[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 13 14:58:22 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d170cb98 by Moritz Muehlenhoff at 2026-08-13T15:58:13+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -925,12 +925,15 @@ CVE-2026-XXXX [OSSN-0105: OpenStack Glance legacy Tasks import bypasses image im
 	NOTE: https://bugs.launchpad.net/glance/+bug/2152110
 CVE-2026-12061
 	- nltk <unfixed>
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-fg7f-2386-8897
 CVE-2026-12072
 	- nltk <unfixed>
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-6hm5-jgcp-p838
 CVE-2026-12074
 	- nltk <unfixed>
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-xh95-f55m-82fw
 CVE-2026-68868 (The Google Cloud Secret Manager secrets backend in Apache Airflow's Go ...)
 	NOT-FOR-US: Apache Airflow provider
@@ -3867,19 +3870,19 @@ CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a ManagedClu
 CVE-2026-71576 (A flaw was found in multicluster-global-hub. The manager component imp ...)
 	NOT-FOR-US: multicluster-global-hub
 CVE-2026-71394 (GNU Emacs for Android improperly validates the table header input in s ...)
-	- emacs <unfixed>
+	- emacs <not-affected> (Only affects builds for Android, SFNT not enabled)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=7621ee1d01229d50e5c0cddea6bf0b01095a62cf
 CVE-2026-71393 (GNU Emacs for Android is vulnerable to an integer overflow in sfnt_rea ...)
-	- emacs <unfixed>
+	- emacs <not-affected> (Only affects builds for Android, SFNT not enabled)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=d51a4722316efe0960994d371e1859099894d1ca
 CVE-2026-71392 (GNU Emacs for Android is vulnerable to an integer overflow in the sfnt ...)
-	- emacs <unfixed>
+	- emacs <not-affected> (Only affects builds for Android, SFNT not enabled)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=c4e20777c26548722a37b03db93243e83a0d6188
 CVE-2026-71391 (GNU Emacs for Android contains an off-by-one error in the gvar table p ...)
-	- emacs <unfixed>
+	- emacs <not-affected> (Only affects builds for Android, SFNT not enabled)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe
 CVE-2026-70622 (tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnera ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d170cb982c61146ec86f58f0f60ef93f299bcbfe

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d170cb982c61146ec86f58f0f60ef93f299bcbfe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/86904b5d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list