[Git][security-tracker-team/security-tracker][master] Add some Debian bug references for reported CVEs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 22:30:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eed1b04e by Salvatore Bonaccorso at 2026-07-26T23:29:07+02:00
Add some Debian bug references for reported CVEs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1396,17 +1396,17 @@ CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated a
 	NOTE: fixed by: https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 (6.2.23)
 	NOTE: Issue exists because of an incomplete fix for CVE-2026-25243.
 CVE-2026-66339 (A flaw was found in libsoup. After a CONNECT tunnel is established thr ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142846)
 	- libsoup2.4 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506951
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/534
 CVE-2026-66338 (A flaw was found in libsoup. The chunked transfer encoding parser uses ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142845)
 	- libsoup2.4 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506950
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/533
 CVE-2026-66337 (A flaw was found in libsoup. An unsigned integer underflow in the soup ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142844)
 	- libsoup2.4 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506949
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/532
@@ -1484,19 +1484,19 @@ CVE-2026-66143 (It is possible to bypass themaximum number of normalized policy
 CVE-2026-66142 (Apache Neethi is vulnerable to uncontrolled recursion when parsing pol ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-66035 (libssh2 through 1.11.1, fixed in commit 42e33d8, contains a pre-authen ...)
-	- libssh2 <unfixed>
+	- libssh2 <unfixed> (bug #1142856)
 	NOTE: https://github.com/libssh2/libssh2/pull/2198
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/42e33d81577ed4b95d4b4f6f845e5ee8efe5eeb4
 CVE-2026-66034 (libssh2 through 1.11.1, fixed in commit a13bb6c, contains a missing bo ...)
-	- libssh2 <unfixed>
+	- libssh2 <unfixed> (bug #1142856)
 	NOTE: https://github.com/libssh2/libssh2/pull/2202
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a13bb6c773f0d55ad1628cede57e99803cd898d9
 CVE-2026-66033 (libssh2 through 1.11.1, fixed in commit a2ed82d, contains a pre-authen ...)
-	- libssh2 <unfixed>
+	- libssh2 <unfixed> (bug #1142856)
 	NOTE: https://github.com/libssh2/libssh2/pull/2401
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/a2ed82d40964bbc0d64cd717aa0a5a892117d2e6
 CVE-2026-66032 (libssh2 through 1.11.1, fixed in commit 5e47761, contains a double-fre ...)
-	- libssh2 <unfixed>
+	- libssh2 <unfixed> (bug #1142856)
 	NOTE: https://github.com/libssh2/libssh2/pull/2180
 	NOTE: Fixed by: https://github.com/libssh2/libssh2/commit/5e4776146552d898b9c0e1b313cd093fa8dc92d0
 CVE-2026-66027 (Suna before 0.9.102 contains a broken access control vulnerability in  ...)
@@ -1799,7 +1799,7 @@ CVE-2026-64208 (In the Linux kernel, the following vulnerability has been resolv
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/2b50aceafe6606ea52ed42aadd1b4d44a188aade (7.1-rc5)
 CVE-2026-63317 (Arbitrary Class Instantiation via XML Feature Generator Descriptor and ...)
-	- apache-opennlp <unfixed>
+	- apache-opennlp <unfixed> (bug #1142855)
 	NOTE: https://lists.apache.org/thread/myr446n8t3gv8gq8wbpxm41olx16d8yj
 	NOTE: https://issues.apache.org/jira/browse/OPENNLP-1890
 CVE-2026-58630 (Improper access control in Azure App Service allows an unauthorized at ...)
@@ -1895,7 +1895,7 @@ CVE-2026-16743 (A flaw was found in accountsservice. The systemd-homed code path
 	NOTE: https://gitlab.freedesktop.org/accountsservice/accountsservice/-/work_items/138
 	NOTE: https://gitlab.freedesktop.org/accountsservice/accountsservice/-/merge_requests/182 (26.26.9)
 CVE-2026-16730 (A flaw was found in dbus-broker. When the process file-descriptor limi ...)
-	- dbus-broker <unfixed>
+	- dbus-broker <unfixed> (bug #1142850)
 	NOTE: https://github.com/bus1/dbus-broker/issues/435
 CVE-2026-16519 (A DLL hijacking vulnerability exists in the GeoVision GV-IP Device Uti ...)
