[Git][security-tracker-team/security-tracker][master] trixie triage, new znuny issue
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Aug 21 12:00:57 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
bb34d8f7 by Moritz Muehlenhoff at 2026-08-21T12:51:20+02:00
trixie triage, new znuny issue
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -65,7 +65,9 @@ CVE-2026-77019 (A vulnerability was determined in CodeAstro Apartment Visitor Ma
NOT-FOR-US: CodeAstro
CVE-2026-77014 (A flaw was found in libsoup's SoupServer HTTP Range header processing. ...)
- libsoup3 <unfixed> (bug #1144976)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/550
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/e82c13ba03defcee10f981ac964f4d570b21a251
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libsoup/-/commit/6ece9e52d918cefa1e99b5f359a22b111bdced75
@@ -126,6 +128,7 @@ CVE-2026-75514 (BunkerWeb is an open-source, next-generation Web Application Fir
NOT-FOR-US: BunkerWeb
CVE-2026-75140 (jsoup through 1.23.2, fixed in commit 862ba2f, contains an uncontrolle ...)
- jsoup <unfixed> (bug #1144972)
+ [trixie] - jsoup <no-dsa> (Minor issue)
NOTE: https://github.com/jhy/jsoup/pull/2556
NOTE: Fixed by: https://github.com/jhy/jsoup/commit/862ba2f1d48ee95609183dbcfc848c9fd7afc76a
CVE-2026-74021 (Unauthenticated Broken Access Control in Chaplin <= 2.6.8 versions.)
@@ -699,9 +702,11 @@ CVE-2026-8619 (An unauthenticated denial-of-service vulnerability was identified
NOT-FOR-US: TPLink
CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with custom en ...)
- expat <unfixed> (bug #1144927)
+ [trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1322
CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentr ...)
- expat <unfixed> (bug #1144926)
+ [trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1326
CVE-2026-76929 (Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows ...)
- wireshark <unfixed> (bug #1144924)
@@ -1584,36 +1589,49 @@ CVE-2026-75148 (cgltf through 1.15 contains an integer overflow vulnerability in
NOT-FOR-US: cgltf
CVE-2026-75147 (FFmpeg before commit 983dae9 contains an out-of-bounds read in the AV1 ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <not-affected> (Vulnerable code not present)
+ [bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
+ [bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24096
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/983dae9c19f46c87d597598c0fd2f2fcee0ad2f8 (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/f175bd50821f9adcded3acacc6b8e04037a92715 (n9.0.1)
+ NOTE: Introduced by https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/330c8f8b936de66d08d5c462845e7fdcbc637b75 (n8.0)
CVE-2026-75146 (FFmpeg before commit 65b0dab contains an out-of-bounds read in the DAS ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24093
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/65b0dab903e5975e036b30ecc58f5935d4f151e0 (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/999f8ba75ce0bf1167677de7e11a5af678fdb866 (n9.0.1)
CVE-2026-75145 (FFmpeg before commit b4c199c contains an incorrect integer narrowing c ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <not-affected> (Vulnerable code not present)
+ [bookworm] - ffmpeg <not-affected> (Vulnerable code not present)
+ [bullseye] - ffmpeg <not-affected> (Vulnerable code not present)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24090
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b4c199c5906ff53368926c2a5839881f41957e7f (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/7646bb4c42e6837a9396c3d9ab8d8cf476e2053b (n9.0.1)
+ NOTE: Introduced by https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/330c8f8b936de66d08d5c462845e7fdcbc637b75 (n8.0)
CVE-2026-75144 (FFmpeg before commit 1cdeb3c contains a heap buffer overflow vulnerabi ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24091
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1cdeb3c4e7f1f8566d846b9b451e01c376398818 (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1afd5c3ddafda4209e0881cd30684b919e99de7c (n9.0.1)
CVE-2026-75143 (FFmpeg before commit 1c10bcc contains a heap buffer overflow in the RI ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24089
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/1c10bcc2e17255dacb717a25ab3db142ce390602 (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/8880a174d08131f94f58a0492d1c8c6d68b74f67 (n9.0.1)
CVE-2026-75142 (FFmpeg before commit 9d786e4 contains a stack buffer overflow in the M ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24087
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/9d786e4b5e9b8482651928574de33772aeee7be1 (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/b274f0d21ba684446fd59b49e00f3f8e9ed954df (n9.0.1)
CVE-2026-75141 (FFmpeg before commit acf5d7c contains a heap buffer overflow in the hv ...)
- ffmpeg <unfixed>
+ [trixie] - ffmpeg <postponed> (Wait until fixed in 7.1.x upstream branch)
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/24088
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/acf5d7cdc1f9ae8752c23e1ea8d7f355ed780781 (master)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/c7132ef8f63c383d11a00a9e3034748d8dd15fb3 (n9.0.1)
@@ -4351,6 +4369,7 @@ CVE-2026-75911 (CodeWhale versions before 0.8.64 fail to properly validate the a
NOT-FOR-US: CodeWhale
CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplo ...)
