[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 30 08:13:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
02686a72 by security tracker role at 2026-08-30T07:13:10+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,51 @@
+CVE-2026-82562 (### Summary    When `qs.parse` is called with `comma: true` and `throw ...)
+	TODO: check
+CVE-2026-82482 (A security vulnerability has been detected in coppermine-gallery Coppe ...)
+	TODO: check
+CVE-2026-82480 (A security flaw has been discovered in NASA cFS up to 7.0.1. The affec ...)
+	TODO: check
+CVE-2026-82479 (A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is th ...)
+	TODO: check
+CVE-2026-82478 (A vulnerability was determined in NASA Trick 19.6.0. This issue affect ...)
+	TODO: check
+CVE-2026-82424 (A weakness has been identified in PHPGurukul Student Information Syste ...)
+	TODO: check
+CVE-2026-82423 (A vulnerability has been found in macrozheng mall up to 1.0.3. The aff ...)
+	TODO: check
+CVE-2026-82422 (A security flaw has been discovered in itsourcecode Sales and Inventor ...)
+	TODO: check
+CVE-2026-82421 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
+	TODO: check
+CVE-2026-82417 (### Summary    `qs.stringify` throws a `TypeError` when it serializes  ...)
+	TODO: check
+CVE-2026-81766 (The Really Simple Security  WordPress plugin before 9.8.0 does not che ...)
+	TODO: check
+CVE-2026-81660 (The Groundhogg \u2014 CRM, Newsletters, and Marketing Automation WordP ...)
+	TODO: check
+CVE-2026-78364 (The MW WP Form WordPress plugin before 5.1.6 does not sanitise and esc ...)
+	TODO: check
+CVE-2026-77970 (Cleartext Storage of Sensitive Information vulnerability in ash-projec ...)
+	TODO: check
+CVE-2026-77846 (Improper Neutralization of Special Elements in Data Query Logic vulner ...)
+	TODO: check
+CVE-2026-77831 (Inefficient Algorithmic Complexity vulnerability in ash-project ash_pa ...)
+	TODO: check
+CVE-2026-76585 (The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 d ...)
+	TODO: check
+CVE-2026-75847 (Cleartext Storage of Sensitive Information vulnerability in ash-projec ...)
+	TODO: check
+CVE-2026-75759 (Improper Verification of Cryptographic Signature vulnerability in erle ...)
+	TODO: check
+CVE-2026-19722 (The WPvivid \u2014 Backup, Migration & Staging WordPress plugin before ...)
+	TODO: check
+CVE-2026-15980 (The MyHome Core plugin for WordPress is vulnerable to Authentication B ...)
+	TODO: check
+CVE-2026-15369 (The Custom User Registration Fields for WooCommerce plugin for WordPre ...)
+	TODO: check
+CVE-2026-14835 (The SOGO Add Script to Individual Pages Header Footer WordPress plugin ...)
+	TODO: check
+CVE-2026-14307 (The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise o ...)
+	TODO: check
 CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory traversal.)
 	- ocaml-cohttp <unfixed>
 	NOTE: https://github.com/mirage/ocaml-cohttp/pull/1145 (6.3.0)
@@ -177,6 +225,7 @@ CVE-2026-81200 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.
 CVE-2026-81026 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.40 d ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-80725 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	{DSA-6477-1}
 	- linux 7.0.3-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/81be30c1f5f2bffda1f04c0efd0746af10b9643a (7.0-rc1)
@@ -1587,6 +1636,7 @@ CVE-2026-80598 (In the Linux kernel, the following vulnerability has been resolv
 	[bookworm] - linux 6.1.180-1
 	NOTE: https://git.kernel.org/linus/7160a57192fb16d7a6fa9b7f5c7ac341d2444a89 (7.2-rc1)
 CVE-2026-80590 (In the Linux kernel, the following vulnerability has been resolved:  i ...)
+	{DSA-6477-1}
 	- linux 7.1.12-1
 	NOTE: https://git.kernel.org/linus/d5dc1e69fd7258ea605c9952e5d5947539159ae3
 CVE-2026-82090 (Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects ex ...)
@@ -3091,6 +3141,7 @@ CVE-2026-80584 (In the Linux kernel, the following vulnerability has been resolv
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/d141f087b1af656f055d7c5793a3e87817ba0bbe (7.2-rc7)
 CVE-2026-80583 (In the Linux kernel, the following vulnerability has been resolved:  A ...)
+	{DSA-6477-1}
 	- linux 7.1.10-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/1ba381759e45d5d0442452cfa5c42e836191a568 (7.2-rc7)
@@ -3142,6 +3193,7 @@ CVE-2026-80573 (In the Linux kernel, the following vulnerability has been resolv
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/5751c781d3c97ab6ce0e2a966156ed882152c415 (7.2-rc7)
 CVE-2026-80572 (In the Linux kernel, the following vulnerability has been resolved:  I ...)
+	{DSA-6477-1}
 	- linux 7.1.10-1
 	NOTE: https://git.kernel.org/linus/c83e79c0842ed29860648bcce5022ef0ba5001c6 (7.2-rc7)
 CVE-2026-80571 (In the Linux kernel, the following vulnerability has been resolved:  p ...)
@@ -3189,6 +3241,7 @@ CVE-2026-80563 (In the Linux kernel, the following vulnerability has been resolv
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/44f3468a0aef1aabdad551898ab7cfa2a9d20e99 (7.2)
 CVE-2026-80562 (In the Linux kernel, the following vulnerability has been resolved:  g ...)
+	{DSA-6477-1}
 	- linux 7.1.10-1
 	NOTE: https://git.kernel.org/linus/600411ea1f2443fdf5b1af9b6480f616d7aff9d0 (7.2)
 CVE-2026-80561 (In the Linux kernel, the following vulnerability has been resolved:  l ...)