 	NOT-FOR-US: GeoVision
@@ -1952,11 +1952,11 @@ CVE-2026-6924 (A bug in the entropy initialization for SiWx917 causes the DRBG t
 CVE-2026-6454 (The Firelight Lightbox plugin for WordPress is vulnerable to Stored DO ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-66139 (OpenStack Zaqar through 22.0.0 allows authentication bypass via an EXT ...)
-	- zaqar <unfixed>
+	- zaqar <unfixed> (bug #1142858)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/7
 	NOTE: https://launchpad.net/bugs/2161254
 CVE-2026-66138 (In OpenStack Ironic Python Agent through 11.6.0, aproject-scoped user  ...)
-	- ironic-python-agent <unfixed>
+	- ironic-python-agent <unfixed> (bug #1142857)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/5
 	NOTE: https://bugs.launchpad.net/ironic-python-agent/+bug/2160050
 CVE-2026-65706 (FFmpeg versions 3.0 through 8.1.2 contain an out-of-bounds write vulne ...)
@@ -2148,7 +2148,7 @@ CVE-2026-XXXX [DNS-over-QUIC heap buffer overflow (RCE)]
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/6
 	NOTE: https://lists.nic.cz/hyperkitty/list/knot-resolver-announce@lists.nic.cz/thread/ESUJGSCVLNPPWB2F3DUPKCVY5KBVPYF2/
 CVE-2026-54422 (In OpenStackIronic Python Agent through 11.5.0, a malicious bootc cont ...)
-	- ironic-python-agent <unfixed>
+	- ironic-python-agent <unfixed> (bug #1142854)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/07/23/4
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2155826
 CVE-2026-58264 [heap-based buffer overrun in command handler]
@@ -2659,7 +2659,7 @@ CVE-2026-57370 (Unauthenticated Cross Site Scripting (XSS) in Visitor Traffic Re
 CVE-2026-57367 (Subscriber Broken Access Control in WP Booking System < 5.12.8.1 versi ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-52684 (If the auth responds very slowly and the records expire in between, th ...)
-	- pdns-recursor <unfixed>
+	- pdns-recursor <unfixed> (bug #1142852)
 	[trixie] - pdns-recursor <no-dsa> (Minor issue)
 	[bookworm] - pdns-recursor <end-of-life> (see DSA 6045)
 	[bullseye] - pdns-recursor <end-of-life> (see DSA 6045)
@@ -3183,7 +3183,7 @@ CVE-2026-16607 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Soft
 CVE-2026-16606 (A vulnerability in Fujitsu Software Linux openFT andFujitsu Software O ...)
 	NOT-FOR-US: Fujitsu
 CVE-2026-16560 (A heap-buffer-overflow flaw was found in Directory Server (389-ds-base ...)
-	- 389-ds-base <unfixed>
+	- 389-ds-base <unfixed> (bug #1142849)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506102
 CVE-2026-16552
 	REJECTED
@@ -3192,7 +3192,7 @@ CVE-2026-16551 (Denial-of-Service in Thinkst Applied Research OpenCanary (MongoD
 CVE-2026-16544 (A flaw was found in AWX. The websocket event consumer performs RBAC au ...)
 	NOT-FOR-US: Ansible Tower
 CVE-2026-16473 (A flaw was found in the sbc library (BlueZ SBC codec). An off-by-one e ...)
-	- sbc <unfixed>
+	- sbc <unfixed> (bug #1142848)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2503650
 CVE-2026-16270 (Open Mercato does not validate regex rules. An attacker with privilege ...)
 	NOT-FOR-US: Open Mercato
@@ -6261,13 +6261,13 @@ CVE-2026-15342 (Plane contains a multi\u2011tenant authorization flaw in its ass
 CVE-2026-15145 (The Essential Addons for Elementor \u2013 Popular Elementor Templates  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12548 (A heap out-of-bounds read flaw was found in libsoup. When parsing mult ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142838)
 	- libsoup2.4 <removed>
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/512
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/524
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/commit/7334c38f1f6aa5e64207cb415cf2509838c52b37 (3.7.1)
 CVE-2026-12547 (SoupAuthManager caches proxy authentication credentials without scopin ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142837)
 	- libsoup2.4 <removed>
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/506
 CVE-2026-11876 (In zenml-io/zenml version 0.94.2, the `GET /api/v1/stack-deployment/st ...)
