[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various CVEs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 24 14:44:14 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
78cc2705 by Salvatore Bonaccorso at 2026-07-24T15:43:32+02:00
Add Debian bug references for various CVEs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1177,7 +1177,7 @@ CVE-2026-22049 (ONTAP versions 9.16.1 and higher with WebAuthn multi-factor auth
CVE-2026-16624 (Cal.com OSS ships lacks authorization on webhook teamId creation, allo ...)
NOT-FOR-US: Cal.com OSS
CVE-2026-16615 (A flaw was found in librest. The PKCE implementation for OAuth authori ...)
- - librest <unfixed>
+ - librest <unfixed> (bug #1142715)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2504432
NOTE: https://gitlab.gnome.org/GNOME/librest/-/issues/25
CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
@@ -4216,7 +4216,7 @@ CVE-2026-16493 (A flaw was found in ansible-core. The _extract_collection_from_g
NOTE: Issue exists due to an incomplete fix for CVE-2026-11332
TODO: check upstream details
CVE-2026-16461 (A stack-based buffer overflow was found in rpcbind's rpcinfo utility. ...)
- - rpcbind <unfixed>
+ - rpcbind <unfixed> (bug #1142716)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502719
CVE-2026-16454 (InEclipse hawkBitversions 1.0.3 and prior, a privilege escalation vuln ...)
TODO: check
@@ -5236,7 +5236,7 @@ CVE-2026-64187 (In the Linux kernel, the following vulnerability has been resolv
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/2094dab19d45c487285617b7b68913d0cc0c1211 (7.2-rc4)
CVE-2026-13577 (Dancer2 versions through 2.1.0 for Perl generate insecure session ids ...)
- - libdancer2-perl <unfixed>
+ - libdancer2-perl <unfixed> (bug #1142718)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/41975698/
CVE-2026-9833 (The Tag Groups is the Advanced Way to Display Your Taxonomy Terms Word ...)
NOT-FOR-US: WordPress plugin
@@ -8154,7 +8154,7 @@ CVE-2026-42168 (django-pyas2 through 1.2.3 is vulnerable to OS command injection
CVE-2026-36669 (An unauthenticated arbitrary file upload vulnerability in ck_upload_ha ...)
NOT-FOR-US: Feng Office
CVE-2026-16118 (A flaw was found in xdgmime. A heap-based buffer overflow can be trigg ...)
- - glib2.0 <unfixed>
+ - glib2.0 <unfixed> (bug #1142717)
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/3992
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2501732
NOTE: https://gitlab.freedesktop.org/xdg/xdgmime/-/work_items/41
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/78cc27057e37b412876a00516b2f158011a96196
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/78cc27057e37b412876a00516b2f158011a96196
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260724/e9f48910/attachment.htm>
More information about the debian-security-tracker-commits
mailing list