[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Aug 18 11:38:05 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dae2554a by Moritz Muehlenhoff at 2026-08-18T12:37:51+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -590,6 +590,7 @@ CVE-2026-20000 (A vulnerability was detected in itsourcecode Hospital Management
 	NOT-FOR-US: itsourcecode System
 CVE-2026-19999 (A security vulnerability has been detected in Open Asset Import Librar ...)
 	- assimp <unfixed>
+	[trixie] - assimp <no-dsa> (Minor issue)
 	NOTE: https://github.com/assimp/assimp/issues/6633
 	NOTE: https://github.com/assimp/assimp/pull/6759
 	NOTE: https://github.com/assimp/assimp/commit/50d767984e78d51b53e2020fdf0967fd624bc377
@@ -652,10 +653,13 @@ CVE-2025-27621 (UpTrain is an open-source platform to evaluate and improve gener
 	TODO: check
 CVE-2026-XXXX [heap out-of-bounds write during Unicode font-name conversion]
 	- antiword <unfixed> (bug #1144645)
+	[trixie] - antiword <postponed> (Revisit when fixed upstream)
 CVE-2026-XXXX [heap out-of-bounds write during OLE PPS name decoding]
 	- antiword <unfixed> (bug #1144644)
+	[trixie] - antiword <postponed> (Revisit when fixed upstream)
 CVE-2026-XXXX [heap out-of-bounds write when appending font-table entry]
 	- antiword <unfixed> (bug #1144643)
+	[trixie] - antiword <postponed> (Revisit when fixed upstream)
 CVE-2026-XXXX [out-of-bounds read in szLpstr/xstrdup may expose adjacent heap data]
 	- antiword <unfixed> (bug #1144642; unimportant)
 	NOTE: Crash in CLI tool, no security impact
@@ -6262,8 +6266,9 @@ CVE-2026-19746 (A vulnerability has been found in Calix GigaSpire 26.1.0. The af
 CVE-2026-19745 (A flaw has been found in Calix GigaSpire 26.1.0. Impacted is an unknow ...)
 	NOT-FOR-US: Calix GigaSpire
 CVE-2026-19617 (A flaw was found in libdm. A local attacker could craft a malicious Lo ...)
-	- lvm2 <unfixed>
+	- lvm2 <unfixed> (unimportant)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2514626
+	NOTE: Doesn't cross any meaningful security boundary
 CVE-2026-19483 (IBM Storage Scale 5.2.3.0 through 5.2.3.8, and 6.0.0.0 through 6.0.1.0 ...)
 	NOT-FOR-US: IBM
 CVE-2026-19297 (IBM Langflow OSS 1.0.0 through 1.9.6 could allow a remote attacker to  ...)
@@ -11930,6 +11935,7 @@ CVE-2026-15060 (When systemd-machined >= v259 (or v258 with a custom `polkit` po
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/8eb162df81b4f684c9d444e458dbf22674f964fb (v261.2)
 CVE-2026-15059 (Local unprivileged users can terminate arbitrary local processes via a ...)
 	- systemd 261~rc3-1
+	[trixie] - systemd <no-dsa> (Minor issue)
 	NOTE: https://github.com/systemd/systemd/security/advisories/GHSA-652q-wxr6-h5j6
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/cde88c4ea364e816619f385a870d074ebc12fe0f (v261-rc3)
 	NOTE: Fixed by: https://github.com/systemd/systemd/commit/a8feb2f23565d39df5c90a753c851c1934a53117 (v258.9)
@@ -24047,7 +24053,9 @@ CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp d006858/e15ef
 	NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
 CVE-2026-15928 (XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a ref ...)
 	- xmlrpc-c <unfixed> (bug #1143065)
-	TODO: check upstream status
+	[trixie] - xmlrpc-c <no-dsa> (Minor issue)
+	NOTE: https://www.themissinglink.com.au/security-advisories/cve-2026-15928
+	NOTE: https://sourceforge.net/p/xmlrpc-c/code/3342/
 CVE-2026-14827 (The Calendar WordPress plugin before 1.3.18 does not properly escape a ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14820 (The Quiz and Survey Master (QSM)  WordPress plugin before 11.1.3 does  ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -46,6 +46,8 @@ gimp
 --
 gst-plugins-bad1.0 (jmm)
 --
+gst-plugins-good1.0
+--
 jackson-databind
 --
 jetty9



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dae2554aa3d00e20a47a40cc7660ef8e2955b248

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dae2554aa3d00e20a47a40cc7660ef8e2955b248
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/d8283dc7/attachment.htm>


More information about the debian-security-tracker-commits mailing list