[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Aug 27 09:00:46 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7715c3ec by Moritz Muehlenhoff at 2026-08-27T10:00:36+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1120,6 +1120,7 @@ CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from th
 	NOT-FOR-US: DB-GPT
 CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When processing a spe ...)
 	- gimp <unfixed>
+	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16583
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/e78fe7ae2a8d3341f6e862c0426265791d5975e6
 CVE-2026-79912 (A vulnerability was detected in TOTOLINK N600R 4.3.0cu.7647_B20210106. ...)
@@ -3526,10 +3527,12 @@ CVE-2026-78541 (A stored OS command injection vulnerability exists in the parent
 	NOT-FOR-US: TPLink
 CVE-2026-78475 (A flaw was found in the file-pix (ESM) plugin in GIMP. When processing ...)
 	- gimp <unfixed>
+	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16580
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/27d83534e637cf160f913ac6d6388d5a5555e9d8
 CVE-2026-78465 (A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit buil ...)
 	- gimp <unfixed>
+	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16578
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/56e580c43a2de9c0005f57018013998999535e4d
 CVE-2026-78417 (Insufficient verification of data authenticity in the IronVNC client i ...)
@@ -8251,11 +8254,13 @@ CVE-2026-XXXX [GHSA-xrfq-jhgh-wqch: Authentication bypass in the web interface]
 	NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/9a12300877a38becda23dada37fd4f9c488801a5 (5.1.1)
 CVE-2026-72889 (Net::OAuth versions before 0.33 for Perl allow the sender to choose th ...)
 	- libnet-oauth-perl 0.33-1 (bug #1144854)
+	[trixie] - libnet-oauth-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42818761/
 	NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-c8rm-g5cm-4pf5
 	NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/c467adf45c8d77ac4b92ad78b3eebf949252ba7f
 CVE-2026-75589 (Net::OAuth versions before 0.33 for Perl check HMAC-SHA1, HMAC-SHA256  ...)
 	- libnet-oauth-perl 0.33-1 (bug #1144855)
+	[trixie] - libnet-oauth-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/42818763/
 	NOTE: https://github.com/vurtdev/Net-OAuth/security/advisories/GHSA-g8xr-69p3-gw56
 	NOTE: Fixed by: https://github.com/vurtdev/Net-OAuth/commit/a1a16b58add85668ef4fcda642a486ceed098eba
@@ -12131,6 +12136,7 @@ CVE-2026-71566 (FakeFish handles incoming credentials by passing them down  to s
 	NOT-FOR-US: FakeFish
 CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1144932)
+	[trixie] - sqlparse <no-dsa> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87 (0.6.0)
 CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
@@ -12205,10 +12211,12 @@ CVE-2026-59902 (Netty is an asynchronous, event-driven network application frame
 	NOTE: Fixed by: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 (netty-4.2.17.Final)
 CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1144932)
+	[trixie] - sqlparse <no-dsa> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-3496-9g83-7v6x
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/53ff44b53e27cff78259acc1af015506fea60f63 (0.6.0)
 CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1144932)
+	[trixie] - sqlparse <no-dsa> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e (0.6.0)
 CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -12231,6 +12239,7 @@ CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1
 	NOT-FOR-US: Discourse
 CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1144932)
+	[trixie] - sqlparse <no-dsa> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f (0.6.0)
 CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -34872,6 +34881,7 @@ CVE-2026-54635 (pytonapi is a Python SDK for TONAPI that provides REST API, stre
 	NOT-FOR-US: pytonapi
 CVE-2026-54620 (sqlite3 provides Ruby bindings for the SQLite3 embedded database. From ...)
 	- ruby-sqlite3 2.9.5-1
+	[trixie] - ruby-sqlite3 <no-dsa> (Minor issue)
 	[bookworm] - ruby-sqlite3 <postponed> (minor issue)
 	[bullseye] - ruby-sqlite3 <postponed> (minor issue)
 	NOTE: https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-j7fr-3v8c-3qc3
@@ -34879,6 +34889,7 @@ CVE-2026-54620 (sqlite3 provides Ruby bindings for the SQLite3 embedded database
 	NOTE: Fixed by: https://github.com/sparklemotion/sqlite3-ruby/commit/b24e1e6076528b7f95f99acf7a81c70d0004c726 (v2.9.5)
 CVE-2026-54619 (sqlite3 provides Ruby bindings for the SQLite3 embedded database. In v ...)
 	- ruby-sqlite3 2.9.5-1
+	[trixie] - ruby-sqlite3 <no-dsa> (Minor issue)
 	[bookworm] - ruby-sqlite3 <postponed> (minor issue)
 	[bullseye] - ruby-sqlite3 <postponed> (minor issue)
 	NOTE: https://github.com/sparklemotion/sqlite3-ruby/security/advisories/GHSA-28hh-pr2h-2w89


=====================================
data/dsa-needed.txt
=====================================
@@ -69,6 +69,8 @@ libdbi-perl (carnil)
 --
 libde265
 --
+libevent
+--
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more 6.12.y versions



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7715c3ecd54a5132e3956237fbb3533faf9a080a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7715c3ecd54a5132e3956237fbb3533faf9a080a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/bf978e04/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list