[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Aug 30 21:44:59 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5002e994 by Moritz Muehlenhoff at 2026-08-30T22:44:05+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -736,6 +736,7 @@ CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
 CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
 	- libsolv <unfixed>
+	[trixie] - libsolv <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
 	TODO: check upstream status, no references from Red Hat
 CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When proce ...)
@@ -2482,6 +2483,7 @@ CVE-2026-78002 (A flaw was found in rsyslog. An unauthenticated remote attacker
 	NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-g72f-gc6v-f2w3
 	NOTE: https://github.com/rsyslog/rsyslog/pull/7525
 	NOTE: https://github.com/rsyslog/rsyslog/commit/667e3f61aec5ee02c5c2ee6f0f8accf6fe4301a9
+	NOTE: https://www.openwall.com/lists/oss-security/2026/08/29/1
 CVE-2026-75871 (GitLab has remediated a vulnerability in the GitLab AI Gateway compone ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-75573 (In MongoDB Connector for BI, mongodrdl may write a TLS private-key pas ...)
@@ -5270,6 +5272,7 @@ CVE-2026-55805 (Improper Neutralization of Input During Web Page Generation ("Cr
 	NOT-FOR-US: Drupal core and addons
 CVE-2026-55588 (ORAS (OCI Registry As Storage) is a CLI and library for managing artif ...)
 	- oras 1.3.3-1
+	[trixie] - oras <no-dsa> (Minor issue)
 	NOTE: https://github.com/oras-project/oras/security/advisories/GHSA-298f-872v-2rcx
 	NOTE: Fixed by: https://github.com/oras-project/oras/commit/440eb65d07a0631f131944d28e7c29d562ec17f3 (v1.3.3)
 CVE-2026-54757 (Compliance-trestle (Trestle) is a Python SDK and command-line tool for ...)
@@ -5412,6 +5415,7 @@ CVE-2026-80182 (In OpenStack Keystone before 29.0.3, tokens obtained via OAuth1
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2153453
 CVE-2026-19499
 	- glibc <unfixed> (bug #1145891)
+	[trixie] - glibc <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2523258
 	NOTE: https://sourceware.org/bugzilla/show_bug.cgi?id=34510
 CVE-2026-80051 (github.com/graphql-go/graphql (GraphQL for Go) through 0.8.1 does not  ...)
@@ -13483,7 +13487,7 @@ CVE-2026-75911 (CodeWhale versions before 0.8.64 fail to properly validate the a
 	NOT-FOR-US: CodeWhale
 CVE-2026-75904 (libmodplug through 0.8.9.1 contains an out-of-bounds read in pat_smplo ...)
 	- libmodplug 1:0.8.9.0-4 (bug #1144933)
-	[trixie] - libmodplug <postponed> (Minor issue, revisit when fixed upstream)
+	[trixie] - libmodplug <no-dsa> (Minor issue)
 	NOTE: https://github.com/Konstanty/libmodplug/issues/103
 CVE-2026-75898 (RAGFlow before 0.26.3 contains a server-side request forgery vulnerabi ...)
 	NOT-FOR-US: RAGFlow
@@ -15076,6 +15080,7 @@ CVE-2026-73851 (Kiota is an OpenAPI based HTTP Client code generator. Prior to 1
 	NOT-FOR-US: Kiota
 CVE-2026-73646 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
 	- node-postcss 8.5.19+~cs10.2.23-1
+	[trixie] - node-postcss <no-dsa> (Minor issue)
 	NOTE: https://github.com/postcss/postcss/security/advisories/GHSA-r28c-9q8g-f849
 	NOTE: Fixed by: https://github.com/postcss/postcss/commit/95663d3eb7ba26f4854dd19d3b4f4425760cf56c (8.5.18)
 CVE-2026-73523 (COVESA Open1722 through 0.9.2 contains an integer truncation vulnerabi ...)
@@ -23632,6 +23637,7 @@ CVE-2026-48813 (Flawfinder is a a static analysis tool for finding vulnerabiliti
 	NOT-FOR-US: Flawfinder
 CVE-2026-48804 (python-socketio is a Python implementation of the Socket.IO realtime c ...)
 	- python-engineio <unfixed> (bug #1144515)
