[Git][security-tracker-team/security-tracker][master] automatic update

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 27 20:19:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4e23d27a by security tracker role at 2026-07-27T19:19:04+00:00
automatic update

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,3 +1,363 @@
+CVE-2026-66759 (A flaw was found in the file-icns plugin in GIMP. When applying a deco ...)
+	TODO: check
+CVE-2026-66758 (A flaw was found in the file-fits plugin in GIMP. When processing a FI ...)
+	TODO: check
+CVE-2026-66757 (A flaw was found in the file-sgi plugin in GIMP. When processing an RL ...)
+	TODO: check
+CVE-2026-66731 (facil.io 0.7.5 through 0.7.6 contains a denial-of-service vulnerabilit ...)
+	TODO: check
+CVE-2026-66730 (facil.io 0.6.0 through 0.7.6 contains a denial-of-service vulnerabilit ...)
+	TODO: check
+CVE-2026-66729 (facil.io 0.6.0 through 0.7.6 contains an integer underflow vulnerabili ...)
+	TODO: check
+CVE-2026-66477 (Unauthenticated Broken Access Control in Gillion <= 4.13 versions.)
+	TODO: check
+CVE-2026-66476 (Administrator Arbitrary File Deletion in Easy Digital Downloads <= 3.6 ...)
+	TODO: check
+CVE-2026-66475 (Shop manager Cross Site Scripting (XSS) in Checkout Field Editor for W ...)
+	TODO: check
+CVE-2026-66474 (Unauthenticated Cross Site Request Forgery (CSRF) in Insert Headers an ...)
+	TODO: check
+CVE-2026-66448 (Contributor Cross Site Scripting (XSS) in Gallery PhotoBlocks <= 1.3.3 ...)
+	TODO: check
+CVE-2026-66445 (Contributor Cross Site Scripting (XSS) in Open User Map <= 1.4.46 vers ...)
+	TODO: check
+CVE-2026-66442 (Subscriber Broken Access Control in YayPricing <= 3.5.6 versions.)
+	TODO: check
+CVE-2026-66438 (Unauthenticated Sensitive Data Exposure in Exclusive Addons Elementor  ...)
+	TODO: check
+CVE-2026-66437 (Contributor Server Side Request Forgery (SSRF) in Feedzy <= 5.2.4 vers ...)
+	TODO: check
+CVE-2026-66434 (Contributor Cross Site Scripting (XSS) in Photonic Gallery & Lightbox  ...)
+	TODO: check
+CVE-2026-66433 (Contributor Cross Site Scripting (XSS) in Location Weather <= 3.0.6 ve ...)
+	TODO: check
+CVE-2026-66428 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Google Review  ...)
+	TODO: check
+CVE-2026-66427 (Administrator SQL Injection in WP Google Review Slider <= 18.4 version ...)
+	TODO: check
+CVE-2026-66399 (phpMyFAQ before 4.1.6 contains a privilege escalation vulnerability in ...)
+	TODO: check
+CVE-2026-66398 (phpMyFAQ before v4.1.6 contains a remote code execution vulnerability  ...)
+	TODO: check
+CVE-2026-66397 (phpMyFAQ before 4.1.6 fails to validate path traversal sequences in th ...)
+	TODO: check
+CVE-2026-66396 (SiYuan before v3.7.2 fails to escape the title-img Individual Attribut ...)
+	TODO: check
+CVE-2026-66395 (SiYuan desktop before v3.7.2 contains a reflected cross-site scripting ...)
+	TODO: check
+CVE-2026-66394 (SiYuan before v3.7.3 contains stored and reflected cross-site scriptin ...)
+	TODO: check
+CVE-2026-66391 (Use of Insufficiently Random Values, Protection Mechanism Failure vuln ...)
+	TODO: check
+CVE-2026-66390 (Improper Neutralization of Input During Web Page Generation ('Cross-si ...)
+	TODO: check
+CVE-2026-66053 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
+	TODO: check
+CVE-2026-66050 (NitroShare Desktop through 0.3.4 contains a path traversal vulnerabili ...)
+	TODO: check
+CVE-2026-66031 (Ekushey Project Manager CRM through version 5.0 contains a stored cros ...)
