[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 12 08:13:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b920d348 by security tracker role at 2026-08-12T07:13:35+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,130 +1,386 @@
+CVE-2026-9318 (tablib prior to 3.10.0 contains a stored cross-site scripting vulnerab ...)
+	TODO: check
+CVE-2026-73250 (Notepad++ is a free and open-source source code editor. Prior to 8.9.7 ...)
+	TODO: check
+CVE-2026-73249 (calibre is an e-book manager. Prior to 9.12.0, the calibre Content Ser ...)
+	TODO: check
+CVE-2026-73248 (calibre is an e-book manager. Prior to 9.12.0, calibre processes attac ...)
+	TODO: check
+CVE-2026-73247 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
+	TODO: check
+CVE-2026-73246 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
+	TODO: check
+CVE-2026-73245 (Kestra is an open-source, event-driven orchestration platform. Prior t ...)
+	TODO: check
+CVE-2026-73244 (kkFileView is a universal file online preview project based on Spring  ...)
+	TODO: check
+CVE-2026-73243 (kkFileView is a universal file online preview project based on Spring  ...)
+	TODO: check
+CVE-2026-73242 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
+	TODO: check
+CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
+	TODO: check
+CVE-2026-73235 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
+	TODO: check
+CVE-2026-73234 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
+	TODO: check
+CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
+	TODO: check
+CVE-2026-73232 (ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a ...)
+	TODO: check
+CVE-2026-73231 (Faker generates massive amounts of fake data in the browser and Node.j ...)
+	TODO: check
+CVE-2026-73230 (Ente provides end-to-end encrypted cloud services and security tools.  ...)
+	TODO: check
+CVE-2026-73229 (Django REST framework is a powerful and flexible toolkit for building  ...)
+	TODO: check
+CVE-2026-73122 (A flaw was found in the multicloud-operators-channel component of Red  ...)
+	TODO: check
+CVE-2026-73036 (Bash-it 3.2.0 contains a terminal escape sequence injection vulnerabil ...)
+	TODO: check
+CVE-2026-73034 (DB-GPT v0.8.1 contains an unauthenticated path traversal vulnerability ...)
+	TODO: check
+CVE-2026-73032 (PapersGPT for Zotero 0.6.1 contains a remote code execution vulnerabil ...)
+	TODO: check
+CVE-2026-73031 (telegram-search contains a stored cross-site scripting vulnerability t ...)
+	TODO: check
+CVE-2026-72526 (A flaw was found in the multicloud-integrations component. The Applica ...)
+	TODO: check
+CVE-2026-71845 (A flaw was found in insights-client. The setDefault() function logs th ...)
+	TODO: check
+CVE-2026-71475 (A flaw was found in insights-client. A compromised managed cluster, re ...)
+	TODO: check
+CVE-2026-71474 (A flaw was found in insights-client. When the application receives a n ...)
+	TODO: check
+CVE-2026-71468 (A flaw was found in acm-search-v2-api-rhel9. When the `getFederationCo ...)
+	TODO: check
+CVE-2026-71467 (A flaw was found in search-v2-api. The authentication middleware in th ...)
+	TODO: check
+CVE-2026-71290 (Improper TLS hostname verification vulnerability in Apache HttpCompone ...)
+	TODO: check
+CVE-2026-70398 (A flaw was found in multicloud-integrations, a component of Red Hat Ad ...)
+	TODO: check
+CVE-2026-70339 (Access of resource using incompatible type ('type confusion') in Micro ...)
+	TODO: check
+CVE-2026-6484 (In an UEFI, Lack of verified boot to certain FV may cause arbitrary co ...)
+	TODO: check
+CVE-2026-68067 (The login endpoint on the Mira cloud API accepts any format-valid stri ...)
+	TODO: check
+CVE-2026-67568 (The distributed Mira Android APK v4.5.15.4 allows an attacker read/wri ...)
+	TODO: check
+CVE-2026-67558 (The Mira Android companion app v4.5.15.4 identifies the paired Mira ho ...)
+	TODO: check
+CVE-2026-66878 (A flaw was found in multicloud-operators-subscription. A privileged us ...)
+	TODO: check
+CVE-2026-66875 (In the Mira hormone monitor device firmware v1.7.1.47 build 01070147,  ...)
