[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 13 14:58:22 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d170cb98 by Moritz Muehlenhoff at 2026-08-13T15:58:13+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -925,12 +925,15 @@ CVE-2026-XXXX [OSSN-0105: OpenStack Glance legacy Tasks import bypasses image im
NOTE: https://bugs.launchpad.net/glance/+bug/2152110
CVE-2026-12061
- nltk <unfixed>
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-fg7f-2386-8897
CVE-2026-12072
- nltk <unfixed>
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-6hm5-jgcp-p838
CVE-2026-12074
- nltk <unfixed>
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-xh95-f55m-82fw
CVE-2026-68868 (The Google Cloud Secret Manager secrets backend in Apache Airflow's Go ...)
NOT-FOR-US: Apache Airflow provider
@@ -3867,19 +3870,19 @@ CVE-2026-71577 (A flaw was found in multicluster-global-hub. During a ManagedClu
CVE-2026-71576 (A flaw was found in multicluster-global-hub. The manager component imp ...)
NOT-FOR-US: multicluster-global-hub
CVE-2026-71394 (GNU Emacs for Android improperly validates the table header input in s ...)
- - emacs <unfixed>
+ - emacs <not-affected> (Only affects builds for Android, SFNT not enabled)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=7621ee1d01229d50e5c0cddea6bf0b01095a62cf
CVE-2026-71393 (GNU Emacs for Android is vulnerable to an integer overflow in sfnt_rea ...)
- - emacs <unfixed>
+ - emacs <not-affected> (Only affects builds for Android, SFNT not enabled)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=d51a4722316efe0960994d371e1859099894d1ca
CVE-2026-71392 (GNU Emacs for Android is vulnerable to an integer overflow in the sfnt ...)
- - emacs <unfixed>
+ - emacs <not-affected> (Only affects builds for Android, SFNT not enabled)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=c4e20777c26548722a37b03db93243e83a0d6188
CVE-2026-71391 (GNU Emacs for Android contains an off-by-one error in the gvar table p ...)
- - emacs <unfixed>
+ - emacs <not-affected> (Only affects builds for Android, SFNT not enabled)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe
CVE-2026-70622 (tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnera ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d170cb982c61146ec86f58f0f60ef93f299bcbfe
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d170cb982c61146ec86f58f0f60ef93f299bcbfe
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/86904b5d/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list