[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 26 09:07:42 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bc460655 by Moritz Muehlenhoff at 2026-08-26T10:06:23+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1674,6 +1674,7 @@ CVE-2026-59984 (OpenEXR is the reference implementation and specification for th
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/c550555a1657398e6a9f96c3530f8b1370a6fd94 (v3.2.11-rc)
 CVE-2026-59983 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	- openexr 3.4.14-0.1
+	[trixie] - openexr <no-dsa> (Minor issue)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-p42q-g5c9-mh9w
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/0efec58d2d28a0ee322f5028dee6fb57d459580e (v3.4.14-rc)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/f0e404f7298cd8563a1d30a64a1c982dbd68fc49 (v3.3.13-rc)
@@ -1690,17 +1691,20 @@ CVE-2026-59335 (Improper handling of case sensitivity (CWE-178) in the identity
 	NOT-FOR-US: Cloud Foundry
 CVE-2026-59189 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	- openexr 3.4.14-0.1
+	[trixie] - openexr <no-dsa> (Minor issue)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-hwmv-39v6-739m
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/55b7958ecb5ac32c427ff39c1e063f6f7bbee77c (v3.4.14-rc)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/aef02224ba282a802de65d16c49c1cdb82089dec (v3.3.13-rc)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/37f03b6ed90f3dd9910f31de3a40f25f2bc2aca1 (v3.2.11-rc)
 CVE-2026-59187 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	- openexr 3.4.14-0.1
+	[trixie] - openexr <no-dsa> (Minor issue)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-6jj8-cxcr-j8hm
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/46e70220dc91dbc1341fac4671704e970b450585 (v3.4.14-rc)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/7e772dd704b9b5d6dc2564647d89f7813f608e94 (v3.3.13-rc)
 CVE-2026-59186 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	- openexr 3.4.14-0.1
+	[trixie] - openexr <no-dsa> (Minor issue)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/security/advisories/GHSA-f667-c4wm-c8gq
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/71907b44ce9a1b05bf3934b8a7821752750731ab (v3.4.14-rc)
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/b1a5887372772d79328f4eb42b7f86352a38170b (v3.3.13-rc)
@@ -19473,8 +19477,9 @@ CVE-2026-29036 (cJSON versions 1.5.0 through 1.7.19 contain an incorrectly-resol
 	- cjson <unfixed>
 	TODO: check, report upstream status
 CVE-2026-29035 (CivetWeb (commit 4a4f0c95) contains a heap and stack buffer overflow v ...)
-	- civetweb <unfixed>
-	TODO: check details upstream
+	- civetweb <unfixed> (unimportant)
+	NOTE: https://github.com/civetweb/civetweb/issues/1381
+	NOTE: MG_EXPERIMENTAL_INTERFACES not enabled in Debian build
 CVE-2026-19594 (Insufficient input sanitization in Snowflake Python API (`snowflake.co ...)
 	NOT-FOR-US: Snowflake Python API
 CVE-2026-19588 (Integer Overflow to Buffer Overflow vulnerability in Samsung Open Sour ...)
@@ -22271,10 +22276,10 @@ CVE-2026-71391 (GNU Emacs for Android contains an off-by-one error in the gvar t
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-71391/
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/emacs.git/commit/?id=95ab9ef627b212d74d321c5bbb5b56a1be7b9fbe
 CVE-2026-70622 (tar-rs versions 0.4.11 through 0.4.46 contain a symlink escape vulnera ...)
-	- rustc <undetermined>
-	- rust-tar <unfixed> (bug #1144402)
+	- rust-tar <unfixed> (bug #1144402; unimportant)
 	NOTE: https://gist.github.com/thesmartshadow/e7dac0bb690ee17b9cc142154cb11726
-	TODO: check, unclear if reported upstream
+	NOTE: Clarified as not in scope by upstream:
+	NOTE: https://github.com/composefs/tar-rs/commit/cd94c46e0d74fbcc50eea3f30665a1b1159254cc
 CVE-2026-6374 (Use of Hard-coded Credentials vulnerability in Zyxel Networks WAH7601  ...)
 	NOT-FOR-US: Zyxel
 CVE-2026-6373 (Exposure of sensitive system information to an unauthorized control sp ...)
@@ -260071,6 +260076,7 @@ CVE-2025-30154 (reviewdog/action-setup is a GitHub action that installs reviewdo
 	NOT-FOR-US: reviewdog/action-setup GitHub action
 CVE-2025-30153 (kin-openapi is a Go project for handling OpenAPI files. Prior to 0.131 ...)
 	- golang-github-getkin-kin-openapi 0.135.0-1
+	[trixie] - golang-github-getkin-kin-openapi <no-dsa> (Minor issue)
 	[bookworm] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
 	[bullseye] - golang-github-getkin-kin-openapi <ignored> (Minor issue; out of LTS support)
 	NOTE: https://github.com/getkin/kin-openapi/security/advisories/GHSA-wq9g-9vfc-cfq9


=====================================
data/dsa-needed.txt
=====================================
@@ -153,7 +153,7 @@ sogo
 starlette
   Matheus Polkorny is proposing an update for review
 --
-suricata-update
+suricata-update (jmm)
   Maintainer prepared debdiff, acked for upload
 --
 tomcat10
@@ -172,7 +172,7 @@ vips
 weechat
   Upstream recommends to use branch from https://github.com/weechat/weechat/commits/4.6/, cf #1142597
 --
-wireshark
+wireshark (jmm)
   Matheus Polkorny prepared an update for review, https://salsa.debian.org/debian/wireshark/-/merge_requests/8
 --
 wordpress



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc460655724e4f857ec7edc5c2fbdc64206c6465

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc460655724e4f857ec7edc5c2fbdc64206c6465
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/65a33c8c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list