[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 30 08:13:16 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
02686a72 by security tracker role at 2026-08-30T07:13:10+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,51 @@
+CVE-2026-82562 (### Summary When `qs.parse` is called with `comma: true` and `throw ...)
+ TODO: check
+CVE-2026-82482 (A security vulnerability has been detected in coppermine-gallery Coppe ...)
+ TODO: check
+CVE-2026-82480 (A security flaw has been discovered in NASA cFS up to 7.0.1. The affec ...)
+ TODO: check
+CVE-2026-82479 (A vulnerability was identified in NASA cFS up to 7.0.1. Impacted is th ...)
+ TODO: check
+CVE-2026-82478 (A vulnerability was determined in NASA Trick 19.6.0. This issue affect ...)
+ TODO: check
+CVE-2026-82424 (A weakness has been identified in PHPGurukul Student Information Syste ...)
+ TODO: check
+CVE-2026-82423 (A vulnerability has been found in macrozheng mall up to 1.0.3. The aff ...)
+ TODO: check
+CVE-2026-82422 (A security flaw has been discovered in itsourcecode Sales and Inventor ...)
+ TODO: check
+CVE-2026-82421 (A vulnerability was identified in itsourcecode Sales and Inventory Sys ...)
+ TODO: check
+CVE-2026-82417 (### Summary `qs.stringify` throws a `TypeError` when it serializes ...)
+ TODO: check
+CVE-2026-81766 (The Really Simple Security WordPress plugin before 9.8.0 does not che ...)
+ TODO: check
+CVE-2026-81660 (The Groundhogg \u2014 CRM, Newsletters, and Marketing Automation WordP ...)
+ TODO: check
+CVE-2026-78364 (The MW WP Form WordPress plugin before 5.1.6 does not sanitise and esc ...)
+ TODO: check
+CVE-2026-77970 (Cleartext Storage of Sensitive Information vulnerability in ash-projec ...)
+ TODO: check
+CVE-2026-77846 (Improper Neutralization of Special Elements in Data Query Logic vulner ...)
+ TODO: check
+CVE-2026-77831 (Inefficient Algorithmic Complexity vulnerability in ash-project ash_pa ...)
+ TODO: check
+CVE-2026-76585 (The Customer Reviews for WooCommerce WordPress plugin before 5.118.0 d ...)
+ TODO: check
+CVE-2026-75847 (Cleartext Storage of Sensitive Information vulnerability in ash-projec ...)
+ TODO: check
+CVE-2026-75759 (Improper Verification of Cryptographic Signature vulnerability in erle ...)
+ TODO: check
+CVE-2026-19722 (The WPvivid \u2014 Backup, Migration & Staging WordPress plugin before ...)
+ TODO: check
+CVE-2026-15980 (The MyHome Core plugin for WordPress is vulnerable to Authentication B ...)
+ TODO: check
+CVE-2026-15369 (The Custom User Registration Fields for WooCommerce plugin for WordPre ...)
+ TODO: check
+CVE-2026-14835 (The SOGO Add Script to Individual Pages Header Footer WordPress plugin ...)
+ TODO: check
+CVE-2026-14307 (The geotargetingwp WordPress plugin before 3.5.6.2 does not sanitise o ...)
+ TODO: check
CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory traversal.)
- ocaml-cohttp <unfixed>
NOTE: https://github.com/mirage/ocaml-cohttp/pull/1145 (6.3.0)
@@ -177,6 +225,7 @@ CVE-2026-81200 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.
CVE-2026-81026 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.40 d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-80725 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6477-1}
- linux 7.0.3-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/81be30c1f5f2bffda1f04c0efd0746af10b9643a (7.0-rc1)
@@ -1587,6 +1636,7 @@ CVE-2026-80598 (In the Linux kernel, the following vulnerability has been resolv
[bookworm] - linux 6.1.180-1
NOTE: https://git.kernel.org/linus/7160a57192fb16d7a6fa9b7f5c7ac341d2444a89 (7.2-rc1)
CVE-2026-80590 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6477-1}
- linux 7.1.12-1
NOTE: https://git.kernel.org/linus/d5dc1e69fd7258ea605c9952e5d5947539159ae3
CVE-2026-82090 (Pocket through 8.33.0.0 allows XSS because "Save to Pocket" injects ex ...)
