[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 14 20:14:33 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1885a5c5 by security tracker role at 2026-08-14T19:14:27+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,249 @@
+CVE-2026-73850 (Emlog is an open source website building system. In 2.6.20 and earlier ...)
+ TODO: check
+CVE-2026-73849 (Emlog is an open source website building system. In 2.6.26 and earlier ...)
+ TODO: check
+CVE-2026-73847 (Emlog is an open source website building system. In 2.6.26 and earlier ...)
+ TODO: check
+CVE-2026-73846 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
+ TODO: check
+CVE-2026-73845 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
+ TODO: check
+CVE-2026-73844 (CKAN MCP Server is a tool for querying CKAN open data portals. Prior t ...)
+ TODO: check
+CVE-2026-73673 (Netis NC63 router firmware V3.0.0.3327 contains an unauthenticated fir ...)
+ TODO: check
+CVE-2026-73633 (Uncontrolled resource consumption vulnerability in the JSON plugin of ...)
+ TODO: check
+CVE-2026-73630 (SiYuan before v3.7.4 contains an information disclosure vulnerability ...)
+ TODO: check
+CVE-2026-73107
+ REJECTED
+CVE-2026-73051 (actix-http versions before 3.12.1 contain an HTTP request smuggling vu ...)
+ TODO: check
+CVE-2026-73049 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
+ TODO: check
+CVE-2026-73048 (SiYuan versions before v3.7.4 contain an information disclosure vulner ...)
+ TODO: check
+CVE-2026-72970 (Heap-based buffer overflow in Microsoft Edge (Chromium-based) allows a ...)
+ TODO: check
+CVE-2026-72859 (Budibase versions 3.39.4 before 3.40.0 contain an authorization regres ...)
+ TODO: check
+CVE-2026-72838 (FileBrowser versions before 2.63.19 fail to enforce the declared Uploa ...)
+ TODO: check
+CVE-2026-72837 (File Browser versions before 2.63.20 fail to honor the createUserDir i ...)
+ TODO: check
+CVE-2026-72836 (FileBrowser before 2.63.19 does not account for case-insensitive files ...)
+ TODO: check
+CVE-2026-72835 (filebrowser versions before v2.63.21 fail to canonicalize paths before ...)
+ TODO: check
+CVE-2026-72834 (filebrowser before 2.63.19 contains a permission bypass in the /api/re ...)
+ TODO: check
+CVE-2026-72833 (The Grav API plugin (getgrav/grav-plugin-api) versions >= 1.0.6 and <= ...)
+ TODO: check
+CVE-2026-72832 (Grav versions from 1.5.2 through 2.0.12 contain a stored cross-site sc ...)
+ TODO: check
+CVE-2026-72831 (The Flex Objects plugin (through 1.4.6, tested with Grav 2.0.11) conta ...)
+ TODO: check
+CVE-2026-72830 (Grav API plugin versions before 1.0.13 fail to enforce API key scope c ...)
+ TODO: check
+CVE-2026-72829 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains a ...)
+ TODO: check
+CVE-2026-72828 (Grav Plugin API (getgrav/grav-plugin-api) before 1.0.13 fails to enfor ...)
+ TODO: check
+CVE-2026-72827 (Grav CMS before 2.0.13 contains a server-side template injection vulne ...)
+ TODO: check
+CVE-2026-72826 (The getgrav/grav-plugin-api plugin before 1.0.13 fails to validate tha ...)
+ TODO: check
+CVE-2026-72825 (The getgrav/grav-plugin-api plugin before 1.0.13 contains an API-key s ...)
+ TODO: check
+CVE-2026-72824 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains a ...)
+ TODO: check
+CVE-2026-72823 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.13 contains a ...)
+ TODO: check
+CVE-2026-72822 (The getgrav/grav-plugin-api Composer package before 1.0.13 (affected < ...)
+ TODO: check
+CVE-2026-72821 (Grav Form plugin versions before 9.1.15 contain a stored cross-site sc ...)
+ TODO: check
+CVE-2026-72820 (Grav versions before 2.0.13 fail to properly validate backup profile r ...)
