[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Aug 30 18:04:46 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
45b34d58 by Moritz Muehlenhoff at 2026-08-30T19:04:25+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -101,6 +101,7 @@ CVE-2026-58581
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e0397dbe1a295e037f16f154aaaa3cff3341fc3d (v11.0.4)
 CVE-2026-82562 (### Summary    When `qs.parse` is called with `comma: true` and `throw ...)
 	- node-qs <unfixed>
+	[trixie] - node-qs <no-dsa> (Minor issue)
 	NOTE: https://github.com/ljharb/qs/security/advisories/GHSA-x5fp-wj9c-mxmx
 	NOTE: Fixed by: https://github.com/ljharb/qs/commit/8859c37470e11b42b547b275e4e9bd0bc8cc5464 (v6.16.0)
 CVE-2026-82482 (A security vulnerability has been detected in coppermine-gallery Coppe ...)
@@ -121,6 +122,7 @@ CVE-2026-82421 (A vulnerability was identified in itsourcecode Sales and Invento
 	NOT-FOR-US: itsourcecode System
 CVE-2026-82417 (### Summary    `qs.stringify` throws a `TypeError` when it serializes  ...)
 	- node-qs <unfixed>
+	[trixie] - node-qs <no-dsa> (Minor issue)
 	NOTE: https://github.com/ljharb/qs/security/advisories/GHSA-4mjr-xmp4-gh2g
 	NOTE: Fixed by: https://github.com/ljharb/qs/commit/e83d321ffafb38cf210683ac31714fce6ce1c6c6 (v6.16.0)
 CVE-2026-81766 (The Really Simple Security  WordPress plugin before 9.8.0 does not che ...)
@@ -153,6 +155,7 @@ CVE-2026-14307 (The geotargetingwp WordPress plugin before 3.5.6.2 does not sani
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82481 (The cohttp package before 6.3.0 for OCaml allows directory traversal.)
 	- ocaml-cohttp <unfixed> (bug #1146137)
+	[trixie] - ocaml-cohttp <no-dsa> (Minor issue)
 	NOTE: https://github.com/mirage/ocaml-cohttp/pull/1145 (6.3.0)
 CVE-2026-82477 (In MITRE SAF Heimdall 2.11.6 through 2.13.x before 2.14.0, an SSRF iss ...)
 	NOT-FOR-US: MITRE SAF Heimdall
@@ -162,6 +165,7 @@ CVE-2026-82475 (iFlytek astron-agent through 1.1.1 contains an authorization byp
 	NOT-FOR-US: iFlytek astron-agent
 CVE-2026-82474 (Sudo through 1.9.17p2 fails to apply intercept policy checks to the ex ...)
 	- sudo <unfixed> (bug #1146136)
+	[trixie] - sudo <no-dsa> (Minor issue)
 	NOTE: https://github.com/sudo-project/sudo/commit/71fbe42dcd5a1c8f799540583a2dfb2ae6221edf
 CVE-2026-82473 (KubeEdge CloudCore through 1.23.1 accepts node task status reports on  ...)
 	NOT-FOR-US: KubeEdge CloudCore
@@ -231,6 +235,7 @@ CVE-2026-14494 (The Sigma Forms Pro plugin for WordPress is vulnerable to Remote
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82343 (A flaw was found in the file-psd plugin in GIMP. When processing a spe ...)
 	- gimp <unfixed> (bug #1146135)
+	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16587
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/6b6a3e6d8ccdf2a7d6488d0df28ec033a9801a38
 CVE-2026-82333 (multer is a middleware for handling multipart/form-data in Node.js. A  ...)
@@ -462,6 +467,7 @@ CVE-2026-55634 (Pimcore is an Open Source Data & Experience Management Platform.
 	NOT-FOR-US: Pimcore
 CVE-2026-55584 (phpSysInfo is a customizable PHP script that displays system informati ...)
 	- phpsysinfo <unfixed>
+	[trixie] - phpsysinfo <no-dsa> (Minor issue)
 	NOTE: https://github.com/phpsysinfo/phpsysinfo/security/advisories/GHSA-786w-p5pm-cvgh
 	NOTE: https://github.com/phpsysinfo/phpsysinfo/commit/019fa2d7e568ea11461adb4bd33da5dc87c4b9ab (v3.4.6)
 CVE-2026-55569 (aqua is a declarative command-line version manager written in Go. Prio ...)
