[Git][security-tracker-team/security-tracker][master] 8 commits: Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Jul 23 15:06:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ba5eacaa by Salvatore Bonaccorso at 2026-07-23T16:03:48+02:00
Process some NFUs

- - - - -
8bed17f3 by Salvatore Bonaccorso at 2026-07-23T16:04:09+02:00
Add new librest issue

- - - - -
620b387d by Salvatore Bonaccorso at 2026-07-23T16:04:22+02:00
Add new 389-ds-base issue

- - - - -
c38ad973 by Salvatore Bonaccorso at 2026-07-23T16:04:36+02:00
Add new systemd issue

- - - - -
66fd116a by Salvatore Bonaccorso at 2026-07-23T16:04:48+02:00
Add sbc issue, CVE-2026-16473

- - - - -
b07001e2 by Salvatore Bonaccorso at 2026-07-23T16:05:03+02:00
Add new duplicati issue, itp'ed

- - - - -
9a5ef793 by Salvatore Bonaccorso at 2026-07-23T16:05:16+02:00
Add new libarchive issue

- - - - -
a03cb112 by Salvatore Bonaccorso at 2026-07-23T16:05:30+02:00
Add new libsoup issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -72,25 +72,25 @@ CVE-2026-60366 (Vulnerability in the Oracle Platform Security for Java product o
 CVE-2026-59676 (A Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability in s ...)
 	TODO: check
 CVE-2026-38766 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
-	TODO: check
+	NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
 CVE-2026-38765 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
-	TODO: check
+	NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
 CVE-2026-38763 (An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a l ...)
-	TODO: check
+	NOT-FOR-US: Unistal Systems Pvt. Ltd.Protegent 360
 CVE-2026-21723 (The alertmanager templates test endpoint (/api/alertmanager/grafana/co ...)
 	NOT-FOR-US: Grafana Labs
 CVE-2026-16653 (A security flaw has been discovered in boazsegev facil.io up to 0.7.58 ...)
-	TODO: check
+	NOT-FOR-US: boazsegev facil.io
 CVE-2026-16632 (A flaw has been found in boazsegev facil.io up to 0.7.4. Affected is t ...)
-	TODO: check
+	NOT-FOR-US: boazsegev facil.io
 CVE-2026-16631 (A vulnerability was detected in publint up to 0.1.4. This impacts the  ...)
-	TODO: check
+	NOT-FOR-US: publint
 CVE-2026-16630 (A security vulnerability has been detected in syncfusion ej2-javascrip ...)
-	TODO: check
+	NOT-FOR-US: syncfusion ej2-javascript-ui-controls
 CVE-2026-16629 (A vulnerability was identified in danger danger-js up to 13.0.7. Impac ...)
-	TODO: check
+	NOT-FOR-US: danger danger-js
 CVE-2026-16628 (A vulnerability was detected in oclif up to 4.23.16. Affected by this  ...)
-	TODO: check
+	NOT-FOR-US: oclif
 CVE-2026-15074 (@fastify/static up to and including version 10.1.0 fails to reject dot ...)
 	TODO: check
 CVE-2026-14899 (The code to parse MIME headers for display when forwarding a message ( ...)
@@ -100,7 +100,7 @@ CVE-2026-14881 (When importing connections in Compass it is possible to override
 CVE-2026-14291 (The security-ninja-premium WordPress plugin before 5.290 does not veri ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-13089 (OIDC::Lite versions through 0.12.1 for Perl allow ID Token signature v ...)
-	TODO: check
+	NOT-FOR-US: OIDC::Lite Perl module
 CVE-2026-13078 (A vulnerability was discovered in MongoDB Server where the server-side ...)
 	TODO: check
 CVE-2026-13077 (A missing bounds check in the BSON CodeWScope element accessors allows ...)
@@ -304,35 +304,40 @@ CVE-2026-40712 (Dell PowerProtect Data Manager, versions prior to 20.2.0.0, cont
 CVE-2026-3482 (IBM Sterling B2B Integrator and IBM Sterling File Gateway6.2.0.0 throu ...)
 	NOT-FOR-US: IBM
 CVE-2026-2406 (Authorization bypass through User-Controlled key vulnerability in Univ ...)
-	TODO: check
+	NOT-FOR-US: Online Registration and Workflow Management System
 CVE-2026-2395 (Improper neutralization of special elements used in an SQL command ('S ...)
-	TODO: check
+	NOT-FOR-US: No Code Platform
 CVE-2026-22049 (ONTAP versions 9.16.1 and higher with WebAuthn multi-factor authentica ...)
 	NOT-FOR-US: NetApp
 CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId creation, allo ...)
-	TODO: check
+	NOT-FOR-US: Cal.com OSS
 CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth authori ...)
-	TODO: check
+	- librest <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2504432
+	NOTE: https://gitlab.gnome.org/GNOME/librest/-/issues/25
 CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
-	TODO: check
+	NOT-FOR-US: Fujitsu
 CVE-2026-16606 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
-	TODO: check
+	NOT-FOR-US: Fujitsu
 CVE-2026-16560 (A heap-buffer-overflow flaw was found in Directory Server (389-ds-base ...)
-	TODO: check
+	- 389-ds-base <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506102
 CVE-2026-16552 (A flaw was found in systemd-tmpfiles. When processing a tmpfiles.d con ...)
-	TODO: check
+	- systemd <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506073
 CVE-2026-16551 (Denial-of-Service in Thinkst Applied Research OpenCanary (MongoDB modu ...)
-	TODO: check
+	NOT-FOR-US: Thinkst Applied Research OpenCanary (MongoDB module)
 CVE-2026-16544 (A flaw was found in AWX. The websocket event consumer performs RBAC au ...)
-	TODO: check
+	NOT-FOR-US: Ansible Tower
 CVE-2026-16473 (A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one e ...)
-	TODO: check