+	TODO: check
+CVE-2026-66832 (When the Mira Android app opens in-app WebView content (e.g., shop red ...)
+	TODO: check
+CVE-2026-66659 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
+	TODO: check
+CVE-2026-66340 (The Mira cloud authentication endpoints do not enforce per-account rat ...)
+	TODO: check
+CVE-2026-66154 (An insufficient certificate validation in a privileged communication w ...)
+	TODO: check
+CVE-2026-66150 (Improper Control of Generation of Code ('Code Injection') Vulnerabilit ...)
+	TODO: check
+CVE-2026-66149 (Improper Control of Generation of Code ('Code Injection') Vulnerabilit ...)
+	TODO: check
+CVE-2026-66148 (An authenticated command injection vulnerability was identified in GMS ...)
+	TODO: check
+CVE-2026-66147 (An unauthenticated command injection vulnerability was identified in t ...)
+	TODO: check
+CVE-2026-66146 (Multiple Cross-Site Scripting (XSS) vulnerabilities were identified in ...)
+	TODO: check
+CVE-2026-66145 (An unauthenticated remote code execution vulnerability was identified  ...)
+	TODO: check
+CVE-2026-66098 (The Mira hormone monitor device firmware accepts a 0x01 write from any ...)
+	TODO: check
+CVE-2026-65655 (When OAuth authentication is enabled and browser-facing TLS terminates ...)
+	TODO: check
+CVE-2026-64954 (Velociraptor allows scheduling new collections via VQL queries in note ...)
+	TODO: check
+CVE-2026-64934 (The Mira cloud API accepts the firmware version reported by the compan ...)
+	TODO: check
+CVE-2026-64927 (A flaw was found in the multicloud-operators-channel component. This v ...)
+	TODO: check
+CVE-2026-63177 (Malcolm is a network traffic analysis tool suite. Prior to version 26. ...)
+	TODO: check
+CVE-2026-63134 (Malcolm is a network traffic analysis tool suite. Prior to version 26. ...)
+	TODO: check
+CVE-2026-63133 (Malcolm is a network traffic analysis tool suite. Prior to version 26. ...)
+	TODO: check
+CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH bac ...)
+	TODO: check
+CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The file-upload comp ...)
+	TODO: check
+CVE-2026-48813 (Flawfinder is a a static analysis tool for finding vulnerabilities in  ...)
+	TODO: check
+CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO realtime c ...)
+	TODO: check
+CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
+	TODO: check
+CVE-2026-48763 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 expose a d ...)
+	TODO: check
+CVE-2026-48762 (TypeBot is a chatbot builder tool. Prior to version 3.16.0, the OpenAI ...)
+	TODO: check
+CVE-2026-45618 (LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior t ...)
+	TODO: check
+CVE-2026-29036 (cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resolved na ...)
+	TODO: check
+CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow v ...)
+	TODO: check
+CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API (`snowflake.co ...)
+	TODO: check
+CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung Open Sour ...)
+	TODO: check
+CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung Open Source ...)
+	TODO: check
+CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass (insecure direc ...)
+	TODO: check
+CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command is gated  ...)
+	TODO: check
+CVE-2026-19217 (The Royal Addons for Elementor  WordPress plugin before 1.7.1065 does  ...)
+	TODO: check
+CVE-2026-19091 (The GeoDirectory \u2013 WP Business Directory Plugin and Classified Li ...)
+	TODO: check
+CVE-2026-19073 (The Order Sync with Zendesk for WooCommerce WordPress plugin before 2. ...)
+	TODO: check
+CVE-2026-19052 (The ProSolution WP Client WordPress plugin before 2.0.9 does not perfo ...)
+	TODO: check
+CVE-2026-19050 (The ProSolution WP Client WordPress plugin before 2.0.9 does not valid ...)
+	TODO: check
+CVE-2026-18962 (The WP Photo Album Plus WordPress plugin before 9.2.09.002 does not ch ...)
+	TODO: check
+CVE-2026-18961 (The Social Login, Passkeys, Magic Link & Email OTP \u2013 Passwordless ...)
+	TODO: check
+CVE-2026-18943 (The WPC Admin Columns WordPress plugin before 2.3.4 does not have auth ...)
