[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 14 20:08:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
37c3b15c by Salvatore Bonaccorso at 2026-08-14T21:07:22+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7664,7 +7664,7 @@ CVE-2026-19343 (A flaw has been found in code-projects Task Management System 1.
 CVE-2026-19342 (A vulnerability was detected in code-projects Task Management System 1 ...)
 	NOT-FOR-US: code-projects
 CVE-2026-15534 (Perl versions through 5.45.1 have out-of-bounds heap reads and writes  ...)
-	- perl <unfixed>
+	- perl <unfixed> (bug #1144413)
 	[trixie] - perl <postponed> (Wait for exposure unstable and coordinate with Perl maintainers)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42536248/
 	NOTE: Fixed by: https://github.com/Perl/perl5/commit/568e6fd238867bb9e99fa3f47cba3169009239e0
@@ -7867,7 +7867,7 @@ CVE-2026-66061 (Home Assistant is open source home automation software focused o
 CVE-2026-66060 (Home Assistant is open source home automation software focused on loca ...)
 	NOT-FOR-US: Home Assistant
 CVE-2026-65819 (gopacket provides packet processing capabilities for Go. Through versi ...)
-	- golang-github-gopacket-gopacket <unfixed>
+	- golang-github-gopacket-gopacket <unfixed> (bug #1144416)
 	[trixie] - golang-github-gopacket-gopacket <no-dsa> (Minor issue)
 	- gopacket <unfixed>
 	[trixie] - gopacket <no-dsa> (Minor issue)
@@ -12564,7 +12564,7 @@ CVE-2026-62324 (Jodit Editor is a WYSIWYG editor with a built-in file browser &
 CVE-2026-55825 (Contao is an Open Source CMS. In versions 5.7.0 through 5.7.6, an auth ...)
 	NOT-FOR-US: Contao CMS
 CVE-2026-54909 (pion/stun is a Go implementation of STUN. Prior to 3.1.3, XORMappedAdd ...)
-	- golang-github-pion-stun-v3 <unfixed>
+	- golang-github-pion-stun-v3 <unfixed> (bug #1144414)
 	- golang-github-pion-stun <unfixed>
 	[trixie] - golang-github-pion-stun <no-dsa> (Minor issue)
 	NOTE: https://github.com/pion/stun/security/advisories/GHSA-34rh-wp3j-6cxc
@@ -16419,7 +16419,7 @@ CVE-2026-62828 (Improper input validation in Microsoft Edge for Android allows a
 CVE-2026-61609 (Pterodactyl is a free, open-source game server management panel. From  ...)
 	NOT-FOR-US: Pterodactyl
 CVE-2026-61487 (Improper Authorization vulnerability in Apache ActiveMQ Broker, Apache ...)
-	- activemq <unfixed>
+	- activemq <unfixed> (bug #1144412)
 	NOTE: https://lists.apache.org/thread/6rwn6cq65dy4lhmsmjf2bxnhbmhkcswz
 CVE-2026-61376 (ELECOM wireless LAN routers and access points devices contain an OS Co ...)
 	NOT-FOR-US: ELECOM wireless LAN routers
@@ -16432,7 +16432,7 @@ CVE-2026-59932 (PhpSpreadsheet is a pure PHP library for reading and writing spr
 CVE-2026-59931 (PhpSpreadsheet is a pure PHP library for reading and writing spreadshe ...)
 	NOT-FOR-US: PhpSpreadsheet
 CVE-2026-59878 (Improper Input Validation vulnerability in Apache ActiveMQ AMQP, Apach ...)
-	- activemq <unfixed>
+	- activemq <unfixed> (bug #1144412)
 	NOTE: https://lists.apache.org/thread/dnyx4d2oldshcj4lthso7b53y4bqmjvn
 CVE-2026-59764 (ELECOM wireless LAN routers and access points devices contain an OS Co ...)
 	NOT-FOR-US: ELECOM wireless LAN routers
@@ -43269,12 +43269,12 @@ CVE-2026-58052 (7-Zip for Windows through 26.01 fails to preserve the Mark-of-th
 	NOTE: https://github.com/bikini/exploitarium/tree/main/7zip-rar5-motw-chain-poc
 	NOTE: https://lists.debian.org/debian-lts/2026/07/msg00038.html
 CVE-2026-58051 (libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but  ...)
-	- libssh2 <unfixed>
+	- libssh2 <unfixed> (bug #1144415)
 	NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
 	NOTE: https://github.com/libssh2/libssh2/pull/2127
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a9758da45a52bc8c630ec9493804d0c6ea30b24a
 CVE-2026-58050 (libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute c ...)
-	- libssh2 <unfixed>
+	- libssh2 <unfixed> (bug #1144415)
 	NOTE: https://github.com/bikini/exploitarium/tree/main/libssh2-publickey-list-calc-poc
 	NOTE: https://github.com/libssh2/libssh2/pull/2128
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/34497525929b9a47f03dfb81887ac896202b7e12



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/37c3b15c2e8263b4361a968acfaa2d55431e5f9d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/37c3b15c2e8263b4361a968acfaa2d55431e5f9d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/5126e2f7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list