[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 26 21:46:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f96efb81 by Salvatore Bonaccorso at 2026-08-26T22:46:09+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -475,9 +475,9 @@ CVE-2026-75466 (libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnera
 	NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/911
 	NOTE: Fixed by: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f14656395b7c83f66ac248c48dc844caebcc1127
 CVE-2026-75325 (DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/a ...)
-	TODO: check
+	NOT-FOR-US: DWSurvey
 CVE-2026-75062 (Improper Neutralization of Directives in Dynamically Evaluated Code (' ...)
-	TODO: check
+	NOT-FOR-US: langfun
 CVE-2026-74754 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.10-1
 	NOTE: https://git.kernel.org/linus/872f486259ae0bc6b73ca4735a15d013241f73e9 (7.2)
@@ -577,9 +577,9 @@ CVE-2026-74734 (In the Linux kernel, the following vulnerability has been resolv
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/42d217add8d80d6e7d9f58f80d11ea9b07ea113e (7.2)
 CVE-2026-73108 (RustDesk versions before 1.4.7 contain an uncontrolled speculative mem ...)
-	TODO: check
+	NOT-FOR-US: RustDesk
 CVE-2026-73102 (RustDesk versions 1.3.9 through 1.4.9 contain a path traversal vulnera ...)
-	TODO: check
+	NOT-FOR-US: RustDesk
 CVE-2026-71171 (Dell Cloud Disaster Recovery, versions20.2 and prior,containan Imprope ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-70419 (Dell Cloud Disaster Recovery, versions 20.2 and prior,containan Improp ...)
@@ -587,7 +587,7 @@ CVE-2026-70419 (Dell Cloud Disaster Recovery, versions 20.2 and prior,containan
 CVE-2026-6178 (The Betheme theme for WordPress is vulnerable to Stored Cross-Site Scr ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-63179 (Winter CMS is a content management system built on the Laravel PHP fra ...)
-	TODO: check
+	NOT-FOR-US: Winter CMS
 CVE-2026-63041 (Reliance on Untrusted Inputs in a Security Decision vulnerability in A ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-5092 (The Greenshift \u2013 animation and page builder blocks plugin for Wor ...)
@@ -597,29 +597,29 @@ CVE-2026-59683 (The OpenRGB network protocol allows to write attacker controlled
 CVE-2026-59682 (Arbitrary file overwrite via SAVE_PROFILE message in OpenRGB.This issu ...)
 	TODO: check
 CVE-2026-58474 (whichllm before 0.5.16 contains a code injection vulnerability in the  ...)
-	TODO: check
+	NOT-FOR-US: whichllm
 CVE-2026-54614 (DebugKit provides a debugging toolbar for CakePHP applications. Prior  ...)
-	TODO: check
+	NOT-FOR-US: DebugKit
 CVE-2026-54606 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
-	TODO: check
+	NOT-FOR-US: SunEditor
 CVE-2026-54569 (SENAITE.CORE is the core framework for the SENAITE laboratory informat ...)
-	TODO: check
+	NOT-FOR-US: SENAITE.CORE
 CVE-2026-54556 (Http4s is a Scala interface for HTTP services. Prior to 0.23.35 and 1. ...)
-	TODO: check
+	NOT-FOR-US: Http4s
 CVE-2026-54553 (Starlette-Admin is a fast, beautiful and extensible administrative int ...)
-	TODO: check
+	NOT-FOR-US: Starlette-Admin
 CVE-2026-54550 (IzPack is a widely used tool for packaging applications on the Java pl ...)
-	TODO: check
+	NOT-FOR-US: IzPack
 CVE-2026-54523 (Kyverno is a policy engine designed for cloud native platform engineer ...)
-	TODO: check
+	NOT-FOR-US: Kyverno
 CVE-2026-54511 (LogTape is an unobtrusive logging library. Prior to 1.3.11, 2.0.14, an ...)
-	TODO: check
+	NOT-FOR-US: LogTape
 CVE-2026-54256 (Winter CMS is a content management system built on the Laravel PHP fra ...)
-	TODO: check
+	NOT-FOR-US: Winter CMS
 CVE-2026-51106 (An issue in TokTok qTox v1.18.4 allows a local attacker to cause a den ...)
-	TODO: check
+	NOT-FOR-US: TokTok qTox
 CVE-2026-48786 (Fleet is an open-source device management platform built on osquery. I ...)
-	TODO: check
+	NOT-FOR-US: Fleet
 CVE-2026-48549 (Nagios Core before 4.5.13 and Nagios XI before 2026R1.5 contains a CSR ...)
 	TODO: check
 CVE-2026-48548 (Nagios Core before 4.5.12 contains a cross-site request forgery vulner ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f96efb81b5dcb8878da85ef19574d87361b56e4d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f96efb81b5dcb8878da85ef19574d87361b56e4d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/5b20f36f/attachment.htm>


More information about the debian-security-tracker-commits mailing list