[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 23 13:20:44 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
31ad5020 by Salvatore Bonaccorso at 2026-07-23T14:19:19+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -284,19 +284,19 @@ CVE-2026-46738 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, cont
 CVE-2026-46737 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-45820 (fflate through 0.8.2 is vulnerable to denial of service via an infinit ...)
-	TODO: check
+	NOT-FOR-US: fflate
 CVE-2026-44276 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-44192 (A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP ...)
-	TODO: check
+	NOT-FOR-US: Ansible Lightspeed Model Context Protocol (MCP) server
 CVE-2026-44191 (A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ...)
-	TODO: check
+	NOT-FOR-US: Visual Studio Code Ansible Lightspeed extension
 CVE-2026-44190 (A flaw was found in the Ansible Lightspeed Visual Studio Code extensio ...)
-	TODO: check
+	NOT-FOR-US: Visual Studio Code Ansible Lightspeed extension
 CVE-2026-44189 (A flaw was found in the Visual Studio Code Ansible Lightspeed extensio ...)
-	TODO: check
+	NOT-FOR-US: Visual Studio Code Ansible Lightspeed extension
 CVE-2026-44187 (A flaw was found in the Ansible Lightspeed extension for Visual Studio ...)
-	TODO: check
+	NOT-FOR-US: Visual Studio Code Ansible Lightspeed extension
 CVE-2026-40714 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
 	NOT-FOR-US: Dell / EMC
 CVE-2026-40712 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) ...)
@@ -2878,19 +2878,19 @@ CVE-2026-46876 (Vulnerability in Oracle Application Testing Suite.   The support
 CVE-2026-46600 (Parsing an invalid SVCB or HTTPS RR can panic when the size of a param ...)
 	TODO: check
 CVE-2026-46556 (FlaskBB is a Forum Software written in Python using the micro framewor ...)
-	TODO: check
+	NOT-FOR-US: FlaskBB
 CVE-2026-46403 (Klever-Go is the Go implementation of the Klever blockchain protocol.  ...)
-	TODO: check
+	NOT-FOR-US: Klever-Go
 CVE-2026-44879 (A vulnerability in the command line interface of ECOS devices could al ...)
 	NOT-FOR-US: HPE
 CVE-2026-44878 (A vulnerability in the web-based management interface of an ECOS devic ...)
 	NOT-FOR-US: HPE
 CVE-2026-43947 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-43946 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-43945 (FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) softwa ...)
-	TODO: check
+	NOT-FOR-US: FUXA
 CVE-2026-42397 (Allocation of Resources Without Limits or Throttling (CWE-770) in Kiba ...)
 	TODO: check
 CVE-2026-3821 (Supermicro (SMC) SMASH services contain an Arbitrary code execution is ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31ad5020fee69b9d51c2796a3c07a032c542ff1e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/31ad5020fee69b9d51c2796a3c07a032c542ff1e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/4510f0f6/attachment.htm>


More information about the debian-security-tracker-commits mailing list