+	TODO: check
+CVE-2026-66030 (Ekushey Project Manager CRM through version 5.0 contains a stored cros ...)
+	TODO: check
+CVE-2026-66029 (Ekushey Project Manager CRM through version 5.0 contains a stored cros ...)
+	TODO: check
+CVE-2026-66028 (Ekushey Project Manager CRM through version 5.0 contains a missing uni ...)
+	TODO: check
+CVE-2026-65894 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to improper  ...)
+	TODO: check
+CVE-2026-65893 (This vulnerability exists in CP PLUS EZ-P21 IP Camera due to an insecu ...)
+	TODO: check
+CVE-2026-65879 (Joomla Extension - joomshaper.com - Unauthenticated mail relay via a h ...)
+	TODO: check
+CVE-2026-65878 (Joomla Extension - joomshaper.com - Authenticated arbitrary file delet ...)
+	TODO: check
+CVE-2026-65877 (Joomla Extension - joomshaper.com - Authenticated SQL injection  in SP ...)
+	TODO: check
+CVE-2026-65876 (Joomla Extension - joomshaper.com - Unauthenticated SQL injection  in  ...)
+	TODO: check
+CVE-2026-65766 (Joomla Extension - joomshaper.com - Unauthenticated SQL injection  in  ...)
+	TODO: check
+CVE-2026-65765 (Joomla Extension - phoca.cz - Path Traversal vulnerability in Phoca Co ...)
+	TODO: check
+CVE-2026-65764 (Joomla Extension - phoca.cz - Reflected XSS vulnerability in Phoca Com ...)
+	TODO: check
+CVE-2026-65568 (Contributor Broken Access Control in Visual Composer Website Builder < ...)
+	TODO: check
+CVE-2026-65567 (Unauthenticated Broken Access Control in Event Tickets <= 5.29.0.1 ver ...)
+	TODO: check
+CVE-2026-65564 (Unauthenticated Sensitive Data Exposure in MapPress Maps for WordPress ...)
+	TODO: check
+CVE-2026-65563 (Author Cross Site Scripting (XSS) in Orbit Fox by ThemeIsle <= 3.0.7 v ...)
+	TODO: check
+CVE-2026-65562 (Contributor Cross Site Scripting (XSS) in BetterDocs <= 4.6.2 versions ...)
+	TODO: check
+CVE-2026-65561 (Contributor Cross Site Scripting (XSS) in WordPress Social Login and R ...)
+	TODO: check
+CVE-2026-65558 (Unauthenticated Server Side Request Forgery (SSRF) in AffiliateX <= 2. ...)
+	TODO: check
+CVE-2026-65557 (Shop manager Cross Site Scripting (XSS) in Abandoned Cart Lite for Woo ...)
+	TODO: check
+CVE-2026-65436 (Editor Arbitrary File Deletion in Kirki <= 6.0.13 versions.)
+	TODO: check
+CVE-2026-65435 (Unauthenticated Broken Access Control in Thrive Leads Version <= 10.9. ...)
+	TODO: check
+CVE-2026-65434 (Subscriber Sensitive Data Exposure in \u042eKassa \u0434\u043b\u044f W ...)
+	TODO: check
+CVE-2026-65433 (Subscriber Broken Access Control in RT Mega Menu \u2013 Mega Menu Buil ...)
+	TODO: check
+CVE-2026-64647 (Next.js is a React framework for building full-stack web applications. ...)
+	TODO: check
+CVE-2026-64646 (Next.js is a React framework for building full-stack web applications. ...)
+	TODO: check
+CVE-2026-64645 (Next.js is a React framework for building full-stack web applications. ...)
+	TODO: check
+CVE-2026-64644 (Next.js is a React framework for building full-stack web applications. ...)
+	TODO: check
+CVE-2026-64643 (Next.js is a React framework for building full-stack web applications. ...)
+	TODO: check
+CVE-2026-64642 (Next.js is a React framework for building full-stack web applications. ...)
+	TODO: check
+CVE-2026-64641 (Next.js is a React framework for building full-stack web applications. ...)
+	TODO: check
+CVE-2026-63077 (In JetBrains TeamCity before 2026.1.3, 2025.11.7 unauthenticated remot ...)
