[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Jul 29 15:11:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3dc4ceee by Salvatore Bonaccorso at 2026-07-29T16:10:45+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -43,16 +43,16 @@ CVE-2026-62325 (goshs is a feature-rich single-binary file server for red teamer
CVE-2026-5626 (The Survey Form Block plugin for WordPress is vulnerable to unauthoriz ...)
NOT-FOR-US: WordPress plugin
CVE-2026-59943 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
- - php-dompdf <unfixed>
+ - php-dompdf <unfixed> (bug #1142987)
NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-j8qw-6jw8-r297
NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0 (v3.1.6)
CVE-2026-59942 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ar ...)
- - php-dompdf <unfixed>
+ - php-dompdf <unfixed> (bug #1142987)
NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-f5gf-2cj8-52g2
NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0 (v3.1.6)
NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/89164eaabe0bb50c462f0b24f740044ba5fb0f99 (v3.1.6)
CVE-2026-59941 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ac ...)
- - php-dompdf <unfixed>
+ - php-dompdf <unfixed> (bug #1142987)
NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-8hg6-c449-896m
NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/7c65e7bbeccf146b2409740405af73949ad129d0 (v3.1.6)
CVE-2026-59921 (Netty is an asynchronous, event-driven network application framework. ...)
@@ -69,16 +69,16 @@ CVE-2026-56821 (Netty is an asynchronous, event-driven network application frame
- netty <unfixed>
NOTE: https://github.com/netty/netty/security/advisories/GHSA-g7hg-vrcf-mvmr
CVE-2026-56722 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
- - php-dompdf <unfixed>
+ - php-dompdf <unfixed> (bug #1142987)
NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-cx96-42px-69fm
NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/6a58996865db05d8fede748507e50ac4b8c5bfd0 (v3.1.6)
NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/bf7b02f642e26007dedc5a22b3d6e15f9931120a (v3.1.6)
CVE-2026-55555 (Dompdf is an HTML to PDF converter for PHP. Versions 3.15 and prior ar ...)
- - php-dompdf <unfixed>
+ - php-dompdf <unfixed> (bug #1142987)
NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-7x2p-4jvh-6384
NOTE: Fixed by: https://github.com/dompdf/dompdf/commit/75c39a083bf7298044fb27399b4cc183054438b4 (v3.1.6)
CVE-2026-55554 (Dompdf is an HTML to PDF converter for PHP. In versions 3.15 and prior ...)
- - php-dompdf <unfixed>
+ - php-dompdf <unfixed> (bug #1142987)
NOTE: https://github.com/dompdf/dompdf/security/advisories/GHSA-wvh6-f5jh-8gw4
CVE-2026-55415 (datamodel-code-generator generates Pydantic v2 models, dataclasses, Ty ...)
NOT-FOR-US: datamodel-code-generator
@@ -268,10 +268,10 @@ CVE-2026-67184 (TinyWeb through 0.0.8 contains a null pointer dereference vulner
CVE-2026-67183 (TinyWeb through 0.0.8 contains a memory leak vulnerability that allows ...)
NOT-FOR-US: TinyWeb
CVE-2026-67182 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)
- - rust-rouille <unfixed>
+ - rust-rouille <unfixed> (bug #1142994)
NOTE: https://github.com/theopaid/CVE-2026-67182-HTTP-Request-Smuggling-Enables-Front-End-Access-Control-Bypass-rouille-
CVE-2026-67181 (Rouille 0.3.3 through 3.6.2 contains an HTTP request smuggling vulnera ...)
- - rust-rouille <unfixed>
+ - rust-rouille <unfixed> (bug #1142994)
NOTE: https://github.com/theopaid/CVE-2026-67181-HTTP-Request-Smuggling-via-Transfer-Encoding-Desynchronization-rouille-
CVE-2026-67178 (MISP installation scripts generated an Apache HTTP virtual-host config ...)
