[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 13 14:11:43 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
de41c3a6 by Moritz Muehlenhoff at 2026-08-13T15:09:29+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -994,6 +994,7 @@ CVE-2026-52059 [RSA-PSS CertificateVerify checks only 0xbc trailer]
 	- mongoose 7.22+ds-1
 CVE-2026-19566 (Net::CIDR::Set versions before 0.23 for Perl allow memory exhaustion a ...)
 	- libnet-cidr-set-perl 0.23-1
+	[trixie] - libnet-cidr-set-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42620063/
 	NOTE: https://github.com/robrwo/perl-Net-CIDR-Set/security/advisories/GHSA-grjr-r4x5-mx4p
 	NOTE: Fixed by: https://github.com/robrwo/perl-Net-CIDR-Set/commit/e16b27db676fd1ca671fbb31208a22c1b1ba9724 (0.23)
@@ -1050,7 +1051,8 @@ CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric mo
 	NOTE: https://github.com/FreeCAD/FreeCAD/pull/31312
 	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/3f60d202a8246958232e2fbc74ba38a83483b74e (1.1.2)
 CVE-2026-73232 (ffuf is a fast web fuzzer written in Go. Prior to 2.2.0, ffuf allows a ...)
-	- ffuf <unfixed>
+	- ffuf <unfixed> (unimportant)
+	NOTE: Crash in CLI tool, no security impact
 	NOTE: https://github.com/ffuf/ffuf/security/advisories/GHSA-jcvh-xf52-2cwm
 	NOTE: https://github.com/ffuf/ffuf/pull/897
 	NOTE: Fixed by: https://github.com/ffuf/ffuf/commit/fb0da86c60443b0dddbc9a86e91e3a6487dff79b (v2.2.0)
@@ -1294,14 +1296,17 @@ CVE-2026-19496
 	NOT-FOR-US: Red Hat sources-api-go
 CVE-2026-73283 (In sshd in OpenSSH before 10.5, the restrict keyword (in authorized_ke ...)
 	- openssh <unfixed> (bug #1144192)
+	[trixie] - openssh <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
 CVE-2026-73282 (In ssh in OpenSSH before 10.5, a use-after-free for realloc data can o ...)
 	- openssh <unfixed> (bug #1144192)
+	[trixie] - openssh <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
 CVE-2026-73281 (In ssh-agent in OpenSSH before 10.5, some operations can occur remotel ...)
 	- openssh <unfixed> (bug #1144192)
+	[trixie] - openssh <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/12/1
 	NOTE: https://www.openssh.org/releasenotes.html#10.5
 CVE-2026-68443 (In the Linux kernel, the following vulnerability has been resolved:  h ...)
@@ -1498,10 +1503,12 @@ CVE-2026-73090 (PeerTube is an ActivityPub-federated video streaming platform. P
 	- peertube <itp> (bug #950821)
 CVE-2026-73089 (Browserslist is a configuration tool for sharing target browsers and N ...)
 	- node-browserslist 4.28.7+~cs8.16.65-1
+	[trixie] - node-browserslist <no-dsa> (Minor issue)
 	NOTE: https://github.com/browserslist/browserslist/security/advisories/GHSA-c83g-rgw3-j3cx
 	NOTE: Fixed by: https://github.com/browserslist/browserslist/commit/f2931a3ff2a3a31abf84ef01a7400b270aad6405 (4.28.7)
 CVE-2026-73088 (Browserslist is a configuration tool for sharing target browsers and N ...)
 	- node-browserslist 4.28.7+~cs8.16.65-1
+	[trixie] - node-browserslist <no-dsa> (Minor issue)
 	NOTE: https://github.com/browserslist/browserslist/security/advisories/GHSA-73wf-gq98-2v4g
 	NOTE: Fixed by: https://github.com/browserslist/browserslist/commit/f9914ad9effc865ccc27d816255625890b31ca51 (4.28.7)
 CVE-2026-73087 (Dozzle is a realtime log viewer for docker containers. From 10.5.2 unt ...)
@@ -1572,12 +1579,14 @@ CVE-2026-73068 (ToolJet is the open-source foundation am AI-native platform for
 	NOT-FOR-US: ToolJet
 CVE-2026-73067 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...)
 	- tesseract <unfixed>
+	[trixie] - tesseract <no-dsa> (Minor issue)
 	NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-x3vq-7rr7-5x3h
 	NOTE: https://github.com/tesseract-ocr/tesseract/pull/4581
 	NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/55287a94b8044c05ce3fd10f5aca6ebbd238e518 (5.5.3)
 	NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/82727cc11c34eaf1249af002d69f6bbae70993b9 (5.5.3)
 CVE-2026-73066 (Tesseract is an open source OCR engine. Prior to 5.5.3, a crafted .tra ...)
 	- tesseract <unfixed>
+	[trixie] - tesseract <no-dsa> (Minor issue)
 	NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7j76-5rq5-5jg8
 	NOTE: https://github.com/tesseract-ocr/tesseract/pull/4588
 	NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/2f4d2f4bf45c363785d7bf1da29b6628f8939a72 (5.5.3)
@@ -3453,6 +3462,7 @@ CVE-2026-6505 (The ACAP framework contains a Time-of-Check to Time-of-Use (TOCTO
 	NOT-FOR-US: Axis Communication
 CVE-2026-6426 (A type mismatch vulnerability was found in QEMU's vhost inflight migra ...)
 	- qemu <unfixed>
