[Git][security-tracker-team/security-tracker][master] Add Debian bug references for some issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Aug 28 16:59:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
14601bce by Salvatore Bonaccorso at 2026-08-28T17:03:34+02:00
Add Debian bug references for some issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -832,11 +832,11 @@ CVE-2026-77438 (Trilium is an open-source hierarchical note-taking application.
 CVE-2026-77365 (The Optimole \u2013 Optimize Images | Convert WebP & AVIF | CDN & Lazy ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77358 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In versions 0.33. ...)
-	- cpp-httplib <unfixed>
+	- cpp-httplib <unfixed> (bug #1145977)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-w7p7-f35j-mw7q
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/2f986fd5e56e7c5f686d965174516360930f371d (v0.50.1)
 CVE-2026-77341 (cpp-httplib is a C++ header-only HTTP/HTTPS library. In version 0.49.0 ...)
-	- cpp-httplib <unfixed>
+	- cpp-httplib <unfixed> (bug #1145976)
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-2r2h-jc8w-w66c
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/568d434e72fc51729d0ad33abffb181e5f7a453d (v0.50.0)
 CVE-2026-76945 (The affected Ebyte device relies on client-managed authentication toke ...)
@@ -1128,18 +1128,18 @@ CVE-2026-13086 (A stack-based buffer overflow in the epm (Endpoint Protection Ma
 CVE-2026-10036 (SpeechBrain before 1.1.1 contains an arbitrary code execution vulnerab ...)
 	TODO: check
 CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG  ...)
-	- gdk-pixbuf <unfixed>
+	- gdk-pixbuf <unfixed> (bug #1145988)
 	NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
 	NOTE: Introduced with: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/4af78023ce7d3b5e3cec422a59bb4f48fa4f5886 (2.43.4)
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01
 	NOTE: The introducing commit is the fix for CVE-2025-7345.
 CVE-2026-80489
-	- glibc <unfixed>
+	- glibc <unfixed> (bug #1145987)
 	[trixie] - glibc <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524870
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34568
 CVE-2026-80179 (A flaw was found in jwcrypto. A remote attacker can send a specially c ...)
-	- python-jwcrypto <unfixed>
+	- python-jwcrypto <unfixed> (bug #1145983)
 	NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-96rv-c4vc-h4f4
 CVE-2026-81501
 	- incus 7.0.1-3
@@ -1415,7 +1415,7 @@ CVE-2026-78260 (Unauthenticated SQL Injection in Epayco <= 8.4.6 versions.)
 CVE-2026-78257 (Contributor PHP Object Injection in Booking and Rental Manager <= 2.7. ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker can tr ...)
-	- rsyslog <unfixed>
+	- rsyslog <unfixed> (bug #1145980)
 	[trixie] - rsyslog <no-dsa> (Minor issue)
 	NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3
 CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
@@ -1807,7 +1807,7 @@ CVE-2026-79939 (Dell PowerProtect Cyber Recovery, versions Prior to 20.3, contai
 CVE-2026-79938 (Dell PowerProtect Cyber Recovery, versions prior to 20.3, contain an I ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-79921 (amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a comprom ...)
-	- golang-github-rabbitmq-amqp091-go <unfixed>
+	- golang-github-rabbitmq-amqp091-go <unfixed> (bug #1145982)
 	NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp
 	NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
 	NOTE: Fixed by (merge): https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0 (v1.13.0)
@@ -4438,7 +4438,7 @@ CVE-2026-79657 (NLTK versions before 3.10.3 contain a remote code execution vuln
 	[trixie] - nltk <no-dsa> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-x99w-6fgc-pmfw
 CVE-2026-79655 (A flaw was found in sos clean, a utility within the sos package. This  ...)
-	- sos <unfixed>
+	- sos <unfixed> (bug #1145981)
 	[trixie] - sos <no-dsa> (Minor issue)
 	- sospreort <removed>
 	NOTE: https://github.com/sosreport/sos/issues/4460



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/14601bce8d79e013c26a6758e621ecf8acdd2c25

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/14601bce8d79e013c26a6758e621ecf8acdd2c25
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260828/d0b5fcc4/attachment.htm>


More information about the debian-security-tracker-commits mailing list