+	TODO: check
+CVE-2026-61511 (vBulletin 5.x through 5.7.5 and 6.x through 6.2.1 contains an eval inj ...)
+	TODO: check
+CVE-2026-59690 (A Missing Authorization vulnerability in Progress Software LoadMaster, ...)
+	TODO: check
+CVE-2026-59689 (An Incorrect Authorization vulnerability in Progress Software LoadMast ...)
+	TODO: check
+CVE-2026-59688 (An OS Command Injection vulnerability in Progress Software LoadMaster, ...)
+	TODO: check
+CVE-2026-59687 (An OS Command Injection vulnerability in Progress Software LoadMaster, ...)
+	TODO: check
+CVE-2026-59686 (An OS Command Injection vulnerability in Progress Software LoadMaster, ...)
+	TODO: check
+CVE-2026-59560 (Subscriber Broken Access Control in FundEngine <= 1.7.8 versions.)
+	TODO: check
+CVE-2026-59559 (Subscriber Cross Site Scripting (XSS) in RT Mega Menu \u2013 Mega Menu ...)
+	TODO: check
+CVE-2026-59558 (Unauthenticated Cross Site Scripting (XSS) in Booking Calendar <= 11.4 ...)
+	TODO: check
+CVE-2026-59557 (Unauthenticated Broken Access Control in Events Made Easy <= 3.1.3 ver ...)
+	TODO: check
+CVE-2026-59556 (Unauthenticated Cross Site Scripting (XSS) in Dynamic Pricing With Dis ...)
+	TODO: check
+CVE-2026-59553 (Unauthenticated Cross Site Scripting (XSS) in Product Feed Manager <=  ...)
+	TODO: check
+CVE-2026-59552 (Unauthenticated Server Side Request Forgery (SSRF) in 3D Flipbook PDF  ...)
+	TODO: check
+CVE-2026-59551 (Subscriber SQL Injection in rtMedia for WordPress, BuddyPress and bbPr ...)
+	TODO: check
+CVE-2026-59550 (Unauthenticated SQL Injection in AWP Classifieds <= 4.4.7 versions.)
+	TODO: check
+CVE-2026-59549 (Unauthenticated SQL Injection in rtMedia for WordPress, BuddyPress and ...)
+	TODO: check
+CVE-2026-59548 (Unauthenticated Sensitive Data Exposure in Byteflows Travel & Hote ...)
+	TODO: check
+CVE-2026-59546 (Subscriber Broken Authentication in Hide My WP Ghost <= 7.0.06 version ...)
+	TODO: check
+CVE-2026-59539 (Subscriber Insecure Direct Object References (IDOR) in Paid Member Sub ...)
+	TODO: check
+CVE-2026-59538 (Unauthenticated SQL Injection in GamiPress <= 7.9.7 versions.)
+	TODO: check
+CVE-2026-59537 (Administrator SQL Injection in Sender \u2013 Newsletter, SMS and Email ...)
+	TODO: check
+CVE-2026-59536 (Unauthenticated Broken Access Control in CoCart \u2013 Headless ecomme ...)
+	TODO: check
+CVE-2026-59535 (Unauthenticated Broken Access Control in Thrive Product Manager <= 10. ...)
+	TODO: check
+CVE-2026-59534 (Unauthenticated Broken Access Control in Post My CF7 Form <= 6.2.0 ver ...)
+	TODO: check
+CVE-2026-59533 (Unauthenticated SQL Injection in Relevanssi Light <= 1.2.2 versions.)
+	TODO: check
+CVE-2026-59532 (Unauthenticated Other Vulnerability Type in Booking and Rental Manager ...)
+	TODO: check
+CVE-2026-59531 (Unauthenticated Unknown in Falcon \u2013 WordPress Optimizations & Twe ...)
+	TODO: check
+CVE-2026-59530 (Unauthenticated Broken Access Control in Stripe For WooCommerce <= 4.0 ...)
+	TODO: check
+CVE-2026-59529 (Unauthenticated Sensitive Data Exposure in Ebook Store <= 6.19 version ...)
+	TODO: check
+CVE-2026-59528 (Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipping Ra ...)
+	TODO: check
+CVE-2026-59527 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
+	TODO: check
+CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP public_key certif ...)
+	TODO: check
+CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver ...)