+ TODO: check
+CVE-2026-72819 (Grav CMS before 2.0.13 contains a remote code execution vulnerability ...)
+ TODO: check
+CVE-2026-72817 (go-chi/chi versions 0.9.0 before 5.3.0 contains an IP spoofing vulnera ...)
+ TODO: check
+CVE-2026-72816 (go-chi/chi through 5.2.1 contains an IP spoofing vulnerability in the ...)
+ TODO: check
+CVE-2026-72815 (go-chi chi versions >= 5.2.1 and before 5.3.0 contain an IP spoofing v ...)
+ TODO: check
+CVE-2026-72814 (The actix-files crate (actix_files) before version 0.6.10 contains an ...)
+ TODO: check
+CVE-2026-72813 (actix-files before 0.6.10 contains a denial of service vulnerability t ...)
+ TODO: check
+CVE-2026-72812 (SiYuan versions before v3.7.4 contain a missing authorization vulnerab ...)
+ TODO: check
+CVE-2026-72811 (SiYuan versions <= v3.7.2 contain a SQL injection vulnerability in the ...)
+ TODO: check
+CVE-2026-72810 (SiYuan versions before v3.7.4 contain a publish-boundary bypass vulner ...)
+ TODO: check
+CVE-2026-69101 (Datavane TIS v5.0.0 contains an XML external entity (XXE) injection vu ...)
+ TODO: check
+CVE-2026-66272 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
+ TODO: check
+CVE-2026-66271 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
+ TODO: check
+CVE-2026-66270 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
+ TODO: check
+CVE-2026-63702 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
+ TODO: check
+CVE-2026-63701 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
+ TODO: check
+CVE-2026-63700 (Dell Wyse Management Suite (WMS), versions prior to 2605.0.2, contain ...)
+ TODO: check
+CVE-2026-63361 (LimeSurvey Community Edition 7.0.5 contains an authenticated reflected ...)
+ TODO: check
+CVE-2026-57472 (Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pat ...)
+ TODO: check
+CVE-2026-57471 (Nozomi Networks Labs identified a CWE-22: Improper Limitation of a Pat ...)
+ TODO: check
+CVE-2026-57469 (Nozomi Networks Labs identified a CWE-352: Cross-Site Request Forgery ...)
+ TODO: check
+CVE-2026-53970 (ZeroBrew version 0.3.1 and prior contains a missing integrity verifica ...)
+ TODO: check
+CVE-2026-49989 (CrateDB is a distributed SQL database. Prior to versions 6.2.8 and 6.3 ...)
+ TODO: check
+CVE-2026-49986 (The Cortex MCP server (`neuro-cortex-memory`), a cross-platform persis ...)
+ TODO: check
+CVE-2026-49826 (Concourse is a container-based automation system written in Go. Prior ...)
+ TODO: check
+CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4 ...)
+ TODO: check
+CVE-2026-49282 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
+ TODO: check
+CVE-2026-49263 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
+ TODO: check
+CVE-2026-48528 (Metacat is data repository software that helps researchers preserve, s ...)
+ TODO: check
+CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amo ...)
+ TODO: check
+CVE-2026-46439 (compliance-trestle is a tooling platform for managing compliance as co ...)
+ TODO: check
+CVE-2026-46380 (compliance-trestle is a tooling platform for managing compliance as co ...)
+ TODO: check
+CVE-2026-1621 (Authentication bypass by primary weakness vulnerability in Universal S ...)
+ TODO: check
+CVE-2026-19884 (In Eclipse Theia versions up to and including 1.69.0, opening a folder ...)
+ TODO: check
+CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on Java (l ...)
+ TODO: check
+CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP response ...)
+ TODO: check
+CVE-2026-19871 (Use of Hard-coded Credentials in the human resources component in Rosk ...)
+ TODO: check
+CVE-2026-19870 (Authorization Bypass Through User-Controlled Key in the payroll module ...)
+ TODO: check
+CVE-2026-19847 (A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20 ...)
+ TODO: check
+CVE-2026-19846 (A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
+ TODO: check
+CVE-2026-19845 (A vulnerability was determined in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
+ TODO: check
+CVE-2026-19844 (A vulnerability was found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Th ...)
