[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 23 20:26:06 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8e031ce7 by Salvatore Bonaccorso at 2026-08-23T21:25:34+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1446,7 +1446,7 @@ CVE-2026-57835
 CVE-2026-56875
 	REJECTED
 CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
-	- capstone <unfixed>
+	- capstone <unfixed> (bug #1145195)
 	[trixie] - capstone <no-dsa> (Minor issue)
 	NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-gf2c-xwcp-hvf4
 	NOTE: https://github.com/capstone-engine/capstone/pull/2968
@@ -1454,7 +1454,7 @@ CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier
 	NOTE: https://github.com/capstone-engine/capstone/pull/2969
 	NOTE: Fixed by: https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed (v5 branch)
 CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
-	- capstone <unfixed>
+	- capstone <unfixed> (bug #1145195)
 	[trixie] - capstone <no-dsa> (Minor issue)
 	NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh
 	NOTE: https://github.com/capstone-engine/capstone/pull/2968
@@ -1527,7 +1527,7 @@ CVE-2026-49244 (SFTPGo is an open source, event-driven file transfer solution. F
 CVE-2026-49217 (Mailu is a mail server as a set of Docker images. Prior to version 202 ...)
 	NOT-FOR-US: Mailu
 CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function builds the ex ...)
-	- onnx <unfixed>
+	- onnx <unfixed> (bug #1145196)
 	[trixie] - onnx <no-dsa> (Minor issue)
 	NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-q56x-g2fj-4rj6
 CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
@@ -1813,7 +1813,7 @@ CVE-2026-74580 (In the Linux kernel, the following vulnerability has been resolv
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
 CVE-2026-19685
-	- network-manager <unfixed>
+	- network-manager <unfixed> (bug #1145199)
 	[trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
 	NOTE: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513
 	NOTE: Introduced with: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf (1.57.1-dev)
@@ -7002,7 +7002,7 @@ CVE-2026-63639 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0
 	NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778 (8.0.10)
 	TODO: check redis and redict
 CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
-	- onnx <unfixed>
+	- onnx <unfixed> (bug #1145196)
 	[trixie] - onnx <no-dsa> (Minor issue)
 	NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-p893-rvq9-2xf9
 	NOTE: https://github.com/onnx/onnx/pull/7880
@@ -7209,7 +7209,7 @@ CVE-2026-45115 (MyBB is free and open source forum software. Prior to 1.8.40, th
 CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.6 ...)
 	NOT-FOR-US: Saleor
 CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in ninenines cow ...)
-	- erlang-cowlib <unfixed>
+	- erlang-cowlib <unfixed> (bug #1145197)
 	[trixie] - erlang-cowlib <not-affected> (Vulnerable code not present)
 	[bookworm] - erlang-cowlib <not-affected> (Vulnerable code not present)
 	[bullseye] - erlang-cowlib <not-affected> (Vulnerable code not present)
@@ -7338,7 +7338,7 @@ CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the addres
 CVE-2026-18392
 	REJECTED
 CVE-2026-17106 (The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, U ...)
-	- golang-github-moby-go-archive <unfixed>
+	- golang-github-moby-go-archive <unfixed> (bug #1145200)
 	NOTE: https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h
 CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 3454 tables ...)
 	- python3.15 <unfixed>
@@ -14708,7 +14708,7 @@ CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer Pentest
 CVE-2026-19734 (Missing Authorization and Authorization Bypass Through User-Controlled ...)
 	NOT-FOR-US: Roskus Prospero Flow CRM
 CVE-2026-19730 (The 'podman quadlet install --replace' command opens the existing dest ...)
-	- podman <unfixed>
+	- podman <unfixed> (bug #1145198)
 	[trixie] - podman <not-affected> (Vulnerable code not present)
 	[bookworm] - podman <not-affected> (Vulnerable code not present)
 	[bullseye] - podman <not-affected> (Vulnerable code not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e031ce7683fb39cfd31a4a8ff2b270dc6184649

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e031ce7683fb39cfd31a4a8ff2b270dc6184649
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260823/6a77908f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list