[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 16 07:00:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
320e60c9 by Salvatore Bonaccorso at 2026-08-16T07:59:37+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11,27 +11,27 @@ CVE-2026-73631 (Exposure of data element to wrong session vulnerability in the J
 	- libstruts1.2-java <removed>
 	NOTE: https://cwiki.apache.org/confluence/display/WW/S2-070
 CVE-2026-19906 (A weakness has been identified in pkp pkp-lib 3.3.0/3.4.0/3.5.0. This  ...)
-	TODO: check
+	NOT-FOR-US: pkp-lib
 CVE-2026-19905 (A weakness has been identified in Jinher OA 1.0. Impacted is an unknow ...)
-	TODO: check
+	NOT-FOR-US: Jinher OA
 CVE-2026-19904 (A vulnerability was found in SourceCodester Online Book Store System 1 ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-19903 (A vulnerability has been found in SourceCodester Online Clothing Store ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-19901 (A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206.  ...)
-	TODO: check
+	NOT-FOR-US: LB-LINK
 CVE-2026-19900 (A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The i ...)
-	TODO: check
+	NOT-FOR-US: LB-LINK
 CVE-2026-19899 (A vulnerability was determined in SourceCodester Class and Exam Timeta ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-19898 (A vulnerability was found in VictoriaMetrics up to 1.146.0. Impacted i ...)
-	TODO: check
+	NOT-FOR-US: VictoriaMetrics
 CVE-2026-19897 (A vulnerability has been found in mangroup dtale up to 3.22.0. This is ...)
-	TODO: check
+	NOT-FOR-US: mangroup dtale
 CVE-2026-19896 (A flaw has been found in mangroup dtale up to 3.22.0. This vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: mangroup dtale
 CVE-2026-19895 (A vulnerability was detected in opensourcepos Open Source Point of Sal ...)
-	TODO: check
+	NOT-FOR-US: opensourcepos Open Source Point of Sale
 CVE-2026-19894 (A security flaw has been discovered in itsourcecode Hospital Managemen ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-19893 (A vulnerability was identified in D-Link DIR-842 2.01.B04. This impact ...)
@@ -674,11 +674,11 @@ CVE-2026-34492 (External control of file name or path vulnerability in Johnson C
 CVE-2026-27871 (Cwe-327 Use of a Broken or Risky Cryptographic Algorithm vulnerability ...)
 	NOT-FOR-US: Johnson Controls
 CVE-2026-19910 (PAX Technology Q80 Application Installer Signature Verification Bypass ...)
-	TODO: check
+	NOT-FOR-US: PAX Technology Q80 Application Installer
 CVE-2026-19909 (PAX Technology Q80 AIP File Parsing Link Following Remote Code Executi ...)
-	TODO: check
+	NOT-FOR-US: PAX Technology Q80
 CVE-2026-19908 (PAX Technology Q80 XCB Daemon Missing Authentication Vulnerability. Th ...)
-	TODO: check
+	NOT-FOR-US: PAX Technology Q80
 CVE-2026-18932
 	REJECTED
 CVE-2026-18807 (The ECS  WordPress plugin before 4.3.8 does not have capability or own ...)
@@ -4751,13 +4751,13 @@ CVE-2026-49986 (The Cortex MCP server (`neuro-cortex-memory`), a cross-platform
 CVE-2026-49826 (Concourse is a container-based automation system written in Go. Prior  ...)
 	NOT-FOR-US: Concourse
 CVE-2026-49457 (erlang_quic is a pure Erlang QUIC implementation. Prior to version 1.4 ...)
-	TODO: check
+	NOT-FOR-US: erlang_quic
 CVE-2026-49282 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
 	TODO: check
 CVE-2026-49263 (Capstone is a disassembly framework. Prior to version 6.0.0-Alpha9, Ca ...)
 	TODO: check
 CVE-2026-48528 (Metacat is data repository software that helps researchers preserve, s ...)
-	TODO: check
+	NOT-FOR-US: Metacat
 CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amo ...)
 	TODO: check
 CVE-2026-46439 (compliance-trestle is a tooling platform for managing compliance as co ...)
@@ -4773,9 +4773,9 @@ CVE-2026-19880 (Path-traversal vulnerability in QOS.CH Sarl Logback-classic on J
 CVE-2026-19879 (A flaw was found in Undertow, an HTTP server, within its HTTP response ...)