+ TODO: check
+CVE-2026-19841 (A flaw has been found in TRENDNET TEW-813DRU 1.01b01. Impacted is an u ...)
+ TODO: check
+CVE-2026-19839 (A vulnerability was detected in SourceCodester Simple Doctors Appointm ...)
+ TODO: check
+CVE-2026-19838 (A security vulnerability has been detected in Webkul Bagisto up to 2.4 ...)
+ TODO: check
+CVE-2026-19837 (A weakness has been identified in Webkul Bagisto up to 2.4.4. This aff ...)
+ TODO: check
+CVE-2026-19836 (A security flaw has been discovered in Webkul Bagisto up to 2.4.4. Aff ...)
+ TODO: check
+CVE-2026-19835 (A vulnerability was identified in Webkul Bagisto up to 2.4.4. Affected ...)
+ TODO: check
+CVE-2026-19834 (A vulnerability was determined in Webkul Bagisto up to 2.4.4. Affected ...)
+ TODO: check
+CVE-2026-19830 (A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1 ...)
+ TODO: check
+CVE-2026-19829 (A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4 ...)
+ TODO: check
+CVE-2026-19828 (A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-2026 ...)
+ TODO: check
+CVE-2026-19827 (A flaw has been found in alldatacenter alldata up to 0.6.8. This impac ...)
+ TODO: check
+CVE-2026-19826 (A vulnerability was detected in alldatacenter alldata up to 0.6.8. Thi ...)
+ TODO: check
+CVE-2026-19825 (A security vulnerability has been detected in SourceCodester Simple Cl ...)
+ TODO: check
+CVE-2026-19824 (A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_ ...)
+ TODO: check
+CVE-2026-19823 (A security flaw has been discovered in Tenda W20E 15.11.0.6(1068_1546_ ...)
+ TODO: check
+CVE-2026-19822 (A vulnerability was identified in Tenda W20E 15.11.0.6(1068_1546_841)_ ...)
+ TODO: check
+CVE-2026-19821 (A vulnerability was determined in Tenda AC12 15.03.06.23_multi_TD01. T ...)
+ TODO: check
+CVE-2026-19815 (A flaw has been found in TOTOLINK A800R 4.1.2cu.5137_B20200730. Affect ...)
+ TODO: check
+CVE-2026-19814 (A vulnerability was detected in TOTOLINK A800R 4.1.2cu.5137_B20200730. ...)
+ TODO: check
+CVE-2026-19813 (A security vulnerability has been detected in TOTOLINK A800R 4.1.2cu.5 ...)
+ TODO: check
+CVE-2026-19812 (A weakness has been identified in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
+ TODO: check
+CVE-2026-19794 (The WP-Stats plugin for WordPress is vulnerable to Stored Cross-Site S ...)
+ TODO: check
+CVE-2026-19768 (Improper control of generation of code ('Code Injection') in the setti ...)
+ TODO: check
+CVE-2026-19682 (A command injection vulnerability exists in Security Center where a re ...)
+ TODO: check
+CVE-2026-19681 (An authenticated command injection vulnerability exists in Security Ce ...)
+ TODO: check
+CVE-2026-19680 (A SQL injection vulnerability exists in Security Center that could all ...)
+ TODO: check
+CVE-2026-19679 (An input validation vulnerability exists in Security Center's file upl ...)
+ TODO: check
+CVE-2026-19639 (An improper access control vulnerability exists where an authenticated ...)
+ TODO: check
+CVE-2026-19636 (An issue was identified in which CSRF tokens were generated using a pr ...)
+ TODO: check
+CVE-2026-19635 (A local privilege escalation vulnerability exists in Security Center. ...)
+ TODO: check
+CVE-2026-19631 (A SQL injection vulnerability exists in Security Center that could all ...)
+ TODO: check
+CVE-2026-19629 (A privilege escalation vulnerability exists in Tenable Security Center ...)
+ TODO: check
+CVE-2026-19628 (A command injection vulnerability exists in Tenable Security Center. A ...)
+ TODO: check
+CVE-2026-19626 (A remote code execution vulnerability exists in Tenable Security Cente ...)
+ TODO: check
+CVE-2026-19188 (A critical OS command injection vulnerability has been identified in t ...)