+	[trixie] - qemu <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513498
 	NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3675
 CVE-2026-6181 (The Device Configuration Framework is vulnerable to an authentication  ...)
@@ -3880,6 +3890,7 @@ CVE-2026-6373 (Exposure of sensitive system information to an unauthorized contr
 	NOT-FOR-US: Zyxel
 CVE-2026-6368 (Calling wordexp with WRDE_APPEND in the GNU C Library version 2.0 to v ...)
 	- glibc <unfixed> (bug #1144252)
+	[trixie] - glibc <no-dsa> (Minor issue)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34090
 	NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0014
 CVE-2026-66915 (Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4. ...)
@@ -3892,14 +3903,17 @@ CVE-2026-66642 (Cross-Site Request Forgery (CSRF) vulnerability in WP Umbrella a
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66486 (GNU cpio is vulnerable to improper encoding or escaping of output in i ...)
 	- cpio <unfixed>
+	[trixie] - cpio <no-dsa> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=2ff9600c9ef32e88759843cdbde74c8db5ae9b30
 CVE-2026-66485 (GNU cpio is vulnerable to an uncontrolled memory allocation in the mak ...)
 	- cpio <unfixed>
+	[trixie] - cpio <no-dsa> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=3cd514031371d8aeeaf2048aa10103e02831aaa9
 CVE-2026-66484 (GNU cpio contains a Path Traversal vulnerability in its tar archive ex ...)
 	- cpio <unfixed>
+	[trixie] - cpio <no-dsa> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-66484
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/cpio.git/commit/?id=e2b9cbdd3354d2b1569b7390d1bc15c1930559ad
 CVE-2026-66411 (DEEBOT PRO M1 and DEEBOT PRO K1VAC incorrectly implement authenticatio ...)
@@ -4214,6 +4228,7 @@ CVE-2026-XXXX [HTML/CSS sanitization bypass via SVG animate `by` attribute]
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f (1.6.18)
 CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a usernam ...)
 	- glibc 2.43-3
+	[trixie] - glibc <no-dsa> (Minor issue)
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34091
 	NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0013
 CVE-2026-68424 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
@@ -9625,11 +9640,13 @@ CVE-2026-6837 (A post-authentication command injection vulnerability in the "exp
 	NOT-FOR-US: Zyxel
 CVE-2026-69249 (python-cryptography is a package designed to expose cryptographic prim ...)
 	- python-cryptography 49.0.0-1
+	[trixie] - python-cryptography <no-dsa> (Minor issue)
 	NOTE: https://github.com/pyca/cryptography/security/advisories/GHSA-jwv3-5hgf-82ww
 	NOTE: https://github.com/pyca/cryptography/pull/14960
 	NOTE: Fixed by: https://github.com/pyca/cryptography/commit/4a12cf49675a184e47f912b00b04f3a629283582 (49.0.0)
 CVE-2026-69248 (cryptography is a package designed to expose cryptographic primitives  ...)
 	- python-cryptography 49.0.0-1
+	[trixie] - python-cryptography <no-dsa> (Minor issue)
 	NOTE: https://github.com/pyca/cryptography/security/advisories/GHSA-m2h6-j472-rp4c
 	NOTE: https://github.com/pyca/cryptography/pull/14888
 	NOTE: Fixed by: https://github.com/pyca/cryptography/commit/4d035a4225965edeffd312079a510ef25fcfdcb2 (49.0.0)
@@ -14048,6 +14065,7 @@ CVE-2026-67201 (V through 0.5.2, fixed in commit 85859f0, contains a server-side
 	- vlang <itp> (bug #1081840)
 CVE-2026-67194 (Courier IMAP before 6.0.1 and Courier Mail Server before 2.0.2 allow a ...)
 	- courier 2.0.3-1
+	[trixie] - courier <no-dsa> (Minor issue)
 	[bookworm] - courier <postponed> (Minor issue; DoS; need authentificated user)
 	[bullseye] - courier <postponed> (Minor issue; DoS; need authentificated user)
 	NOTE: Fixed by: https://github.com/svarshavchik/courier-libs/commit/b5b5581aabea3efadf5e2944947ff0214aa3533e
@@ -22260,6 +22278,7 @@ CVE-2026-47671 (Nhost is an open source Firebase alternative with GraphQL. In ve
 	NOT-FOR-US: Nhost
 CVE-2026-47667 (CImg Library is a C++ library for image processing. Prior to version 4 ...)
 	- cimg <unfixed> (bug #1142677)
+	[trixie] - cimg <no-dsa> (Minor issue)
 	[bookworm] - cimg <postponed> (minor issue; DoS)
 	[bullseye] - cimg <postponed> (minor issue; DoS)
 	NOTE: https://github.com/GreycLab/CImg/security/advisories/GHSA-rmfc-grgj-qwhv



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de41c3a6aeb9194414c6613943b4d33e142cc7af

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de41c3a6aeb9194414c6613943b4d33e142cc7af
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/f8996ebf/attachment.htm>


More information about the debian-security-tracker-commits mailing list