NOT-FOR-US: MISP
@@ -292,14 +292,14 @@ CVE-2026-66918 (Pivotick fails to sanitize attacker-controlled SVG markup suppli
CVE-2026-66913 (Lookyloo did not enforce limits on the decompressed size of uploaded c ...)
NOT-FOR-US: Lookyloo
CVE-2026-66754 (Rouille 0.1.6 through 3.6.2 contains a reachable assertion vulnerabili ...)
- - rust-rouille <unfixed>
+ - rust-rouille <unfixed> (bug #1142994)
NOTE: https://github.com/theopaid/CVE-2026-66754-Remote-Denial-of-Service-via-Reachable-Assertion-in-URL-Prefix-Handling-rouille-
CVE-2026-66753 (tiny-http through 0.12.0 contains an HTTP header injection vulnerabili ...)
- - rust-tiny-http <unfixed>
+ - rust-tiny-http <unfixed> (bug #1142989)
NOTE: https://github.com/theopaid/CVE-2026-66753-HTTP-Header-Injection-via-Unvalidated-CR-and-LF-in-Header-Values-tiny_http-/tree/master
NOTE: https://github.com/tiny-http/tiny-http/issues/288
CVE-2026-66752 (tiny-http through 0.12.0 contains an HTTP request smuggling vulnerabil ...)
- - rust-tiny-http <unfixed>
+ - rust-tiny-http <unfixed> (bug #1142989)
NOTE: https://github.com/theopaid/CVE-2026-66752-HTTP-Request-Smuggling-via-Unparsed-Transfer-Encoding-Values-tiny_http-/tree/master
NOTE: https://github.com/tiny-http/tiny-http/issues/287
CVE-2026-66751 (Let's Chat 0.3.0 through 0.4.8 contains an improper authorization vuln ...)
@@ -311,7 +311,7 @@ CVE-2026-66749 (Let's Chat 0.4.0 through 0.4.8 contains a null dereference vulne
CVE-2026-66748 (Camaleon CMS versions 2.1.1 through 2.9.1 contains an authenticated re ...)
NOT-FOR-US: Camaleon CMS
CVE-2026-66746 (Rouille 0.4.0 through 3.6.2 contains an HTTP response splitting vulner ...)
- - rust-rouille <unfixed>
+ - rust-rouille <unfixed> (bug #1142994)
NOTE: https://github.com/theopaid/CVE-2026-66746-HTTP-Response-Splitting-via-Unvalidated-Response-Header-Values-rouille-
CVE-2026-66745 (Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 202607 ...)
NOT-FOR-US: Artica Proxy
@@ -331,7 +331,7 @@ CVE-2026-65881 (Joomla Extension - joomdle.com - Insecure default configuration
CVE-2026-65880 (Joomla Extension - balbooa.com - Unauthenticated remote code execution ...)
NOT-FOR-US: Joomla
CVE-2026-65624 (Allocation of Resources Without Limits or Throttling vulnerability in ...)
- - erlang-cowboy <unfixed>
+ - erlang-cowboy <unfixed> (bug #1142988)
NOTE: https://cna.erlef.org/cves/CVE-2026-65624.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-65624
NOTE: Introduced with: https://github.com/ninenines/cowboy/commit/309780a9fda145c262a47ac7811ffd50a0271c5b (2.0.0-pre.4)
@@ -367,7 +367,7 @@ CVE-2026-59878 (Improper Input Validation vulnerability in Apache ActiveMQ AMQP,
CVE-2026-59764 (ELECOM wireless LAN routers and access points devices contain an OS Co ...)
NOT-FOR-US: ELECOM wireless LAN routers
CVE-2026-59248 (Allocation of resources without limits vulnerability in ninenines cowl ...)