+ TODO: check
+CVE-2026-18403 (LimeSurvey Community Edition 7.0.5 contains an authenticated SQL injec ...)
+ TODO: check
+CVE-2026-16772 (In Akaunting versions <= 3.1.21, low\u2011privileged authenticated use ...)
+ TODO: check
+CVE-2026-13198 (Nozomi Networks Labs identified a CWE-362: Concurrent Execution using ...)
+ TODO: check
+CVE-2026-13197 (Nozomi Networks Labs identified a CWE-362: Concurrent Execution using ...)
+ TODO: check
+CVE-2026-13196 (Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnera ...)
+ TODO: check
+CVE-2026-13002 (A flow has been identified into dnssec.c library, causing an infinite ...)
+ TODO: check
+CVE-2026-12366 (Zephyr's dynamic kernel-object disposal path unref_check() in kernel/u ...)
+ TODO: check
+CVE-2026-12365 (A use-after-free exists in the Zephyr second-generation work queue (ke ...)
+ TODO: check
+CVE-2026-12364 (The user-space system-call verifier z_vrfy_z_log_msg_static_create() i ...)
+ TODO: check
+CVE-2026-12363 (The LoRaWAN Fragmented Data Block Transport service (subsys/lorawan/se ...)
+ TODO: check
+CVE-2025-7639 (The vulnerability, if exploited, could allow an authenticated miscrean ...)
+ TODO: check
+CVE-2025-71405 (chi versions before v5.2.2 contain an open redirect vulnerability in t ...)
+ TODO: check
+CVE-2023-7347
+ REJECTED
CVE-2026-XXXX [RUSTSEC-2025-0168]
- rust-zip 2.5.0-1
NOTE: https://rustsec.org/advisories/RUSTSEC-2025-0168.html
@@ -313,7 +559,7 @@ CVE-2026-19746 (A vulnerability has been found in Calix GigaSpire 26.1.0. The af
TODO: check
CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknow ...)
TODO: check
-CVE-2026-19617 (A flaw was found in libdm. A remote attacker could craft a malicious L ...)
+CVE-2026-19617 (A flaw was found in libdm. A local attacker could craft a malicious Lo ...)
TODO: check
CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 ...)
NOT-FOR-US: IBM
@@ -816,7 +1062,8 @@ CVE-2026-73340 (Contributor Cross Site Scripting (XSS) in Featured Image from UR
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73266 (A flaw was found in the clusterclaims-controller component of Multiclu ...)
NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
-CVE-2026-73188 (Unauthenticated Sensitive Data Exposure in KiviCare <= 4.5.1 versions.)
+CVE-2026-73188
+ REJECTED
NOT-FOR-US: WordPress plugin or theme
CVE-2026-73038 (NodeBB before 4.15.0 contains a stored cross-site scripting vulnerabil ...)
NOT-FOR-US: NodeBB
@@ -1117,7 +1364,8 @@ CVE-2026-28186 (Subscriber Broken Access Control in Travelfic Toolkit <= 1.5.1 v
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28185 (Unauthenticated Broken Authentication in Log in with Google <= 1.4.2 v ...)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-28184 (Subscriber SQL Injection in Form Maker by 10Web <= 1.15.44 versions.)
+CVE-2026-28184
+ REJECTED
NOT-FOR-US: WordPress plugin or theme
CVE-2026-28182 (Subscriber Cross Site Scripting (XSS) in AcyMailing SMTP Newsletter <= ...)
NOT-FOR-US: WordPress plugin or theme
@@ -1290,7 +1538,7 @@ CVE-2026-13048 (Data::MuForm::Localizer versions through 0.05 for Perl execute P
CVE-2026-13051 (Form::Processor::Field::HtmlArea versions from 0.06 through 1.162360 f ...)
