[Git][security-tracker-team/security-tracker][master] Update information on two CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 27 07:35:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b7c9b7f9 by Salvatore Bonaccorso at 2026-08-27T08:34:40+02:00
Update information on two CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3396,7 +3396,7 @@ CVE-2026-76842 (The Mercado Pago Node.js SDK interpolates caller-supplied identi
 CVE-2026-76841 (Xinference loads models with Hugging Face remote code execution uncond ...)
 	NOT-FOR-US: Xinference
 CVE-2026-76840 (RustDesk's Windows clipboard redirection copies a peer-supplied length ...)
-	TODO: check
+	NOT-FOR-US: RustDesk
 CVE-2026-76838 (Hi.Events validates a webhook destination only when it is registered,  ...)
 	NOT-FOR-US: Hi.Events
 CVE-2026-76837 (Baserow interpolates a user's display name into the rich-text mention  ...)
@@ -28031,7 +28031,7 @@ CVE-2026-71263 (The LINUXTCP port of FreeModbus contains an off-by-one bounds ch
 CVE-2026-71262 (IoTSharp BlobStorageController.cs lacks the [Authorize] attribute appl ...)
 	NOT-FOR-US: IoTSharp
 CVE-2026-71261 (dr_libs dr_wav.h (all versions through current master) contains an int ...)
-	TODO: check
+	TODO: check if embedded copy has security impact in roc-toolkit, qtads, qt6-multimedia, octave-ltfat, raylib, dosbox-x, mlpack and faudio
 CVE-2026-71260 (ESPHome through 2026.7.0-dev discloses plaintext passwords via its web ...)
 	NOT-FOR-US: ESPHome
 CVE-2026-71259 (ESPHome through 2026.7.0-dev contains an operator-precedence bug in th ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7c9b7f9fbb8fa9c13e46511e9bfd87400769390

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7c9b7f9fbb8fa9c13e46511e9bfd87400769390
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/7be65354/attachment.htm>


More information about the debian-security-tracker-commits mailing list