[Git][security-tracker-team/security-tracker][master] Unify some notes style
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 16 13:57:28 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2925125b by Salvatore Bonaccorso at 2026-08-16T14:57:04+02:00
Unify some notes style
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -18875,7 +18875,7 @@ CVE-2026-58041 (A flaw in Node.js node:sqlite allows a stale StatementSyncIterat
[bookworm] - nodejs <not-affected> (vulnerable code introduced in v22 with experimental sqlite module)
[bullseye] - nodejs <not-affected> (vulnerable code introduced in v22 with experimental sqlite module)
NOTE: https://nodejs.org/en/blog/vulnerability/july-2026-security-releases#nodesqlite-sqltagstore-iterator-replay-can-re-execute-writes-cve-2026-58041---medium
- NOTE: Fixed by commit: https://github.com/nodejs/node/commit/af9ff0490ce834f3b28efbc2551f96a03a829fd2 (v24.18.1)
+ NOTE: Fixed by: https://github.com/nodejs/node/commit/af9ff0490ce834f3b28efbc2551f96a03a829fd2 (v24.18.1)
NOTE: experimental status for v22
CVE-2026-56848 (A flaw in Node.js HTTP/2 handling allows `nghttp2_session_mem_send()` ...)
- nodejs 24.19.0+dfsg+~cs24.13.3-1
@@ -120035,9 +120035,9 @@ CVE-2026-28493 (ImageMagick is free and open-source software used for editing an
[bookworm] - imagemagick <not-affected> (vulnerable code is not present)
[bullseye] - imagemagick <not-affected> (vulnerable code is not present)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-r39q-jr8h-gcq2
- NOTE: Fixed by: [1/3] https://github.com/ImageMagick/ImageMagick/commit/6cefe972445185cbb9c76651231d52512e0ec14b (7.1.2-16)
- NOTE: Fixed by: [2/3] https://github.com/ImageMagick/ImageMagick/commit/47a803cc139a6eebf14fca5f1d5dd25c7782cc98 (7.1.2-16)
- NOTE: Fixed by: [3/3] https://github.com/ImageMagick/ImageMagick/commit/cd7acd2c4bea5c953fae062d9ce43d11374dcb60 (7.1.2-16)
+ NOTE: Fixed by [1/3]: https://github.com/ImageMagick/ImageMagick/commit/6cefe972445185cbb9c76651231d52512e0ec14b (7.1.2-16)
+ NOTE: Fixed by [2/3]: https://github.com/ImageMagick/ImageMagick/commit/47a803cc139a6eebf14fca5f1d5dd25c7782cc98 (7.1.2-16)
+ NOTE: Fixed by [3/3]: https://github.com/ImageMagick/ImageMagick/commit/cd7acd2c4bea5c953fae062d9ce43d11374dcb60 (7.1.2-16)
NOTE: im6 not affected see https://github.com/ImageMagick/ImageMagick6/issues/404
CVE-2026-28433 (Misskey is an open source, federated social media platform. All Misske ...)