NOT-FOR-US: Form::Processor Perl module
CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a server ad ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1298,7 +1546,7 @@ CVE-2026-6464 (Untrusted data inclusion in PostgreSQL psql COPY may allow a serv
NOTE: https://www.postgresql.org/support/security/CVE-2026-6464/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TYPE co ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1306,7 +1554,7 @@ CVE-2026-6469 (Incorrect ownership assignment in PostgreSQL ALTER TABLE ALTER TY
NOTE: https://www.postgresql.org/support/security/CVE-2026-6469/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an object crea ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1314,7 +1562,7 @@ CVE-2026-6470 (Missing authorization in PostgreSQL DDL commands allows an object
NOTE: https://www.postgresql.org/support/security/CVE-2026-6470/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a non-supe ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1322,7 +1570,7 @@ CVE-2026-6471 (Missing authorization in PostgreSQL logical decoding allows a non
NOTE: https://www.postgresql.org/support/security/CVE-2026-6471/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data type functi ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1330,7 +1578,7 @@ CVE-2026-14662 (Integer wraparound in PostgreSQL tsvector and tsquery data type
NOTE: https://www.postgresql.org/support/security/CVE-2026-14662/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows a use ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1338,7 +1586,7 @@ CVE-2026-14663 (Cleartext storage in PostgreSQL pgcrypto disabled ciphers allows
NOTE: https://www.postgresql.org/support/security/CVE-2026-14663/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query author to e ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1346,7 +1594,7 @@ CVE-2026-14664 (Heap buffer overflow in PostgreSQL regexp allows the query autho
NOTE: https://www.postgresql.org/support/security/CVE-2026-14664/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role membership, role ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1354,7 +1602,7 @@ CVE-2026-14666 (Incomplete tracking in PostgreSQL of changes to role membership,
NOTE: https://www.postgresql.org/support/security/CVE-2026-14666/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type selectivit ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1362,7 +1610,7 @@ CVE-2026-14668 (Type confusion regarding input of PostgreSQL ctid data type sele
NOTE: https://www.postgresql.org/support/security/CVE-2026-14668/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows the par ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1370,7 +1618,7 @@ CVE-2026-14669 (Heap buffer overflow in PostgreSQL to_char(timestamptz) allows t
NOTE: https://www.postgresql.org/support/security/CVE-2026-14669/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied hash allows ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1378,7 +1626,7 @@ CVE-2026-14670 (Heap buffer overflow in PostgreSQL plperl return of a tied hash
NOTE: https://www.postgresql.org/support/security/CVE-2026-14670/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14671 (Type confusion in PostgreSQL module "refint" allows an object creator ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1394,7 +1642,7 @@ CVE-2026-14672 (Observable response discrepancy in PostgreSQL SCRAM authenticati
NOTE: https://www.postgresql.org/support/security/CVE-2026-14672/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14673 (Untrusted search path in PostgreSQL amcheck allows a grantee of amchec ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1409,7 +1657,7 @@ CVE-2026-14676 (Heap buffer overflow in PostgreSQL pg_stat_statements allows the
NOTE: https://www.postgresql.org/support/security/CVE-2026-14676/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and plperl all ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1417,7 +1665,7 @@ CVE-2026-14677 (Integer wraparound in PostgreSQL 32-bit builds of pltcl and plpe
NOTE: https://www.postgresql.org/support/security/CVE-2026-14677/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit function reads ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1425,7 +1673,7 @@ CVE-2026-14678 (Buffer over-read in PostgreSQL pg_trgm index picksplit function
NOTE: https://www.postgresql.org/support/security/CVE-2026-14678/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching allows an o ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1433,7 +1681,7 @@ CVE-2026-14679 (Stack buffer overflow in PostgreSQL argument name matching allow
NOTE: https://www.postgresql.org/support/security/CVE-2026-14679/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-14680 (Type confusion with PostgreSQL "internal" data type arguments allows a ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1449,7 +1697,7 @@ CVE-2026-14681 (Improper enforcement of message integrity in PostgreSQL GSSAPI s
NOTE: https://www.postgresql.org/support/security/CVE-2026-14681/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object owner t ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1457,7 +1705,7 @@ CVE-2026-15741 (SQL injection in PostgreSQL EXTRACT() deparse allows an object o
NOTE: https://www.postgresql.org/support/security/CVE-2026-15741/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-15742 (Integer wraparound in PostgreSQL fuzzystrmatch allows a user to direct ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1472,7 +1720,7 @@ CVE-2026-16238 (Type confusion in PostgreSQL pg_restore_attribute_stats() allows
NOTE: https://www.postgresql.org/support/security/CVE-2026-16238/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows a user t ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1480,7 +1728,7 @@ CVE-2026-16239 (Type confusion in PostgreSQL "portal"/cursor lifecycle allows a
NOTE: https://www.postgresql.org/support/security/CVE-2026-16239/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server administ ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1488,7 +1736,7 @@ CVE-2026-16241 (Integer underflow in PostgreSQL ECPG allows a database server ad
NOTE: https://www.postgresql.org/support/security/CVE-2026-16241/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a user to d ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1496,7 +1744,7 @@ CVE-2026-18024 (Buffer over-read in PostgreSQL ascii() SQL function allows a use
NOTE: https://www.postgresql.org/support/security/CVE-2026-18024/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1504,7 +1752,7 @@ CVE-2026-18408 (Untrusted data inclusion in pg_dump in PostgreSQL allows a malic
NOTE: https://www.postgresql.org/support/security/CVE-2026-18408/
NOTE: https://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/
CVE-2026-19385 (Heap buffer overflow in PostgreSQL pg_dump of long function transform ...)