+	[trixie] - python-engineio <no-dsa> (Minor issue)
 	NOTE: https://github.com/miguelgrinberg/python-socketio/security/advisories/GHSA-5w7q-77mv-v69f
 	NOTE: Fixed by: https://github.com/miguelgrinberg/python-socketio/commit/4bec3ef87bcfd6ab5b94cd3ac09d873283a6960e (v5.16.4)
 CVE-2026-48765 (TypeBot is a chatbot builder tool. Versions prior to 3.17.0 allow a lo ...)
@@ -25195,10 +25201,12 @@ CVE-2026-49179 (Improper neutralization of special elements used in a command ('
 	NOT-FOR-US: Microsoft
 CVE-2026-48809 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
 	- python-engineio <unfixed> (bug #1144516)
+	[trixie] - python-engineio <no-dsa> (Minor issue)
 	NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-m9gh-vj53-gvh9
 	TODO: checking upstream commit fixing issue, confusing infomation advisory claims both 4.13.2 and 4.13.5 to fix issue
 CVE-2026-48802 (python-engineio is a Python implementation of the Engine.IO realtime c ...)
 	- python-engineio <unfixed> (bug #1144517)
+	[trixie] - python-engineio <no-dsa> (Minor issue)
 	NOTE: https://github.com/miguelgrinberg/python-engineio/security/advisories/GHSA-cgwc-pv48-fhj5
 CVE-2026-48790 (Turso CLI is the command line interface (CLI) to the open-source datab ...)
 	NOT-FOR-US: Turso CLI
@@ -29215,6 +29223,7 @@ CVE-2026-58262 (Klever-Go is the Go implementation of the Klever blockchain prot
 	NOT-FOR-US: Klever-Go
 CVE-2026-54338 (JupyterHub is software that allows users to create a multi-user server ...)
 	- jupyterhub <unfixed> (bug #1143967)
+	[trixie] - jupyterhub <no-dsa> (Minor issue)
 	NOTE: https://github.com/jupyterhub/jupyterhub/security/advisories/GHSA-p43p-whwx-q52h
 	NOTE: Fixed by: https://github.com/jupyterhub/jupyterhub/commit/d6dc595f84b7509969686da31d87d6d69e7fce0a (5.5.0)
 CVE-2026-52880 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
@@ -52166,6 +52175,7 @@ CVE-2026-59205 (Pillow is a Python imaging library. Prior to 12.3.0, Pillow's Im
 	NOTE: Fixed by: https://github.com/python-pillow/Pillow/commit/a9ffc42bedf4fc0a7ef8d6486e7f9e81e3397721 (12.3.0)
 CVE-2026-59204 (Pillow is a Python imaging library. From 8.2.0 through 12.2.0, src/lib ...)
 	- pillow 12.3.0-1 (bug #1142274)
+	[trixie] - pillow <no-dsa> (Minor issue)
 	[bookworm] - pillow <postponed> (Minor issue, DoS)
 	[bullseye] - pillow <ignored> (JPEG2000 support not built)
 	NOTE: https://github.com/python-pillow/Pillow/security/advisories/GHSA-vjc4-5qp5-m44j
@@ -56578,6 +56588,7 @@ CVE-2026-12593 (The implementation of an internalandundocumentedDashboardAPI end
 	NOT-FOR-US: QT Axivion
 CVE-2026-12590 (Impact: In body-parser versions prior to 1.20.6 (1.x line) and 2.3.0 ( ...)
 	- node-body-parser 2.3.0+~1.19.6-1 (bug #1143074)
+	[trixie] - node-body-parser <no-dsa> (Minor issue)
 	NOTE: https://github.com/expressjs/body-parser/security/advisories/GHSA-v422-hmwv-36x6
 	NOTE: https://github.com/expressjs/body-parser/pull/698
 	NOTE: Fixed by: https://github.com/expressjs/body-parser/commit/2322e111cc321413ec2b7b76d01be533d3de9d7d (v2.3.0)


=====================================
data/dsa-needed.txt
=====================================
@@ -62,7 +62,7 @@ jupyterlab
 --
 kamailio
 --
-keystone
+keystone (jmm)
 --
 kitty
 --
@@ -116,6 +116,8 @@ py7zr
 python-authlib
   possibly move trixie to 1.6.12
 --
+python-django
+--
 python-git
 --
 python-msgpack



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5002e9949dc4a577dfba6ba82c2cad62dc64c172

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5002e9949dc4a577dfba6ba82c2cad62dc64c172
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260830/37c52f4f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list