+	TODO: check
+CVE-2026-18844 (The firmware of thePulsetto Vagus Nerve Stimulatoraccepts several undi ...)
+	TODO: check
+CVE-2026-18789 (The Ezoic WordPress plugin before 2.23.1 does not properly restrict ac ...)
+	TODO: check
+CVE-2026-18710 (A MongoDB driver component could write sensitive configuration informa ...)
+	TODO: check
+CVE-2026-18634 (An insecure handling of serialized objects vulnerability was found in  ...)
+	TODO: check
+CVE-2026-18474 (The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise a ...)
+	TODO: check
+CVE-2026-18391 (The WooCommerce Subscriptions WordPress plugin before 9.1.0 does not v ...)
+	TODO: check
+CVE-2026-18366 (The Events Manager  WordPress plugin before 7.4.1 does not properly sc ...)
+	TODO: check
+CVE-2026-18230 (The WP Directory Kit WordPress plugin before 1.5.6 does not sanitise a ...)
+	TODO: check
+CVE-2026-18057 (The Events Manager  WordPress plugin before 7.4.1 does not sanitise an ...)
+	TODO: check
+CVE-2026-18049 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not pe ...)
+	TODO: check
+CVE-2026-18048 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not va ...)
+	TODO: check
+CVE-2026-18046 (The Cookie Consent  WordPress plugin before 0.0.10 does not correctly  ...)
+	TODO: check
+CVE-2026-18035 (The User Access Manager WordPress plugin before 2.3.15 does not apply  ...)
+	TODO: check
+CVE-2026-17013 (The WP Photo Album Plus WordPress plugin before 9.2.07.002 does not sa ...)
+	TODO: check
+CVE-2026-16977 (The Form Maker by 10Web  WordPress plugin before 1.15.45 does not prop ...)
+	TODO: check
+CVE-2026-16737 (The WP Travel Engine  WordPress plugin before 6.8.5 does not perform a ...)
+	TODO: check
+CVE-2026-16538 (The Wallet for WooCommerce WordPress plugin before 1.6.10 does not ver ...)
+	TODO: check
+CVE-2026-16294 (The PowerPress Podcasting plugin by Blubrry WordPress plugin before 11 ...)
+	TODO: check
+CVE-2026-16253 (The Total Upkeep  WordPress plugin before 1.17.3 does not adequately p ...)
+	TODO: check
+CVE-2026-16230 (The Formidable Digital Signatures plugin for WordPress is vulnerable t ...)
+	TODO: check
+CVE-2026-16066 (The Welcart e-Commerce WordPress plugin before 2.11.34 does not saniti ...)
+	TODO: check
+CVE-2026-16051 (The wpmudev-updates WordPress plugin before 5.0.1 does not verify the  ...)
+	TODO: check
+CVE-2026-15606 (The Frontend Admin by DynamiApps plugin for WordPress is vulnerable to ...)
+	TODO: check
+CVE-2026-15388 (The Cookie Consent  WordPress plugin before 0.0.10 does not correctly  ...)
+	TODO: check
+CVE-2026-15249 (The Patterns Kit WordPress plugin through 1.0.3 does not escape a link ...)
+	TODO: check
+CVE-2026-15039 (The giftware WordPress plugin before 4.2.10 does not validate the type ...)
+	TODO: check
+CVE-2026-14925 (The Import WP  WordPress plugin before 2.14.23 does not perform any au ...)
+	TODO: check
+CVE-2026-14863 (FileRun up to and including version 2026.2.0 contains an OS command in ...)
+	TODO: check
+CVE-2026-14859 (The WP Crowdfunding WordPress plugin before 2.2.1 does not check the c ...)
+	TODO: check
+CVE-2026-14858 (The WP Crowdfunding WordPress plugin before 2.2.1 does not verify orde ...)
+	TODO: check
+CVE-2026-14857 (The WP Crowdfunding WordPress plugin before 2.2.1 does not verify owne ...)
+	TODO: check
+CVE-2026-13613 (The KiviCare  WordPress plugin before 4.5.2 does not properly sanitise ...)
+	TODO: check
+CVE-2026-13612 (The KiviCare  WordPress plugin before 4.5.2 does not verify that the r ...)
