[Git][security-tracker-team/security-tracker][master] Updates for some glances issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 17 21:00:27 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d6a08ec3 by Salvatore Bonaccorso at 2026-08-17T22:00:12+02:00
Updates for some glances issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -159,13 +159,24 @@ CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, ver
 CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket deco ...)
 	NOT-FOR-US: JetBrains
 CVE-2026-68520 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
-	TODO: check
+	- glances 4.5.6+dfsg-1
+	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-4h34-v6r8-mmjc
+	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/8d0f8276c2abd2e9d400bd6c84bdfba0dfcab065 (v4.5.6)
 CVE-2026-68519 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
-	TODO: check
+	- glances 4.5.6+dfsg-1
+	[trixie] - glances <not-affected> (Incomplete fix for CVE-2026-53925 not applied)
+	[bookworm] - glances <not-affected> (Incomplete fix for CVE-2026-53925 not applied)
+	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-59fj-m2j6-hcxh
+	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/5c07c0d96423e9d5b9de71dd92e3717c66f504bd
+	NOTE: CVE exists because of an incomplete fix for CVE-2026-53925.
 CVE-2026-68518 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
-	TODO: check
+	- glances 4.5.6+dfsg-1
+	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-qcpp-8x79-hhp3
+	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/9c280eae5419da680827024b60f6265956e31994 (v4.5.6)
 CVE-2026-68517 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
-	TODO: check
+	- glances 4.5.6+dfsg-1
+	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg
+	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/890858944ab9d03730ec6b1ba42d4015e6d85db5 (v4.5.6)
 CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription component. T ...)
 	NOT-FOR-US: Red Hat Multicluster Global Hub
 CVE-2026-64868 (New API is a large language mode (LLM) gateway and artificial intellig ...)
@@ -177,7 +188,12 @@ CVE-2026-64865 (New API is a large language mode (LLM) gateway and artificial in
 CVE-2026-64859 (New API is a large language mode (LLM) gateway and artificial intellig ...)
 	NOT-FOR-US: New API
 CVE-2026-62982 (Glances is an open-source system cross-platform monitoring tool. From  ...)
-	TODO: check
+	- glances 4.5.6+dfsg-1
+	[trixie] - glances <not-affected> (Vulnerable code not present)
+	[bookworm] - glances <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-73wf-9vmv-5pv9
+	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/ea4cf2f54f0d961e24aa0b24fff9584bab39db93
+	NOTE: CVE exists because of an incomplete fix for CVE-2026-32608.
 CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
 	TODO: check
 CVE-2026-60107
@@ -50998,6 +51014,7 @@ CVE-2026-53925 (Glances is an open-source system cross-platform monitoring tool.
 	[trixie] - glances <no-dsa> (Minor issue)
 	[bookworm] - glances <postponed> (Minor issue; secure_popen operator interpretation present in secure.py, reachable via actions.py; requires config write access)
 	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-3vwc-qwhc-3mj7
+	NOTE: When fixing this CVE make sure to fix it completely to not open up CVE-2026-68519
 CVE-2026-50573 (pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` ...)
 	- pnpm <itp> (bug #985669)
 CVE-2026-50549 (Cursor is a code editor built for programming with AI. Prior to 3.0, C ...)
@@ -61292,7 +61309,7 @@ CVE-2026-44705 (tmp is a temporary file and directory creator for node.js. Prior
 	[bullseye] - node-tmp <postponed> (Minor issue)
 	NOTE: https://github.com/raszi/node-tmp/security/advisories/GHSA-ph9p-34f9-6g65
 	NOTE: Fixed by: https://github.com/raszi/node-tmp/commit/efa4a06f24374797ae32ab2b6ae39b7a611ae429 (v0.2.6)
-	NOTE: When fixing this issue make sure to fix it completely to not open up CVE-2026-49982
+	NOTE: When fixing this CVE make sure to make it complete to not open up CVE-2026-49982.
 CVE-2026-44693 (Pi-hole FTL is the core engine of the Pi-hole network-level advertisem ...)
 	NOT-FOR-US: Pi-hole FTL
 CVE-2026-44692 (Sharp is a content management framework built for Laravel as a package ...)
@@ -116816,6 +116833,7 @@ CVE-2026-32608 (Glances is an open-source system cross-platform monitoring tool.
 	[bookworm] - glances <no-dsa> (Minor issue)
 	NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-vcv2-q258-wrg7
 	NOTE: Fixed by: https://github.com/nicolargo/glances/commit/5680a5da4afdf762fd44ced1f8160fb6d5c5dd16 (v4.5.2)
+	NOTE: When fixing this CVE make sure to make it complete to not open up CVE-2026-62982.
 CVE-2026-32606 (IncusOS is an immutable OS image dedicated to running Incus. Prior to  ...)
 	NOT-FOR-US: IncusOS
 CVE-2026-32596 (Glances is an open-source system cross-platform monitoring tool. Prior ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6a08ec3430b0a2a9618e010c7981af61127e107

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6a08ec3430b0a2a9618e010c7981af61127e107
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/5131e9b1/attachment.htm>


More information about the debian-security-tracker-commits mailing list