 	TODO: check
 CVE-2026-19871 (Use of Hard-coded Credentials in the human resources component in Rosk ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19870 (Authorization Bypass Through User-Controlled Key in the payroll module ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19847 (A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20 ...)
 	NOT-FOR-US: TOTOLINK
 CVE-2026-19846 (A vulnerability was identified in TOTOLINK A800R 4.1.2cu.5137_B2020073 ...)
@@ -4801,13 +4801,13 @@ CVE-2026-19834 (A vulnerability was determined in Webkul Bagisto up to 2.4.4. Af
 CVE-2026-19830 (A vulnerability was found in TRENDnet TEW-816DRM GURNC4.OT182B-C-TN-R1 ...)
 	NOT-FOR-US: TRENDnet
 CVE-2026-19829 (A security flaw has been discovered in 648540858 wvp-GB28181-pro 2.7.4 ...)
-	TODO: check
+	NOT-FOR-US: 648540858 wvp-GB28181-pro
 CVE-2026-19828 (A vulnerability was identified in 648540858 wvp-GB28181-pro 2.7.4-2026 ...)
-	TODO: check
+	NOT-FOR-US: 648540858 wvp-GB28181-pro
 CVE-2026-19827 (A flaw has been found in alldatacenter alldata up to 0.6.8. This impac ...)
-	TODO: check
+	NOT-FOR-US: alldatacenter alldata
 CVE-2026-19826 (A vulnerability was detected in alldatacenter alldata up to 0.6.8. Thi ...)
-	TODO: check
+	NOT-FOR-US: alldatacenter alldata
 CVE-2026-19825 (A security vulnerability has been detected in SourceCodester Simple Cl ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-19824 (A weakness has been identified in Tenda W20E 15.11.0.6(1068_1546_841)_ ...)
@@ -5134,9 +5134,9 @@ CVE-2026-49096 (Uncaught Exception (CWE-248) in Kibana Cases can lead to denial
 CVE-2026-49089 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
 	TODO: check
 CVE-2026-45774 (compliance-trestle is a tooling platform for managing compliance as co ...)
-	TODO: check
+	NOT-FOR-US: compliance-trestle
 CVE-2026-45725 (compliance-trestle is a tooling platform for managing compliance as co ...)
-	TODO: check
+	NOT-FOR-US: compliance-trestle
 CVE-2026-3883
 	REJECTED
 CVE-2026-19811 (A security flaw has been discovered in TOTOLINK A800R 4.1.2cu.5137_B20 ...)
@@ -5154,39 +5154,39 @@ CVE-2026-19788 (A vulnerability was found in Tenda AC1206 15.03.06.23_multi_TD01
 CVE-2026-19787 (A vulnerability was determined in SourceCodester Air Cargo Management  ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-19786 (A vulnerability was found in francoisjacquet RosarioSIS up to 12.8. Th ...)
-	TODO: check
+	NOT-FOR-US: francoisjacquet RosarioSIS
 CVE-2026-19785 (A vulnerability has been found in francoisjacquet RosarioSIS up to 12. ...)
-	TODO: check
+	NOT-FOR-US: francoisjacquet RosarioSIS
 CVE-2026-19784 (A flaw has been found in francoisjacquet RosarioSIS up to 12.8. This a ...)
-	TODO: check
+	NOT-FOR-US: francoisjacquet RosarioSIS
 CVE-2026-19771 (A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_N ...)
-	TODO: check
+	NOT-FOR-US: Baicells EG3661M
 CVE-2026-19770 (A vulnerability was identified in feedmob fm-mcp-servers 0.0.3. Affect ...)
-	TODO: check
+	NOT-FOR-US: feedmob fm-mcp-servers
 CVE-2026-19767 (A weakness has been identified in itsourcecode Hospital Management Sys ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-19765 (A security flaw has been discovered in eyaushev swagger-testcase-mcp 5 ...)
-	TODO: check
+	NOT-FOR-US: eyaushev swagger-testcase-mcp
 CVE-2026-19764 (A vulnerability was identified in Raisecom Communication Command and D ...)