+	- sbc <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2503650
 CVE-2026-16270 (Open Mercato does not validate regex rules. An attacker with privilege ...)
-	TODO: check
+	NOT-FOR-US: Open Mercato
 CVE-2026-16232 (An authentication bypass vulnerability in the Check Point SmartConsole ...)
-	TODO: check
+	NOT-FOR-US: Check Point
 CVE-2026-16157 (Duplicati v2.3.0.1 backup software gives Authenticated Users MODIFY pe ...)
-	TODO: check
+	- duplicati <itp> (bug #969188)
 CVE-2026-15787 (The Ultimate Addons for Elementor plugin for WordPress is vulnerable t ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-14985 (The Analog Way Picturall Quad Compact Mark II version 3.5.8, contains  ...)
@@ -2904,31 +2909,35 @@ CVE-2026-42397 (Allocation of Resources Without Limits or Throttling (CWE-770) i
 CVE-2026-3821 (Supermicro (SMC) SMASH services contain an Arbitrary code execution is ...)
 	NOT-FOR-US: Supermicro
 CVE-2026-35290 (Vulnerability in Oracle Application Testing Suite.   The supported ver ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-35287 (Vulnerability in Oracle Application Testing Suite.   The supported ver ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-34316 (Vulnerability in the Oracle Commerce Service Center product of Oracle  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-30633 (Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via craf ...)
-	TODO: check
+	NOT-FOR-US: knowns-dev/knowns
 CVE-2026-30632 (Directory traversal vulnerability in knowns-dev/knowns 0.11.4 via craf ...)
-	TODO: check
+	NOT-FOR-US: knowns-dev/knowns
 CVE-2026-30631 (An issue was discovered in bytebot-ai in commit 3d37894ce07ef8d8b40adc ...)
-	TODO: check
+	NOT-FOR-US: bytebot-ai
 CVE-2026-21954 (Vulnerability in the Oracle Retail Xstore Point of Service product of  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-21953 (Vulnerability in the Oracle Retail Xstore Point of Service product of  ...)
-	TODO: check
+	NOT-FOR-US: Oracle
 CVE-2026-16517 (A signed integer overflow vulnerability was found in libarchive's ZIP  ...)
-	TODO: check
+	- libarchive <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2505492
+	NOTE: https://github.com/libarchive/libarchive/issues/3225
+	NOTE: https://github.com/libarchive/libarchive/pull/3228
+	NOTE: Fixed by: https://github.com/libarchive/libarchive/commit/1c6e7b491f60fce335c20a9692f870d1f1ca39aa
 CVE-2026-16492 (A weakness has been identified in umijs umi up to 4.6.63. The affected ...)
-	TODO: check
+	NOT-FOR-US: umijs umi
 CVE-2026-16490 (A security flaw has been discovered in itsourcecode Hospital Managemen ...)
 	NOT-FOR-US: itsourcecode System
 CVE-2026-16489 (A vulnerability was identified in jsforce up to 3.10.16. This issue af ...)
-	TODO: check
+	NOT-FOR-US: jsforce
 CVE-2026-16488 (A vulnerability was determined in QUSETIONS MiniCode-Python 0.1.0. Thi ...)
-	TODO: check
+	NOT-FOR-US: QUSETIONS MiniCode-Python
 CVE-2026-16486 (A vulnerability was found in SourceCodester Class and Exam Timetabling ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-16485 (A vulnerability has been found in SourceCodester Class and Exam Timeta ...)
@@ -10810,15 +10819,30 @@ CVE-2026-15720 (InOpen5GS through version 2.7.7 a pre-authenticationheap out-of-
 CVE-2026-15715 (A vulnerability was identified in SourceCodester Class and Exam Timeta ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-15714 (An out-of-bounds read vulnerability was found in libsoup's multipart p ...)
-	TODO: check
+	- libsoup3 <unfixed>
+	- libsoup2.4 <removed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499942
+	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/542
 CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implementation. ...)
-	TODO: check
+	- libsoup3 <unfixed>
+	- libsoup2.4 <removed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499941
+	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/541
 CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in libsoup's (ver ...)
-	TODO: check
+	- libsoup3 <unfixed>
+	- libsoup2.4 <removed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499939
+	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540
 CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing impleme ...)
-	TODO: check
+	- libsoup3 <unfixed>
+	- libsoup2.4 <removed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499924
+	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/515
 CVE-2026-15709 (A flaw was found in libsoup's WebSocket implementation when using the  ...)
-	TODO: check
+	- libsoup3 <unfixed>
+	- libsoup2.4 <removed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499922
+	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/511
 CVE-2026-15703 (A vulnerability was detected in SourceCodester Simple and Nice Shoppin ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-15702 (A security vulnerability has been detected in tamagui up to 2.3.0. Thi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ed7793a9745ce2ccfbf939d33f2c1d5eca7bfd5f...a03cb112b7789afadfa97e1dc924cf577de5e781

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ed7793a9745ce2ccfbf939d33f2c1d5eca7bfd5f...a03cb112b7789afadfa97e1dc924cf577de5e781
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260723/3a3f0dfb/attachment.htm>


More information about the debian-security-tracker-commits mailing list