[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Aug 31 16:41:15 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
46c1b148 by Moritz Muehlenhoff at 2026-08-31T17:13:27+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -283,102 +283,123 @@ CVE-2026-40463 (WaveSuite is affected by an insufficient role-based access contr
NOT-FOR-US: Nokia
CVE-2026-18054
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/1f24066fc88d33455ee54a20f29994d9e69997ba (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/5fbd2fe1cc54259d045d00d4966aa2db1ba990d6 (v11.0.4)
CVE-2026-15264
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a113e0c53fb50d78529fd5ea79e3b8313a7ddcaa (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/7cd760867bdf753ac8d41c9567a1d36eb6d7aee8 (v11.0.4)
CVE-2026-17516
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4085
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/95687639e647ec917226e6d3a6713a2b373e1ffe (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/3ecb483c4c727d382b856c70f47ff54a68ce2bf5 (v11.0.4)
CVE-2026-65928
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3846
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/370882d0869567e5f21b95229a763171e319d0db (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e00b9c9193de00f5782cb919d91eb80d255017fe (v11.0.4)
CVE-2026-65929
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3844
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/0c43f801c0d7a31ef05bc22914cca0b0e28210a8 (v11.1.0-rc3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/ffe6640f445cf27513627e9295fa3de23b000261 (v11.0.4)
CVE-2026-50624
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3917
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/0be94d8d9c28e6b7235b34133d057090fe93be6c (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/88a0e5e45b41d407cf9adf1f2cf6f20f394a578d (v11.0.4)
CVE-2026-66022
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4073
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/df12999cc81339ffb252875608919c72ccc37bcd (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/5b105521527ec01dc7cf2f3834ddef935ab127f0 (v11.0.4)
CVE-2026-61402
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/733a98a552e4bd68932de1f58bd6ea39b57b261c (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/6680c5612401c1eaa49eba134d14d374fefeb9d4 (v11.0.4)
CVE-2026-63110
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/b9d248dfaca5e31377ea4f7204aae788a050bafd (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/82520d7759557062a5fae2211e3c79bbd5f01ed3 (v11.0.4)
CVE-2026-63323
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3938
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/5cc182ba39a3ca8ec9ba0576de9696be76dc087d (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a7f027cff81c8047707d574f0e4ec57e66c63452 (v11.0.4)
CVE-2026-61476
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3875
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/f404bf0e6504e0412a00ea64708f17d2a5e3f869 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a4abe1f1fa6f465b64fb400bea14c72bd5e32ac9 (v11.0.4)
CVE-2026-63320
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3626
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/772488562053c1299fc3667a49b3ff1858f83979 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/c159357f8c38cc4c64bacaebe8eeaf68af2a4b69 (v11.0.4)
CVE-2026-63321
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a6e0519ea8ed6fc84fab9bf9ca82c7a55780f880 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/52c7bb369b23dfcafb6e6d90665c777797b55e88 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/f348425fddae38e0c1d6823501890acfb2a3bfb1 (v11.0.4)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/9a06bb17256c0a38f0b53025bf804d2e2035f93f (v11.0.4)
CVE-2026-63322
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3607
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/4727cc883b7e81d2c30b9801af54482d65b84292 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/95b9a1bf26fef7c44f4925f78ade7fa824ed5e76 (v11.0.4)
CVE-2026-63109
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3989
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/861372428b05f74a1cf9a8af22a863aa7b46c7ce (v11.1.0-rc1)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/37cec1fe0e4e14385a19e3c13012e8b06387758a (v11.0.4)
CVE-2026-16288
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4039
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/bd9b3c50f458ce24fee084916cf0eba58bd9a33b (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/26d21226515b89a9039b168fd0511f1945fe8b72 (v11.0.4)
CVE-2026-61404
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/acba2d78176d8235b81fd886b37642ae6c464982 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d91e0141c52b0f39c8d0cb4b0f1cbb0d9aee6550 (v11.0.4)
CVE-2026-61405
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3890
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/8e0ddb4a6ebd1c3d2dfd067f82b6d92de5b23e30 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/a7d7f39ddb6abf4cec8e6eed94599065855137bd (v11.0.4)
CVE-2026-61406
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3899
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/647ba95eda5a21518f84c6593ed97e0447f38a90 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/550725189217c23b31de47d917135303981c1f7c (v11.0.4)
CVE-2026-58582
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3615
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/ff5a9eb13c862ed274ea0d0682a6573411e31543 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/db51779dc442cab2d95d64795b0cec64da4d47b2 (v11.0.4)
CVE-2026-58581
- qemu 1:11.1.0+ds-1
+ [trixie] - qemu <no-dsa> (Minor issue)
NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/3614
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/702216619e2a1afd5039520114f4d245d7011f09 (v11.1.0-rc2)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/e0397dbe1a295e037f16f154aaaa3cff3341fc3d (v11.0.4)
@@ -1065,6 +1086,7 @@ CVE-2026-82247 (gitoxide's gix-url crate (<= 0.32.0, fixed in 0.37.1) uses a han
- rust-gix-url 0.37.1-1
[trixie] - rust-gix-url <no-dsa> (Minor issue)
- rust-gix-transport 0.58.1-1
+ [trixie] - rust-gix-transport <no-dsa> (Minor issue)
NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-jrcm-326h-gpp8
CVE-2026-82246 (Budibase Server before 3.41.3 contains a server-side request forgery v ...)
NOT-FOR-US: Budibase
@@ -6330,6 +6352,7 @@ CVE-2026-15310 (When decompressing crafted zip files using the bzip/LZMA/Zstanda
- python3.15 <unfixed>
- python3.14 <unfixed>
- python3.13 <unfixed>
+ [trixie] - python3.13 <no-dsa> (Minor issue)
- python3.11 <removed>
- python3.9 <removed>
NOTE: https://mail.python.org/archives/list/security-announce@python.org/thread/YUHXURX2WZGKGNA4ANYBQS2VZRYQ5JNK/
@@ -6812,6 +6835,7 @@ CVE-2026-78378 (Ransomlook contains a Redis glob pattern injection vulnerability
NOT-FOR-US: RansomLook
CVE-2026-78376 (A flaw was found in WebKitGTK. Processing malicious web content can ca ...)
- webkit2gtk <unfixed>
+ [trixie] - webkit2gtk <postponed> (Fix along with future DSA)
[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
[bullseye] - webkit2gtk <end-of-life> (EOL in bullseye)
- wpewebkit <unfixed>
=====================================
data/dsa-needed.txt
=====================================
@@ -26,7 +26,7 @@ bouncycastle
cacti
probably best to move to 1.2.31
--
-chromum (dilinger)
+chromium (dilinger)
--
containerd
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/46c1b14867605cfc40e1c32f6280965bca350248
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/46c1b14867605cfc40e1c32f6280965bca350248
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/93ea482f/attachment.htm>
More information about the debian-security-tracker-commits
mailing list