-	TODO: check
+	NOT-FOR-US: Raisecom Communication Command and Dispatch Management Platform
 CVE-2026-19763 (A vulnerability was determined in DTStack Taier 1.4.0. Affected by thi ...)
-	TODO: check
+	NOT-FOR-US: DTStack Taier
 CVE-2026-19762 (A vulnerability was found in DTStack Taier 1.4.0. Affected by this vul ...)
-	TODO: check
+	NOT-FOR-US: DTStack Taier
 CVE-2026-19761 (A vulnerability has been found in DTStack Taier 1.4.0. Affected is the ...)
-	TODO: check
+	NOT-FOR-US: DTStack Taier
 CVE-2026-19758 (A vulnerability was determined in dromara lamp-cloud up to 5.10.0. Thi ...)
-	TODO: check
+	NOT-FOR-US: dromara lamp-cloud
 CVE-2026-19757 (A vulnerability was found in Dromara lamp-cloud up to 5.10.0. This vul ...)
-	TODO: check
+	NOT-FOR-US: Dromara lamp-cloud
 CVE-2026-19756 (A vulnerability has been found in Dromara lamp-cloud up to 5.10.0. Thi ...)
-	TODO: check
+	NOT-FOR-US: Dromara lamp-cloud
 CVE-2026-19753 (A vulnerability was detected in Model Context Protocol mcp-rdf-explore ...)
-	TODO: check
+	NOT-FOR-US: Model Context Protocol mcp-rdf-explorer
 CVE-2026-19752 (A vulnerability was found in EnzoVezzaro mcp-dominican-layer up to 39d ...)
-	TODO: check
+	NOT-FOR-US: EnzoVezzaro mcp-dominican-layer
 CVE-2026-19751 (A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373 ...)
-	TODO: check
+	NOT-FOR-US: EnzoVezzaro mcp-dominican-layer
 CVE-2026-19750 (A flaw has been found in Tenda CH, CP and TX3 V21.x/V22.x/V25.x/V26.x/ ...)
 	NOT-FOR-US: Tenda
 CVE-2026-19749 (A vulnerability was detected in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, C ...)
@@ -5196,9 +5196,9 @@ CVE-2026-19748 (A security vulnerability has been detected in Tenda CH7, CH7G, C
 CVE-2026-19747 (A weakness has been identified in Tenda CH7, CH7G, CH10, CP3, CP3 Pro, ...)
 	NOT-FOR-US: Tenda
 CVE-2026-19746 (A vulnerability has been found in Calix GigaSpire 26.1.0. The affected ...)
-	TODO: check
+	NOT-FOR-US: Calix GigaSpire
 CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknow ...)
-	TODO: check
+	NOT-FOR-US: Calix GigaSpire
 CVE-2026-19617 (A flaw was found in libdm. A local attacker could craft a malicious Lo ...)
 	TODO: check
 CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 ...)
@@ -6080,9 +6080,9 @@ CVE-2026-23603 (Blind SSRF in OAuth2 avatar synchronization via unvalidated OIDC
 CVE-2026-21832 (HCL AION is affected by a vulnerability where indirect prompt injectio ...)
 	NOT-FOR-US: HCL
 CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer Pentestify be ...)
-	TODO: check
+	NOT-FOR-US: maalfer Pentestify
 CVE-2026-19734 (Missing Authorization and Authorization Bypass Through User-Controlled ...)
-	TODO: check
+	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19730 (The 'podman quadlet install --replace' command opens the existing dest ...)
 	TODO: check
 CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management component  ...)
@@ -6662,17 +6662,17 @@ CVE-2026-49473 (@cedar-policy/authorization-for-expressjs is an open-source Expr
 CVE-2026-49466 (Draft List is a WordPress plugin to manage and promote unpublished con ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-48791 (sigstore-java is a sigstore java client for interacting with sigstore  ...)
-	TODO: check
+	NOT-FOR-US: sigstore-java
 CVE-2026-47718 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-47717 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-46731 (Dell Display and Peripheral Manager (DDPM Windows), versions prior to  ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-46688 (The Meeting Room Booking System (MRBS) is a PHP-based application for  ...)
-	TODO: check
+	NOT-FOR-US: Meeting Room Booking System (MRBS)
 CVE-2026-46382 (The Meeting Room Booking System (MRBS) is a PHP-based application for  ...)
