[Git][security-tracker-team/security-tracker][master] Add first batch of Debian bugs reported for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 27 18:10:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
57d0df66 by Salvatore Bonaccorso at 2026-08-27T19:09:26+02:00
Add first batch of Debian bugs reported for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -346,7 +346,7 @@ CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the community.ge
 CVE-2026-78360
 	NOT-FOR-US: fedora-infra/anitya
 CVE-2026-77117
-	- glibc <unfixed>
+	- glibc <unfixed> (bug #1145880)
 	[trixie] - glibc <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523274
 CVE-2026-9668 (With legitimate user credentials in hand, attackers can construct mali ...)
@@ -754,7 +754,7 @@ CVE-2026-7487 (GitLab has remediated an issue in GitLab EE affecting all version
 CVE-2026-79940 (Dell iDRAC9, 14G versions prior to 7.00.00.182 and 15G/16G versions pr ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-79902 (A flaw was found in the Seattle FilmWorks plugin in GIMP. When process ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145872)
 	[trixie] - gimp <not-affected> (Vulnerable code not present)
 	[bookworm] - gimp <not-affected> (Vulnerable code not present)
 	[bullseye] - gimp <not-affected> (Vulnerable code not present)
@@ -1112,12 +1112,12 @@ CVE-2026-80191 (GROWI applies its page-viewer permission check to attachment req
 CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how much da ...)
 	NOT-FOR-US: LeafWiki
 CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ, the Linux ...)
-	- bluez <unfixed>
+	- bluez <unfixed> (bug #1145869)
 	[trixie] - bluez <no-dsa> (Minor issue)
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
 CVE-2026-80185 (BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can  ...)
-	- bluez <unfixed>
+	- bluez <unfixed> (bug #1145870)
 	[trixie] - bluez <no-dsa> (Minor issue)
 	NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
@@ -1126,7 +1126,7 @@ CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or esca
 CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from the mult ...)
 	NOT-FOR-US: DB-GPT
 CVE-2026-80101 (A flaw was found in the file-xwd plugin in GIMP. When processing a spe ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145871)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16583
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/e78fe7ae2a8d3341f6e862c0426265791d5975e6
@@ -3078,7 +3078,7 @@ CVE-2026-17548 (Missing authorization in Checkmk <2.5.0p12, <2.4.0p36, <2.3.0p50
 CVE-2026-16601 (The CM Map Locations \u2013 Visualize and share your locations in a fe ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-16599 (GNU wget is vulnerable to denial of service in its FTP OPIE/S-KEY auth ...)
-	- wget <unfixed> (unimportant)
+	- wget <unfixed> (unimportant; bug #1145868)
 	NOTE: https://cert.pl/en/posts/2026/08/CVE-2026-16599/
 	NOTE: Fixed by: https://gitlab.com/gnuwget/wget/-/commit/e9697d98e7249b0f68a6be040a4f3dcc5bc101fa
 	NOTE: Hang in CLI tool, no security impact
@@ -3327,7 +3327,7 @@ CVE-2026-76816 (Netty is an asynchronous, event-driven network application frame
 	NOTE: Fixed by: https://github.com/netty/netty/commit/1b5abc6443b63726c72cdd285af2feb7ddbb8ff7 (netty-4.2.17.Final)
 	NOTE: Fixed by: https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961 (netty-4.1.137.Final)
 CVE-2026-76098 (Mistune is a Python Markdown parser with renderers and plugins. Versio ...)
-	- mistune <unfixed>
+	- mistune <unfixed> (bug #1145881)
 	NOTE: https://github.com/lepture/mistune/security/advisories/GHSA-6m44-fpc8-c3rq
 	NOTE: https://github.com/lepture/mistune/commit/0938fb781d0aded99de801b340ec1f8debeae5b2 (v3.3.3)
 CVE-2026-76063 (The FundEngine \u2013 Donation and Crowdfunding Platform plugin for Wo ...)
@@ -3542,12 +3542,12 @@ CVE-2026-8173 (The web GUI of affected Murrelektronik Xelity switches logs MAC a
 CVE-2026-78541 (A stored OS command injection vulnerability exists in the parent-contr ...)
 	NOT-FOR-US: TPLink
 CVE-2026-78475 (A flaw was found in the file-pix (ESM) plugin in GIMP. When processing ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145874)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16580
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/27d83534e637cf160f913ac6d6388d5a5555e9d8
 CVE-2026-78465 (A flaw was found in the file-pcx plugin in GIMP, affecting 32-bit buil ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1145875)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16578
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/56e580c43a2de9c0005f57018013998999535e4d
@@ -3588,7 +3588,7 @@ CVE-2026-78370 (RansomLook contains an authorization flaw in its legacy database
 CVE-2026-78369 (RansomLook contains a missing authentication vulnerability in the /adm ...)
 	NOT-FOR-US: RansomLook
 CVE-2026-78367 (A vulnerability was found in RPM's rpmbuild tarball processing. When p ...)
-	- rpm <unfixed>
+	- rpm <unfixed> (bug #1145876)
 	[trixie] - rpm <no-dsa> (Minor issue)
 	NOTE: https://github.com/rpm-software-management/rpm/issues/4314
 CVE-2026-78365 (Authorization Bypass Through User-Controlled Key in the supplier API i ...)
@@ -3598,7 +3598,7 @@ CVE-2026-78337 (Unrestricted Upload of File with Dangerous Type in the company l
 CVE-2026-78329 (Improper input validation vulnerability in Apache Camel Undertow compo ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-78323 (A flaw was found in JSS (Java Security Services). The JSSTrustManager  ...)
-	- jss <unfixed>
+	- jss <unfixed> (bug #1145877)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2521775
 	TODO: check upstream details
 CVE-2026-78321 (The HTTP media server on DJI drones does not enforce sufficient limits ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/57d0df66e8ca48e174d00b42c4205fd05691d871

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/57d0df66e8ca48e174d00b42c4205fd05691d871
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/be28e899/attachment.htm>


More information about the debian-security-tracker-commits mailing list