unfixed>
+ [trixie] - optee-os <no-dsa> (Minor issue)
NOTE: https://github.com/OP-TEE/optee_os/pull/7899
NOTE: Fixed by: https://github.com/OP-TEE/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833
CVE-2026-71964 (CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file ...)
@@ -6795,9 +6799,11 @@ CVE-2026-18574 (An authentication bypass vulnerability in Check Point Security M
NOT-FOR-US: Check Point Security Management Server
CVE-2026-18508 (A flaw was found in GNU tar. When extracting an archive with the --one ...)
- tar <unfixed> (bug #1143836)
+ [trixie] - tar <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509843
CVE-2026-18477 (A TOCTOU (Time-of-Check Time-of-Use) vulnerability in GNU tar's increm ...)
- tar <unfixed> (bug #1143836)
+ [trixie] - tar <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509735
CVE-2026-18248 (@fastify/aws-lambda version 6.4.0 decorates each Fastify request with ...)
NOT-FOR-US: fastify/aws-lambda
@@ -20110,12 +20116,12 @@ CVE-2026-63731 (HyperDX before 2.31.0 contains a server-side request forgery vul
CVE-2026-63730 (HyperDX before 2.31.0 contains a server-side request forgery vulnerabi ...)
NOT-FOR-US: HyperDX
CVE-2026-63729 (The SyncTeX parser (synctex_parser.c) shipped with TeX Live and embedd ...)
- - texlive-bin 2026.20260303.78225+ds-2
- [trixie] - texlive-bin <no-dsa> (Minor issue)
- - texstudio 4.9.6+ds-1
- - okular <unfixed>
+ - texlive-bin 2026.20260303.78225+ds-2 (unimportant)
+ - texstudio 4.9.6+ds-1 (unimportant)
+ - okular <unfixed> (unimportant)
NOTE: Fixed by: https://github.com/TeX-Live/texlive-source/commit/002dcd3eac30db5c352f53d4181737961cc7ee9a (svn78081)
NOTE: https://fatihhcelik.github.io/posts/evince-synctex-heap-use-after-free/
+ NOTE: Crash in CLI/GUI tool, no security impact
CVE-2026-63728 (Gitleaks prior to 8.30.1 contains a template injection vulnerability t ...)
NOT-FOR-US: Gitleaks
CVE-2026-62414 (Joomla Extension - joomlack.fr - Improper access control in Page Build ...)
@@ -26758,14 +26764,17 @@ CVE-2026-49978 (DOMPurify is a DOM-only cross-site scripting sanitizer for HTML,
NOTE: Fixed by: https://github.com/cure53/DOMPurify/commit/ca30f070c360df162a3e3848e80e6fd3c9e74bff (3.4.7)
CVE-2026-49855 (Tornado is a Python web framework and asynchronous networking library. ...)
- python-tornado <unfixed> (bug #1142277)
+ [trixie] - python-tornado <no-dsa> (Minor issue)
NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-mgf9-4vpg-hj56
NOTE: Fixed by: https://github.com/tornadoweb/tornado/commit/ff808b33adc52d89a549376a5e3628e92abbc8ff (v6.5.6)
CVE-2026-49854 (Tornado is a Python web framework and asynchronous networking library. ...)
- python-tornado <unfixed> (bug #1142277)
+ [trixie] - python-tornado <no-dsa> (Minor issue)
NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-cx3h-4qpv-8hc9
NOTE: Fixed by: https://github.com/tornadoweb/tornado/commit/96dc88c2a05705287856b2cd6b4b4034f9a6aaac (v6.5.6)
CVE-2026-49853 (Tornado is a Python web framework and asynchronous networking library. ...)
- python-tornado <unfixed> (bug #1142277)
+ [trixie] - python-tornado <no-dsa> (Minor issue)
NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-3x9g-8vmp-wqvf
CVE-2026-49808 (Concurrent execution using shared resource with improper synchronizati ...)
NOT-FOR-US: Microsoft
@@ -28675,6 +28684,9 @@ CVE-2026-57219 (RabbitMQ is a messaging and streaming broker. Prior to 3.13.15,
NOTE: https://github.com/rabbitmq/rabbitmq-server/commit/98b1daf740237c85941e8addcbea6e74f4a2743c (v4.2.6)
CVE-2026-57218 (RabbitMQ is a messaging and streaming broker. Prior to 4.2.6, RabbitMQ ...)
- rabbitmq-server 4.3.0-2
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x)
+ [bullseye] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x)
NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-wmrr-4h5v-5ch7
NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/16092
NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/16097
@@ -28703,6 +28715,9 @@ CVE-2026-57215 (RabbitMQ is a messaging and streaming broker. Prior to 3.13.15,
NOTE: https://github.com/rabbitmq/rabbitmq-server/commit/c84f3c880e0f22b49c01237cf8f86e176eeadc72 (v4.2.6)
CVE-2026-57214 (RabbitMQ is a messaging and streaming broker. Prior to 4.2.5, the Rabb ...)
- rabbitmq-server 4.3.0-2
+ [trixie] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x)
+ [bookworm] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x)
+ [bullseye] - rabbitmq-server <not-affected> (Vulnerable code not present, only affects 4.2.x)
NOTE: https://github.com/rabbitmq/rabbitmq-server/security/advisories/GHSA-6jfq-prw2-7rwp
NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/15606
NOTE: https://github.com/rabbitmq/rabbitmq-server/pull/15608
@@ -283025,6 +283040,7 @@ CVE-2024-43698 (Kieback & Peter's DDC4000 seriesuses weak credentials, which may
NOT-FOR-US: Kieback & Peter's DDC4000 series
CVE-2024-42643 (Integer Overflow in fast_ping.c in SmartDNS Release46 allows remote at ...)
- smartdns <unfixed> (bug #1086146)
+ [trixie] - smartdns <no-dsa> (Minor issue)
[bookworm] - smartdns <postponed> (minor issue; DoS)
[bullseye] - smartdns <postponed> (minor issue; DoS)
NOTE: https://github.com/pymumu/smartdns/issues/1779
=====================================
data/dsa-needed.txt
=====================================
@@ -121,6 +121,8 @@ python-httplib2 (carnil)
python-msgpack
Problems with autopkgtests, maintainer pinged and waiting for feedback
--
+rabbitmq-server
+--
redis
--
roundcube
@@ -146,10 +148,14 @@ rust-wasmtime
--
shaarli
--
+spip
+--
srt
--
starlette
--
+swift
+--
tomcat10
--
tomcat11
@@ -168,6 +174,8 @@ vim
--
vips
--
+weechat
+--
xorg-server
--
xrdp
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eee6a607a64cbb8b950d07362c59e532d8bd0cd3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eee6a607a64cbb8b950d07362c59e532d8bd0cd3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/83993731/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list