@@ -3091,6 +3141,7 @@ CVE-2026-80584 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/d141f087b1af656f055d7c5793a3e87817ba0bbe (7.2-rc7)
CVE-2026-80583 (In the Linux kernel, the following vulnerability has been resolved: A ...)
+ {DSA-6477-1}
- linux 7.1.10-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1ba381759e45d5d0442452cfa5c42e836191a568 (7.2-rc7)
@@ -3142,6 +3193,7 @@ CVE-2026-80573 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/5751c781d3c97ab6ce0e2a966156ed882152c415 (7.2-rc7)
CVE-2026-80572 (In the Linux kernel, the following vulnerability has been resolved: I ...)
+ {DSA-6477-1}
- linux 7.1.10-1
NOTE: https://git.kernel.org/linus/c83e79c0842ed29860648bcce5022ef0ba5001c6 (7.2-rc7)
CVE-2026-80571 (In the Linux kernel, the following vulnerability has been resolved: p ...)
@@ -3189,6 +3241,7 @@ CVE-2026-80563 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/44f3468a0aef1aabdad551898ab7cfa2a9d20e99 (7.2)
CVE-2026-80562 (In the Linux kernel, the following vulnerability has been resolved: g ...)
+ {DSA-6477-1}
- linux 7.1.10-1
NOTE: https://git.kernel.org/linus/600411ea1f2443fdf5b1af9b6480f616d7aff9d0 (7.2)
CVE-2026-80561 (In the Linux kernel, the following vulnerability has been resolved: l ...)
@@ -3208,6 +3261,7 @@ CVE-2026-80558 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.105-1
NOTE: https://git.kernel.org/linus/3660b98d1204b419f6a77e9a295f148dcf38d042 (7.2)
CVE-2026-80557 (In the Linux kernel, the following vulnerability has been resolved: l ...)
+ {DSA-6477-1}
- linux 7.1.10-1
NOTE: https://git.kernel.org/linus/00ead17c7de137a692edee59f2772e6af687e8eb (7.2)
CVE-2026-80556 (In the Linux kernel, the following vulnerability has been resolved: m ...)
@@ -3306,6 +3360,7 @@ CVE-2026-80537 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/cc3144da377de5fb422d44a2311f978623f7c900 (7.2-rc7)
CVE-2026-80536 (In the Linux kernel, the following vulnerability has been resolved: x ...)
+ {DSA-6477-1}
- linux 7.1.10-1
NOTE: https://git.kernel.org/linus/813f8136a2ce1fee266d02a7df73db6e8a541604 (7.2-rc7)
CVE-2026-80535 (In the Linux kernel, the following vulnerability has been resolved: x ...)
@@ -7488,6 +7543,7 @@ CVE-2026-74663 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/dedd34b0f2310e28c5f6d4875cfbf4b7ed821c01 (7.2-rc7)
CVE-2026-74662 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6477-1}
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/653d7ddf6cba867777a3d14c4f83ace008c5ad13 (7.2-rc7)
CVE-2026-74661 (In the Linux kernel, the following vulnerability has been resolved: m ...)
@@ -7528,6 +7584,7 @@ CVE-2026-74654 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/e2fe6a0efecbef00e3ecc2db64dd5afa8c212b41 (7.2-rc7)
CVE-2026-74653 (In the Linux kernel, the following vulnerability has been resolved: s ...)
+ {DSA-6477-1}
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/1423415471274abda87024967d7fe2206ceee0ea (7.2-rc7)
CVE-2026-74651 (In the Linux kernel, the following vulnerability has been resolved: s ...)
@@ -7606,6 +7663,7 @@ CVE-2026-74628 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/2195424c3da2ef1829a63b807e3a900a90e57d85 (7.2-rc7)
CVE-2026-74626 (In the Linux kernel, the following vulnerability has been resolved: N ...)