@@ -725,6 +731,7 @@ CVE-2026-82330 (A flaw was found in the file-pvr plugin in GIMP. When processing
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/ae584e9338774388db9705bd8ff5cb4bd308268a
 CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing a spe ...)
 	- gimp <unfixed> (bug #1146133)
+	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
 CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
@@ -732,9 +739,10 @@ CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library use
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
 	TODO: check upstream status, no references from Red Hat
 CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When proce ...)
-	- gimp <unfixed> (bug #1146132)
+	- gimp <unfixed> (bug #1146132; unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16584
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/2fba61f28efaebdc170e951e499e42820fbf633a
+	NOTE: Building of optional Plug-In for Amiga IFF/ILBM not enabled.
 CVE-2026-82261 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experime ...)
 	NOT-FOR-US: SvelteKit
 CVE-2026-82260 (SvelteKit (@sveltejs/kit) versions >=2.49.0 and <=2.52.1 with experime ...)
@@ -749,9 +757,11 @@ CVE-2026-82256 (SvelteKit before 2.69.1 fails to properly validate remote form f
 	NOT-FOR-US: SvelteKit
 CVE-2026-82255 (gitoxide versions from 0.25.4 contain an HTTP credential leak vulnerab ...)
 	- rust-gix-transport 0.57.0-1
+	[trixie] - rust-gix-transport <no-dsa> (Minor issue)
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-9857-6mw7-fq2m
 CVE-2026-82254 (gitoxide before 0.69.0 contains unchecked array indexing in delta appl ...)
 	- rust-gix-pack 0.70.0-1
+	[trixie] - rust-gix-pack <no-dsa> (Minor issue)
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-x494-mj8g-cj27
 CVE-2026-82253 (gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contai ...)
 	TODO: check
@@ -761,6 +771,7 @@ CVE-2026-82251 (gitoxide before 0.52.1 fails to validate submodule names from .g
 	TODO: check
 CVE-2026-82250 (gitoxide gix-packetline versions before 0.21.5 contain a panic vulnera ...)
 	- rust-gix-packetline 0.22.0-1
+	[trixie] - rust-gix-packetline <no-dsa> (Minor issue)
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-2vh6-hw4j-32ww
 CVE-2026-82249 (gitoxide before 0.38.2 fails to validate carriage return characters in ...)
 	TODO: check
@@ -768,6 +779,7 @@ CVE-2026-82248 (gix-worktree-state before 0.33.0 (part of gitoxide) allows writi
 	TODO: check
 CVE-2026-82247 (gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a hand-roll ...)
 	- rust-gix-url 0.37.1-1
+	[trixie] - rust-gix-url <no-dsa> (Minor issue)
 	- rust-gix-transport 0.58.1-1
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-jrcm-326h-gpp8
 CVE-2026-82246 (Budibase Server before 3.41.3 contains a server-side request forgery v ...)
@@ -985,6 +997,7 @@ CVE-2026-37237 (vLLM up to and including 0.17.0 allows remote attackers to cause
 	- vllm <itp> (bug #1095237)
 CVE-2026-37236 (grpc-gateway v2.28.0 is vulnerable to Incorrect Access Control. The ap ...)
 	- golang-github-grpc-ecosystem-grpc-gateway 2.30.0-1
+	[trixie] - golang-github-grpc-ecosystem-grpc-gateway <no-dsa> (Minor issue)
 	NOTE: https://github.com/grpc-ecosystem/grpc-gateway/commit/72123cd4f32545f6e1376873f412dcdcbcf29acc (v2.29.0)
 CVE-2026-33607 (An attacker that has valid credentials can use IMAP LIST command to co ...)
 	- dovecot <unfixed> (bug #1146018)
@@ -1016,6 +1029,7 @@ CVE-2026-18393 (A flaw was found in FFmpeg. The tdsc_load_cursor() function writ
 	TODO: check
 CVE-2026-15603 (morgan is an HTTP request logger middleware for Node.js. In versions p ...)
 	- node-morgan <unfixed>
+	[trixie] - node-morgan <no-dsa> (Minor issue)
 	NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-jxfw-x594-9x9m
 CVE-2026-14942
 	REJECTED
@@ -2175,6 +2189,7 @@ CVE-2026-10036 (SpeechBrain before 1.1.1 contains an arbitrary code execution vu
 	NOT-FOR-US: SpeechBrain
 CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG  ...)
