[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 27 08:41:22 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d871d68a by Moritz Muehlenhoff at 2026-08-27T08:48:42+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -391,9 +391,11 @@ CVE-2026-80233 (CAYIN CMS-WS, CMS-SE, and SMP series products developed by CAYIN
 	NOT-FOR-US: CAYIN CMS-WS and CMS-SE and SMP series products
 CVE-2026-80206 (NLTK before 3.10.3 contains a regular expression denial of service (Re ...)
 	- nltk 3.10.3-1
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-w3v8-gmh9-3wv7
 CVE-2026-80205 (NLTK versions before 3.10.0 contain a regular expression denial of ser ...)
 	- nltk 3.10.0-1
+	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-rrv8-h7p8-rx55
 CVE-2026-80204 (The Grav API plugin (getgrav/grav-plugin-api) before 1.0.18 does not a ...)
 	NOT-FOR-US: Grav plugin
@@ -420,6 +422,7 @@ CVE-2026-77801 (GitLab has remediated an issue in GitLab CE/EE affecting all ver
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia diagram  ...)
 	- dia <unfixed>
+	[trixie] - dia <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/581
 CVE-2026-77557 (A malicious actor with access to the network could exploit an Improper ...)
 	NOT-FOR-US: Ubiquiti UniFi
@@ -476,8 +479,9 @@ CVE-2026-75960 (Rently Smart Home versions 20.1.0 and prior are vulnerable to an
 CVE-2026-75896 (Use of Hard-coded Credentials vulnerability in T\xdcB\u0130TAK B\u0130 ...)
 	NOT-FOR-US: Liderahenk
 CVE-2026-75466 (libjpeg-turbo 3.2.0 contains an integer division-by-zero vulnerability ...)
-	- libjpeg-turbo <unfixed>
+	- libjpeg-turbo <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/libjpeg-turbo/libjpeg-turbo/issues/911
+	NOTE: Introduced by: https://github.com/sysfce2/libjpeg-turbo/commit/285744829a1ed5b12dfff61a6a39da0eea0b8405 (3.1.90)
 	NOTE: Fixed by: https://github.com/libjpeg-turbo/libjpeg-turbo/commit/f14656395b7c83f66ac248c48dc844caebcc1127
 CVE-2026-75325 (DWSurvey v6.14.0 is is vulnerable to authentication bypass via the '/a ...)
 	NOT-FOR-US: DWSurvey
@@ -756,10 +760,12 @@ CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how m
 	NOT-FOR-US: LeafWiki
 CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ, the Linux ...)
 	- bluez <unfixed>
+	[trixie] - bluez <no-dsa> (Minor issue)
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
 CVE-2026-80185 (BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can  ...)
 	- bluez <unfixed>
+	[trixie] - bluez <no-dsa> (Minor issue)
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
 CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or escape the ...)
@@ -2312,7 +2318,6 @@ CVE-2026-78562 (The Verdure Core plugin for WordPress is vulnerable to Local Fil
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78468
 	REJECTED
-	NOT-FOR-US: WordPress plugin
 CVE-2026-78379 (Improper neutralization of input used for LLM prompting in the python_ ...)
 	NOT-FOR-US: Amazon
 CVE-2026-78322 (A flaw was found in file-roller. When opening or extracting a maliciou ...)
@@ -2905,10 +2910,8 @@ CVE-2026-78470 (The WP Project Manager Pro plugin for WordPress is vulnerable to
 	NOT-FOR-US: WordPress plugin
 CVE-2026-78467
 	REJECTED
-	NOT-FOR-US: WordPress plugin
 CVE-2026-78466
 	REJECTED
-	NOT-FOR-US: WordPress plugin
 CVE-2026-78435 (A vulnerability has been found in Faveo Helpdesk up to 2.0.3. Affected ...)
 	NOT-FOR-US: Faveo Helpdesk
 CVE-2026-78434 (A flaw has been found in Faveo Helpdesk up to 2.0.3. This impacts the  ...)
@@ -7770,6 +7773,13 @@ CVE-2026-19875 (IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attac
 	NOT-FOR-US: IBM
 CVE-2026-19672 (The tarfile module's tar and data  extraction filters created director ...)
 	- python3.15 <unfixed>
+	- python3.14 <unfixed>
+	- python3.13 <unfixed>
+	[trixie] - python3.13 <no-dsa> (Minor issue)
+	- python3.11 <removed>
+	- python3.9 <removed>
+	- pypy3 <unfixed>
+	[trixie] - pypy3 <no-dsa> (Minor issue)
 	NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/J2WT2ALRWEXQJOB3C7Q2HYWUXP3CINWO/
 	NOTE: https://github.com/python/cpython/issues/155999
 	NOTE: https://github.com/python/cpython/pull/156000


=====================================
data/dsa-needed.txt
=====================================
@@ -23,12 +23,14 @@ amd64-microcode (carnil)
 bouncycastle
   possibly move to 1.85 for trixie
 --
+bubblewrap (jmm)
+--
 cacti
   probably best to move to 1.2.31
 --
 chromium (dilinger)
 --
-cockpit
+cockpit (jmm)
 --
 containerd
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d871d68aa86f841ce8d5ebd1d3fc034747573804

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d871d68aa86f841ce8d5ebd1d3fc034747573804
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/1d386f8d/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list