+	TODO: check
+CVE-2026-59239 (Stored Cross-site Scripting (CWE-79) in the email module in Roskus Pro ...)
+	TODO: check
+CVE-2026-58662 (Improper Validation of Specified Quantity in Input, Out-of-bounds Read ...)
+	TODO: check
+CVE-2026-58389 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
+	TODO: check
+CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when reconstruct ...)
+	TODO: check
+CVE-2026-58023 (Out-of-bounds Read vulnerability in Apache Thrift c_glib bindings.  Th ...)
+	TODO: check
+CVE-2026-57917 (proCertum SmartSignparses external XML entities from arbitrary crafted ...)
+	TODO: check
+CVE-2026-57916 (proCertum SmartSign opens Certificate Practice Statement (CPS) URI wit ...)
+	TODO: check
+CVE-2026-56538 (An endpoint in HCL Connections is vulnerable to information disclosure ...)
+	TODO: check
+CVE-2026-56537 (HCL Connections is vulnerable to information disclosure which could al ...)
+	TODO: check
+CVE-2026-55971 (Heap-based Buffer Overflow vulnerability in Apache Thrift C++ bindings ...)
+	TODO: check
+CVE-2026-55970 (Buffer Over-read vulnerability in Apache Thrift C++ bindings.  This is ...)
+	TODO: check
+CVE-2026-55969 (Integer Overflow or Wraparound vulnerability in Apache Thrift C++, c_g ...)
+	TODO: check
+CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources Without Li ...)
+	TODO: check
+CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not veri ...)
+	TODO: check
+CVE-2026-55737 (Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerabil ...)
+	TODO: check
+CVE-2026-55579 (Pheditor is a single-file editor and file manager written in PHP. From ...)
+	TODO: check
+CVE-2026-55578 (Pheditor is a single-file editor and file manager written in PHP. From ...)
+	TODO: check
+CVE-2026-54890 (Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erl ...)
+	TODO: check
+CVE-2026-54540 (Pheditor is a single-file editor and file manager written in PHP. Prio ...)
+	TODO: check
+CVE-2026-54272 (ip-address is a library for parsing and manipulating IPv4 and IPv6 add ...)
+	TODO: check
+CVE-2026-51304 (sqlite 3.41 has a use-after-free (UAF) vulnerability in the ORDER BY c ...)
+	TODO: check
+CVE-2026-51303 (A use-after-free (UAF) vulnerability was discovered in the core parsin ...)
+	TODO: check
+CVE-2026-51302 (SQLite 3.41 has a use-after-free vulnerability exists in the expressio ...)
+	TODO: check
+CVE-2026-51300 (A use-after-free vulnerability exists in the expression parsing and me ...)
+	TODO: check
+CVE-2026-51298 (sqlite 3.41 is vulnerable to use after free in the JSON extraction fun ...)
+	TODO: check
+CVE-2026-51297 (sqlite 3.41 has a use-after-free vulnerability in the JSON parsing log ...)
+	TODO: check
+CVE-2026-51296 (SQLite 3.41 has a use-after-free vulnerability in jsonRemoveFunc of SQ ...)
+	TODO: check
+CVE-2026-51244 (schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability  ...)
+	TODO: check
+CVE-2026-51235 (LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function ...)
+	TODO: check
+CVE-2026-49158 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
+	TODO: check
+CVE-2026-48586 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
+	TODO: check
+CVE-2026-48145 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
+	TODO: check
+CVE-2026-48144 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
+	TODO: check
+CVE-2026-48052 (Papra is a minimalistic document management and archiving platform. Pr ...)
+	TODO: check
+CVE-2026-48051 (Papra is a minimalistic document management and archiving platform. Pr ...)
+	TODO: check
+CVE-2026-48030 (Pheditor is a single-file editor and file manager written in PHP. From ...)
+	TODO: check
+CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module ...)
+	TODO: check
+CVE-2026-45623 (PostCSS takes a CSS file and provides an API to analyze and modify its ...)
+	TODO: check
+CVE-2026-45112 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
+	TODO: check
+CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability i ...)
+	TODO: check
+CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erlang OT ...)
+	TODO: check
+CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
+	TODO: check
+CVE-2026-40000 (The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)
+	TODO: check
+CVE-2026-24252 (NVIDIA NeMo for Linux contains a vulnerability where an attacker may c ...)