-	TODO: check
+	NOT-FOR-US: Meeting Room Booking System (MRBS)
 CVE-2026-3835 (The Prevent Direct Access \u2013 Protect WordPress Files plugin for Wo ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19657 (ScadaLTS 2.7.8.1reflects user-supplied input into an HTML response wit ...)
@@ -7127,7 +7127,7 @@ CVE-2026-49467 (Pingvin Share X is a secure and easy self-hosted file sharing pl
 CVE-2026-49349 (regclient is a Docker and OCI Registry Client in Go. Prior to version  ...)
 	TODO: check
 CVE-2026-49262 (In the Aimeos Pagible content management system prior to version 0.10. ...)
-	TODO: check
+	NOT-FOR-US: Aimeos Pagible content management system
 CVE-2026-48554 (Nagios Core before 4.5.14 and Nagios XI before 2026R1.7 are vulnerable ...)
 	TODO: check
 CVE-2026-48553 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 are vulnerable ...)
@@ -7157,9 +7157,9 @@ CVE-2026-47227 (Admidio is an open-source user management solution. `modules/cat
 CVE-2026-47226 (Admidio is an open-source user management solution. Prior to version 5 ...)
 	NOT-FOR-US: Admidio
 CVE-2026-44741 (Pimcore's Admin Classic Bundle provides a Backend UI for Pimcore. Vers ...)
-	TODO: check
+	NOT-FOR-US: Pimcore
 CVE-2026-42018 (JFrog Artifactory could return an internal anonymous-user token to an  ...)
-	TODO: check
+	NOT-FOR-US: JFrog Artifactory
 CVE-2026-26035 (An Improper Authentication vulnerability [CWE-287] vulnerability in Fo ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-19548 (Multiple Use-After-Free vulnerabilities were found in the add_archive_ ...)
@@ -7596,7 +7596,7 @@ CVE-2026-5917 (libgit2 versions v0.27.0 through v1.9.0 built with the libssh2 SS
 CVE-2026-55676 (Malcolm is a network traffic analysis tool suite. The file-upload comp ...)
 	NOT-FOR-US: Malcolm
 CVE-2026-48813 (Flawfinder is a a static analysis tool for finding vulnerabilities in  ...)
-	TODO: check
+	NOT-FOR-US: Flawfinder
 CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO realtime c ...)
 	TODO: check
 CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
@@ -9139,7 +9139,7 @@ CVE-2026-48809 (python-engineio is a Python implementation of the Engine.IO real
 CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
 	TODO: check
 CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the open-source datab ...)
-	TODO: check
+	NOT-FOR-US: Turso CLI
 CVE-2026-48771 (ishankportfolio is a portfolio website. Prior to version 1.0.1, contac ...)
 	NOT-FOR-US: ishankportfolio
 CVE-2026-48767 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
@@ -9225,9 +9225,9 @@ CVE-2026-48375 (ColdFusion is affected by an Incorrect Authorization vulnerabili
 CVE-2026-48362 (ColdFusion is affected by an Improper Neutralization of Special Elemen ...)
 	NOT-FOR-US: Adobe
 CVE-2026-48056 (Streambert is a cross-platform Electron Desktop App to stream and down ...)
-	TODO: check
+	NOT-FOR-US: Streambert
 CVE-2026-48046 (Streambert is a cross-platform Electron Desktop App to stream and down ...)
-	TODO: check
+	NOT-FOR-US: Streambert
 CVE-2026-47940 (Lightroom Classic is affected by an Integer Overflow or Wraparound vul ...)
 	NOT-FOR-US: Adobe
 CVE-2026-47922 (CAI Content Credentials is affected by a Server-Side Request Forgery ( ...)
@@ -9245,21 +9245,21 @@ CVE-2026-47285 (Improper neutralization of special elements used in a command ('
 CVE-2026-46670 (YesWiki is a wiki system written in PHP. Prior to version 4.6.4,  an u ...)
 	NOT-FOR-US: YesWiki
 CVE-2026-43606 (Observable Timing Discrepancy in the AMD Vitis Libraries ECDSA secp256 ...)