- {DSA-6438-1}
+ {DSA-6438-1 DLA-4740-1}
- postgresql-18 18.6-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -1982,7 +2230,7 @@ CVE-2026-53783 (rsync before3.5.0 contains a time-of-check to time-of-use (TOCTO
CVE-2026-53786 (rsyncbefore 3.5.0contains a filter rule bypass vulnerability that allo ...)
- rsync <unfixed>
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
-CVE-2026-53798 (rsync tbefore 3.5.0contains a privilege confusion vulnerability in the ...)
+CVE-2026-53798 (rsync before 3.5.0contains a privilege confusion vulnerability in the ...)
- rsync <unfixed>
NOTE: https://download.samba.org/pub/rsync/NEWS#3.5.0
CVE-2026-53788 (rsync before 3.5.0contains a newline injection vulnerability in the na ...)
@@ -16731,7 +16979,7 @@ CVE-2026-61547
- librabbitmq 0.17.0-1
NOTE: https://github.com/alanxz/rabbitmq-c/security/advisories/GHSA-hfjv-vcp3-39wh
NOTE: Fixed by: https://github.com/alanxz/rabbitmq-c/commit/02d278663f3a93db9fe4fb4e7e34dc96b83c107b (v0.17.0)
-CVE-2026-58224 [The CTDB protocol has bounds checking issues]
+CVE-2026-58224 (A flaw was found in Samba's CTDB, the clustered database service used ...)
{DSA-6401-1}
- samba 2:4.24.5+dfsg-1
NOTE: https://www.samba.org/samba/security/CVE-2026-58224-advisory.html
@@ -20647,7 +20895,7 @@ CVE-2026-65482 (Contributor Cross Site Scripting (XSS) in LA-Studio Element Kit
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65481 (Contributor Local File Inclusion in Vino <= 1.9 versions.)
NOT-FOR-US: WordPress plugin or theme
-CVE-2026-65480 (Contributor Cross Site Scripting (XSS) in TheGem <= 5.11.1 versions.)
+CVE-2026-65480 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65479 (Subscriber Broken Access Control in Reviewer <= 3.14.2 versions.)
NOT-FOR-US: WordPress plugin or theme
@@ -35129,6 +35377,7 @@ CVE-2026-59946 (Composer is a dependency Manager for the PHP language. Prior to
NOTE: Fixed by: https://github.com/composer/composer/commit/502c6c4f699802d9cf464728b3e8a95674f919a0 (2.10.2)
NOTE: Fixed by: https://github.com/composer/composer/commit/c50b1efd13ebd73f6dca19b31424c5a02bf93cc1 (2.2.29)
CVE-2026-59939 (httplib2 is a comprehensive HTTP client library for Python. Prior to 0 ...)