+	TODO: check
+CVE-2026-13457 (The InstaWP Connect \u2013 1-click WP Staging & Migration plugin for W ...)
+	TODO: check
+CVE-2026-13177 (The Eventin  WordPress plugin before 4.1.20 does not properly restrict ...)
+	TODO: check
+CVE-2026-13171 (The Eventin  WordPress plugin before 4.1.20 does not perform an author ...)
+	TODO: check
+CVE-2026-13168 (The Eventin  WordPress plugin before 4.1.20 does not properly restrict ...)
+	TODO: check
+CVE-2026-12976 (The LearnPress  WordPress plugin before 4.4.4 does not verify that a u ...)
+	TODO: check
+CVE-2026-12235 (The Linkable Loadable Extensions (llext) subsystem mis-handles PLT/REL ...)
+	TODO: check
+CVE-2026-12234 (The userspace syscall verifiers z_vrfy_zsock_sendmsg() and z_vrfy_zsoc ...)
+	TODO: check
+CVE-2026-12233 (The PSA Protected Storage credential backend (subsys/net/lib/tls_crede ...)
+	TODO: check
+CVE-2026-12232 (The Intel ALH digital-audio-interface driver function dai_alh_get_prop ...)
+	TODO: check
+CVE-2025-15687 (A security flaw has been discovered in Open5GS up to 2.7.6. Impacted i ...)
+	TODO: check
+CVE-2025-15686 (A vulnerability has been found in Open5GS up to 2.7.6. Affected by thi ...)
+	TODO: check
+CVE-2025-15685 (A flaw has been found in Open5GS up to 2.7.1. Affected by this vulnera ...)
+	TODO: check
+CVE-2025-15684 (A vulnerability was detected in Open5GS up to 2.7.6. Affected is the f ...)
+	TODO: check
+CVE-2024-14044 (A vulnerability was identified in Open5GS up to 2.7.1. This issue affe ...)
+	TODO: check
+CVE-2024-14043 (A vulnerability was determined in Open5GS up to 2.7.1. This vulnerabil ...)
+	TODO: check
+CVE-2024-14042 (A vulnerability was found in Open5GS up to 2.7.1. This affects the fun ...)
+	TODO: check
 CVE-2026-19496
 	NOT-FOR-US: Red Hat sources-api-go
-CVE-2026-73283
+CVE-2026-73283 (In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_ke ...)
 	- openssh <unfixed> (bug #1144192)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
-CVE-2026-73282
+CVE-2026-73282 (In ssh in OpenSSH before 10.5, a use-after-free for realloc data can o ...)
 	- openssh <unfixed> (bug #1144192)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
-CVE-2026-73281
+CVE-2026-73281 (In ssh-agent in OpenSSH before 10.5, some operations can occur remotel ...)
 	- openssh <unfixed> (bug #1144192)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
-CVE-2026-68443 [hwmon: (gigabyte_waterforce) Stop device IO before calling hid_hw_stop]
+CVE-2026-68443 (In the Linux kernel, the following vulnerability has been resolved:  h ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/ff0c5c53d08274e200b48a4d53aa078265e873cb (7.2-rc5)
-CVE-2026-68442 [btrfs: don't propagate EXTENT_FLAG_LOGGING to split extent maps]
+CVE-2026-68442 (In the Linux kernel, the following vulnerability has been resolved:  b ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/5eff4d5b17fa1950e80bfd1ba43dc0699e61a644 (7.2-rc5)
-CVE-2026-68440 [net: txgbe: fix heap overflow when reading module EEPROM]
+CVE-2026-68440 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.6-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/6a905a71fd43ce8b45f05044b11491337f232c9d (7.2-rc5)
-CVE-2026-68439 [wifi: mt76: mt7925: fix possible NULL-pointer deref in mt7925_mcu_bss_he_tlv()]
+CVE-2026-68439 (In the Linux kernel, the following vulnerability has been resolved:  w ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/8d1b6738c1ab48c086b17e7994034aca94258931 (7.2-rc5)
-CVE-2026-68438 [smp: Make CSD lock acquisition atomic for debug mode]
+CVE-2026-68438 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.6-1
 	[trixie] - linux <not-affected> (Vulnerable code not present)
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/35551efb155e3b83445a6c3f66cb498d5efc182c (7.2-rc5)
-CVE-2026-68437 [drm/imagination: Fit paired fragment job in the correct CCCB]
+CVE-2026-68437 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/4baf9e70cb756d78dd56419f8baee2978a72d0c3 (7.2-rc1)
