[Git][security-tracker-team/security-tracker][master] Updates for some glances issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 17 21:00:27 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d6a08ec3 by Salvatore Bonaccorso at 2026-08-17T22:00:12+02:00
Updates for some glances issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -159,13 +159,24 @@ CVE-2026-70412 (Dell iDRAC9, versions prior to 7.20.30.50, and Dell iDRAC10, ver
CVE-2026-68762 (In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket deco ...)
NOT-FOR-US: JetBrains
CVE-2026-68520 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
- TODO: check
+ - glances 4.5.6+dfsg-1
+ NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-4h34-v6r8-mmjc
+ NOTE: Fixed by: https://github.com/nicolargo/glances/commit/8d0f8276c2abd2e9d400bd6c84bdfba0dfcab065 (v4.5.6)
CVE-2026-68519 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
- TODO: check
+ - glances 4.5.6+dfsg-1
+ [trixie] - glances <not-affected> (Incomplete fix for CVE-2026-53925 not applied)
+ [bookworm] - glances <not-affected> (Incomplete fix for CVE-2026-53925 not applied)
+ NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-59fj-m2j6-hcxh
+ NOTE: Fixed by: https://github.com/nicolargo/glances/commit/5c07c0d96423e9d5b9de71dd92e3717c66f504bd
+ NOTE: CVE exists because of an incomplete fix for CVE-2026-53925.
CVE-2026-68518 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
- TODO: check
+ - glances 4.5.6+dfsg-1
+ NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-qcpp-8x79-hhp3
+ NOTE: Fixed by: https://github.com/nicolargo/glances/commit/9c280eae5419da680827024b60f6265956e31994 (v4.5.6)
CVE-2026-68517 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
- TODO: check
+ - glances 4.5.6+dfsg-1
+ NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-fp27-88fp-2phg
+ NOTE: Fixed by: https://github.com/nicolargo/glances/commit/890858944ab9d03730ec6b1ba42d4015e6d85db5 (v4.5.6)
CVE-2026-66792 (A flaw was found in the multicloud-operators-subscription component. T ...)
NOT-FOR-US: Red Hat Multicluster Global Hub
CVE-2026-64868 (New API is a large language mode (LLM) gateway and artificial intellig ...)
@@ -177,7 +188,12 @@ CVE-2026-64865 (New API is a large language mode (LLM) gateway and artificial in
CVE-2026-64859 (New API is a large language mode (LLM) gateway and artificial intellig ...)
NOT-FOR-US: New API
CVE-2026-62982 (Glances is an open-source system cross-platform monitoring tool. From ...)
- TODO: check
+ - glances 4.5.6+dfsg-1
+ [trixie] - glances <not-affected> (Vulnerable code not present)
+ [bookworm] - glances <not-affected> (Vulnerable code not present)
+ NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-73wf-9vmv-5pv9
+ NOTE: Fixed by: https://github.com/nicolargo/glances/commit/ea4cf2f54f0d961e24aa0b24fff9584bab39db93
+ NOTE: CVE exists because of an incomplete fix for CVE-2026-32608.
CVE-2026-61666 (websocket-driver is a WebSocket protocol handler with pluggable I/O. P ...)
TODO: check
CVE-2026-60107
@@ -50998,6 +51014,7 @@ CVE-2026-53925 (Glances is an open-source system cross-platform monitoring tool.
[trixie] - glances <no-dsa> (Minor issue)
[bookworm] - glances <postponed> (Minor issue; secure_popen operator interpretation present in secure.py, reachable via actions.py; requires config write access)
NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-3vwc-qwhc-3mj7
+ NOTE: When fixing this CVE make sure to fix it completely to not open up CVE-2026-68519
CVE-2026-50573 (pnpm is a package manager. Prior to 10.34.0 and 11.4.0, `pnpm install` ...)
- pnpm <itp> (bug #985669)
CVE-2026-50549 (Cursor is a code editor built for programming with AI. Prior to 3.0, C ...)
@@ -61292,7 +61309,7 @@ CVE-2026-44705 (tmp is a temporary file and directory creator for node.js. Prior
[bullseye] - node-tmp <postponed> (Minor issue)
NOTE: https://github.com/raszi/node-tmp/security/advisories/GHSA-ph9p-34f9-6g65
NOTE: Fixed by: https://github.com/raszi/node-tmp/commit/efa4a06f24374797ae32ab2b6ae39b7a611ae429 (v0.2.6)
- NOTE: When fixing this issue make sure to fix it completely to not open up CVE-2026-49982
+ NOTE: When fixing this CVE make sure to make it complete to not open up CVE-2026-49982.
CVE-2026-44693 (Pi-hole FTL is the core engine of the Pi-hole network-level advertisem ...)
NOT-FOR-US: Pi-hole FTL
CVE-2026-44692 (Sharp is a content management framework built for Laravel as a package ...)
@@ -116816,6 +116833,7 @@ CVE-2026-32608 (Glances is an open-source system cross-platform monitoring tool.
[bookworm] - glances <no-dsa> (Minor issue)
NOTE: https://github.com/nicolargo/glances/security/advisories/GHSA-vcv2-q258-wrg7
NOTE: Fixed by: https://github.com/nicolargo/glances/commit/5680a5da4afdf762fd44ced1f8160fb6d5c5dd16 (v4.5.2)
+ NOTE: When fixing this CVE make sure to make it complete to not open up CVE-2026-62982.
CVE-2026-32606 (IncusOS is an immutable OS image dedicated to running Incus. Prior to ...)
NOT-FOR-US: IncusOS
CVE-2026-32596 (Glances is an open-source system cross-platform monitoring tool. Prior ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6a08ec3430b0a2a9618e010c7981af61127e107
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d6a08ec3430b0a2a9618e010c7981af61127e107
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260817/5131e9b1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list