[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 23 14:18:57 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
ad7d7c24 by Salvatore Bonaccorso at 2026-08-23T15:18:12+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -111,17 +111,17 @@ CVE-2026-6258
CVE-2026-68769
REJECTED
CVE-2026-68768 (hashcat contains a heap-based buffer overflow (out-of-bounds write) in ...)
- - hashcat <unfixed>
+ - hashcat <unfixed> (bug #1145171)
NOTE: https://github.com/hashcat/hashcat/issues/4740
NOTE: https://github.com/hashcat/hashcat/pull/4754
NOTE: Fixed by: https://github.com/hashcat/hashcat/commit/68f56a2d8712867a8520bf4dcf07f6145c23df89
CVE-2026-68767 (hashcat's fgetl() function in src/filehandling.c writes a null termina ...)
- - hashcat <unfixed>
+ - hashcat <unfixed> (bug #1145171)
NOTE: https://github.com/hashcat/hashcat/issues/4739
NOTE: https://github.com/hashcat/hashcat/pull/4750
NOTE: Fixed by: https://github.com/hashcat/hashcat/commit/93b55d37d3b2340013d4036f10181ddc67d44249
CVE-2026-68766 (hashcat fails to restrict command-line options when parsing restore fi ...)
- - hashcat <unfixed>
+ - hashcat <unfixed> (bug #1145171)
NOTE: https://github.com/hashcat/hashcat/issues/4738
NOTE: Fixed by: https://github.com/hashcat/hashcat/commit/fcae69f2438ff8eae0dc8e206b78067a1e465ed4
CVE-2026-66917 (Joomla Extension - joomgalleryfriends.net - Stored XSS in JoomGallery ...)
@@ -170,10 +170,10 @@ CVE-2026-62382 (PasswordPusher versions v1.45.11 through v2.9.5 contain an impro
CVE-2026-62381 (luci-lib-px5g (LuCI) contains a heap-based buffer overflow in the nati ...)
NOT-FOR-US: luci-lib-px5g (LuCI)
CVE-2026-62380 (Netty (io.netty:netty-codec-socks) versions 4.2.0.Final through 4.2.16 ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145167)
NOTE: https://github.com/netty/netty/security/advisories/GHSA-cc6x-ffm5-83wf
CVE-2026-62243 (Netty (io.netty:netty-handler) versions from 4.2.0.Final through 4.2.1 ...)
- - netty <unfixed>
+ - netty <unfixed> (bug #1145167)
NOTE: https://github.com/netty/netty/security/advisories/GHSA-p85m-gvr3-788c
CVE-2026-62204 (SiYuan versions before v3.7.4 fail to validate that packageName matche ...)
NOT-FOR-US: SiYuan
@@ -823,7 +823,7 @@ CVE-2026-XXXX [OpenZFS Linux open zpool manipulation and escapes via unprivilege
NOTE: https://github.com/openzfs/zfs/issues/18936
NOTE: https://github.com/openzfs/zfs/pull/18959
CVE-2026-77682 [Use a user message to trigger form autofill]
- - epiphany-browser <unfixed>
+ - epiphany-browser <unfixed> (bug #1145177)
NOTE: https://gitlab.gnome.org/GNOME/epiphany/-/merge_requests/2147
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/epiphany/-/commit/e85444e03490cff1584251028a11d5dfeb3accac (50.6)
CVE-2026-66786
@@ -841,7 +841,7 @@ CVE-2026-77414 (JSONata is a JSON query and transformation language. Prior to 1.
CVE-2026-77413 (JSONata is a JSON query and transformation language. Prior to 1.8.8 an ...)
NOT-FOR-US: jsonata-js
CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From 0.124.0 u ...)
- - golang-github-getkin-kin-openapi <unfixed>
+ - golang-github-getkin-kin-openapi <unfixed> (bug #1145174)
[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
@@ -849,10 +849,10 @@ CVE-2026-77354 (kin-openapi is a Go project for handling OpenAPI files. From 0.1
NOTE: https://github.com/getkin/kin-openapi/pull/923
NOTE: Fixed by: https://github.com/getkin/kin-openapi/commit/1223a0f215d2cf9beb2d9eb9ea2649d001c21388 (v0.142.0)
CVE-2026-77220 (PDFio before 1.6.5 contains a dangling pointer vulnerability in the di ...)
- - ippsample <unfixed>
+ - ippsample <unfixed> (bug #1145176)
NOTE: Fixed by: https://github.com/michaelrsweet/pdfio/commit/22b9afc800c5833f9e851e35938972bd4c76a357 (v1.6.5)
CVE-2026-77219 (GNU Emacs before 31.0.91 contains an integer overflow in the PBM/PPM/P ...)
- - emacs <unfixed>
+ - emacs <unfixed> (bug #1145175)
NOTE: https://debbugs.gnu.org/cgi/bugreport.cgi?bug=81344
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=b07e634e4cf45162ae0178e32092b040587f2c6c (emacs-31.0.91)
CVE-2026-77002 (The SmilePass Selfie Login WordPress plugin through 1.0.2 does not per ...)
@@ -862,7 +862,7 @@ CVE-2026-77001 (The Social Login & Sharing buttons with Analytics By SoClever Wo
CVE-2026-77000 (The WP Social Media Login WordPress plugin through 1.0.6 does not veri ...)
