[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 15 13:53:59 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d1f808c6 by Salvatore Bonaccorso at 2026-08-15T14:53:26+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -545,10 +545,10 @@ CVE-2026-74440 [drm/xe: Wait on external BO kernel fences in exec IOCTL]
CVE-2026-8840 (The Booking calendar, Appointment Booking System plugin for WordPress ...)
NOT-FOR-US: WordPress plugin
CVE-2026-74250 (In OpenStack Ironic before 38.0.1, the autodetect deploy interface may ...)
- - ironic <unfixed>
+ - ironic <unfixed> (bug #1144458)
NOTE: https://bugs.launchpad.net/ossa/+bug/2163017
CVE-2026-74248 (OpenStack Octavia through 18.0.0 mishandles quality of service (QoS) p ...)
- - octavia <unfixed>
+ - octavia <unfixed> (bug #1144459)
NOTE: https://www.openwall.com/lists/oss-security/2026/08/13/12
NOTE: https://bugs.launchpad.net/octavia/+bug/2161500
CVE-2026-74247 (A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT en ...)
@@ -4838,7 +4838,7 @@ CVE-2026-XXXX [RUSTSEC-2026-0221]
NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0221.html
NOTE: https://github.com/smol-rs/event-listener/pull/163
CVE-2026-12876
- - nltk <unfixed>
+ - nltk <unfixed> (bug #1144456)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-ff5c-cp5c-9wjf
CVE-2026-12841
- nltk 3.10.3-1
@@ -4908,7 +4908,7 @@ CVE-2026-73489 (Russh is a Rust SSH client & server library. Prior to 0.62.4, an
NOTE: https://github.com/Eugeny/russh/security/advisories/GHSA-cqjc-rmpq-xprq
NOTE: Fixed by: https://github.com/Eugeny/russh/commit/8912512371820167a12a0a638bd666856ce458ad (v0.62.4)
CVE-2026-73480 (gdu fails to strip terminal escape sequences from directory and file n ...)
- - gdu <unfixed>
+ - gdu <unfixed> (bug #1144461)
NOTE: https://github.com/dundee/gdu/issues/615
NOTE: https://github.com/dundee/gdu/pull/616
NOTE: Fixed by: https://github.com/dundee/gdu/commit/5d76fab735f190fd645896de90ac9982b6382aeb
@@ -4921,11 +4921,11 @@ CVE-2026-73421 (NextAuth.js provides authentication for Next.js. From next-auth
CVE-2026-73420 (NextAuth.js provides authentication for Next.js. Prior to @auth/core 0 ...)
NOT-FOR-US: Next.js
CVE-2026-73417 (jupyterlab is an extensible environment for interactive and reproducib ...)
- - jupyterlab <unfixed>
+ - jupyterlab <unfixed> (bug #1144463)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-pppj-hq3g-57pj
NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
CVE-2026-73416 (jupyterlab is an extensible environment for interactive and reproducib ...)
- - jupyterlab <unfixed>
+ - jupyterlab <unfixed> (bug #1144464)
NOTE: https://github.com/jupyterlab/jupyterlab/security/advisories/GHSA-89vp-jrxv-24w8
NOTE: Fixed by: https://github.com/jupyterlab/jupyterlab/commit/be9303f5bcd5308eaeae953c5a3c903046682c2c (v4.5.10)
CVE-2026-73408 (Budibase is an open-source low-code platform. Prior to 3.39.18, packag ...)
@@ -7520,7 +7520,7 @@ CVE-2026-63134 (Malcolm is a network traffic analysis tool suite. Prior to versi
CVE-2026-63133 (Malcolm is a network traffic analysis tool suite. Prior to version 26. ...)
NOT-FOR-US: Malcolm
CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SSH bac ...)
- - libgit2 <unfixed>
+ - libgit2 <unfixed> (bug #1144465)
NOTE: Fixed by: https://github.com/libgit2/libgit2/commit/b2105b8e60798cb28086d4c648b1cb4854eadccb (v1.9.7)
CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The file-upload comp ...)