+	TODO: check
+CVE-2026-17612 (Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to a ...)
+	TODO: check
+CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability. Processing a c ...)
+	TODO: check
+CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library. Proces ...)
+	TODO: check
+CVE-2026-17572 (Heap-based buffer overflow in the SOHM list-index deserialization code ...)
+	TODO: check
+CVE-2026-17570 (Improper access control in the PAM password history endpoints in Devol ...)
+	TODO: check
+CVE-2026-17569 (Improper access control in the NetBox synchronizer in Devolutions Serv ...)
+	TODO: check
+CVE-2026-17568 (Improper access control in the role membership management endpoint in  ...)
+	TODO: check
+CVE-2026-17552 (Plack::App::Prerender versions before 0.3.0 for Perl can proxy to an a ...)
+	TODO: check
+CVE-2026-17534 (Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL S ...)
+	TODO: check
+CVE-2026-17531 (A weakness has been identified in unitedbyai droidclaw up to 0.5.3. Af ...)
+	TODO: check
+CVE-2026-17530 (A security flaw has been discovered in AstrBotDevs AstrBot up to 4.25. ...)
+	TODO: check
+CVE-2026-17529 (A vulnerability was identified in AstrBotDevs AstrBot up to 4.25.5. Af ...)
+	TODO: check
+CVE-2026-17527 (In containerized-data-importer (CDI), the aggregated cdi.kubevirt.io:v ...)
+	TODO: check
+CVE-2026-17523 (A flaw was found in the kernel. An unprivileged local user can exploit ...)
+	TODO: check
+CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. ...)
+	TODO: check
+CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected i ...)
+	TODO: check
+CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This  ...)
+	TODO: check
+CVE-2026-17192 (A VCO feature does not sufficiently validate caller-supplied input, al ...)
+	TODO: check
+CVE-2026-17191 (An input validation vulnerability exists in an API component of the or ...)
+	TODO: check
+CVE-2026-16812 (VeloCloud Orchestrator (VCO) on-prem has a security issue where this i ...)
+	TODO: check
+CVE-2026-16554 (cJSON library is vulnerable to an integer overflow in the print_string ...)
+	TODO: check
+CVE-2026-16481 (A Server-Side Request Forgery (SSRF) and credential exfiltration vulne ...)
+	TODO: check
+CVE-2026-15799
+	REJECTED
+CVE-2026-15003 (A flaw was found in the GNU Binutils (Binary Utilities) linker. This v ...)
+	TODO: check
+CVE-2026-14856 (A stored Cross-Site Scripting (XSS) vulnerability in the file upload f ...)
+	TODO: check
+CVE-2026-14837 (Multiple Lenze products are affected by an improper signature verifica ...)
+	TODO: check
+CVE-2026-12991 (The lack of cryptographic mechanisms to ensure the integrity and authe ...)
+	TODO: check
+CVE-2026-12990 (An access control vulnerability in the mobile app (APK v5.5.0) for Gho ...)
+	TODO: check
+CVE-2026-12989 (A lack of authentication in the mobile app (APK v5.5.0) for Ghost Robo ...)
+	TODO: check
+CVE-2026-12495 (Denial-of-service (DoS) vulnerability due to a stack buffer overflow i ...)
+	TODO: check
+CVE-2026-12383 (A flaw was found in the Event-Driven Ansible (EDA) server. The Externa ...)
+	TODO: check
+CVE-2026-10819 (Mattermost versions 11.6.x <= 11.6.5, 10.11.x <= 10.11.20, 11.8.x <= 1 ...)
+	TODO: check
+CVE-2026-10683 (In the Synopsys DesignWare I2C driver (drivers/i2c/i2c_dw.c) operating ...)
+	TODO: check
+CVE-2026-10682 (The userspace verifier z_vrfy_log_filter_set() for the log_filter_set  ...)
+	TODO: check
+CVE-2026-10600 (Mattermost versions 11.8.x <= 11.8.0, 11.7.x <= 11.7.3, 11.6.x <= 11.6 ...)
+	TODO: check
+CVE-2025-59181 (Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a ...)
+	TODO: check
+CVE-2025-59180 (Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a ...)
