[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Aug 14 11:43:52 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b2bc88ba by Moritz Muehlenhoff at 2026-08-14T12:43:00+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -441,6 +441,7 @@ CVE-2026-56865 (A malicious GOPROXY was previously capable of forging up to two
 	- golang-1.26 <unfixed> (bug #1144341)
 	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80744
@@ -452,6 +453,7 @@ CVE-2026-56864 (A malicious GOSUMDB was capable of serving arbitrary module cont
 	- golang-1.26 <unfixed> (bug #1144341)
 	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80745
@@ -463,6 +465,7 @@ CVE-2026-56859 (Previously, DecodeElement would reset the depth counter causing
 	- golang-1.26 <unfixed> (bug #1144341)
 	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80481
@@ -474,6 +477,7 @@ CVE-2026-56853 (When a server is configured to support unencrypted HTTP/2, it re
 	- golang-1.26 <unfixed> (bug #1144341)
 	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80205
@@ -485,6 +489,7 @@ CVE-2026-56860 (Previously, resolving relative paths containing parent directory
 	- golang-1.26 <unfixed> (bug #1144341)
 	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80494
@@ -496,6 +501,7 @@ CVE-2026-56862 (Handshake messages, such as KeyUpdate, are always considered as
 	- golang-1.26 <unfixed> (bug #1144341)
 	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80528
@@ -507,6 +513,7 @@ CVE-2026-56858 (Previously, pathological inputs could close an unescaped '/' ear
 	- golang-1.26 <unfixed> (bug #1144341)
 	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80435
@@ -518,6 +525,7 @@ CVE-2026-33818 (Enforce a recursion limit in Unmarshal to prevent stack exhausti
 	- golang-1.26 <unfixed> (bug #1144341)
 	- golang-1.25 <unfixed> (bug #1144342)
 	- golang-1.24 <removed>
+	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
 	- golang-1.15 <removed>
 	NOTE: https://github.com/golang/go/issues/80405
@@ -1468,15 +1476,18 @@ CVE-2026-73519 (WolfStack before 25.9.2 contains a hard-coded cluster-authentica
 	NOT-FOR-US: WolfStack
 CVE-2026-73501 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.144 ...)
 	- golang-github-getkin-kin-openapi <unfixed> (bug #1144345)
+	[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-r277-6w6q-xmqw
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/f0407d53b0730280266f454b755010e7eeb985da (v0.144.0)
 CVE-2026-73500 (etcd is a distributed key-value store for the data of a distributed sy ...)
 	- etcd <unfixed> (bug #1144346)
+	[trixie] - etcd <no-dsa> (Minor issue)
 	NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-6vch-q96h-7gc3
 	NOTE: https://github.com/etcd-io/etcd/pull/22130
 	NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/f73cba7d920019f91a1ea1f6697833e42731f057 (v3.5.33)
 CVE-2026-73499 (etcd is a distributed key-value store for the data of a distributed sy ...)
 	- etcd <unfixed> (bug #1144346)
+	[trixie] - etcd <no-dsa> (Minor issue)
 	NOTE: https://github.com/etcd-io/etcd/security/advisories/GHSA-xg4h-6gfc-h4m8
 	NOTE: Fixed by: https://github.com/etcd-io/etcd/commit/e863b001bbf3367003a543aa3099db9892134cd7 (v3.5.33)
 CVE-2026-73498 (MCP Atlassian is a Model Context Protocol (MCP) server for Atlassian p ...)
@@ -2497,12 +2508,14 @@ CVE-2026-73243 (kkFileView is a universal file online preview project based on S
 	NOT-FOR-US: kkFileView
 CVE-2026-73242 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.30.0+dfsg-1
+	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-vv64-95pc-vj9v
 	NOTE: https://github.com/FreeRDP/FreeRDP/pull/13065
 	NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/0adf5e30d01be84e190a359a7bdd37bc51d740cc (3.30.0)
 CVE-2026-73241 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.30.0+dfsg-1
+	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-rqgv-grx4-xm6x
 	NOTE: https://github.com/FreeRDP/FreeRDP/pull/13065
@@ -2657,6 +2670,7 @@ CVE-2026-19579 (Snipe-IT before 8.6.0 contains an authorization bypass (insecure
 	- snipe-it <itp> (bug #1005172)
 CVE-2026-19550 (A flaw was found in FreeIPA. The trust-fetch-domains command is gated  ...)
 	- freeipa <unfixed>
+	[trixie] - freeipa <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2514019
 CVE-2026-19217 (The Royal Addons for Elementor  WordPress plugin before 1.7.1065 does  ...)
 	NOT-FOR-US: WordPress plugin
@@ -3154,10 +3168,12 @@ CVE-2026-72712 (Nmap versions up to and including 7.99 contains a denial of serv
 	NOTE: Crash in CLI tool, no security impact
 CVE-2026-72694 (A flaw was found in MRTG. When the MRTG daemon is started as a root us ...)
 	- mrtg <unfixed>
+	[trixie] - mrtg <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460973
 	NOTE: Fixed by: https://github.com/oetiker/mrtg/commit/30e19216bfadc0148f347cb0a42fd5e2016e6269
 CVE-2026-72693 (`openvt -u` is intended to identify the owner of the current VT and th ...)
 	- kbd <unfixed>
+	[trixie] - kbd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462115
 	NOTE: Fixed by: https://github.com/legionus/kbd/commit/78d5ae119742e87baa7dbe0f5c4107e7533fd698 (v2.10.0)
 CVE-2026-72610 (A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.1 ...)
@@ -5004,6 +5020,7 @@ CVE-2026-66760 (SAP Approuter does not correctly validate client certificates in
 	NOT-FOR-US: SAP
 CVE-2026-63622 (A flaw was found in libvirt. A local attacker, specifically a process  ...)
 	- libvirt 12.6.0-1
+	[trixie] - libvirt <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513065
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/801160fd414ca2cc402bc01ead09b7ed4c3b8f5b (v12.6.0-rc2)
 CVE-2026-5304 (An ACAP configuration file lacks input validation, which could potenti ...)
@@ -5445,6 +5462,7 @@ CVE-2026-64940 (Tegalog -Fumy Otegaru Memo Logger- provided by Nishishi Factory
 	NOT-FOR-US: Nishishi Factory
 CVE-2026-63623 (A flaw was found in libvirt. During storage volume clone or convert op ...)
 	- libvirt 12.6.0-1
+	[trixie] - libvirt <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513066
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/69335a484768d550854da1133d5490074695e825 (v12.6.0-rc2)
 CVE-2026-63106 (ReadyEcommerce before 4.5.2 contains an unauthenticated SQL injection  ...)
@@ -10725,6 +10743,7 @@ CVE-2026-18322 (The Smart Popup by Supsystic plugin for WordPress is vulnerable
 	NOT-FOR-US: WordPress plugin
 CVE-2026-18103 (A flaw was found in dhcp-server. A remote attacker with network access ...)
 	- isc-dhcp <removed>
+	[trixie] - isc-dhcp <ignored> (ISC DHCP not covered by security support in Trixie)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2508081
 CVE-2026-17515 (The MLSImport: IDX Plugin & MLS Plugin for Real Estate Listings WordPr ...)
 	NOT-FOR-US: WordPress plugin



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bc88ba0050ac79720c6c33a8992e6f77fd9502

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b2bc88ba0050ac79720c6c33a8992e6f77fd9502
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/a55be9bb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list