[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 13 14:11:43 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
de41c3a6 by Moritz Muehlenhoff at 2026-08-13T15:09:29+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -994,6 +994,7 @@ CVE-2026-52059 [RSA-PSS CertificateVerify checks only 0xbc trailer]
- mongoose 7.22+ds-1
CVE-2026-19566 (Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion a ...)
- libnet-cidr-set-perl 0.23-1
+ [trixie] - libnet-cidr-set-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42620063/
NOTE: https://github.com/robrwo/perl-Net-CIDR-Set/security/advisories/GHSA-grjr-r4x5-mx4p
NOTE: Fixed by: https://github.com/robrwo/perl-Net-CIDR-Set/commit/e16b27db676fd1ca671fbb31208a22c1b1ba9724 (0.23)
@@ -1050,7 +1051,8 @@ CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric mo
NOTE: https://github.com/FreeCAD/FreeCAD/pull/31312
NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/3f60d202a8246958232e2fbc74ba38a83483b74e (1.1.2)
CVE-2026-73232 (ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a ...)
- - ffuf <unfixed>
+ - ffuf <unfixed> (unimportant)
+ NOTE: Crash in CLI tool, no security impact
NOTE: https://github.com/ffuf/ffuf/security/advisories/GHSA-jcvh-xf52-2cwm
NOTE: https://github.com/ffuf/ffuf/pull/897
NOTE: Fixed by: https://github.com/ffuf/ffuf/commit/fb0da86c60443b0dddbc9a86e91e3a6487dff79b (v2.2.0)
@@ -1294,14 +1296,17 @@ CVE-2026-19496
NOT-FOR-US: Red Hat sources-api-go
CVE-2026-73283 (In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_ke ...)
- openssh <unfixed> (bug #1144192)
+ [trixie] - openssh <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
NOTE: https://www.openssh.org/releasenotes.html#10.5
CVE-2026-73282 (In ssh in OpenSSH before 10.5, a use-after-free for realloc data can o ...)
- openssh <unfixed> (bug #1144192)
+ [trixie] - openssh <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
NOTE: https://www.openssh.org/releasenotes.html#10.5
CVE-2026-73281 (In ssh-agent in OpenSSH before 10.5, some operations can occur remotel ...)
- openssh <unfixed> (bug #1144192)
+ [trixie] - openssh <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
NOTE: https://www.openssh.org/releasenotes.html#10.5
CVE-2026-68443 (In the Linux kernel, the following vulnerability has been resolved: h ...)
@@ -1498,10 +1503,12 @@ CVE-2026-73090 (PeerTube is an ActivityPub-federated video streaming platform. P
- peertube <itp> (bug #950821)
CVE-2026-73089 (Browserslist is a configuration tool for sharing target browsers and N ...)
- node-browserslist 4.28.7+~cs8.16.65-1
+ [trixie] - node-browserslist <no-dsa> (Minor issue)
NOTE: https://github.com/browserslist/browserslist/security/advisories/GHSA-c83g-rgw3-j3cx
NOTE: Fixed by: https://github.com/browserslist/browserslist/commit/f2931a3ff2a3a31abf84ef01a7400b270aad6405 (4.28.7)
CVE-2026-73088 (Browserslist is a configuration tool for sharing target browsers and N ...)
- node-browserslist 4.28.7+~cs8.16.65-1
+ [trixie] - node-browserslist <no-dsa> (Minor issue)
NOTE: https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g
NOTE: Fixed by: https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51 (4.28.7)
CVE-2026-73087 (Dozzle is a realtime log viewer for docker containers. From 10.5.2 unt ...)
@@ -1572,12 +1579,14 @@ CVE-2026-73068 (ToolJet is the open-source foundation am AI-native platform for
NOT-FOR-US: ToolJet
CVE-2026-73067 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-x3vq-7rr7-5x3h
NOTE: https://github.com/tesseract-ocr/tesseract/pull/4581
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/55287a94b8044c05ce3fd10f5aca6ebbd238e518 (5.5.3)
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/82727cc11c34eaf1249af002d69f6bbae70993b9 (5.5.3)
CVE-2026-73066 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7j76-5rq5-5jg8
NOTE: https://github.com/tesseract-ocr/tesseract/pull/4588
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/2f4d2f4bf45c363785d7bf1da29b6628f8939a72 (5.5.3)
@@ -3453,6 +3462,7 @@ CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTO
NOT-FOR-US: Axis Communication
CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost inflight migra ...)
