[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 15 16:02:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a02e5b54 by Salvatore Bonaccorso at 2026-08-15T17:01:52+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,9 +1,9 @@
 CVE-2026-73194
-	- libdbi-perl <unfixed>
+	- libdbi-perl <unfixed> (bug #1144471)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707363/
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/29b72ae7d2a8114a734a55840bf1c45b89207809 (1.652)
 CVE-2026-73193
-	- libdbi-perl <unfixed>
+	- libdbi-perl <unfixed> (bug #1144470)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42707360/
 	NOTE: Fixed by: https://github.com/perl5-dbi/dbi/commit/c751ae5a5a6f56c2f8284f37c1f4d43500352ef1 (1.652)
 CVE-2026-15689
@@ -7128,7 +7128,7 @@ CVE-2026-18673 (When kuma-dp is configured with the Envoy admin API on a Unix do
 CVE-2026-18669 (IBM i 7.6, 7.5, 7.4, and 7.3 is vulnerable to a privilege escalation a ...)
 	NOT-FOR-US: IBM
 CVE-2026-18663 (A flaw was found in 389-ds-base. The get_ldapmessage_controls_ext() fu ...)
-	- 389-ds-base <unfixed>
+	- 389-ds-base <unfixed> (bug #1144475)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2510631
 CVE-2026-18652 (Velociraptor allows reading Stacked result sets from the GUI. Velocira ...)
 	NOT-FOR-US: Rapid7
@@ -7553,12 +7553,12 @@ CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer over
 CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API (`snowflake.co ...)
 	TODO: check
 CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung Open Sour ...)
-	- rlottie <unfixed>
+	- rlottie <unfixed> (bug #1144473)
 	[trixie] - rlottie <no-dsa> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/600
 	NOTE: https://github.com/Samsung/rlottie/commit/27f2f23ece8a98f3e0a870e2c125faaac37e8904
 CVE-2026-19587 (Uncontrolled Resource Consumption vulnerability in Samsung Open Source ...)
-	- rlottie <unfixed>
+	- rlottie <unfixed> (bug #1144472)
 	[trixie] - rlottie <no-dsa> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/599
 	NOTE: https://github.com/Samsung/rlottie/commit/34465a9e93c38af9a5287ad28400bb932c1a2a92
@@ -10570,7 +10570,7 @@ CVE-2026-19433 (Authorization Bypass Through User-Controlled Key in the contact
 CVE-2026-19429
 	REJECTED
 CVE-2026-19404 (A flaw was found in 389 Directory Server. The CleanAllRUV and Abort Cl ...)
-	- 389-ds-base <unfixed>
+	- 389-ds-base <unfixed> (bug #1144474)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513036
 CVE-2026-19278 (A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine ( ...)
 	NOT-FOR-US: Red Hat Advanced Cluster Security
@@ -13704,7 +13704,7 @@ CVE-2024-6541 (The Class Mediator fails to correctly validate or sanitize `messa
 CVE-2024-39024 (In Packetfence 13.2.0, the WebGui interface setting allows authenticat ...)
 	NOT-FOR-US: Packetfence
 CVE-2026-18938 (A flaw was found in p11-kit. A local attacker, or one with equivalent  ...)
-	- p11-kit <unfixed>
+	- p11-kit <unfixed> (bug #1144476)
 	[trixie] - p11-kit <no-dsa> (Minor issue)
 	NOTE: https://github.com/p11-glue/p11-kit/pull/777
 	NOTE: Fixed by: https://github.com/p11-glue/p11-kit/commit/3e64244e538550c6a7fcf826fa8c50a4604416dc (0.26.5)
@@ -17753,7 +17753,7 @@ CVE-2026-18358 (A flaw was found in gnome-remote-desktop as shipped in Red Hat E
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462876
 	TODO: does not affect an upstream version, but need to check if still only Red Hat specific, check details RH bug
 CVE-2026-18321 (Buffer overflow in NTPsec's Zyfer refclock allows local attacker to cr ...)
-	- ntpsec <unfixed>
+	- ntpsec <unfixed> (bug #1144477)
 	[trixie] - ntpsec <no-dsa> (Minor issue)
 	[bookworm] - ntpsec <postponed> (minor issue; DoS)
 	[bullseye] - ntpsec <postponed> (minor issue; DoS)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a02e5b5495c56e0a507b3b1d9e0ad2a100b8f08f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a02e5b5495c56e0a507b3b1d9e0ad2a100b8f08f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260815/971dfbe4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list