+ {DSA-6441-1}
- python-httplib2 0.32.0-1
NOTE: https://github.com/httplib2/httplib2/security/advisories/GHSA-j5g9-f88f-gfj3
NOTE: Fixed by: https://github.com/httplib2/httplib2/commit/87581ad6cf752fe3da2090c59058261d2d00a427 (v0.32.0)
@@ -42931,6 +43180,7 @@ CVE-2026-13676 (fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonica
NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-4c8g-83qw-93j6
NOTE: Embedded fast-uri used and provided as node-fast-uri, starting with forky
CVE-2026-13595 (A flaw was found in the libblkid library of util-linux. During nested ...)
+ {DSA-6442-1}
- util-linux 2.42.2-1
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2494101
NOTE: https://github.com/util-linux/util-linux/commit/c0186f14fbdb02f64c8e0ba701ce727ea764ff4c (master)
@@ -52600,6 +52850,7 @@ CVE-2026-53615 [Integer Overflow or Wraparound in libblkid/src/partitions/dos.c]
- util-linux <unfixed> (bug #1140197)
NOTE: https://github.com/util-linux/util-linux/security/advisories/GHSA-h4rw-gv36-wmp5
CVE-2026-53614 [Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment Variable - nosuid/noexec Bypass in SUID mount(8)]
+ {DSA-6442-1}
- util-linux 2.42.2-1 (bug #1140196)
[bookworm] - util-linux <not-affected> (Vulnerable code introduced later)
[bullseye] - util-linux <not-affected> (Vulnerable code introduced later)
@@ -52607,11 +52858,13 @@ CVE-2026-53614 [Local Privilege Escalation via LIBMOUNT_FORCE_MOUNT2 Environment
NOTE: Fixed by: https://github.com/util-linux/util-linux/commit/31e37c1c7dcf25b76ccf41391fe934a75644c661 (v2.42.2)
NOTE: Fixed by: https://github.com/util-linux/util-linux/commit/cc81bbcec598cb91f0eb8456282f33eed820ed5f (v2.41.5)
CVE-2026-53613 [Local Privilege Escalation via TOCTOU in mount(8) - Target Path Redirection]
+ {DSA-6442-1}
- util-linux 2.42.2-1 (bug #1140195)
NOTE: https://github.com/util-linux/util-linux/security/advisories/GHSA-8gj5-72r3-428g
NOTE: Fixed by: https://github.com/util-linux/util-linux/commit/0d3d55975aa3492c62fd345eac38f41cd166c0b0 (v2.42.2)
NOTE: Fixed by: https://github.com/util-linux/util-linux/commit/0b010025a0e429bc80355c94db86a843395d49e2 (v2.41.5)
CVE-2026-53612 [Local Privilege Escalation via TOCTOU in mount(8) hook_owner.c chmod/chown]
+ {DSA-6442-1}
- util-linux 2.42.2-1 (bug #1140194)
[bookworm] - util-linux <not-affected> (Vulnerable code introduced later)
[bullseye] - util-linux <not-affected> (Vulnerable code introduced later)
@@ -55632,7 +55885,7 @@ CVE-2026-6893 (A flaw was found in dracut. A remote attacker on the adjacent net
[trixie] - dracut <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2459963
NOTE: https://github.com/dracut-ng/dracut/pull/2469
-CVE-2026-53472
+CVE-2026-53472 (A flaw was found in migration-planner. Insufficient validation of the ...)
NOT-FOR-US: kubev2v/migration-planner
CVE-2026-9758 (Improper comparison with the certificates trusted list in S2OPC allows ...)
NOT-FOR-US: S2OPC library
@@ -63608,7 +63861,7 @@ CVE-2026-46243 (In the Linux kernel, the following vulnerability has been resolv
[bookworm] - linux 6.1.174-1
[bullseye] - linux 5.10.257-1
NOTE: https://git.kernel.org/linus/3da1fdf4efbc490041eb4f836bf596201203f8f2 (7.1-rc5)
-CVE-2026-47192
+CVE-2026-47192 (kas is a setup tool for bitbake based projects. Starting in version 4. ...)