- qemu <unfixed>
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513498
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3675
CVE-2026-6181 (The Device Configuration Framework is vulnerable to an authentication ...)
@@ -3880,6 +3890,7 @@ CVE-2026-6373 (Exposure of sensitive system information to an unauthorized contr
NOT-FOR-US: Zyxel
CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to v ...)
- glibc <unfixed> (bug #1144252)
+ [trixie] - glibc <no-dsa> (Minor issue)
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34090
NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014
CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
@@ -3892,14 +3903,17 @@ CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella a
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66486 (GNU cpio is vulnerable to improper encoding or escaping of output in i ...)
- cpio <unfixed>
+ [trixie] - cpio <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=2ff9600c9ef32e88759843cdbde74c8db5ae9b30
CVE-2026-66485 (GNU cpio is vulnerable to an uncontrolled memory allocation in the mak ...)
- cpio <unfixed>
+ [trixie] - cpio <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=3cd514031371d8aeeaf2048aa10103e02831aaa9
CVE-2026-66484 (GNU cpio contains a Path Traversal vulnerability in its tar archive ex ...)
- cpio <unfixed>
+ [trixie] - cpio <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=e2b9cbdd3354d2b1569b7390d1bc15c1930559ad
CVE-2026-66411 (DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authenticatio ...)
@@ -4214,6 +4228,7 @@ CVE-2026-XXXX [HTML/CSS sanitization bypass via SVG animate `by` attribute]
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f (1.6.18)
CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a usernam ...)
- glibc 2.43-3
+ [trixie] - glibc <no-dsa> (Minor issue)
NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34091
NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0013
CVE-2026-68424 (In the Linux kernel, the following vulnerability has been resolved: m ...)
@@ -9625,11 +9640,13 @@ CVE-2026-6837 (A post-authentication command injection vulnerability in the "exp
NOT-FOR-US: Zyxel
CVE-2026-69249 (python-cryptography is a package designed to expose cryptographic prim ...)
- python-cryptography 49.0.0-1
+ [trixie] - python-cryptography <no-dsa> (Minor issue)
NOTE: https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww
NOTE: https://github.com/pyca/cryptography/pull/14960
NOTE: Fixed by: https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582 (49.0.0)
CVE-2026-69248 (cryptography is a package designed to expose cryptographic primitives ...)
- python-cryptography 49.0.0-1
+ [trixie] - python-cryptography <no-dsa> (Minor issue)
NOTE: https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c
NOTE: https://github.com/pyca/cryptography/pull/14888
NOTE: Fixed by: https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2 (49.0.0)
@@ -14048,6 +14065,7 @@ CVE-2026-67201 (V through 0.5.2, fixed in commit 85859f0, contains a server-side
- vlang <itp> (bug #1081840)
CVE-2026-67194 (Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow a ...)
- courier 2.0.3-1
+ [trixie] - courier <no-dsa> (Minor issue)
[bookworm] - courier <postponed> (Minor issue; DoS; need authentificated user)
[bullseye] - courier <postponed> (Minor issue; DoS; need authentificated user)
NOTE: Fixed by: https://github.com/svarshavchik/courier-libs/commit/b5b5581aabea3efadf5e2944947ff0214aa3533e
@@ -22260,6 +22278,7 @@ CVE-2026-47671 (Nhost is an open source Firebase alternative with GraphQL. In ve
NOT-FOR-US: Nhost
CVE-2026-47667 (CImg Library is a C++ library for image processing. Prior to version 4 ...)
- cimg <unfixed> (bug #1142677)
+ [trixie] - cimg <no-dsa> (Minor issue)
[bookworm] - cimg <postponed> (minor issue; DoS)
[bullseye] - cimg <postponed> (minor issue; DoS)
NOTE: https://github.com/GreycLab/CImg/security/advisories/GHSA-rmfc-grgj-qwhv
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de41c3a6aeb9194414c6613943b4d33e142cc7af
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de41c3a6aeb9194414c6613943b4d33e142cc7af
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/f8996ebf/attachment.htm>
More information about the debian-security-tracker-commits
mailing list