 	- gdk-pixbuf <unfixed> (bug #1145988)
+	[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
 	NOTE: Introduced with: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/4af78023ce7d3b5e3cec422a59bb4f48fa4f5886 (2.43.4)
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/efe658674bd103d1c9bf50809d5767a3f6dd5a01
@@ -2197,6 +2212,7 @@ CVE-2026-81500
 	NOTE: https://github.com/lxc/incus/security/advisories/GHSA-9pqw-c7m4-xvg7
 CVE-2026-18374 (Passing an effectively empty string to the `,ccs=` syntax extension of ...)
 	- glibc <unfixed>
+	[trixie] - glibc <no-dsa> (Minor issue)
 	NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0015
 CVE-2026-81827 (Affected versions of Flowintel incorrectly attempted to validate login ...)
 	NOT-FOR-US: Flowintel
@@ -2856,6 +2872,7 @@ CVE-2026-79938 (Dell PowerProtect Cyber Recovery, versions prior to 20.3, contai
 	NOT-FOR-US: Dell / EMC
 CVE-2026-79921 (amqp091-go is a Go AMQP 0.9.1 client. Before version 1.13.0, a comprom ...)
 	- golang-github-rabbitmq-amqp091-go 1.14.0-1 (bug #1145982)
+	[trixie] - golang-github-rabbitmq-amqp091-go <no-dsa> (Minor issue)
 	NOTE: https://github.com/rabbitmq/amqp091-go/security/advisories/GHSA-6c5v-hqjr-5xxp
 	NOTE: https://github.com/rabbitmq/amqp091-go/pull/353
 	NOTE: Fixed by (merge): https://github.com/rabbitmq/amqp091-go/commit/6beb7b51f59e46ddcf8066ad498dad32491d3be0 (v1.13.0)
@@ -3161,18 +3178,22 @@ CVE-2025-70340 (A Broken Access Control vulnerability exists in ThingsBoard Prof
 	NOT-FOR-US: ThingsBoard
 CVE-2025-70293 (An issue was discovered in Denx U-Boot before 2026.04. An integer over ...)
 	- u-boot <unfixed>
+	[trixie] - u-boot <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
 	NOTE: https://source.denx.de/u-boot/u-boot/-/commit/fc16c847a1c9c6e0ee1f605849cc500a04c21602 (v2026.04-rc1)
 CVE-2025-70292
 	- u-boot <unfixed>
+	[trixie] - u-boot <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
 	NOTE: https://source.denx.de/u-boot/u-boot/-/commit/870aff99a279ed428c5a2560b2441b3079ddb34b (v2026.04-rc1)
 CVE-2025-70291
 	- u-boot <unfixed>
+	[trixie] - u-boot <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
 	NOTE: https://source.denx.de/u-boot/u-boot/-/commit/99416665f006b925db12f6c02b11f9da02c10c5a (v2026.04-rc1)
 CVE-2025-70290 (An issue was discovered in Denx U-Boot before 2026.04. An integer over ...)
 	- u-boot <unfixed>
+	[trixie] - u-boot <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/08/28/4
 	NOTE: https://source.denx.de/u-boot/u-boot/-/commit/c8f0294285f6588322363e1711bc57118e6fc9a3 (v2026.04-rc1)
 CVE-2025-62341 (HCL Connections is vulnerable to server-side request forgery (SSRF) wh ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -26,10 +26,14 @@ bouncycastle
 cacti
   probably best to move to 1.2.31
 --
+chromum (dilinger)
+--
 containerd
 --
 cups
 --
+dovecot
+--
 dulwich
 --
 firebird3.0
@@ -88,6 +92,8 @@ nodejs
 --
 node-dompurify
 --
+nsd
+--
 openexr
 --
 pacemaker
@@ -139,6 +145,8 @@ runc
 rust-wasmtime
   for CVE-2026-34987 CVE-2026-34971, rest would also be fine to ignore
 --
+sabnzbdplus
+--
 shaarli
 --
 sogo



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45b34d589d21a31ed64d71d73b03b95c54862fa1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/45b34d589d21a31ed64d71d73b03b95c54862fa1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260830/ef69e0ae/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list