[Git][security-tracker-team/security-tracker][master] 2 commits: mark CVE-2026-1642 as postponed for Bullseye

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sun Feb 8 00:04:19 GMT 2026



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d8b6f407 by Thorsten Alteholz at 2026-02-08T00:44:05+01:00
mark CVE-2026-1642 as postponed for Bullseye

- - - - -
18c911bf by Thorsten Alteholz at 2026-02-08T01:02:06+01:00
mark CVE-2026-2100 as not-affected for Bullseye, vulnerable code introduced in v0.25.6

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -240,6 +240,8 @@ CVE-2020-37079 (Wing FTP Server versions prior to 6.2.7 contain a cross-site req
 	NOT-FOR-US: Wing FTP Server
 CVE-2026-2100 [NULL dereference via C_DeriveKey with specific NULL parameters]
 	- p11-kit <unfixed>
+	[bullseye] - p11-kit <not-affected> (vulnerable code introduced in v0.25.6)
+	NOTE: Introduced by: https://github.com/p11-glue/p11-kit/commit/d7523b1031938fdd9740757f90e903aa09f5397d (0.25.6)
 	NOTE: Fixed by: https://github.com/p11-glue/p11-kit/commit/39f3b5ed3deccc2772e21ffb7d269329e3ecb600 (0.26.2)
 CVE-2026-2103 (Infor SyteLine ERP uses hard-coded static cryptographic keys to encryp ...)
 	NOT-FOR-US: Infor SyteLine ERP
@@ -1042,6 +1044,7 @@ CVE-2026-20056 (A vulnerability in the Dynamic Vectoring and Streaming (DVS) Eng
 	NOT-FOR-US: Cisco
 CVE-2026-1642 (A vulnerability exists in NGINX OSS and NGINX Plus when configured to  ...)
 	- nginx <unfixed> (bug #1127053)
+	[bullseye] - nginx <postponed> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/02/05/1
 	NOTE: https://my.f5.com/manage/s/article/K000159824
 	NOTE: Fixed by: https://github.com/nginx/nginx/commit/784fa05025cb8cd0c770f99bc79d2794b9f85b6e (release-1.28.2)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/51755976b19f274ea9dff64da3237d1c83479b67...18c911bf77b5b1166da3193b48976b3de472f5df

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/51755976b19f274ea9dff64da3237d1c83479b67...18c911bf77b5b1166da3193b48976b3de472f5df
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260208/ffcae55c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list