-CVE-2026-68429 [drm/dp_mst: Handle torn-down topology gracefully in drm_dp_mst_topology_queue_probe()]
+CVE-2026-68429 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/613059875958e7b217b250ed14c3b189f9488421 (7.2-rc2)
-CVE-2026-68450 [btrfs: free mapping node on duplicate reloc root insert]
+CVE-2026-68450 (In the Linux kernel, the following vulnerability has been resolved:  b ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/6a8269b6459ed870a8156c106a0f597383907872 (7.2-rc5)
-CVE-2026-68449 [ata: sata_dwc_460ex: fix infinite loop in NCQ tag completion bit-scanning]
+CVE-2026-68449 (In the Linux kernel, the following vulnerability has been resolved:  a ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	NOTE: https://git.kernel.org/linus/c2130f6553f4a5cbdc259de069600117a995f197 (7.2-rc4)
-CVE-2026-68448 [ovl: check access to copy_file_range source with src mounter creds]
+CVE-2026-68448 (In the Linux kernel, the following vulnerability has been resolved:  o ...)
 	- linux 7.1.6-1
 	NOTE: https://git.kernel.org/linus/a1e0eb8f55cfe09bb31a202a388babc411292656 (7.2-rc5)
-CVE-2026-68447 [drm/amdkfd: clamp v9 CRIU control stack checkpoint copy to BO size]
+CVE-2026-68447 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.6-1
 	NOTE: https://git.kernel.org/linus/426ffae6ecc7ec77d32bf8be065c21a1b881b084 (7.2-rc2)
-CVE-2026-68446 [drm/vmwgfx: Validate vmw_surface_metadata::array_size]
+CVE-2026-68446 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	NOTE: https://git.kernel.org/linus/a4f55260f7f7d4dc4d0ee55063dfb0c457b77991 (7.2-rc5)
-CVE-2026-68445 [drm/vc4: Prevent shader BO mappings from becoming writable]
+CVE-2026-68445 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	NOTE: https://git.kernel.org/linus/0c9e6367639548307d3f578f6943ce72c9d39087 (7.2-rc5)
-CVE-2026-68444 [firmware: arm_ffa: Fix NULL dereference in ffa_partition_info_get()]
+CVE-2026-68444 (In the Linux kernel, the following vulnerability has been resolved:  f ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/8ae5f8e4836667fcaffdf2e3c6068b0a8b364dd8 (7.2-rc4)
-CVE-2026-68441 [net/sched: Handle TC_ACT_REDIRECT from qdisc filter chains]
+CVE-2026-68441 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.6-1
 	NOTE: https://git.kernel.org/linus/ec48b3be2c8595dd290be883dbd4fb8b2f9f5d5e (7.2-rc5)
-CVE-2026-68436 [drm/amd/display: use kvzalloc to allocate struct dc]
+CVE-2026-68436 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.6-1
 	NOTE: https://git.kernel.org/linus/75050390151a14802be433c3856ddcb483cecd24 (7.2-rc2)
-CVE-2026-68435 [LoongArch: Fix address space mismatch in kexec command line lookup]
+CVE-2026-68435 (In the Linux kernel, the following vulnerability has been resolved:  L ...)
 	- linux 7.1.6-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/485ed44db5694d8d2e5027f63ad608e705286f30 (7.2-rc5)
-CVE-2026-68434 [serial: 8250_mid: Fix NULL function pointer dereference on DNV/ICX-D/SNR platforms]
+CVE-2026-68434 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	NOTE: https://git.kernel.org/linus/7fb13fd7e9a59a37cd911efff83abe19e3ee029d (7.2-rc5)
-CVE-2026-68433 [libceph: bound get_version reply decode to front len]
+CVE-2026-68433 (In the Linux kernel, the following vulnerability has been resolved:  l ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	NOTE: https://git.kernel.org/linus/d3c32939fa0e3ee9b883b9a0fd1972c5c444e3d0 (7.2-rc5)
-CVE-2026-68432 [vxlan: require CAP_NET_ADMIN in the device netns for changelink]
+CVE-2026-68432 (In the Linux kernel, the following vulnerability has been resolved:  v ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	NOTE: https://git.kernel.org/linus/3a61bd9637f3d929aa846e4eb3d98b48c26fcb0e (7.2-rc5)
-CVE-2026-68431 [ksmbd: validate minimum PDU size for transform requests]
+CVE-2026-68431 (In the Linux kernel, the following vulnerability has been resolved:  k ...)
