[Git][security-tracker-team/security-tracker][master] 3 commits: CVE-2026-60103/blender: bookworm,bullseye postponed
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Wed Jul 15 06:56:03 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
31a41dd6 by Sylvain Beucler at 2026-07-15T07:55:48+02:00
CVE-2026-60103/blender: bookworm,bullseye postponed
- - - - -
9b3b264a by Sylvain Beucler at 2026-07-15T07:55:50+02:00
CVE-2026-12725,CVE-2026-12969/dnsmasq: bookworm,bullseye postponed
- - - - -
befba73a by Sylvain Beucler at 2026-07-15T07:55:53+02:00
CVE-2026-11623/tmux: bookworm,bullseye not-affected
(trixie probably neither, cf. possible introductory commit at https://ubuntu.com/security/CVE-2026-11623 )
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -329,6 +329,8 @@ CVE-2026-60121 (Vitec Flamingo 4.12.2 contains an unauthenticated OS command inj
CVE-2026-60103 (Blender 3.0.0 through 5.1.2 contains an out-of-bounds read vulnerabili ...)
- blender <unfixed>
[trixie] - blender <no-dsa> (Minor issue)
+ [bookworm] - blender <postponed> (Minor issue, OOB read)
+ [bullseye] - blender <postponed> (Minor issue, OOB read)
NOTE: https://projects.blender.org/blender/blender/pulls/161273
NOTE: Fixed by: https://projects.blender.org/blender/blender/commit/968972a918b5ed2d534295b639c54449d7de11cd
CVE-2026-59523 (Missing Authorization vulnerability in NSquared Simply Schedule Appoin ...)
@@ -15596,6 +15598,8 @@ CVE-2026-13007 (Tenable Identity Exposure contains multiple unauthenticated API
CVE-2026-12969 (An out-of-bounds read vulnerability exists in dnsmasq's find_soa() fun ...)
- dnsmasq 2.93-1
[trixie] - dnsmasq <no-dsa> (Minor issue)
+ [bookworm] - dnsmasq <postponed> (Minor issue)
+ [bullseye] - dnsmasq <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2491663
NOTE: Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=14094e88beca519c53151184cc4553656672b54f (v2.93rc1)
CVE-2026-12958 (Missing symlink validation in Language Servers for AWS may allow an ar ...)
@@ -16318,6 +16322,8 @@ CVE-2026-12862 (Untrusted user data was passed verbatim to Excel exports for adm
CVE-2026-12725 (A heap-based buffer overflow was found in dnsmasq. When DNSSEC validat ...)
- dnsmasq 2.93-1
[trixie] - dnsmasq <no-dsa> (Minor issue)
+ [bookworm] - dnsmasq <postponed> (Minor issue)
+ [bullseye] - dnsmasq <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2490763
NOTE: Fixed by: https://thekelleys.org.uk/gitweb/?p=dnsmasq.git;a=commit;h=36d081e37477027fd721fea498f3760f529034ad (v2.93test10)
CVE-2026-12628 (IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Pro ...)
@@ -24374,9 +24380,11 @@ CVE-2026-24315 (SAP Fiori Launchpad allows attackers to craft malicious URLs tha
CVE-2026-11623 (A security vulnerability has been detected in tmux up to 3.6a. Affecte ...)
- tmux 3.6b-1 (bug #1140487)
[trixie] - tmux <no-dsa> (Minor issue)
- [bullseye] - tmux <postponed> (minor issue; hard to exploit)
+ [bookworm] - tmux <not-affected> (SIXEL support introduced in v3.4)
+ [bullseye] - tmux <not-affected> (SIXEL support introduced in v3.4)
NOTE: Fixed by: https://github.com/tmux/tmux/commit/fc6d94a9f8a593bd8b7031650802084385d4ee03 (3.7)
NOTE: Fixed by: https://github.com/tmux/tmux/commit/b8434182c9ead062be8d50a1ff88e98b41108c1f (3.6b)
+ NOTE: https://gist.github.com/XlabAITeam/f0d9952595f795129a3258ba73bbc3cb
CVE-2026-11621 (A weakness has been identified in Dcat-Admin up to 2.2.3-beta. This im ...)
NOT-FOR-US: Dcat-Admin
CVE-2026-11620 (A security flaw has been discovered in TOTOLINK EX200 4.0.3c.7646. Thi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/082c7270ec24861f176297e81391971ac24bfbe8...befba73ad7ae4374e014225d08eb113d16617e85
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/082c7270ec24861f176297e81391971ac24bfbe8...befba73ad7ae4374e014225d08eb113d16617e85
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260715/75b6b1f1/attachment.htm>
More information about the debian-security-tracker-commits
mailing list