[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 12 12:37:09 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2a34e31f by Moritz Muehlenhoff at 2026-08-12T13:35:47+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1924,21 +1924,21 @@ CVE-2026-20770 (Protection mechanism failure for some Cluster Management Toolkit
 CVE-2026-20769 (Improper conditions check for the Intel(R) NPU Driver for all versions ...)
 	TODO: check
 CVE-2026-20765 (Incorrect comparison for some Intel(R) TDX Guest software before versi ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20763 (Incorrect calculation for some Intel(R) TDX Guest software before vers ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20755 (Protection mechanism failure for some LLM Scaler software within Ring  ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20752 (Improper authentication for some Intel(R) PROSet/Wireless WiFi Softwar ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20749 (Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Software wit ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20747 (Improper conditions check for some Intel(R) PROSet/Wireless WiFi Softw ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20745 (Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software fo ...)
 	NOT-FOR-US: Intel
 CVE-2026-20741 (Improper access control for some Intel(R) PROSet/Wireless WiFi Softwar ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20739 (Improper conditions check for some Intel(R) PROSet/Wireless WiFi Softw ...)
 	NOT-FOR-US: Intel
 CVE-2026-20737 (Exposure of sensitive information to an unauthorized actor for some In ...)
@@ -1948,13 +1948,13 @@ CVE-2026-20734 (Improper initialization in some firmware for some Intel(R) Activ
 CVE-2026-20731 (Improper buffer restrictions for the Intel(R) NPU Driver for all versi ...)
 	TODO: check
 CVE-2026-20728 (Protection mechanism failure for some Intel Extension for TensorFlow s ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20727 (Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Softwa ...)
 	NOT-FOR-US: Intel
 CVE-2026-20715 (Improper input validation in some firmware for some Intel(R) Active Ma ...)
 	TODO: check
 CVE-2026-20712 (Incomplete cleanup in some UEFI firmware for some Intel(R) reference p ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20708 (Insertion of sensitive information into log file in the subsystem for  ...)
 	TODO: check
 CVE-2026-20705 (Insecure storage of sensitive information in the Intel(R) TDX module f ...)
@@ -1968,17 +1968,17 @@ CVE-2026-19546 (A flaw was found in DBI. This is a fix for a partial fix for CVE
 CVE-2026-19539 (Authorization Bypass Through User-Controlled Key in the ticket managem ...)
 	TODO: check
 CVE-2026-19519 (A flaw was found in claircore's RPM package scanner. Crafted RPM heade ...)
-	TODO: check
+	NOT-FOR-US: claircore
 CVE-2026-19434 (Cross-site Scripting in the finding renderer in maalfer Pentestify bef ...)
-	TODO: check
+	NOT-FOR-US: Pentestify
 CVE-2026-19418 (The referrer enforcement introduced with TYPO3-CORE-SA-2020-006 (CVE-2 ...)
 	NOT-FOR-US: TYPO3 (core or extensions)
 CVE-2026-19078 (A flaw was found in the oauth-server component. This open redirect vul ...)
-	TODO: check
+	NOT-FOR-US: Red Hat OpenShift Container Platform 4
 CVE-2026-18972 (An authenticated attacker can spoof another GUI user's identity by sen ...)
-	TODO: check
+	NOT-FOR-US: Velociraptor
 CVE-2026-18860 (Velociraptor allows multi-tenant deployments named "Orgs".  By default ...)
-	TODO: check
+	NOT-FOR-US: Velociraptor
 CVE-2026-18712 (An issue in MongoDB Server's Queryable Encryption maintenance operatio ...)
 	- mongodb <removed>
 CVE-2026-18711 (An issue in MongoDB Server's query execution engine could allow an aut ...)
@@ -2028,7 +2028,7 @@ CVE-2026-18688 (An issue in MongoDB Server's aggregation framework could allow a
 CVE-2026-18687 (MongoDB Server's handling of a Queryable Encryption maintenance operat ...)
 	- mongodb <removed>
 CVE-2026-18640 (The NewNotebook API does not sufficiently sanitize its parameters allo ...)
-	TODO: check
+	NOT-FOR-US: Velociraptor
 CVE-2026-18639 (When Velociraptor is configured to use an OIDC IdP for authentication, ...)
 	NOT-FOR-US: Velociraptor
 CVE-2026-18638 (Any authenticated Velociraptor user \u2014 including one holding only  ...)
@@ -2054,17 +2054,17 @@ CVE-2026-15567 (A flaw was found in Wildfly. A remote unauthenticated attacker c
 CVE-2026-15565 (A flaw was found in Undertow. A remote attacker can cause Out of Memor ...)
 	TODO: check
 CVE-2026-15563 (A flaw was found in EAP's IIOP. The listener's NameService would accep ...)
-	TODO: check
+	NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15562 (A flaw was found in EAP's jboss-remoting. A remote unauthenticated att ...)
-	TODO: check
+	NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15561 (A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder.  ...)
 	TODO: check
 CVE-2026-15560 (when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attack ...)
-	TODO: check
+	NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15556 (A flaw was found in Picketlink's SP signature validation; a SAML respo ...)
-	TODO: check
+	NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15555 (A flaw was found in JBoss marshalling. The Infinispan session replicat ...)
-	TODO: check
+	NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
 CVE-2026-15554 (the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attri ...)
 	TODO: check
 CVE-2026-15426 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and Marketing Auto ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a34e31f9f4bd6b75777bcb81befbb970a88c4a4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2a34e31f9f4bd6b75777bcb81befbb970a88c4a4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/f13deffb/attachment.htm>


More information about the debian-security-tracker-commits mailing list