 	- linux 7.1.6-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/cfc0b8e5080aec87700774e8568765eaa4b7b92b (7.2-rc5)
-CVE-2026-68430 [drm/amdgpu/gfx8: drop unecessary BUG_ON()]
+CVE-2026-68430 (In the Linux kernel, the following vulnerability has been resolved:  d ...)
 	- linux 7.1.6-1
 	[trixie] - linux 6.12.101-1
 	NOTE: https://git.kernel.org/linus/84a1a8a952ab4b8c23c5dd1f2eea4049cb4914f5 (7.2-rc2)
-CVE-2026-19556
+CVE-2026-19556 (Use after free in V8 in Google Chrome prior to 151.0.7922.137 allowed  ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19557
+CVE-2026-19557 (Use after free in TabStrip in Google Chrome on Mac prior to 151.0.7922 ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19558
+CVE-2026-19558 (Use after free in Extensions in Google Chrome prior to 151.0.7922.137  ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19559
+CVE-2026-19559 (Use after free in HTML in Google Chrome prior to 151.0.7922.137 allowe ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
-CVE-2026-19560
+CVE-2026-19560 (Use after free in Blink in Google Chrome prior to 151.0.7922.137 allow ...)
 	- chromium <unfixed>
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9214 (Insufficient input validation vulnerability in the NETGEAR R7000 model ...)
@@ -766,7 +1022,7 @@ CVE-2026-65678 (Use after free in Windows Win32K allows an authorized attacker t
 	NOT-FOR-US: Microsoft
 CVE-2026-65675 (No cwe for this issue in Visual Studio Code CoPilot Chat Extension all ...)
 	NOT-FOR-US: Microsoft
-CVE-2026-65673 (CVET-EOP)
+CVE-2026-65673 (Entra Connect Elevation of Privilege Vulnerability)
 	NOT-FOR-US: Microsoft
 CVE-2026-65672 (Heap-based buffer overflow in Windows Remote Access API allows an auth ...)
 	NOT-FOR-US: Microsoft
@@ -10738,7 +10994,7 @@ CVE-2026-62268
 	NOTE: Fixed by: https://github.com/borgbackup/borg/commit/3e9ed6d1ad6d3531b39c07b8ef3ecf41fce4437f (1.4.5)
 	NOTE: Fixed by: https://github.com/borgbackup/borg/commit/141888f2fabcd57a300547c2aa63212cb213924d (1.4.5)
 CVE-2026-9672
-	{DSA-6409-1}
+	{DSA-6409-1 DLA-4731-1}
 	- libgd2 2.3.3-14 (bug #1143152)
 	- php8.4 8.4.24-1 (unimportant)
 	[trixie] - php8.4 8.4.24-1~deb13u1
@@ -10758,14 +11014,14 @@ CVE-2026-17544 (Attacker-provided inputs to bccomp() could lead to an out-of-bou
 	NOTE: Fixed by: https://github.com/php/php-src/commit/fa18dab73f9340448c0d5c0a1d75d3fec844b358 (php-8.4.24)
 	NOTE: Introduced with: https://github.com/php/php-src/commit/063c3c852236ecbe45ab23c0fb271b6292ce82c3 (php-8.4.3RC1)
 CVE-2026-17543 (Improper escaping of backslashes in attacker-provided parameters would ...)
-	{DSA-6406-1}
+	{DSA-6406-1 DLA-4733-1 DLA-4732-1}
 	- php8.4 8.4.24-1 (bug #1143153)
 	- php8.2 <removed>
 	- php7.4 <removed>
 	NOTE: https://github.com/php/php-src/security/advisories/GHSA-7qpv-r5mr-78m4
 	NOTE: Fixed by: https://github.com/php/php-src/commit/53ac7025451c6481d44cf1835bb8385299a6a3a3 (php-8.4.24)
 CVE-2026-7260 (Circular symbolic links in phar archives could lead to unbounded recur ...)