-	TODO: check
+	NOT-FOR-US: AMD
 CVE-2026-42976 (Missing authentication for critical function in Windows RPC API allows ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-42142 (TypeBot is a chatbot builder tool. Prior to version 3.17.0, the `handl ...)
-	TODO: check
+	NOT-FOR-US: TypeBot
 CVE-2026-40375 (Missing authorization in Dynamics Business Central allows an authorize ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-39452 (Protection mechanism failure for some Intel(R) Transfer Learning Tool  ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-35502 (Deserialization of untrusted data for some Intel(R) Extension for PyTo ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-34635 (is affected by a Use of Hard-coded Cryptographic Key vulnerability tha ...)
 	NOT-FOR-US: Adobe
 CVE-2026-34175 (Uncontrolled search path for some Hardware-Aware-Automated-MachineLear ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-33922 (A path traversal vulnerability was discovered in the Offline archives  ...)
 	NOT-FOR-US: Nozomi Arc
 CVE-2026-33921 (The Windows installer deployed Npcap leaving its access restriction op ...)
@@ -9267,13 +9267,13 @@ CVE-2026-33921 (The Windows installer deployed Npcap leaving its access restrict
 CVE-2026-32791 (Untrusted search path for some Intel(R) Performance Counter Monitor (I ...)
 	NOT-FOR-US: Intel
 CVE-2026-32788 (Uncontrolled search path for some Approximate Bayesian Inference Frame ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-32677 (Path traversal for some gaudi-container-runtime before version 1.24.0  ...)
 	NOT-FOR-US: gaudi-container-runtime
 CVE-2026-28757 (Protection mechanism failure for some Intel(R) Workload Services Frame ...)
 	NOT-FOR-US: Intel
 CVE-2026-28729 (Integer overflow in the UEFI firmware for the Intel(R) Slim Bootloader ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-28707 (Protection mechanism failure for some LLM-on-Ray before version 1.0 wi ...)
 	NOT-FOR-US: Intel
 CVE-2026-28700 (Uncontrolled search path for some EquiTriton before version f5ddbb5 wi ...)
@@ -9285,21 +9285,21 @@ CVE-2026-27302 (Adobe Campaign Classic (ACC) is affected by an Incorrect Authori
 CVE-2026-25652 (is affected by an Incorrect Authorization vulnerability that could res ...)
 	NOT-FOR-US: Adobe
 CVE-2026-25194 (Out-of-bounds write in the firmware for the Intel(R) Slim Bootloader m ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-24911 (Stack-based buffer overflow for some Intel(R) PROSet/Wireless WiFi Sof ...)
 	NOT-FOR-US: Intel
 CVE-2026-24693 (Protection mechanism failure for some Intel(R) oneCCL Bindings for PyT ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-24099 (Use after free for some Intel(R) PROSet/Wireless WiFi Software for Win ...)
 	NOT-FOR-US: Intel
 CVE-2026-22887 (Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi So ...)
 	NOT-FOR-US: Intel
 CVE-2026-21400 (Protection mechanism failure for some Intel(R) AI Reference Models bef ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-21399 (Heap-based buffer overflow for the Intel(R) Open Volume Kernel Library ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-21387 (Protection mechanism failure for some Intel(R) LLM Library for PyTorch ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-21279 (is affected by an Improper Input Validation vulnerability that could r ...)
 	NOT-FOR-US: Adobe
 CVE-2026-21273 (is affected by an Improper Input Validation vulnerability that could r ...)
@@ -9313,9 +9313,9 @@ CVE-2026-20908 (Time-of-check time-of-use race condition for the Intel(R) NPU Dr
 CVE-2026-20906 (Protection mechanism failure for some Intel(R) Neural Compressor softw ...)
 	NOT-FOR-US: Intel
 CVE-2026-20903 (Protection mechanism failure for some Intel(R) AI Containers before ve ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20898 (Improper access control in the firmware for some in Alias Checking Tru ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20891 (Improper authentication for some Intel(R) PROSet/Wireless WiFi Softwar ...)
 	NOT-FOR-US: Intel
 CVE-2026-20890 (Improper privilege management for some Intel(R) PROSet/Wireless WiFi S ...)
@@ -9323,11 +9323,11 @@ CVE-2026-20890 (Improper privilege management for some Intel(R) PROSet/Wireless
 CVE-2026-20886 (Out-of-bounds write for some Intel(R) PROSet/Wireless WiFi Software fo ...)
