[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Aug 26 11:51:35 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
dfb4d562 by Moritz Muehlenhoff at 2026-08-26T12:51:07+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1244,33 +1244,33 @@ CVE-2026-65081 (NVIDIA NemoClaw for Linux contains a vulnerability in its instal
 CVE-2026-64705 (A buffer overflow was addressed with improved bounds checking. This is ...)
 	NOT-FOR-US: Apple
 CVE-2026-63404 (Faktory is a language-agnostic background job server. In versions prio ...)
-	TODO: check
+	NOT-FOR-US: Faktory
 CVE-2026-63403 (Faktory is a language-agnostic background job server. In versions prio ...)
-	TODO: check
+	NOT-FOR-US: Faktory
 CVE-2026-62865 (Typebot is an open-source chatbot builder. In self-hosted versions pri ...)
-	TODO: check
+	NOT-FOR-US: Typebot
 CVE-2026-62862 (Typebot is an open-source chatbot builder. In self-hosted versions up  ...)
-	TODO: check
+	NOT-FOR-US: Typebot
 CVE-2026-62861 (TypeBot is a chatbot builder tool. Prior to 3.18.0, any authenticated  ...)
-	TODO: check
+	NOT-FOR-US: Typebot
 CVE-2026-59981 (OpenEXR is the reference implementation and specification for the EXR  ...)
 	TODO: check
 CVE-2026-58108 (The personal access token removal query selects fromPersonalAccessToke ...)
 	NOT-FOR-US: Ericsson
 CVE-2026-58097 (mp_SetEnddisc() copied a user-supplied PSN endpoint value without leng ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58096 (LcpDecodeConfig() did not validate the length of received endpoint dis ...)
 	TODO: check
 CVE-2026-58095 (mp_Enddisc() used incorrect length calculations when formatting endpoi ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58094 (The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a la ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58093 (The TIOCSCTTY ioctl handler drops the tty lock in order to acquire the ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58092 (In FreeBSD 15.0, the kernel structure used to represent user credentia ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58091 (The implementation of this ioctl attempts to acquire locks on all chan ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58090 (The SOCK_STREAM receive path in the unix socket implementation failed  ...)
 	TODO: check
 CVE-2026-58089 (When a process calls execve(2) to execute a setuid or setgid image, hw ...)
@@ -1314,23 +1314,23 @@ CVE-2026-3002 (The Gutenverse \u2013 Ultimate WordPress FSE Blocks Addons & Ecos
 CVE-2026-39113 (Buffer Overflow vulnerability in SQLite affected version source snapsh ...)
 	TODO: check
 CVE-2026-38474 (GazellePW (GazellePosterWall) commit 86c4bedf727691b5a97af42a4864869d1 ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-38473 (A Stored XSS vulnerability in the subtitle deletion flow in GazellePW  ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-38472 (A Stored XSS vulnerability in forum reward comments in GazellePW (Gaze ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-38470 (A Broken access control vulnerability in the API user endpoint in Gaze ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-38469 (A Stored XSS vulnerability in the custom bonus title feature in Gazell ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-38468 (A SQL injection vulnerability in the country-code lookup endpoint in G ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-38467 (A SQL injection vulnerability in the tags manager in GazellePW (Gazell ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-38466 (A Stored XSS vulnerability in the torrent remaster custom title featur ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-38465 (A Stored XSS vulnerability in the donor avatar mouse-over text feature ...)
-	TODO: check
+	NOT-FOR-US: GazellePW
 CVE-2026-32637 (Velero is an open source tool for backing up, restoring, and migrating ...)
 	TODO: check
 CVE-2026-29988 (A cleartext transmission of sensitive information vulnerability in the ...)
@@ -2374,7 +2374,7 @@ CVE-2026-19801 (The BetterLinks \u2013 Link Shortener, Link Cloaking, Redirects,
 CVE-2026-19568 (A maliciously crafted SVG file, when parsed through Autodesk 3ds Max,  ...)
 	NOT-FOR-US: Autodesk
 CVE-2026-17113 (A flaw was found in CRI-O's container-creation environment-variable ha ...)
-	TODO: check
+	- cri-o <itp> (bug #979702)
 CVE-2026-17089 (The Events Manager \u2013 Calendar, Bookings, Tickets, and more! plugi ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16783 (A maliciously crafted ABC file, when parsed through Autodesk 3ds Max,  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dfb4d562ccec79583ef7370c598ecd9ac833b022

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dfb4d562ccec79583ef7370c598ecd9ac833b022
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/f89aa582/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list