[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 13:55:06 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e14e50d7 by Salvatore Bonaccorso at 2026-08-14T14:51:09+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -733,12 +733,12 @@ CVE-2026-73514 (The address_standardizer extension for PostGIS through 3.7.0, fi
 CVE-2026-73509 (OpenList a file list program that supports multiple storage. Prior to  ...)
 	NOT-FOR-US: OpenList
 CVE-2026-73508 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1144384)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-mfg7-5gfp-c4w3
 	NOTE: https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b (netty-4.2.16.Final)
 	NOTE: https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 (netty-4.1.136.Final)
 CVE-2026-73507 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1144384)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-v74w-7mr3-4qg3
 	NOTE: https://github.com/netty/netty/commit/5b68c61f37aa4a3045cba624cbea239655c9003b (netty-4.2.16.Final)
 	NOTE: https://github.com/netty/netty/commit/bb2ff68a1fb71cb4b0eb9a9e17b66c52aff680c6 (netty-4.1.136.Final)
@@ -2970,22 +2970,22 @@ CVE-2026-73218 (Cursor is a code editor built for programming with AI. Prior to
 CVE-2026-73217 (Cursor is a code editor built for programming with AI. Prior to 3.1.2, ...)
 	NOT-FOR-US: Cursor
 CVE-2026-73216 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
-	- coturn <unfixed>
+	- coturn <unfixed> (bug #1144385)
 	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-f6hc-79w3-p8pq
 	NOTE: Fixed by: https://github.com/coturn/coturn/commit/3c5b2615fd405c4e7c5bf3fbeef895c94a90671b (4.17.0)
 CVE-2026-73215 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
-	- coturn <unfixed>
+	- coturn <unfixed> (bug #1144385)
 	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-847g-qmc6-6m4r
 	NOTE: Fixed by: https://github.com/coturn/coturn/commit/4adbd82e78456e13109bf44deed4ec3aceb0bab2 (4.17.0)
 CVE-2026-73214 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
-	- coturn <unfixed>
+	- coturn <unfixed> (bug #1144385)
 	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-5x2p-4vqj-f6m4
 	NOTE: https://github.com/coturn/coturn/pull/2003
 	NOTE: Fixed by: https://github.com/coturn/coturn/commit/beb4de9dcb6a475129595b943c9a34264420df09 (4.16.0)
 	NOTE: https://github.com/coturn/coturn/pull/2012
 	NOTE: Fixed by: https://github.com/coturn/coturn/commit/37e13d1d60af8f1422c01b5e9f1c6bc355d03b85 (4.16.0)
 CVE-2026-73213 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
-	- coturn <unfixed>
+	- coturn <unfixed> (bug #1144385)
 	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-4v97-rxjj-4f99
 	NOTE: Fixed by: https://github.com/coturn/coturn/commit/6c13608c28a04af5d63abddd7565a0dcc4771c28 (4.16.0)
 CVE-2026-73212 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
@@ -5373,18 +5373,18 @@ CVE-2026-72565 (A SQL injection vulnerability in Tencent APIJSON through 8.1.8 a
 CVE-2026-72564 (An improper authorization vulnerability in fosrl/pangolin through v1.2 ...)
 	NOT-FOR-US: fosrl/pangolin
 CVE-2026-71969 (OP-TEE OS through 4.10.0, fixed in commit 7b8b494, contains a buffer u ...)
-	- optee-os <unfixed>
+	- optee-os <unfixed> (bug #1144386)
 	[trixie] - optee-os <no-dsa> (Minor issue)
 	NOTE: https://github.com/OP-TEE/optee_os/pull/7898
 	NOTE: https://github.com/OP-TEE/optee_os/pull/7808
 	NOTE: Fixed by: https://github.com/OP-TEE/optee_os/commit/7b8b494e0a324cefec8ed386b7de413b44f1aaf3
 CVE-2026-71968 (OP-TEE OS through 4.10.0, fixed in commit 8794043, contains a use-afte ...)
-	- optee-os <unfixed>
+	- optee-os <unfixed> (bug #1144386)
 	[trixie] - optee-os <no-dsa> (Minor issue)
 	NOTE: https://github.com/OP-TEE/optee_os/pull/7900
 	NOTE: Fixed by: https://github.com/OP-TEE/optee_os/commit/8794043c4065c26a2b8b1313794ba5ba5f06d296
 CVE-2026-71967 (OP-TEE OS through 4.10.0, fixed in commit 0aadfc2, contains a null poi ...)
-	- optee-os <unfixed>
+	- optee-os <unfixed> (bug #1144386)
 	[trixie] - optee-os <no-dsa> (Minor issue)
 	NOTE: https://github.com/OP-TEE/optee_os/pull/7899
 	NOTE: Fixed by: https://github.com/OP-TEE/optee_os/commit/0aadfc23407f50e770eb5ddd871fc208f5626833
@@ -12655,7 +12655,7 @@ CVE-2025-69946 (SourceCodester Modern Loan Management System 1.0 is vulnerable t
 CVE-2025-15669 (The Bit Form  WordPress plugin before 3.1.4 does not sanitise one of i ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-56818 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1144384)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2507476
 	TODO: check missing upstream GHSA
 CVE-2026-9611



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e14e50d765e04cebc4d62c5575a10379c30a36c1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e14e50d765e04cebc4d62c5575a10379c30a36c1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/9e6780cd/attachment.htm>


More information about the debian-security-tracker-commits mailing list