[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 20 22:49:41 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d2d1bc2e by Moritz Muehlenhoff at 2026-08-20T23:01:43+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1643,12 +1643,14 @@ CVE-2026-64850 (Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprin
 	NOT-FOR-US: Grav CMS
 CVE-2026-63652 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.28.0+dfsg-1
+	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-9g22-w2gr-vcmp
 	NOTE: https://github.com/FreeRDP/FreeRDP/pull/12993
 	NOTE: Fixed by: https://github.com/FreeRDP/FreeRDP/commit/caf653c0ba1c75ec8f298d1baa59770102a5d14c (3.28.0)
 CVE-2026-63633 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.28.0+dfsg-1
+	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-72j9-356v-88xq
 	NOTE: https://github.com/FreeRDP/FreeRDP/pull/12993
@@ -1659,6 +1661,7 @@ CVE-2026-63407 (Grav API Plugin is a RESTful API for Grav CMS that provides full
 	NOT-FOR-US: Grav plugin
 CVE-2026-63117 (FreeRDP is a free implementation of the Remote Desktop Protocol. Prior ...)
 	- freerdp3 3.28.0+dfsg-1
+	[trixie] - freerdp3 <no-dsa> (Minor issue)
 	- freerdp2 <removed>
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-v64m-xxfw-hrv6
 	NOTE: https://github.com/FreeRDP/FreeRDP/pull/12980
@@ -2013,9 +2016,9 @@ CVE-2026-76048 (A flaw has been found in SourceCodester Simple Online Food Order
 CVE-2026-76032 (Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any auth ...)
 	NOT-FOR-US: Pydio Cells
 CVE-2026-76014 (A vulnerability has been found in BusyBox up to 1.30.1. This vulnerabi ...)
-	- busybox <unfixed>
+	- busybox <unfixed> (unimportant)
 	NOTE: https://github.com/mirror/busybox/issues/124
-	TODO: check details, reported as issue on github mirror
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-76008 (A flaw has been found in Comfast CF-N1-S 2.6.0.1. This affects the fun ...)
 	NOT-FOR-US: Comfast
 CVE-2026-76004 (A security vulnerability has been detected in UTT HiPER 1250GW up to 3 ...)
@@ -4135,6 +4138,7 @@ CVE-2026-15571 (A flaw was found in the legacy client-initiated account-linking
 	- keycloak <itp> (bug #1088287)
 CVE-2026-75900 (An out-of-bounds read vulnerability was found in swtpm's SWTPM_NVRAM_C ...)
 	- swtpm <unfixed> (bug #1144810)
+	[trixie] - swtpm <no-dsa> (Minor issue)
 	NOTE: https://github.com/stefanberger/swtpm/pull/1155
 	NOTE: Fixed by: https://github.com/stefanberger/swtpm/commit/dc5f5ee3d8261a4d9814ad5da69164a118822401 (master)
 	NOTE: Fixed by: https://github.com/stefanberger/swtpm/commit/afc9e512a0459b12776e8fa509cfa039908c6be6 (v0.10.2)
@@ -4718,6 +4722,7 @@ CVE-2026-73692
 	REJECTED
 CVE-2026-73502 (kin-openapi is a Go project for handling OpenAPI files. From 0.2.0 unt ...)
 	- golang-github-getkin-kin-openapi <unfixed> (bug #1144951)
+	[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-jpcw-4wr7-c3vq
 	NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/68ac2affa325514d7d6e731204d6a1edf6bdff64 (v0.144.0)
 CVE-2026-73426 (Trix is a what-you-see-is-what-you-get rich text editor for everyday w ...)
@@ -5237,6 +5242,7 @@ CVE-2026-23938 (An authenticated administrator is able to crash Zabbix server or
 	NOTE: https://support.zabbix.com/browse/ZBX-28075
 CVE-2026-23937 (The Zabbix API host.get action can be exploited by authenticated users ...)
 	- zabbix <unfixed> (bug #1144945)
+	[trixie] - zabbix <no-dsa> (Minor issue)
 	NOTE: https://support.zabbix.com/browse/ZBX-28074
 CVE-2026-23935 (A Zabbix administrator is able to read out of bounds memory by utilizi ...)
 	- zabbix <unfixed> (bug #1144946)
@@ -5983,6 +5989,7 @@ CVE-2026-19998 (A weakness has been identified in code-projects Online Shopping
 	NOT-FOR-US: code-projects
 CVE-2026-19693 (extract-zip through 2.0.1 containment-checks only the parent directory ...)
 	- node-extract-zip <unfixed> (bug #1144934)
+	[trixie] - node-extract-zip <no-dsa> (Minor issue)
 	NOTE: https://github.com/max-mapper/extract-zip/pull/160
 CVE-2026-18674 (On a Kong Mesh global control plane, resources received over the zone- ...)
 	TODO: check


=====================================
data/dsa-needed.txt
=====================================
@@ -36,12 +36,16 @@ cups
 --
 dulwich
 --
+emacs (jmm)
+--
 erlang (aron)
 --
 firebird3.0
 --
 firebird4.0
 --
+freecad
+--
 gimp
 --
 gst-plugins-bad1.0 (jmm)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2d1bc2e641d526996d0d1246c1f4399f000cf5b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d2d1bc2e641d526996d0d1246c1f4399f000cf5b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/4e63fd4b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list