[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Aug 21 15:48:43 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
05740c72 by Salvatore Bonaccorso at 2026-08-21T16:48:00+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -216,7 +216,7 @@ CVE-2026-72854 (msgpack_unpacker_expand_buffer in src/unpack.c, reached through
CVE-2026-72852 (hank-ai/darknet sizes a convolutional layer's weight and output heap b ...)
NOT-FOR-US: hank-ai/darknet
CVE-2026-72847 (broot renders each file and directory name in its interactive tree vie ...)
- - rust-broot <unfixed>
+ - rust-broot <unfixed> (bug #1145024)
NOTE: https://github.com/Canop/broot/issues/1188
NOTE: Fixed by: https://github.com/Canop/broot/commit/4ba40f7d47af78457c7656f15eba71d63d97fce5
NOTE: Fixed by: https://github.com/Canop/broot/commit/0717a94b3c0efa19c7bbcfe0fb49a2374752a168
@@ -339,7 +339,7 @@ CVE-2026-64961 (ATutor is vulnerable to authentication bypass .Although a token
CVE-2026-64960 (ATutor Gameme module allows users to upload files of any type and exte ...)
NOT-FOR-US: ATutor
CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems. Prior to 2. ...)
- - nix <unfixed>
+ - nix <unfixed> (bug #1145021)
NOTE: https://github.com/NixOS/nix/security/advisories/GHSA-6h4g-g5j9-fm5f
NOTE: https://github.com/NixOS/nix/pull/15401
NOTE: Fixed by: https://github.com/NixOS/nix/commit/26679828f74ee6e82a4100904e6361f993ff5390 (2.35.0)
@@ -548,7 +548,7 @@ CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow Remote Code Execution Vul
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/b1f46e63c82065bd60e84359fb729380d5b043bf
TODO: check
CVE-2026-18300 (GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
- - gegl <unfixed>
+ - gegl <unfixed> (bug #1145018)
NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-453/
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gegl/-/commit/d3d262008299341c5b032b354021632ceadb2799
CVE-2026-18299 (GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerabili ...)
@@ -1091,14 +1091,14 @@ CVE-2026-75628 (Punk::OAuth2 versions before 0.03 for Perl allow an attacker-cho
CVE-2026-75616 (An OS command injection vulnerability exists in the web management int ...)
NOT-FOR-US: TPLink
CVE-2026-75596 (Netty is an asynchronous, event-driven network application framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145017)
NOTE: https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4
NOTE: https://github.com/netty/netty/pull/17213
NOTE: Fixed by: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 (netty-4.2.17.Final)
NOTE: https://github.com/netty/netty/pull/17217
NOTE: Fixed by: https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961 (netty-4.1.137.Final)
CVE-2026-75595 (Netty is an asynchronous, event-driven network application framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145017)
NOTE: https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4
NOTE: https://github.com/netty/netty/pull/17213
NOTE: Fixed by: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 (netty-4.2.17.Final)
@@ -1143,7 +1143,7 @@ CVE-2026-68559 (Wekan is open source kanban built with Meteor. From 9.57 until 9
CVE-2026-68558 (Wekan is open source kanban built with Meteor. From 8.36 until 9.74, t ...)
- wekan <itp> (bug #819238)
CVE-2026-68555 (Coturn is a free open source implementation of TURN and STUN Server. I ...)
- - coturn <unfixed>
+ - coturn <unfixed> (bug #1145022)
NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-hpq3-g7x4-h7xx
NOTE: Fixed by: https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7 (4.16.0)
CVE-2026-68554 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
@@ -5000,7 +5000,7 @@ CVE-2026-69189 (Hoppscotch is an open source API development ecosystem. Prior to
CVE-2026-69160 (OpenList a file list program that supports multiple storage. Prior to ...)
NOT-FOR-US: OpenList
CVE-2026-68939 (Pyenv provides simple Python version management. Prior to 2.8.0, is_ve ...)
- - pyenv <unfixed>
+ - pyenv <unfixed> (bug #1145023)
[trixie] - pyenv <no-dsa> (Minor issue)
NOTE: https://github.com/pyenv/pyenv/security/advisories/GHSA-g478-f579-9vp9
NOTE: Fixed by: https://github.com/pyenv/pyenv/commit/95df7dbc7b34595b47c9b922de198547effda819 (v2.8.0)
@@ -5153,7 +5153,7 @@ CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an
CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kriptok Cr ...)
TODO: check
CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
- - lz4-java <unfixed>
+ - lz4-java <unfixed> (bug #1145019)
NOTE: https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
NOTE: Fixed by: https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da (v1.11.1)
CVE-2026-59940 (Seroval facilitates JS value stringification, including complex struct ...)
@@ -6021,12 +6021,12 @@ CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Impro
CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Travers ...)
NOT-FOR-US: Dell / EMC
CVE-2026-59903 (Netty is an asynchronous, event-driven network application framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145017)
NOTE: https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46
NOTE: https://github.com/netty/netty/pull/17213 (4.2-branch)
NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
CVE-2026-59902 (Netty is an asynchronous, event-driven network application framework. ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145017)
NOTE: https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f
NOTE: https://github.com/netty/netty/pull/17213 (4.2-branch)
NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
@@ -20133,7 +20133,7 @@ CVE-2026-62996 (Smarty is a template engine for PHP, facilitating the separation
NOTE: https://github.com/smarty-php/smarty/pull/1195
NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e (v5.8.4)
CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
- - smarty4 <unfixed>
+ - smarty4 <unfixed> (bug #1145020)
[trixie] - smarty4 <no-dsa> (Minor issue)
- smarty3 <unfixed>
[trixie] - smarty3 <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05740c724542f2781b0fb4989a148a590342becf
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05740c724542f2781b0fb4989a148a590342becf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/f8fb1255/attachment.htm>
More information about the debian-security-tracker-commits
mailing list