NOT-FOR-US: Misskey
@@ -271605,10 +271605,10 @@ CVE-2024-12426 (Exposure of Environmental Variables and arbitrary INI file value
NOTE: https://www.libreoffice.org/about-us/security/advisories/cve-2024-12426
NOTE: [1/2] https://gerrit.libreoffice.org/c/core/+/176797
NOTE: [2/2] https://gerrit.libreoffice.org/c/core/+/177987
- NOTE: Fixed by commit [1/2] https://git.libreoffice.org/core/+/d6c89af2598e866aa9cb4fa3600691fb558befdb%5E%21 (libreoffice-24.8.4.1)
- NOTE: Fixed by commit [2/2] https://git.libreoffice.org/core/+/b63aa51c55244ee67410201fa5e7c003427b1009%5E%21 (libreoffice-24.8.4.1)
- NOTE: Fixed by commit [1/2] https://github.com/LibreOffice/core/commit/a22d185ef7d141676e8a4db15471bfe6d283cb8c (distro/cib/libreoffice-6-4)
- NOTE: Fixed by commit [2/2] https://github.com/LibreOffice/core/commit/4915889ab56bc946264c257391ba6eeedfdfad95 (distro/cib/libreoffice-6-4)
+ NOTE: Fixed by [1/2]: https://git.libreoffice.org/core/+/d6c89af2598e866aa9cb4fa3600691fb558befdb%5E%21 (libreoffice-24.8.4.1)
+ NOTE: Fixed by [2/2]: https://git.libreoffice.org/core/+/b63aa51c55244ee67410201fa5e7c003427b1009%5E%21 (libreoffice-24.8.4.1)
+ NOTE: Fixed by [1/2]: https://github.com/LibreOffice/core/commit/a22d185ef7d141676e8a4db15471bfe6d283cb8c (distro/cib/libreoffice-6-4)
+ NOTE: Fixed by [2/2]: https://github.com/LibreOffice/core/commit/4915889ab56bc946264c257391ba6eeedfdfad95 (distro/cib/libreoffice-6-4)
CVE-2024-12425 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
{DSA-5846-1 DLA-4020-1}
- libreoffice 4:24.8.4-1
@@ -317219,15 +317219,15 @@ CVE-2024-39908 (REXML is an XML toolkit for Ruby. The REXML gem before 3.3.1 has
NOTE: https://www.ruby-lang.org/en/news/2024/07/16/dos-rexml-cve-2024-39908/
NOTE: https://github.com/advisories/GHSA-4xqq-m2hx-25v8
NOTE: https://github.com/ruby/rexml/issues/232#issuecomment-2585211411
- NOTE: Fixed by commit [1/9] https://github.com/ruby/rexml/commit/b8a5f4cd5c8fe29c65d7a00e67170223d9d2b50e
- NOTE: Fixed by commit [2/9] https://github.com/ruby/rexml/commit/0af55fa49d4c9369f90f239a9571edab800ed36e
- NOTE: Fixed by commit [3/9] https://github.com/ruby/rexml/commit/c1b64c174ec2e8ca2174c51332670e3be30c865f
- NOTE: Fixed by commit [4/9] https://github.com/ruby/rexml/commit/9f1415a2616c77cad44a176eee90e8457b4774b6
- NOTE: Fixed by commit [5/9] https://github.com/ruby/rexml/commit/c33ea498102be65082940e8b7d6d31cb2c6e6ee2
- NOTE: Fixed by commit [6/9] https://github.com/ruby/rexml/commit/a79ac8b4b42a9efabe33a0be31bd82d33fd50347
- NOTE: Fixed by commit [7/9] https://github.com/ruby/rexml/commit/67efb5951ed09dbb575c375b130a1e469f437d1f
- NOTE: Fixed by commit [8/9] https://github.com/ruby/rexml/commit/1f1e6e9b40bf339894e843dfd679c2fb1a5ddbf2
- NOTE: Fixed by commit [9/9] https://github.com/ruby/rexml/commit/910e5a2b487cb5a30989884a39f9cad2cc499cfc
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/b8a5f4cd5c8fe29c65d7a00e67170223d9d2b50e
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/0af55fa49d4c9369f90f239a9571edab800ed36e
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/c1b64c174ec2e8ca2174c51332670e3be30c865f
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/9f1415a2616c77cad44a176eee90e8457b4774b6
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/c33ea498102be65082940e8b7d6d31cb2c6e6ee2
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/a79ac8b4b42a9efabe33a0be31bd82d33fd50347
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/67efb5951ed09dbb575c375b130a1e469f437d1f
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/1f1e6e9b40bf339894e843dfd679c2fb1a5ddbf2
+ NOTE: Fixed by: https://github.com/ruby/rexml/commit/910e5a2b487cb5a30989884a39f9cad2cc499cfc
CVE-2024-39887 (An SQL Injection vulnerability in Apache Superset exists due to improp ...)
NOT-FOR-US: Apache Superset
CVE-2024-39700 (JupyterLab extension template is a `copier` template for JupyterLab e ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2925125b6df84d646db21e086cdd5119d2eedd43
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2925125b6df84d646db21e086cdd5119d2eedd43
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260816/4887bf4f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list