+	TODO: check
+CVE-2025-59178 (Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a ...)
+	TODO: check
+CVE-2025-59177 (Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a ...)
+	TODO: check
+CVE-2025-59172 (Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a ...)
+	TODO: check
+CVE-2025-50455 (SQL injection vulnerability exists in the order_by parameter of the /c ...)
+	TODO: check
 CVE-2026-XXXX [heap buffer overflow WRITE in memextract() STORED path]
 	- unzip <unfixed> (bug #1142906)
 CVE-2026-XXXX [stack out-of-bounds NUL write in EF_SMARTZIP handler]
@@ -63,25 +423,25 @@ CVE-2026-10082 (The Advanced Ads  WordPress plugin before 2.0.23 does not saniti
 	NOT-FOR-US: WordPress plugin
 CVE-2025-15662 (The Printcart Web to Print Product Designer for WooCommerce WordPress  ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-64536 [staging: rtl8723bs: fix OOB reads in is_ap_in_tkip() IE loop]
+CVE-2026-64536 (In the Linux kernel, the following vulnerability has been resolved:  s ...)
 	- linux 7.1.4-1
 	[trixie] - linux 6.12.96-1
 	NOTE: https://git.kernel.org/linus/3bf39f711ff27c64be8680a8938bcc5001982e81 (7.2-rc3)
-CVE-2026-64535 [nvmet-tcp: Fix potential UAF when ddgst mismatch]
+CVE-2026-64535 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.3-1
 	NOTE: https://git.kernel.org/linus/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a (7.1-rc4)
-CVE-2026-64534 [nvmet-tcp: check INIT_FAILED before nvmet_req_uninit in digest error path]
+CVE-2026-64534 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.3-1
 	NOTE: https://git.kernel.org/linus/4606467a75cfc16721937272ed29462a750b60c8 (7.1-rc2)
-CVE-2026-64533 [fs/ntfs3: validate lcns_follow in log_replay conversion]
+CVE-2026-64533 (In the Linux kernel, the following vulnerability has been resolved:  f ...)
 	- linux 7.1.5-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/6a4c53a2e26a865565bd6a460961e8d6fcb32329 (7.2-rc1)
-CVE-2026-64532 [fs/ntfs3: bound NTFS_DE view.data_off in UpdateRecordData{Root,Allocation}]
+CVE-2026-64532 (In the Linux kernel, the following vulnerability has been resolved:  f ...)
 	- linux 7.1.5-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/3e127829e57f5190f612412ece4541cb96d5ec7a (7.2-rc1)
-CVE-2026-64531 [net: openvswitch: reject oversized nested action attrs]
+CVE-2026-64531 (In the Linux kernel, the following vulnerability has been resolved:  n ...)
 	- linux 7.1.5-1
 	[bullseye] - linux <not-affected> (Vulnerable code not present)
 	NOTE: https://git.kernel.org/linus/3f1f755366687d051174739fb99f7d560202f60b (7.2-rc4)
@@ -6131,51 +6491,51 @@ CVE-2026-54441
 	[trixie] - mbedtls <no-dsa> (Minor issue; can be fixed via point releases)
 	[bookworm] - mbedtls <end-of-life> (EOL in bookworm LTS)
 CVE-2026-16420 (Type Confusion in WebAudio in Google Chrome prior to 150.0.7871.182 al ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16421 (Inappropriate implementation in WebAudio in Google Chrome prior to 150 ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16413 (Out of bounds write in ANGLE in Google Chrome prior to 150.0.7871.182  ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16414 (Insufficient validation of untrusted input in Chromecast in Google Chr ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16415 (Insufficient validation of untrusted input in Extensions in Google Chr ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16416 (Integer overflow in Chromecast in Google Chrome prior to 150.0.7871.18 ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16417 (Uninitialized Use in Skia in Google Chrome prior to 150.0.7871.182 all ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16418 (Stack buffer overflow in V8 in Google Chrome prior to 150.0.7871.182 a ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16419 (Out of bounds read and write in ANGLE in Google Chrome on Android prio ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16422 (Insufficient validation of untrusted input in Certificate in Google Ch ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16423 (Use after free in UI in Google Chrome prior to 150.0.7871.182 allowed  ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-16424 (Use after free in GPU in Google Chrome on Android prior to 150.0.7871. ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-9499 (An out-of-bounds read (buffer over-read) vulnerability exists in QText ...)