 	NOT-FOR-US: Intel
 CVE-2026-20885 (Improper authentication in the Intel(R) TDX module for some Intel(R) p ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20878 (Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Softwa ...)
 	NOT-FOR-US: Intel
 CVE-2026-20799 (Untrusted search path for some Battery Life Diagnostic Tool software b ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20795 (Improper buffer restrictions for some Intel(R) PROSet/Wireless WiFi So ...)
 	NOT-FOR-US: Intel
 CVE-2026-20789 (Improper access control for some Intel(R) PROSet/Wireless WiFi Softwar ...)
@@ -9345,9 +9345,9 @@ CVE-2026-20778 (Out-of-bounds read for some Intel(R) PROSet/Wireless WiFi Softwa
 CVE-2026-20776 (Improper conditions check for some Intel(R) PROSet/Wireless WiFi Softw ...)
 	TODO: check
 CVE-2026-20775 (Uncaught exception for some Intel(R) TDX modules within Ring 0: Trust  ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20770 (Protection mechanism failure for some Cluster Management Toolkit for K ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20769 (Improper conditions check for the Intel(R) NPU Driver for all versions ...)
 	TODO: check
 CVE-2026-20765 (Incorrect comparison for some Intel(R) TDX Guest software before versi ...)
@@ -9371,7 +9371,7 @@ CVE-2026-20739 (Improper conditions check for some Intel(R) PROSet/Wireless WiFi
 CVE-2026-20737 (Exposure of sensitive information to an unauthorized actor for some In ...)
 	NOT-FOR-US: Intel
 CVE-2026-20734 (Improper initialization in some firmware for some Intel(R) Active Mana ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20731 (Improper buffer restrictions for the Intel(R) NPU Driver for all versi ...)
 	TODO: check
 CVE-2026-20728 (Protection mechanism failure for some Intel Extension for TensorFlow s ...)
@@ -9379,17 +9379,17 @@ CVE-2026-20728 (Protection mechanism failure for some Intel Extension for Tensor
 CVE-2026-20727 (Null pointer dereference for some Intel(R) PROSet/Wireless WiFi Softwa ...)
 	NOT-FOR-US: Intel
 CVE-2026-20715 (Improper input validation in some firmware for some Intel(R) Active Ma ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20712 (Incomplete cleanup in some UEFI firmware for some Intel(R) reference p ...)
 	NOT-FOR-US: Intel
 CVE-2026-20708 (Insertion of sensitive information into log file in the subsystem for  ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20705 (Insecure storage of sensitive information in the Intel(R) TDX module f ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20702 (Protection mechanism failure for some Intel(R) Data Center Attestation ...)
-	TODO: check
+	NOT-FOR-US: Intel
 CVE-2026-20349 (A vulnerability in the Remote Access SSL VPN service for Cisco Secure  ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-19546 (A flaw was found in DBI. This is a fix for a partial fix for CVE-2026- ...)
 	- libdbi-perl <not-affected> (Red Hat-specific backport issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2513963
@@ -10461,13 +10461,13 @@ CVE-2026-55814 (Missing Authentication in Apache Ranger Download APIs on version
 CVE-2026-55799 (Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apa ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-48159 (use-reducer-async is a React useReducer with async actions. Between 20 ...)
-	TODO: check
+	NOT-FOR-US: use-reducer-async
 CVE-2026-48158 (use-context-selector is a React useContextSelector hook in userland Be ...)
-	TODO: check
+	NOT-FOR-US: use-context-selector
 CVE-2026-48048 (XWiki Platform is a generic wiki platform. XWiki discovered that the p ...)
 	NOT-FOR-US: XWiki
 CVE-2026-47754 (Metacat is data repository software that helps researchers preserve, s ...)
-	TODO: check
+	NOT-FOR-US: Metacat
 CVE-2026-44630 (Improper validation of length fields in the Apache IoTDB RPC service m ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-44416 (Remote Code Execution via Arbitrary Class Instantiation inplugin-schem ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/320e60c9e8765e3e587a8286a9bf7eb9837e84b8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/320e60c9e8765e3e587a8286a9bf7eb9837e84b8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/ee7e7d63/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list