[Git][security-tracker-team/security-tracker][master] Add Debian bug reference for some issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 16:51:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
43bb102d by Salvatore Bonaccorso at 2026-08-14T17:50:43+02:00
Add Debian bug reference for some issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -93,7 +93,7 @@ CVE-2026-73531 (django-helpdesk before 2.3.3 contains a stored cross-site script
 CVE-2026-73530 (Flyto2 Core before 2.28.0 contains a server-side request forgery guard ...)
 	NOT-FOR-US: Flyto2 Core
 CVE-2026-73489 (Russh is a Rust SSH client & server library. Prior to 0.62.4, an authe ...)
-	- rust-russh <unfixed>
+	- rust-russh <unfixed> (bug #1144400)
 	NOTE: https://github.com/Eugeny/russh/security/advisories/GHSA-cqjc-rmpq-xprq
 	NOTE: Fixed by: https://github.com/Eugeny/russh/commit/8912512371820167a12a0a638bd666856ce458ad (v0.62.4)
 CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory and file n ...)
@@ -4949,7 +4949,7 @@ CVE-2026-73035 (npm-check-updates through 23.0.2, fixed in commit b554b84, conta
 CVE-2026-73033 (Sucuri Security WordPress plugin through version 2.7.3 contains a path ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-73030 (unearth through 0.18.2, fixed in commit 6c78164, contains a path trave ...)
-	- unearth <unfixed>
+	- unearth <unfixed> (bug #1144401)
 	[trixie] - unearth <no-dsa> (Minor issue)
 	NOTE: https://github.com/frostming/unearth/issues/180
 	NOTE: https://github.com/frostming/unearth/pull/181
@@ -5452,7 +5452,7 @@ CVE-2026-71391 (GNU Emacs for Android contains an off-by-one error in the gvar t
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe
 CVE-2026-70622 (tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnera ...)
 	- rustc <undetermined>
-	- rust-tar <unfixed>
+	- rust-tar <unfixed> (bug #1144402)
 	NOTE: https://gist.github.com/thesmartshadow/e7dac0bb690ee17b9cc142154cb11726
 	TODO: check, unclear if reported upstream
 CVE-2026-6374 (Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601  ...)
@@ -8520,22 +8520,22 @@ CVE-2026-64663 (Statamic is a Laravel and Git powered content management system
 CVE-2026-64662 (Statamic is a Laravel and Git powered content management system (CMS). ...)
 	NOT-FOR-US: Statamic CMS
 CVE-2026-64655 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Prior to  ...)
-	- gh <unfixed>
+	- gh <unfixed> (bug #1144403)
 	[trixie] - gh <no-dsa> (Minor issue)
 	NOTE: https://github.com/cli/cli/security/advisories/GHSA-mm27-mwq9-fr5g
 	NOTE: https://github.com/cli/cli/commit/55dbb4dc6b7edb10b48e3d7fc5bccd32318d1b55 (v2.97.0)
 CVE-2026-64654 (GitHub CLI (gh) is GitHub's official command line tool. Prior to versi ...)
-	- gh <unfixed>
+	- gh <unfixed> (bug #1144403)
 	[trixie] - gh <no-dsa> (Minor issue)
 	NOTE: https://github.com/cli/cli/security/advisories/GHSA-3m3g-3wcr-px46
 	NOTE: https://github.com/cli/cli/commit/2a1409fe88d416cc85fc96fb5bc473f83ed5a054 (v2.97.0)
 CVE-2026-64653 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Prior to  ...)
-	- gh <unfixed>
+	- gh <unfixed> (bug #1144403)
 	[trixie] - gh <no-dsa> (Minor issue)
 	NOTE: https://github.com/cli/cli/security/advisories/GHSA-4fjg-2h4q-fwg3
 	NOTE: https://github.com/cli/cli/commit/0c2eea6338a2323cfff000160b9b5a56a38d2a06 (v2.97.0)
 CVE-2026-64652 (GitHub CLI (gh) is GitHub's official command line tool. Prior to versi ...)
-	- gh <unfixed>
+	- gh <unfixed> (bug #1144403)
 	[trixie] - gh <no-dsa> (Minor issue)
 	NOTE: https://github.com/cli/cli/security/advisories/GHSA-cg6r-mpgc-h9mm
 	NOTE: https://github.com/cli/cli/commit/3f6a16a9f8c7fe9676aa8d8f47b399310dd231c3 (v2.97.0)
@@ -34408,7 +34408,7 @@ CVE-2026-59833 (SiYuan is an open-source personal knowledge management system. P
 CVE-2026-59832 (SiYuan is an open-source personal knowledge management system. Prior t ...)
 	NOT-FOR-US: SiYuan
 CVE-2026-59831 (GitHub CLI (gh) is GitHub\u2019s official command line tool. From 2.10 ...)
-	- gh <unfixed>
+	- gh <unfixed> (bug #1144403)
 	[trixie] - gh <no-dsa> (Minor issue)
 	NOTE: https://github.com/cli/cli/security/advisories/GHSA-8cg3-r6g9-fpg2
 	NOTE: Fixed by: https://github.com/cli/cli/commit/b300f2ec7ec9dc9addc39b2ad88c54097ded7ca0 (v2.96.0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/43bb102df9ed82707c6dc2ffd16b1648a990bd72

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/43bb102df9ed82707c6dc2ffd16b1648a990bd72
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/b3f8f6f7/attachment.htm>


More information about the debian-security-tracker-commits mailing list