NOT-FOR-US: WordPress plugin
CVE-2026-76905 (kin-openapi is a Go project for handling OpenAPI files. From 0.10.0 un ...)
- - golang-github-getkin-kin-openapi <unfixed>
+ - golang-github-getkin-kin-openapi <unfixed> (bug #1145173)
[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
@@ -2138,7 +2138,7 @@ CVE-2026-63495 (Libevent is an event notification library. From 2.2.0-alpha-dev
CVE-2026-63490 (Handlebars.java provides logic-less and semantic Mustache templates wi ...)
NOT-FOR-US: Handlebars.java
CVE-2026-63481 (Hurl is a command line tool that runs and tests HTTP requests defined ...)
- - rust-hurl <unfixed>
+ - rust-hurl <unfixed> (bug #1145168)
NOTE: https://github.com/Orange-OpenSource/hurl/security/advisories/GHSA-7w2g-9mf9-324m
NOTE: https://github.com/Orange-OpenSource/hurl/pull/5119
NOTE: Fixed by: https://github.com/Orange-OpenSource/hurl/commit/ed91c894c2cf11704422010554037e3ba70b446e
@@ -2495,7 +2495,7 @@ CVE-2026-XXXX [OSSN-0103]
NOTE: https://review.opendev.org/c/openstack/manila/+/998388
NOTE: https://bugs.launchpad.net/manila/+bug/2161287
CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
- - openssl <unfixed>
+ - openssl <unfixed> (bug #1145172)
[trixie] - openssl <postponed> (Minor issue, fix along with future update)
NOTE: https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a (openssl-4.0)
NOTE: https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b (openssl-3.6)
@@ -3564,19 +3564,19 @@ CVE-2026-66613 (Unauthenticated Remote Code Execution (RCE) in JetEngine <= 3.8.
CVE-2026-66596 (Unauthenticated Cross Site Scripting (XSS) in Newsletter <= 9.3.3 vers ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-65612 (nnn does not sanitize the filename variable. An attacker can place a f ...)
- - nnn <unfixed>
+ - nnn <unfixed> (bug #1145170)
[trixie] - nnn <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
CVE-2026-65611 (nnn does not sanitize the path variable. An attacker can createa direc ...)
- - nnn <unfixed>
+ - nnn <unfixed> (bug #1145170)
[trixie] - nnn <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
CVE-2026-65610 (nnn stores homelen variable as uchar_t, which can only represent value ...)
- - nnn <unfixed>
+ - nnn <unfixed> (bug #1145170)
[trixie] - nnn <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
CVE-2026-65609 (nnn is vulnerable to Out-of-Bound write vulnerability.Due to lack of v ...)
- - nnn <unfixed>
+ - nnn <unfixed> (bug #1145170)
[trixie] - nnn <no-dsa> (Minor issue)
NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-65609
CVE-2026-64852 (Grav API Plugin is a RESTful API for Grav CMS that provides full headl ...)
@@ -7488,14 +7488,14 @@ CVE-2026-67678 (File Upload vulnerability in RainyGao-Hithub DocSys v.2.02.80 al
CVE-2026-66795 (A flaw was found in the managedcluster-import-controller. The Certific ...)
NOT-FOR-US: Red Hat Multicluster Engine for Kubernetes
CVE-2026-65976 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until contin ...)
- - deskflow <unfixed>
+ - deskflow <unfixed> (bug #1145169)
NOTE: https://github.com/deskflow/deskflow/security/advisories/GHSA-jf7g-qghg-p54x
NOTE: Fixed by: https://github.com/deskflow/deskflow/commit/8a535fd5dd48315eaaf6b93d5c7534d0592addef
NOTE: Fixed by: https://github.com/deskflow/deskflow/commit/bcd3a658fc3b2ad735146fdc9efefa9462d195b7
CVE-2026-65974 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
NOT-FOR-US: ERPNext
CVE-2026-65832 (Deskflow is a keyboard and mouse sharing app. Prior to continuous buil ...)
- - deskflow <unfixed>
+ - deskflow <unfixed> (bug #1145169)
NOTE: https://github.com/deskflow/deskflow/security/advisories/GHSA-8rcq-7w87-h64j
NOTE: Fixed by: https://github.com/deskflow/deskflow/commit/205a3c803e5298d56683660736ec1a41b671b56e
CVE-2026-65822 (ERPNext is a free and open source Enterprise Resource Planning tool. P ...)
@@ -7579,7 +7579,7 @@ CVE-2026-63669 (ApostropheCMS is an open-source Node.js content management syste
CVE-2026-63667 (ApostropheCMS is an open-source Node.js content management system. Pri ...)
NOT-FOR-US: ApostropheCMS
CVE-2026-63409 (Deskflow is a keyboard and mouse sharing app. From 1.17.0 until contin ...)
- - deskflow <unfixed>
+ - deskflow <unfixed> (bug #1145169)
NOTE: https://github.com/deskflow/deskflow/security/advisories/GHSA-gmvh-3c73-m5gg
NOTE: Fixed by: https://github.com/deskflow/deskflow/commit/8266fbbe6af93fa370018886c7f1f35d2cee8b3f
CVE-2026-63178 (Onyx is an open-source AI platform. Prior to 4.3.0, Onyx Enterprise Ed ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ad7d7c249ed83a3c2e092c4bf8469a1fa00dfb49
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ad7d7c249ed83a3c2e092c4bf8469a1fa00dfb49
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260823/3f2fd97e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list