[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 13 15:58:06 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dd1d07c7 by Moritz Muehlenhoff at 2026-08-13T16:57:57+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -38,16 +38,19 @@ CVE-2026-73493 (Http4s (http4s-blaze-server) is a minimal, idiomatic Scala inter
 	NOT-FOR-US: Http4s (http4s-blaze-server)
 CVE-2026-73492 (Loofah is a general library for manipulating and transforming HTML/XML ...)
 	- ruby-loofah 2.25.2-1
+	[trixie] - ruby-loofah <no-dsa> (Minor issue)
 	NOTE: https://github.com/flavorjones/loofah/security/advisories/GHSA-5qhf-9phg-95m2
 	NOTE: https://github.com/flavorjones/loofah/pull/308
 	NOTE: Fixed by: https://github.com/flavorjones/loofah/commit/f1be9d893b5a8dd79240441a912d8897e74c38c0 (v2.25.2)
 CVE-2026-73491 (Loofah is a general library for manipulating and transforming HTML/XML ...)
 	- ruby-loofah 2.25.2-1
+	[trixie] - ruby-loofah <no-dsa> (Minor issue)
 	NOTE: https://github.com/flavorjones/loofah/security/advisories/GHSA-8whx-365g-h9vv
 	NOTE: https://github.com/flavorjones/loofah/pull/308
 	NOTE: Fixed by: https://github.com/flavorjones/loofah/commit/5e91af861e3cdab47b91dd0b81f3afdfd13a5e19 (v2.25.2)
 CVE-2026-73490 (Loofah is a general library for manipulating and transforming HTML/XML ...)
 	- ruby-loofah 2.25.2-1
+	[trixie] - ruby-loofah <no-dsa> (Minor issue)
 	NOTE: https://github.com/flavorjones/loofah/security/advisories/GHSA-9wjq-cp2p-hrgf
 	NOTE: https://github.com/flavorjones/loofah/pull/308
 	NOTE: Fixed by: https://github.com/flavorjones/loofah/commit/20867b9be689521887364b74822c41ef830523c9 (v2.25.2)
@@ -1055,16 +1058,19 @@ CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop Protocol.
 	NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/pull/13065
 CVE-2026-73235 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
 	- freecad <unfixed>
+	[trixie] - freecad <no-dsa> (Minor issue)
 	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-cp6c-87x9-xf49
 	NOTE: https://github.com/FreeCAD/FreeCAD/pull/31280
 	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/7d1b8f5806db578db99feb348e55a6b0eaff7c73 (1.1.2)
 CVE-2026-73234 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
 	- freecad <unfixed>
+	[trixie] - freecad <no-dsa> (Minor issue)
 	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-5vqh-3v38-jw2r
 	NOTE: https://github.com/FreeCAD/FreeCAD/pull/31281
 	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/f19b18b7d93729a29a90e96e0ae192b5d054b86d (1.1.2)
 CVE-2026-73233 (FreeCAD is a free and open-source multiplatform 3D parametric modeler. ...)
 	- freecad <unfixed>
+	[trixie] - freecad <no-dsa> (Minor issue)
 	NOTE: https://github.com/FreeCAD/FreeCAD/security/advisories/GHSA-2rq3-gx3h-489q
 	NOTE: https://github.com/FreeCAD/FreeCAD/pull/31312
 	NOTE: Fixed by: https://github.com/FreeCAD/FreeCAD/commit/3f60d202a8246958232e2fbc74ba38a83483b74e (1.1.2)
@@ -3344,45 +3350,59 @@ CVE-2026-XXXX [GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses pa
 	NOTE: Fixed by: https://github.com/flatpak/xdg-dbus-proxy/commit/7cf6be73b7ad84f3c54d6fdae069c955948f78e4 (0.1.8)
 CVE-2026-73141 [GHSA-xmcv-mjpv-x46q: Audio decoders: stack VLA exhaustion]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-xmcv-mjpv-x46q
 CVE-2026-73142 [GHSA-5xr9-fmm8-7p8x: remotetrx NetUplink: connection object leak DoS]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-5xr9-fmm8-7p8x
 CVE-2026-73143 [GHSA-38fq-mrrg-8rmr: RtlTcp: malformed greeting causes daemon exit]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-38fq-mrrg-8rmr
 CVE-2026-73144 [GHSA-qccg-7pw6-787v: FRN module: unbounded memory growth]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-qccg-7pw6-787v
 CVE-2026-73145 [GHSA-58ph-q79f-7x9x: HTTP server: unbounded request accumulation]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-58ph-q79f-7x9x
 CVE-2026-73146 [GHSA-r2gm-p682-3mpm: svxreflector: use-after-free via reentrant client deletion]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-r2gm-p682-3mpm
 CVE-2026-73147 [GHSA-pc2g-2p95-4cr5: TCL command injection in reflector client]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-pc2g-2p95-4cr5
 CVE-2026-73148 [GHSA-6wgq-wg3w-jgvx: svxreflector: use-after-free write via dangling JSON reference]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-6wgq-wg3w-jgvx
 CVE-2026-73149 [GHSA-mh75-5pr3-qv2p: NetRx: out-of-bounds read via unvalidated MsgAudio length]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-mh75-5pr3-qv2p
 CVE-2026-73150 [GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-4f8x-49pf-3x5v
 CVE-2026-73151 [GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-x5r8-rq62-q9cj
 CVE-2026-73152 [GHSA-4g8q-rgxf-fmgf: EchoLink proxy: integer truncation in message length]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-4g8q-rgxf-fmgf
 CVE-2026-73153 [GHSA-624p-cp8x-6hp6: EchoLink RTCP/SDES: out-of-bounds read]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-624p-cp8x-6hp6
 CVE-2026-73154 [GHSA-5g48-xjmf-7p4q: StationData::setData stack overflow]
 	- svxlink 26.05.1-1
+	[trixie] - svxlink <no-dsa> (Minor issue)
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-5g48-xjmf-7p4q
 CVE-2026-XXXX [GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems]
 	- ostree 2026.3-1 (bug #1144106)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dd1d07c7e23ede686f6dcbbb90b0cebb37696329

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dd1d07c7e23ede686f6dcbbb90b0cebb37696329
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260813/cafd4935/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list