[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 27 08:41:22 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d871d68a by Moritz Muehlenhoff at 2026-08-27T08:48:42+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -391,9 +391,11 @@ CVE-2026-80233 (CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN
NOT-FOR-US: CAYIN CMS-WS and CMS-SE and SMP series products
CVE-2026-80206 (NLTK before 3.10.3 contains a regular expression denial of service (Re ...)
- nltk 3.10.3-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-w3v8-gmh9-3wv7
CVE-2026-80205 (NLTK versions before 3.10.0 contain a regular expression denial of ser ...)
- nltk 3.10.0-1
+ [trixie] - nltk <no-dsa> (Minor issue)
NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-rrv8-h7p8-rx55
CVE-2026-80204 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not a ...)
NOT-FOR-US: Grav plugin
@@ -420,6 +422,7 @@ CVE-2026-77801 (GitLab has remediated an issue in GitLab CE/EE affecting all ver
NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia diagram ...)
- dia <unfixed>
+ [trixie] - dia <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/581
CVE-2026-77557 (A malicious actor with access to the network could exploit an Improper ...)
NOT-FOR-US: Ubiquiti UniFi
@@ -476,8 +479,9 @@ CVE-2026-75960 (Rently Smart Home versions 20.1.0 and prior are vulnerable to an
CVE-2026-75896 (Use of Hard-coded Credentials vulnerability in T\xdcB\u0130TAK B\u0130 ...)
NOT-FOR-US: Liderahenk
CVE-2026-75466 (libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability ...)
- - libjpeg-turbo <unfixed>
+ - libjpeg-turbo <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/911
+ NOTE: Introduced by: https://github.com/sysfce2/libjpeg-turbo/commit/285744829a1ed5b12dfff61a6a39da0eea0b8405 (3.1.90)
NOTE: Fixed by: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f14656395b7c83f66ac248c48dc844caebcc1127
CVE-2026-75325 (DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/a ...)
NOT-FOR-US: DWSurvey
@@ -756,10 +760,12 @@ CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how m
NOT-FOR-US: LeafWiki
CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ, the Linux ...)
- bluez <unfixed>
+ [trixie] - bluez <no-dsa> (Minor issue)
NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
NOTE: Fixed by: https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
CVE-2026-80185 (BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can ...)
- bluez <unfixed>
+ [trixie] - bluez <no-dsa> (Minor issue)
NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
NOTE: Fixed by: https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or escape the ...)
@@ -2312,7 +2318,6 @@ CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local Fil
NOT-FOR-US: WordPress plugin
CVE-2026-78468
REJECTED
- NOT-FOR-US: WordPress plugin
CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the python_ ...)
NOT-FOR-US: Amazon
CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a maliciou ...)
@@ -2905,10 +2910,8 @@ CVE-2026-78470 (The WP Project Manager Pro plugin for WordPress is vulnerable to
NOT-FOR-US: WordPress plugin
CVE-2026-78467
REJECTED
- NOT-FOR-US: WordPress plugin
CVE-2026-78466
REJECTED
- NOT-FOR-US: WordPress plugin
CVE-2026-78435 (A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected ...)
NOT-FOR-US: Faveo Helpdesk
CVE-2026-78434 (A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the ...)
@@ -7770,6 +7773,13 @@ CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attac
NOT-FOR-US: IBM
CVE-2026-19672 (The tarfile module's tar and data extraction filters created director ...)
- python3.15 <unfixed>
+ - python3.14 <unfixed>
+ - python3.13 <unfixed>
+ [trixie] - python3.13 <no-dsa> (Minor issue)
+ - python3.11 <removed>
+ - python3.9 <removed>
+ - pypy3 <unfixed>
+ [trixie] - pypy3 <no-dsa> (Minor issue)
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/
NOTE: https://github.com/python/cpython/issues/155999
NOTE: https://github.com/python/cpython/pull/156000
=====================================
data/dsa-needed.txt
=====================================
@@ -23,12 +23,14 @@ amd64-microcode (carnil)
bouncycastle
possibly move to 1.85 for trixie
--
+bubblewrap (jmm)
+--
cacti
probably best to move to 1.2.31
--
chromium (dilinger)
--
-cockpit
+cockpit (jmm)
--
containerd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d871d68aa86f841ce8d5ebd1d3fc034747573804
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d871d68aa86f841ce8d5ebd1d3fc034747573804
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/1d386f8d/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list