NOT-FOR-US: Malcolm
@@ -9409,14 +9409,14 @@ CVE-2026-17061 (A Deserialization of Untrusted Data vulnerability affecting SIMU
CVE-2026-15567 (A flaw was found in Wildfly. A remote unauthenticated attacker can tri ...)
- wildfly <itp> (bug #752018)
CVE-2026-15565 (A flaw was found in Undertow. A remote attacker can cause Out of Memor ...)
- - undertow <unfixed>
+ - undertow <unfixed> (bug #1144457)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490628
CVE-2026-15563 (A flaw was found in EAP's IIOP. The listener's NameService would accep ...)
NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
CVE-2026-15562 (A flaw was found in EAP's jboss-remoting. A remote unauthenticated att ...)
NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
CVE-2026-15561 (A flaw was found in EAP's undertow http/1.1 chunked-transfer decoder. ...)
- - undertow <unfixed>
+ - undertow <unfixed> (bug #1144457)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2483133
CVE-2026-15560 (when EAP runs with -secmgr, the openjdk-orb's JDKBridge honours attack ...)
NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
@@ -9425,12 +9425,12 @@ CVE-2026-15556 (A flaw was found in Picketlink's SP signature validation; a SAML
CVE-2026-15555 (A flaw was found in JBoss marshalling. The Infinispan session replicat ...)
NOT-FOR-US: Red Hat JBoss Enterprise Application Platform
CVE-2026-15554 (the Undertow AJP listener honours forged ssl_cert and is_ssl AJP attri ...)
- - undertow <unfixed>
+ - undertow <unfixed> (bug #1144457)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2480601
CVE-2026-15426 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and Marketing Auto ...)
NOT-FOR-US: WordPress plugin
CVE-2026-14180 (A flaw was found in the ChunkReader component of the Undertow HTTP ser ...)
- - undertow <unfixed>
+ - undertow <unfixed> (bug #1144457)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2494771
CVE-2026-13739 (A legacy endpoint in Command Center contained an unauthenticated serve ...)
NOT-FOR-US: Commvault
@@ -12438,7 +12438,7 @@ CVE-2026-12570 (A vulnerability in keras-team/keras versions <= 3.15.0 allows fo
- keras <removed>
[bullseye] - keras <end-of-life> (EOL in bullseye LTS)
CVE-2026-12372 (A Server-Side Request Forgery (SSRF) vulnerability exists in nltk/nltk ...)
- - nltk <unfixed>
+ - nltk <unfixed> (bug #1144456)
[trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513003
CVE-2026-70395 (Improper Neutralization of Special Elements in Data Query Logic vulner ...)
@@ -13666,7 +13666,7 @@ CVE-2026-12584 (The Payment Gateway for Redsys & WooCommerce Lite WordPress plug
CVE-2026-12501 (The WP Travel Engine WordPress plugin before 6.8.2 does not verify tha ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12261 (A vulnerability in `nltk.downloader` in nltk/nltk versions <= 3.9.4 al ...)
- - nltk <unfixed>
+ - nltk <unfixed> (bug #1144456)
[trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://huntr.com/bounties/8b8c381e-08a8-4e4f-bb46-a320c96a364f
CVE-2026-11976 (The official MonsterInsights Pro update distribution bucket (`monster- ...)
@@ -16606,7 +16606,7 @@ CVE-2026-18243 (Certain HP DesignJet products may be potentially vulnerable to c
CVE-2026-15430 (Improper access control in the IRP_MJ_WRITE command interface in Wellb ...)
NOT-FOR-US: Wellbia XIGNCODE3
CVE-2026-12259 (In nltk version 3.9.4, the `nltk.downloader.Downloader._download_packa ...)
- - nltk <unfixed>
+ - nltk <unfixed> (bug #1144456)
[trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://huntr.com/bounties/659ccf6d-12d4-4d4a-84c0-078633c35a5d
CVE-2026-0392 (eParakst\u012bt\u0101js 3.0 for Windows before version 1.10.0 retrieve ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1f808c65911651d293791be04db07e6edb4db43
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d1f808c65911651d293791be04db07e6edb4db43
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260815/bb69333c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list