@@ -6860,10 +6860,10 @@ CVE-2026-16266 (Versions of the package mongo-object before 3.0.3 are vulnerable
 CVE-2026-15927 (A flaw was found in Red Hat Quay's repository-level mirror configurati ...)
 	NOT-FOR-US: Quay
 CVE-2026-15812 (A vulnerability was found in the internal Access Control List (ACL) su ...)
-	- kronosnet <unfixed>
+	- kronosnet <unfixed> (bug #1142847)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500851
 CVE-2026-15811 (A vulnerability was found in kronosnet's (version <=1.34) cryptographi ...)
-	- kronosnet <unfixed>
+	- kronosnet <unfixed> (bug #1142847)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500849
 CVE-2026-15788 (BuildKit's cache mount source= selector on Windows Container on Window ...)
 	- golang-github-moby-buildkit <itp> (bug #1094971)
@@ -7260,10 +7260,10 @@ CVE-2026-16244 (A security vulnerability has been detected in itsourcecode Hospi
 CVE-2026-16242 (A flaw was found in the Konnectivity proxy-server configuration for ho ...)
 	NOT-FOR-US: Konnectivity proxy-server
 CVE-2026-15813 (A vulnerability was found in the network packet de-fragmentation engin ...)
-	- kronosnet <unfixed>
+	- kronosnet <unfixed> (bug #1142847)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2500854
 CVE-2026-15588 (A denial-of-service and resource exhaustion vulnerability exists withi ...)
-	- glib2.0 <unfixed>
+	- glib2.0 <unfixed> (bug #1142835)
 	[trixie] - glib2.0 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/glib/-/issues/3985
 	NOTE: https://gitlab.gnome.org/GNOME/glib/-/merge_requests/5240
@@ -13829,27 +13829,27 @@ CVE-2026-15720 (InOpen5GS through version 2.7.7 a pre-authenticationheap out-of-
 CVE-2026-15715 (A vulnerability was identified in SourceCodester Class and Exam Timeta ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-15714 (An out-of-bounds read vulnerability was found in libsoup's multipart p ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142843)
 	- libsoup2.4 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499942
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/542
 CVE-2026-15713 (A vulnerability was found in libsoup's HTTP/2 protocol implementation. ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142842)
 	- libsoup2.4 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499941
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/541
 CVE-2026-15712 (A heap buffer over-read vulnerability was discovered in libsoup's (ver ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142841)
 	- libsoup2.4 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499939
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/540
 CVE-2026-15711 (A vulnerability was found in libsoup's WebSocket frame parsing impleme ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142840)
 	- libsoup2.4 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499924
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/515
 CVE-2026-15709 (A flaw was found in libsoup's WebSocket implementation when using the  ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142839)
 	- libsoup2.4 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2499922
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/issues/511
@@ -13955,7 +13955,7 @@ CVE-2026-12523 (Summary    Cloudflare quiche's HTTP/3 layer was discovered to be
 CVE-2026-12512 (The Quotes llama WordPress plugin before 3.1.6 does not properly sanit ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12478 (The fix for CVE-2026-0716 (commit 6ff7ef0, libsoup 3.6.6) placed the i ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1142836)
 	[trixie] - libsoup3 <not-affected> (Fix for CVE-2026-0716 not applied)
 	[bookworm] - libsoup3 <not-affected> (Fix for CVE-2026-0716 not applied)
 	- libsoup2.4 <not-affected> (Fix for CVE-2026-0716 not applied)
@@ -52543,7 +52543,7 @@ CVE-2026-39531 (Improper Neutralization of Special Elements used in an SQL Comma
 CVE-2026-39461 (libcasper(3) communicates with helper processes via UNIX domain socket ...)
 	NOT-FOR-US: FreeBSD
 CVE-2026-36189 (Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrust ...)
-	- uncrustify <unfixed>
+	- uncrustify <unfixed> (bug #1142851)
 	NOTE: https://github.com/uncrustify/uncrustify/issues/4636
 	NOTE: https://github.com/uncrustify/uncrustify/pull/4641
 	NOTE: https://github.com/uncrustify/uncrustify/pull/4650



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eed1b04e99770af2fc258ff5bec8f06273e6d48c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eed1b04e99770af2fc258ff5bec8f06273e6d48c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/657496cc/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list