@@ -10570,7 +10930,7 @@ CVE-2026-63096 (Dendrite through 0.13.8 contains a server-side request forgery v
 	NOT-FOR-US: Dendrite
 CVE-2026-63095 (Dendrite through 0.13.8 contains an improper authorization vulnerabili ...)
 	NOT-FOR-US: Dendrite
-CVE-2026-63094 (SigNoz through 0.133.0 contains an open redirect vulnerability in the  ...)
+CVE-2026-63094 (SigNoz before 0.134.0 contains an open redirect vulnerability in the S ...)
 	NOT-FOR-US: SigNoz
 CVE-2026-63093 (Cursor for Windows version 3.2.16 contains a binary planting vulnerabi ...)
 	NOT-FOR-US: Cursor
@@ -10798,31 +11158,31 @@ CVE-2026-14266
 	NOTE: depending on 7zip. Mark this version as fixed version.
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-444/
 CVE-2026-15899 (Use after free in CameraCapture in Google Chrome on Mac prior to 150.0 ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15900 (Use after free in GPU in Google Chrome on Android prior to 150.0.7871. ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15901 (Use after free in Network in Google Chrome prior to 150.0.7871.128 all ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15902 (Use after free in Cast in Google Chrome prior to 150.0.7871.128 allowe ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15903 (Out of bounds read and write in V8 in Google Chrome prior to 150.0.787 ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15904 (Use after free in Ozone in Google Chrome on Linux prior to 150.0.7871. ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-15905 (Use after free in Aura in Google Chrome prior to 150.0.7871.128 allowe ...)
-	{DSA-6396-1}
+	{DSA-6396-1 DLA-4701-1}
 	- chromium 150.0.7871.181-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-59173 (Uncontrolled Resource Consumption vulnerability in Apache Traffic Serv ...)
@@ -44786,7 +45146,8 @@ CVE-2026-10532 (Deserialization of untrusted data vulnerability in QOS.CH Sarl l
 	[bookworm] - logback <no-dsa> (Minor issue)
 	[bullseye] - logback <postponed> (minor issue)
 	NOTE: https://logback.qos.ch/news.html#1.5.34
-CVE-2026-10517 (A flaw was found in Clair. The fetcher component makes outbound HTTP r ...)
+CVE-2026-10517
+	REJECTED
 	NOT-FOR-US: Clair
 CVE-2026-10283 (A vulnerability was detected in Bottelet DaybydayCRM up to 2.2.1. Affe ...)
 	NOT-FOR-US: Bottelet DaybydayCRM
@@ -52659,10 +53020,10 @@ CVE-2026-9157 (Improper input validation, Unrestricted upload of file with dange
 	NOT-FOR-US: Gmission
 CVE-2026-9089 (The ConnectWise Automate\u2122 Agent does not fully verify the authent ...)
 	NOT-FOR-US: ConnectWise
-CVE-2026-5434
-	REJECTED
-CVE-2026-5433
-	REJECTED
+CVE-2026-5434 (Honeywell Control Network Module (CNM)contains insertion of sensitive  ...)
+	TODO: check
+CVE-2026-5433 (Honeywell Control Network Module (CNM)contains command injection vulne ...)
+	TODO: check
 CVE-2026-5118 (The Divi Form Builder plugin for WordPress is vulnerable to privilege  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-4858 (Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4 ...)
@@ -68455,7 +68816,8 @@ CVE-2026-41606 (Uncontrolled Recursion vulnerability in Apache Thrift.  This iss
 	[bookworm] - thrift <no-dsa> (Minor issue)
 	[bullseye] - thrift <postponed> (Minor issue, DoS)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/04/28/3
-CVE-2026-41603 (Improper Validation of Certificate with Host Mismatch vulnerability in ...)
+CVE-2026-41603
+	REJECTED
 	[experimental] - thrift 0.23.0-1
 	- thrift 0.23.0-3 (bug #1135348)
 	[trixie] - thrift <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e23d27abf4db6f2b355d98e3864e1b6faf69b1a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e23d27abf4db6f2b355d98e3864e1b6faf69b1a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260727/94f6c733/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list