[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 15 16:02:21 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a02e5b54 by Salvatore Bonaccorso at 2026-08-15T17:01:52+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
CVE-2026-73194
- - libdbi-perl <unfixed>
+ - libdbi-perl <unfixed> (bug #1144471)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707363/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809 (1.652)
CVE-2026-73193
- - libdbi-perl <unfixed>
+ - libdbi-perl <unfixed> (bug #1144470)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707360/
NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1 (1.652)
CVE-2026-15689
@@ -7128,7 +7128,7 @@ CVE-2026-18673 (When kuma-dp is configured with the Envoy admin API on a Unix do
CVE-2026-18669 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation a ...)
NOT-FOR-US: IBM
CVE-2026-18663 (A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base <unfixed> (bug #1144475)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2510631
CVE-2026-18652 (Velociraptor allows reading Stacked result sets from the GUI. Velocira ...)
NOT-FOR-US: Rapid7
@@ -7553,12 +7553,12 @@ CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer over
CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API (`snowflake.co ...)
TODO: check
CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung Open Sour ...)
- - rlottie <unfixed>
+ - rlottie <unfixed> (bug #1144473)
[trixie] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/600
NOTE: https://github.com/Samsung/rlottie/commit/27f2f23ece8a98f3e0a870e2c125faaac37e8904
CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung Open Source ...)
- - rlottie <unfixed>
+ - rlottie <unfixed> (bug #1144472)
[trixie] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/599
NOTE: https://github.com/Samsung/rlottie/commit/34465a9e93c38af9a5287ad28400bb932c1a2a92
@@ -10570,7 +10570,7 @@ CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the contact
CVE-2026-19429
REJECTED
CVE-2026-19404 (A flaw was found in 389 Directory Server. The CleanAllRUV and Abort Cl ...)
- - 389-ds-base <unfixed>
+ - 389-ds-base <unfixed> (bug #1144474)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513036
CVE-2026-19278 (A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine ( ...)
NOT-FOR-US: Red Hat Advanced Cluster Security
@@ -13704,7 +13704,7 @@ CVE-2024-6541 (The Class Mediator fails to correctly validate or sanitize `messa
CVE-2024-39024 (In Packetfence 13.2.0, the WebGui interface setting allows authenticat ...)
NOT-FOR-US: Packetfence
CVE-2026-18938 (A flaw was found in p11-kit. A local attacker, or one with equivalent ...)
- - p11-kit <unfixed>
+ - p11-kit <unfixed> (bug #1144476)
[trixie] - p11-kit <no-dsa> (Minor issue)
NOTE: https://github.com/p11-glue/p11-kit/pull/777
NOTE: Fixed by: https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc (0.26.5)
@@ -17753,7 +17753,7 @@ CVE-2026-18358 (A flaw was found in gnome-remote-desktop as shipped in Red Hat E
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462876
TODO: does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug
CVE-2026-18321 (Buffer overflow in NTPsec's Zyfer refclock allows local attacker to cr ...)
- - ntpsec <unfixed>
+ - ntpsec <unfixed> (bug #1144477)
[trixie] - ntpsec <no-dsa> (Minor issue)
[bookworm] - ntpsec <postponed> (minor issue; DoS)
[bullseye] - ntpsec <postponed> (minor issue; DoS)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a02e5b5495c56e0a507b3b1d9e0ad2a100b8f08f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a02e5b5495c56e0a507b3b1d9e0ad2a100b8f08f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260815/971dfbe4/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list