@@ -3208,6 +3261,7 @@ CVE-2026-80558 (In the Linux kernel, the following vulnerability has been resolv
 	[trixie] - linux 6.12.105-1
 	NOTE: https://git.kernel.org/linus/3660b98d1204b419f6a77e9a295f148dcf38d042 (7.2)
 CVE-2026-80557 (In the Linux kernel, the following vulnerability has been resolved:  l ...)
+	{DSA-6477-1}
 	- linux 7.1.10-1
 	NOTE: https://git.kernel.org/linus/00ead17c7de137a692edee59f2772e6af687e8eb (7.2)
 CVE-2026-80556 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
@@ -3306,6 +3360,7 @@ CVE-2026-80537 (In the Linux kernel, the following vulnerability has been resolv
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/cc3144da377de5fb422d44a2311f978623f7c900 (7.2-rc7)
 CVE-2026-80536 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	{DSA-6477-1}
 	- linux 7.1.10-1
 	NOTE: https://git.kernel.org/linus/813f8136a2ce1fee266d02a7df73db6e8a541604 (7.2-rc7)
 CVE-2026-80535 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
@@ -7488,6 +7543,7 @@ CVE-2026-74663 (In the Linux kernel, the following vulnerability has been resolv
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/dedd34b0f2310e28c5f6d4875cfbf4b7ed821c01 (7.2-rc7)
 CVE-2026-74662 (In the Linux kernel, the following vulnerability has been resolved:  i ...)
+	{DSA-6477-1}
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/653d7ddf6cba867777a3d14c4f83ace008c5ad13 (7.2-rc7)
 CVE-2026-74661 (In the Linux kernel, the following vulnerability has been resolved:  m ...)
@@ -7528,6 +7584,7 @@ CVE-2026-74654 (In the Linux kernel, the following vulnerability has been resolv
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41 (7.2-rc7)
 CVE-2026-74653 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
+	{DSA-6477-1}
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/1423415471274abda87024967d7fe2206ceee0ea (7.2-rc7)
 CVE-2026-74651 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
@@ -7606,6 +7663,7 @@ CVE-2026-74628 (In the Linux kernel, the following vulnerability has been resolv
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/2195424c3da2ef1829a63b807e3a900a90e57d85 (7.2-rc7)
 CVE-2026-74626 (In the Linux kernel, the following vulnerability has been resolved:  N ...)
+	{DSA-6477-1}
 	- linux 7.1.9-1
 	NOTE: https://git.kernel.org/linus/d2121faf133ac3bf9531b53a7e21273649a08517 (7.2)
 CVE-2026-74625 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
@@ -26620,35 +26678,45 @@ CVE-2026-68871 (The Yandex Lockbox secrets backend in Apache Airflow's Yandex pr
 CVE-2026-68872 (The AWS Systems Manager Parameter Store and Secrets Manager backends i ...)
 	NOT-FOR-US: Apache Airflow provider
 CVE-2026-74998 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses f ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b (1.6.18)
 CVE-2026-75006 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficien ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223 (1.6.18)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9 (1.6.18)
 CVE-2026-75003 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b (1.6.18)
 CVE-2026-75007 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP se ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540 (1.6.18)
 CVE-2026-75004 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper ru ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e (1.6.18)
 CVE-2026-74997 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_lea ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd (1.6.18)
 	NOTE: Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a (release-1.6)
 CVE-2026-75002 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea (1.6.18)
 CVE-2026-75010 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c (1.6.18)
 CVE-2026-74999 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8 (1.6.18)
 CVE-2026-75000 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HT ...)
+	{DLA-4760-1}
 	- roundcube 1.6.18+dfsg-1 (bug #1144059)
 	NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f (1.6.18)
 CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a usernam ...)
@@ -31631,6 +31699,7 @@ CVE-2026-64566 (In the Linux kernel, the following vulnerability has been resolv
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/430ea57d6daf765e88f90046afbfd1e071cb7200 (7.2-rc4)
 CVE-2026-64581 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
+	{DSA-6477-1}
 	- linux 7.1.6-1
 	NOTE: https://git.kernel.org/linus/c283e9ada7fcb7dd4b10592623086b2e6d2f9925 (7.2-rc4)
 CVE-2026-64580 (In the Linux kernel, the following vulnerability has been resolved:  x ...)
@@ -41291,6 +41360,7 @@ CVE-2026-64217 (In the Linux kernel, the following vulnerability has been resolv
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/0ef37eef83fad3542ee06db2940433ae1a92b39d (7.1-rc5)
 CVE-2026-64216 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
+	{DSA-6477-1}
 	- linux 7.0.12-1
 	[bookworm] - linux <not-affected> (Vulnerable code not present)
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -188740,6 +188810,7 @@ CVE-2025-40075 (In the Linux kernel, the following vulnerability has been resolv
 	[trixie] - linux 6.12.63-1
 	NOTE: https://git.kernel.org/linus/50c127a69cd6285300931853b352a1918cfa180f (6.18-rc1)
 CVE-2025-40074 (In the Linux kernel, the following vulnerability has been resolved:  i ...)
+	{DSA-6477-1}
 	- linux 6.17.6-1
 	NOTE: https://git.kernel.org/linus/6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8 (6.18-rc1)
 CVE-2025-40073 (In the Linux kernel, the following vulnerability has been resolved:  d ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/02686a729b643e94936186e847e33cacaf4aad98

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/02686a729b643e94936186e847e33cacaf4aad98
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260830/e4d0f95e/attachment.htm>


More information about the debian-security-tracker-commits mailing list