[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 23 20:26:06 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8e031ce7 by Salvatore Bonaccorso at 2026-08-23T21:25:34+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1446,7 +1446,7 @@ CVE-2026-57835
CVE-2026-56875
REJECTED
CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
- - capstone <unfixed>
+ - capstone <unfixed> (bug #1145195)
[trixie] - capstone <no-dsa> (Minor issue)
NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-gf2c-xwcp-hvf4
NOTE: https://github.com/capstone-engine/capstone/pull/2968
@@ -1454,7 +1454,7 @@ CVE-2026-55894 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier
NOTE: https://github.com/capstone-engine/capstone/pull/2969
NOTE: Fixed by: https://github.com/capstone-engine/capstone/commit/e17ee44a8307ea33375b4727ac4f987650bf7bed (v5 branch)
CVE-2026-55893 (Capstone is a disassembly framework. In 6.0.0-Alpha9 and earlier, Caps ...)
- - capstone <unfixed>
+ - capstone <unfixed> (bug #1145195)
[trixie] - capstone <no-dsa> (Minor issue)
NOTE: https://github.com/capstone-engine/capstone/security/advisories/GHSA-3hpv-wr3j-rxwh
NOTE: https://github.com/capstone-engine/capstone/pull/2968
@@ -1527,7 +1527,7 @@ CVE-2026-49244 (SFTPGo is an open source, event-driven file transfer solution. F
CVE-2026-49217 (Mailu is a mail server as a set of Docker images. Prior to version 202 ...)
NOT-FOR-US: Mailu
CVE-2026-49114 (In ONNX before 1.21.0, the 'save_external_data' function builds the ex ...)
- - onnx <unfixed>
+ - onnx <unfixed> (bug #1145196)
[trixie] - onnx <no-dsa> (Minor issue)
NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-q56x-g2fj-4rj6
CVE-2026-48590 (XML Injection vulnerability in joshnuss xml_builder (XmlBuilder module ...)
@@ -1813,7 +1813,7 @@ CVE-2026-74580 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/de845981da67a6b049080c87e605130b0c30adc5 (7.2-rc7)
CVE-2026-19685
- - network-manager <unfixed>
+ - network-manager <unfixed> (bug #1145199)
[trixie] - network-manager <not-affected> (Fix for CVE-2025-9615 not applied)
NOTE: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/merge_requests/2513
NOTE: Introduced with: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/e85cc46d0b36cdba50fe8411cc93d55a49ebfccf (1.57.1-dev)
@@ -7002,7 +7002,7 @@ CVE-2026-63639 (Valkey is a distributed key-value database. Prior to 7.2.14, 8.0
NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/f8d2027e8d4df790ac04974bf606408c8ea62778 (8.0.10)
TODO: check redis and redict
CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for machine le ...)
- - onnx <unfixed>
+ - onnx <unfixed> (bug #1145196)
[trixie] - onnx <no-dsa> (Minor issue)
NOTE: https://github.com/onnx/onnx/security/advisories/GHSA-p893-rvq9-2xf9
NOTE: https://github.com/onnx/onnx/pull/7880
@@ -7209,7 +7209,7 @@ CVE-2026-45115 (MyBB is free and open source forum software. Prior to 1.8.40, th
CVE-2026-44472 (Saleor is an e-commerce platform. From 2.10.0rc1 until 3.21.67, 3.22.6 ...)
NOT-FOR-US: Saleor
CVE-2026-43971 (Improper Encoding or Escaping of Output vulnerability in ninenines cow ...)
- - erlang-cowlib <unfixed>
+ - erlang-cowlib <unfixed> (bug #1145197)
[trixie] - erlang-cowlib <not-affected> (Vulnerable code not present)
[bookworm] - erlang-cowlib <not-affected> (Vulnerable code not present)
[bullseye] - erlang-cowlib <not-affected> (Vulnerable code not present)
@@ -7338,7 +7338,7 @@ CVE-2026-18534 (ArcSearch for iOS versions prior to 1.48.0 could keep the addres
CVE-2026-18392
REJECTED
CVE-2026-17106 (The tar extraction routines in moby/go-archive (Unpack, UnpackLayer, U ...)
- - golang-github-moby-go-archive <unfixed>
+ - golang-github-moby-go-archive <unfixed> (bug #1145200)
NOTE: https://github.com/moby/go-archive/security/advisories/GHSA-hfg8-hc9c-6c3h
CVE-2026-17084 (The "stringprep" module didn't process characters from RFC 3454 tables ...)
- python3.15 <unfixed>
@@ -14708,7 +14708,7 @@ CVE-2026-19744 (Cross-site Scripting in the Markdown renderer in maalfer Pentest
CVE-2026-19734 (Missing Authorization and Authorization Bypass Through User-Controlled ...)
NOT-FOR-US: Roskus Prospero Flow CRM
CVE-2026-19730 (The 'podman quadlet install --replace' command opens the existing dest ...)
- - podman <unfixed>
+ - podman <unfixed> (bug #1145198)
[trixie] - podman <not-affected> (Vulnerable code not present)
[bookworm] - podman <not-affected> (Vulnerable code not present)
[bullseye] - podman <not-affected> (Vulnerable code not present)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e031ce7683fb39cfd31a4a8ff2b270dc6184649
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8e031ce7683fb39cfd31a4a8ff2b270dc6184649
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260823/6a77908f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list