- kas 5.3-1
[trixie] - kas <no-dsa> (Minor issue)
[bookworm] - kas <not-affected> (Vulnerable code not present)
@@ -63616,7 +63869,7 @@ CVE-2026-47192
NOTE: https://github.com/siemens/kas/security/advisories/GHSA-4vqc-wpwg-vh7j
NOTE: Introduced with: https://github.com/siemens/kas/commit/a2480fe59b6421eb96cf3bd86527ae6e412a331e (4.8)
NOTE: Fixed by: https://github.com/siemens/kas/commit/5b2114becfc154b16ef496d24f8c2191a2297f57 (5.3)
-CVE-2026-47191
+CVE-2026-47191 (kas is a setup tool for bitbake based projects. Prior to version 5.3, ...)
- kas 5.3-1
[trixie] - kas <no-dsa> (Minor issue)
[bookworm] - kas <no-dsa> (Minor issue)
@@ -67544,7 +67797,7 @@ CVE-2026-41579 (runc is a CLI tool for spawning and running containers according
NOTE: https://www.openwall.com/lists/oss-security/2026/06/13/2
NOTE: https://github.com/opencontainers/runc/security/advisories/GHSA-xjvp-4fhw-gc47
NOTE: Fixed by: https://github.com/opencontainers/runc/commit/864db8042dbb191028676f80addf8c35f348aee2
-CVE-2026-47766
+CVE-2026-47766 (crun is an open source OCI Container Runtime fully written in C. Prior ...)
- crun 1.28-1
[trixie] - crun <no-dsa> (Minor issue)
[bookworm] - crun <no-dsa> (Minor issue)
@@ -74933,7 +75186,7 @@ CVE-2026-6479 (Uncontrolled recursion in PostgreSQL SSL and GSS negotiation allo
- postgresql-13 <removed>
NOTE: https://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/
CVE-2026-6473 (Integer wraparound in multiple PostgreSQL server features allows an un ...)
- {DSA-6438-1 DSA-6270-1 DSA-6269-1 DLA-4646-1}
+ {DSA-6438-1 DSA-6270-1 DSA-6269-1 DLA-4740-1 DLA-4646-1}
- postgresql-18 18.4-1
- postgresql-17 <removed>
- postgresql-15 <removed>
@@ -101633,6 +101886,7 @@ CVE-2024-40849 (A race condition was addressed with additional validation. This
CVE-2023-7342 (HiSecOS web server versions 03.4.00 prior to 04.1.00 contains a privil ...)
NOT-FOR-US: HiSecOS web server
CVE-2026-27456 (util-linux is a random collection of Linux utilities. Prior to version ...)
+ {DSA-6442-1}
- util-linux 2.42-1
[bookworm] - util-linux <no-dsa> (Minor issue)
[bullseye] - util-linux <postponed> (Minor issue)
@@ -148244,7 +148498,7 @@ CVE-2025-14633 (The F70 Lead Document Download plugin for WordPress is vulnerabl
NOT-FOR-US: WordPress plugin
CVE-2025-14591 (In Delphix Continuous Compliance version 2025.3.0 and later, following ...)
NOT-FOR-US: Perforce
-CVE-2025-14300 (The HTTPS service on Tapo C200 V3 exposes a connectAP interface withou ...)
+CVE-2025-14300 (The HTTPS service on Tapo C200 v3, v5, C425 v1.2 and C100 v5 exposes a ...)
NOT-FOR-US: TP-Link
CVE-2025-14299 (The HTTPS server on Tapo C200 V3 does not properly validate the Conten ...)
NOT-FOR-US: TP-Link
@@ -195154,7 +195408,7 @@ CVE-2025-8715 (Improper neutralization of newlines in pg_dump in PostgreSQL allo
NOTE: https://www.postgresql.org/support/security/CVE-2025-8715/
NOTE: https://git.postgresql.org/gitweb/?p=postgresql.git;a=commitdiff;h=70693c645f6e490b9ed450e8611e94ab7af3aad2 (master)
CVE-2025-8714 (Untrusted data inclusion in pg_dump in PostgreSQL allows a malicious s ...)
- {DLA-4273-1}
+ {DLA-4740-1 DLA-4273-1}
- postgresql-17 17.6-1
[trixie] - postgresql-17 17.6-0+deb13u1
- postgresql-15 <removed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1885a5c515eee894de4f43520da6319cf9aedda9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1885a5c515eee894de4f43520da6319cf9aedda9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260814/5af20ecc/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list