-	{DSA-6406-1}
+	{DSA-6406-1 DLA-4733-1 DLA-4732-1}
 	- php8.4 8.4.24-1 (bug #1143153)
 	- php8.2 <removed>
 	- php7.4 <removed>
@@ -21169,7 +21425,7 @@ CVE-2026-10675 (In Zephyr's Bluetooth Mesh PB-ADV provisioning bearer (subsys/bl
 CVE-2026-10674 (The NXP LPUART serial driver (drivers/serial/uart_mcux_lpuart.c), when ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
 CVE-2026-47010 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6425-1 DLA-4703-1 DLA-4702-1}
+	{DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1
 	- openjdk-21 21.0.12+8-1
@@ -21178,7 +21434,7 @@ CVE-2026-47010 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
 	- openjdk-8 8u502-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-46917 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6425-1 DLA-4703-1 DLA-4702-1}
+	{DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1
 	- openjdk-21 21.0.12+8-1
@@ -21186,7 +21442,7 @@ CVE-2026-46917 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
 	- openjdk-11 11.0.32+9-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-47021 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6425-1 DLA-4703-1 DLA-4702-1}
+	{DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1
 	- openjdk-21 21.0.12+8-1
@@ -21195,7 +21451,7 @@ CVE-2026-47021 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
 	- openjdk-8 8u502-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-47027 (Vulnerability in Oracle Java SE (component: Libraries).  Supported ver ...)
-	{DSA-6425-1 DLA-4703-1 DLA-4702-1}
+	{DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1
 	- openjdk-21 21.0.12+8-1
@@ -21204,7 +21460,7 @@ CVE-2026-47027 (Vulnerability in Oracle Java SE (component: Libraries).  Support
 	- openjdk-8 8u502-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-47059 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6425-1 DLA-4703-1 DLA-4702-1}
+	{DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1
 	- openjdk-21 21.0.12+8-1
@@ -21213,7 +21469,7 @@ CVE-2026-47059 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Ora
 	- openjdk-8 8u502-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-46968 (Vulnerability in Oracle Java SE (component: JSSE).  Supported versions ...)
-	{DSA-6425-1 DLA-4703-1 DLA-4702-1}
+	{DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1
 	- openjdk-21 21.0.12+8-1
@@ -21222,7 +21478,7 @@ CVE-2026-46968 (Vulnerability in Oracle Java SE (component: JSSE).  Supported ve
 	- openjdk-8 8u502-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-60147 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6425-1 DLA-4703-1 DLA-4702-1}
+	{DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1
 	- openjdk-21 21.0.12+8-1
@@ -21236,7 +21492,7 @@ CVE-2026-47058 (Vulnerability in Oracle Java SE (component: Scripting).  Support
 	- openjdk-8 8u502-ga-1
 	NOTE: https://openjdk.org/groups/vulnerability/advisories/2026-07-21
 CVE-2026-47063 (Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle Gr ...)
-	{DSA-6425-1 DLA-4703-1 DLA-4702-1}
+	{DSA-6431-1 DSA-6425-1 DLA-4703-1 DLA-4702-1}
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1
 	- openjdk-21 21.0.12+8-1
@@ -89599,7 +89855,7 @@ CVE-2026-5250
 CVE-2026-4801 (The Page Builder Gutenberg Blocks \u2013 CoBlocks plugin for WordPress ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-41254 (Little CMS (lcms2) through 2.18 has an integer overflow in CubeSize in ...)
-	{DSA-6425-1 DSA-6262-1 DLA-4703-1 DLA-4702-1 DLA-4568-1}
+	{DSA-6431-1 DSA-6425-1 DSA-6262-1 DLA-4703-1 DLA-4702-1 DLA-4568-1}
 	- lcms2 2.17-1.1 (bug #1134335)
 	- openjdk-26 26.0.2+10-1
 	- openjdk-25 25.0.4+7-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b920d3485ea26b00db6199cd701471222faf9c75

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b920d3485ea26b00db6199cd701471222faf9c75
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/baace2e4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list