[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 13:10:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e9ed6385 by Salvatore Bonaccorso at 2026-08-26T14:09:22+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1281,7 +1281,7 @@ CVE-2026-58108 (The personal access token removal query selects fromPersonalAcce
 CVE-2026-58097 (mp_SetEnddisc() copied a user-supplied PSN endpoint value without leng ...)
 	NOT-FOR-US: FreeBSD
 CVE-2026-58096 (LcpDecodeConfig() did not validate the length of received endpoint dis ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58095 (mp_Enddisc() used incorrect length calculations when formatting endpoi ...)
 	NOT-FOR-US: FreeBSD
 CVE-2026-58094 (The FIOSSHMLPGCNF ioctl(2) operation configures the page size for a la ...)
@@ -1293,35 +1293,35 @@ CVE-2026-58092 (In FreeBSD 15.0, the kernel structure used to represent user cre
 CVE-2026-58091 (The implementation of this ioctl attempts to acquire locks on all chan ...)
 	NOT-FOR-US: FreeBSD
 CVE-2026-58090 (The SOCK_STREAM receive path in the unix socket implementation failed  ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-58089 (When a process calls execve(2) to execute a setuid or setgid image, hw ...)
-	TODO: check
+	NOT-FOR-US: FreeBSD
 CVE-2026-57171 (Compliance-trestle (Trestle) is a Python SDK and command-line tool for ...)
-	TODO: check
+	NOT-FOR-US: compliance-trestle
 CVE-2026-57170 (Compliance-trestle (Trestle) is a Python SDK and command-line tool for ...)
-	TODO: check
+	NOT-FOR-US: compliance-trestle
 CVE-2026-55805 (Improper Neutralization of Input During Web Page Generation ("Cross-si ...)
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-55588 (ORAS (OCI Registry As Storage) is a CLI and library for managing artif ...)
 	TODO: check
 CVE-2026-54757 (Compliance-trestle (Trestle) is a Python SDK and command-line tool for ...)
-	TODO: check
+	NOT-FOR-US: compliance-trestle
 CVE-2026-54467 (On the Trusted Firmware-M (TF-M) 2 through 2.3.0 platform before 00d1b ...)
 	TODO: check
 CVE-2026-53965 (The MCP PHP SDK (Composer package mcp/sdk) is the official Model Conte ...)
-	TODO: check
+	NOT-FOR-US: MCP PHP SDK (Composer package mcp/sdk)
 CVE-2026-52776 (Compliance-trestle (Trestle) is a tooling platform for managing compli ...)
-	TODO: check
+	NOT-FOR-US: compliance-trestle
 CVE-2026-52491 (An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an ...)
 	TODO: check
 CVE-2026-52489 (Buffer Overflow vulnerability in gpac 31becc9e08b88e525a4a62013a4000de ...)
 	TODO: check
 CVE-2026-51368 (An issue in Beijing Tongtech Co., Ltd tongweb v.7.0.24 in the Spring H ...)
-	TODO: check
+	NOT-FOR-US: tongweb
 CVE-2026-45019 (Chainlit is a Python framework for building production-ready conversat ...)
-	TODO: check
+	NOT-FOR-US: Chainlit
 CVE-2026-45018 (Chainlit is a Python framework for building production-ready conversat ...)
-	TODO: check
+	NOT-FOR-US: Chainlit
 CVE-2026-44476 (Doorkeeper is an OAuth 2 provider for Ruby on Rails. In version 1.9.0, ...)
 	TODO: check
 CVE-2026-43670 (A Content Security Policy bypass was addressed with improved enforceme ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9ed6385555980285d8ae8c44c6a0fb4e898c9fd

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e9ed6385555980285d8ae8c44c6a0fb4e898c9fd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/06a6e7a7/attachment.htm>


More information about the debian-security-tracker-commits mailing list