+ {DSA-6477-1}
- linux 7.1.9-1
NOTE: https://git.kernel.org/linus/d2121faf133ac3bf9531b53a7e21273649a08517 (7.2)
CVE-2026-74625 (In the Linux kernel, the following vulnerability has been resolved: n ...)
@@ -26620,35 +26678,45 @@ CVE-2026-68871 (The Yandex Lockbox secrets backend in Apache Airflow's Yandex pr
CVE-2026-68872 (The AWS Systems Manager Parameter Store and Secrets Manager backends i ...)
NOT-FOR-US: Apache Airflow provider
CVE-2026-74998 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, responses f ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/62d33c8a0dc3fd0dd03984220dc9709e8e0de43b (1.6.18)
CVE-2026-75006 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, insufficien ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/8a92380b06b5df1481e034c4f40d6a6546c21223 (1.6.18)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/92f85c883594e5be757154f94548a9ba903455c9 (1.6.18)
CVE-2026-75003 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, an unclosed ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/1cebea03474305d9f75a9a33d30880d290b5591b (1.6.18)
CVE-2026-75007 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the LDAP se ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/e6cc1e121effeaec6d916feb4e019d2828924540 (1.6.18)
CVE-2026-75004 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper ru ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/a1afb8fd1f00ed4cb9376c072bb5ca5ded64495e (1.6.18)
CVE-2026-74997 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the cmd_lea ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/b8f90e28a46d42e79a69568cba897f8f4223d9cd (1.6.18)
NOTE: Follow-up: https://github.com/roundcube/roundcubemail/commit/495d211638f222336b20f4744545c53712426c2a (release-1.6)
CVE-2026-75002 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, mail search ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/73233abe581b3b31cefd00041c7086c40e1793ea (1.6.18)
CVE-2026-75010 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the modoboa ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/65b8ea9d8304b10f1d3bda5bcc82f9c682cf804c (1.6.18)
CVE-2026-74999 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, the "Add to ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/32f20c6bfd12dff9cfb6880ae303e740f0804fe8 (1.6.18)
CVE-2026-75000 (In Roundcube Webmail before 1.6.18 and 1.7.x before 1.7.3, improper HT ...)
+ {DLA-4760-1}
- roundcube 1.6.18+dfsg-1 (bug #1144059)
NOTE: Fixed by: https://github.com/roundcube/roundcubemail/commit/4a2bb87d9ea93578acb9bb03599abf754c33a33f (1.6.18)
CVE-2026-6791 (When expanding paths that begin with a tilde (~) followed by a usernam ...)
@@ -31631,6 +31699,7 @@ CVE-2026-64566 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/430ea57d6daf765e88f90046afbfd1e071cb7200 (7.2-rc4)
CVE-2026-64581 (In the Linux kernel, the following vulnerability has been resolved: x ...)
+ {DSA-6477-1}
- linux 7.1.6-1
NOTE: https://git.kernel.org/linus/c283e9ada7fcb7dd4b10592623086b2e6d2f9925 (7.2-rc4)
CVE-2026-64580 (In the Linux kernel, the following vulnerability has been resolved: x ...)
@@ -41291,6 +41360,7 @@ CVE-2026-64217 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/0ef37eef83fad3542ee06db2940433ae1a92b39d (7.1-rc5)
CVE-2026-64216 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6477-1}
- linux 7.0.12-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -188740,6 +188810,7 @@ CVE-2025-40075 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.63-1
NOTE: https://git.kernel.org/linus/50c127a69cd6285300931853b352a1918cfa180f (6.18-rc1)
CVE-2025-40074 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6477-1}
- linux 6.17.6-1
NOTE: https://git.kernel.org/linus/6ad8de3cefdb6ffa6708b21c567df0dbf82c43a8 (6.18-rc1)
CVE-2025-40073 (In the Linux kernel, the following vulnerability has been resolved: d ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/02686a729b643e94936186e847e33cacaf4aad98
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/02686a729b643e94936186e847e33cacaf4aad98
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260830/e4d0f95e/attachment.htm>
More information about the debian-security-tracker-commits
mailing list