[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 21 15:48:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
05740c72 by Salvatore Bonaccorso at 2026-08-21T16:48:00+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -216,7 +216,7 @@ CVE-2026-72854 (msgpack_unpacker_expand_buffer in src/unpack.c, reached through
 CVE-2026-72852 (hank-ai/darknet sizes a convolutional layer's weight and output heap b ...)
 	NOT-FOR-US: hank-ai/darknet
 CVE-2026-72847 (broot renders each file and directory name in its interactive tree vie ...)
-	- rust-broot <unfixed>
+	- rust-broot <unfixed> (bug #1145024)
 	NOTE: https://github.com/Canop/broot/issues/1188
 	NOTE: Fixed by: https://github.com/Canop/broot/commit/4ba40f7d47af78457c7656f15eba71d63d97fce5
 	NOTE: Fixed by: https://github.com/Canop/broot/commit/0717a94b3c0efa19c7bbcfe0fb49a2374752a168
@@ -339,7 +339,7 @@ CVE-2026-64961 (ATutor is vulnerable to authentication bypass .Although a token
 CVE-2026-64960 (ATutor Gameme module allows users to upload files of any type and exte ...)
 	NOT-FOR-US: ATutor
 CVE-2026-64846 (Nix is a package manager for Linux and other Unix systems. Prior to 2. ...)
-	- nix <unfixed>
+	- nix <unfixed> (bug #1145021)
 	NOTE: https://github.com/NixOS/nix/security/advisories/GHSA-6h4g-g5j9-fm5f
 	NOTE: https://github.com/NixOS/nix/pull/15401
 	NOTE: Fixed by: https://github.com/NixOS/nix/commit/26679828f74ee6e82a4100904e6361f993ff5390 (2.35.0)
@@ -548,7 +548,7 @@ CVE-2026-18301 (GIMP PSD File Parsing Integer Overflow Remote Code Execution Vul
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/b1f46e63c82065bd60e84359fb729380d5b043bf
 	TODO: check
 CVE-2026-18300 (GIMP HDR File Parsing Integer Overflow Remote Code Execution Vulnerabi ...)
-	- gegl <unfixed>
+	- gegl <unfixed> (bug #1145018)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-453/
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gegl/-/commit/d3d262008299341c5b032b354021632ceadb2799
 CVE-2026-18299 (GStreamer rtpsbcdepay Use-After-Free Remote Code Execution Vulnerabili ...)
@@ -1091,14 +1091,14 @@ CVE-2026-75628 (Punk::OAuth2 versions before 0.03 for Perl allow an attacker-cho
 CVE-2026-75616 (An OS command injection vulnerability exists in the web management int ...)
 	NOT-FOR-US: TPLink
 CVE-2026-75596 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1145017)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4
 	NOTE: https://github.com/netty/netty/pull/17213
 	NOTE: Fixed by: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 (netty-4.2.17.Final)
 	NOTE: https://github.com/netty/netty/pull/17217
 	NOTE: Fixed by: https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961 (netty-4.1.137.Final)
 CVE-2026-75595 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1145017)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-fccg-mwvh-qqg4
 	NOTE: https://github.com/netty/netty/pull/17213
 	NOTE: Fixed by: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 (netty-4.2.17.Final)
@@ -1143,7 +1143,7 @@ CVE-2026-68559 (Wekan is open source kanban built with Meteor. From 9.57 until 9
 CVE-2026-68558 (Wekan is open source kanban built with Meteor. From 8.36 until 9.74, t ...)
 	- wekan <itp> (bug #819238)
 CVE-2026-68555 (Coturn is a free open source implementation of TURN and STUN Server. I ...)
-	- coturn <unfixed>
+	- coturn <unfixed> (bug #1145022)
 	NOTE: https://github.com/coturn/coturn/security/advisories/GHSA-hpq3-g7x4-h7xx
 	NOTE: Fixed by: https://github.com/coturn/coturn/commit/a97f1924bb435bec49d6d91ae01fa2487c2e1bf7 (4.16.0)
 CVE-2026-68554 (Coturn is a free open source implementation of TURN and STUN Server. P ...)
@@ -5000,7 +5000,7 @@ CVE-2026-69189 (Hoppscotch is an open source API development ecosystem. Prior to
 CVE-2026-69160 (OpenList a file list program that supports multiple storage. Prior to  ...)
 	NOT-FOR-US: OpenList
 CVE-2026-68939 (Pyenv provides simple Python version management. Prior to 2.8.0, is_ve ...)
-	- pyenv <unfixed>
+	- pyenv <unfixed> (bug #1145023)
 	[trixie] - pyenv <no-dsa> (Minor issue)
 	NOTE: https://github.com/pyenv/pyenv/security/advisories/GHSA-g478-f579-9vp9
 	NOTE: Fixed by: https://github.com/pyenv/pyenv/commit/95df7dbc7b34595b47c9b922de198547effda819 (v2.8.0)
@@ -5153,7 +5153,7 @@ CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an
 CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kriptok Cr ...)
 	TODO: check
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
-	- lz4-java <unfixed>
+	- lz4-java <unfixed> (bug #1145019)
 	NOTE: https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
 	NOTE: Fixed by: https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da (v1.11.1)
 CVE-2026-59940 (Seroval facilitates JS value stringification, including complex struct ...)
@@ -6021,12 +6021,12 @@ CVE-2026-59910 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) an Impro
 CVE-2026-59909 (Dell ObjectScale, versions prior to 4.3.0.1, contain(s) a Path Travers ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-59903 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1145017)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-8c42-7qj2-3j46
 	NOTE: https://github.com/netty/netty/pull/17213 (4.2-branch)
 	NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
 CVE-2026-59902 (Netty is an asynchronous, event-driven network application framework.  ...)
-	- netty <unfixed>
+	- netty <unfixed> (bug #1145017)
 	NOTE: https://github.com/netty/netty/security/advisories/GHSA-2qj4-mmr9-4v2f
 	NOTE: https://github.com/netty/netty/pull/17213 (4.2-branch)
 	NOTE: https://github.com/netty/netty/pull/17217 (4.1-branch)
@@ -20133,7 +20133,7 @@ CVE-2026-62996 (Smarty is a template engine for PHP, facilitating the separation
 	NOTE: https://github.com/smarty-php/smarty/pull/1195
 	NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/3c9f77a2e06ce319ae0092496af32cc8f3adc52e (v5.8.4)
 CVE-2026-62992 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
-	- smarty4 <unfixed>
+	- smarty4 <unfixed> (bug #1145020)
 	[trixie] - smarty4 <no-dsa> (Minor issue)
 	- smarty3 <unfixed>
 	[trixie] - smarty3 <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05740c724542f2781b0fb4989a148a590342becf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/05740c724542f2781b0fb4989a148a590342becf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260821/f8fb1255/attachment.htm>


More information about the debian-security-tracker-commits mailing list