- libmodplug <unfixed> (bug #1144933)
+ [trixie] - libmodplug <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/Konstanty/libmodplug/issues/103
CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery vulnerabi ...)
NOT-FOR-US: RAGFlow
@@ -4982,6 +5001,7 @@ CVE-2026-69160 (OpenList a file list program that supports multiple storage. Pri
NOT-FOR-US: OpenList
CVE-2026-68939 (Pyenv provides simple Python version management. Prior to 2.8.0, is_ve ...)
- pyenv <unfixed>
+ [trixie] - pyenv <no-dsa> (Minor issue)
NOTE: https://github.com/pyenv/pyenv/security/advisories/GHSA-g478-f579-9vp9
NOTE: Fixed by: https://github.com/pyenv/pyenv/commit/95df7dbc7b34595b47c9b922de198547effda819 (v2.8.0)
CVE-2026-68927 (MobSF is a mobile application security testing tool used. Prior to 4.5 ...)
@@ -5062,6 +5082,7 @@ CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability caused ...)
- expat <unfixed> (bug #1144925)
+ [trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1321
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
@@ -5415,11 +5436,13 @@ CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 3454
- python3.15 <unfixed>
- python3.14 <unfixed>
- python3.13 <unfixed>
+ [trixie] - python3.13 <no-dsa> (Minor issue)
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed>
+ [trixie] - pypy3 <no-dsa> (Minor issue)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/EUHHTC6EV7HCLSUHP25C5VHSV4V2MUZN/
NOTE: https://github.com/python/cpython/issues/155292
NOTE: https://github.com/python/cpython/pull/155293
@@ -5431,11 +5454,13 @@ CVE-2026-15806 (The HTTPPasswordMgr class in the urllib.request module, along wi
- python3.15 <unfixed>
- python3.14 <unfixed>
- python3.13 <unfixed>
+ [trixie] - python3.13 <no-dsa> (Minor issue)
- python3.11 <removed>
- python3.9 <removed>
- python2.7 <removed>
[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
- pypy3 <unfixed>
+ [trixie] - pypy3 <no-dsa> (Minor issue)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/3OKPE5S75KDNA7FY7AI3PL2MXM2X5RB3/
NOTE: https://github.com/python/cpython/issues/155694
NOTE: https://github.com/python/cpython/pull/155696
@@ -16821,10 +16846,12 @@ CVE-2026-24329 (A flaw was found in wildfly-core. A remote user authenticated as
- wildfly <itp> (bug #752018)
CVE-2026-19518 (Improper Validation of Specified Quantity in Input vulnerability in Sa ...)
- rlottie <unfixed> (bug #1144646)
+ [trixie] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/596
NOTE: Fixed by: https://github.com/Samsung/rlottie/commit/2cab35db755b0e39df40b679969495e90d39c578
CVE-2026-19517 (Improper Validation of Specified Quantity in Input and Allocation of R ...)
- rlottie <unfixed> (bug #1144646)
+ [trixie] - rlottie <no-dsa> (Minor issue)
NOTE: https://github.com/Samsung/rlottie/pull/596
NOTE: Fixed by: https://github.com/Samsung/rlottie/commit/2cab35db755b0e39df40b679969495e90d39c578
CVE-2026-19516 (A caller-supplied X-Grafana-URL request header controls the destinatio ...)
@@ -257205,7 +257232,9 @@ CVE-2025-26695 (When requesting an OpenPGP key from a WKD server, an incorrect p
- thunderbird 1:128.8.0esr-1
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2025-18/#CVE-2025-26695
CVE-2025-25977 (An issue in canvg v.4.0.2 allows an attacker to execute arbitrary code ...)
- NOT-FOR-US: canvg
+ - znuny 6.5.24-1
+ [trixie] - znuny <no-dsa> (Non-free not supported)
+ NOTE: https://www.znuny.org/en/releases/znuny-lts-6-5-24
CVE-2025-25940 (VisiCut 2.1 allows code execution via Insecure XML Deserialization in ...)
NOT-FOR-US: VisiCut
CVE-2025-25620 (Unifiedtransform 2.0 is vulnerable to Cross Site Scripting (XSS) in th ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -44,6 +44,8 @@ firebird4.0
--
freecad
--
+gegl (jmm)
+--
gimp
--
gst-plugins-bad1.0 (jmm)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb34d8f7736d90b0def7ea3cc6c202808183c606
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bb34d8f7736d90b0def7ea3cc6c202808183c606
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/1f703132/attachment.htm>
More information about the debian-security-tracker-commits
mailing list