- - erlang-cowlib <unfixed>
+ - erlang-cowlib <unfixed> (bug #1142982)
[trixie] - erlang-cowlib <not-affected> (Vulnerable code not present)
[bookworm] - erlang-cowlib <not-affected> (Vulnerable code not present)
[bullseye] - erlang-cowlib <not-affected> (Vulnerable code not present)
@@ -555,7 +555,7 @@ CVE-2026-16496 (The terraform-mcp-server before version 1.1.0 is vulnerable to a
CVE-2026-16462 (In PROCON-WEB SCADA the endpoint 'GetGridData' is not properly sanitiz ...)
NOT-FOR-US: PROCON-WEB SCADA
CVE-2026-16313 (A flaw was found in sg3_utils. The sg_inq command, when invoked with t ...)
- - sg3-utils <unfixed>
+ - sg3-utils <unfixed> (bug #1143004)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2502845
NOTE: https://github.com/doug-gilbert/sg3_utils/pull/83
CVE-2026-15992 (The WP Password Policy plugin for WordPress is vulnerable to Privilege ...)
@@ -1180,15 +1180,15 @@ CVE-2026-64537 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f3e02edd8322b31b8e6517faa6ba053bf29d1e26 (7.2-rc1)
CVE-2026-66759 (A flaw was found in the file-icns plugin in GIMP. When applying a deco ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1142992)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/abb3129a8ecb79bf3af6df03bc35ddf8f7aaba20
CVE-2026-66758 (A flaw was found in the file-fits plugin in GIMP. When processing a FI ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1142991)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/issues/16528
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/89ae907fea5ccc8bd1f626dbe01fdcfe29940ac9
CVE-2026-66757 (A flaw was found in the file-sgi plugin in GIMP. When processing an RL ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1142990)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16494
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2884
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/adb89f0f2c086240fc49f6e2c946d89e10b66a70
@@ -1380,7 +1380,7 @@ CVE-2026-59528 (Subscriber Sensitive Data Exposure in ShipTime: Discounted Shipp
CVE-2026-59527 (Unauthenticated SQL Injection in MapSVG <= 8.14.0 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP public_key certif ...)
- - erlang <unfixed>
+ - erlang <unfixed> (bug #1142985)
NOTE: https://github.com/erlang/otp/security/advisories/GHSA-622p-qfh6-c352
NOTE: https://cna.erlef.org/cves/CVE-2026-59251.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-59251
@@ -1388,7 +1388,7 @@ CVE-2026-59251 (Allocation of resources without limits in Erlang/OTP public_key
NOTE: Fixed by: https://github.com/erlang/otp/commit/f04c6bba38de1cf1b1836a7d9a9fbe239bd939e8 (OTP-27.3.4.15)
NOTE: Fixed by: https://github.com/erlang/otp/commit/f8580fc117098c08165f46c26fd0750c5cfb2a90 (OTP-29.0.4, OTP-28.5.0.4)
CVE-2026-59250 (Classic buffer overflow in the Erlang/OTP megaco flex scanner C driver ...)
- - erlang <unfixed>
+ - erlang <unfixed> (bug #1142985)
NOTE: https://github.com/erlang/otp/security/advisories/GHSA-7xgh-gmgf-q2g7
NOTE: https://cna.erlef.org/cves/CVE-2026-59250.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-59250
@@ -1403,7 +1403,7 @@ CVE-2026-58389 (Allocation of Resources Without Limits or Throttling vulnerabili
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/ht2mjt8m3vz9v0h5pqzvc4r4nzfxwtrw
CVE-2026-58227 (The Erlang/OTP ssl application does not detect cycles when reconstruct ...)
- - erlang <unfixed>
+ - erlang <unfixed> (bug #1142985)
NOTE: https://github.com/erlang/otp/security/advisories/GHSA-r5jr-mq46-vmhw
NOTE: https://cna.erlef.org/cves/CVE-2026-58227.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-58227
@@ -1434,7 +1434,7 @@ CVE-2026-55968 (Inefficient Algorithmic Complexity, Allocation of Resources With
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/gxhhfyr6flr5vzr4qnxm13p6fc41qstp
CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does not veri ...)
- - erlang <unfixed>
+ - erlang <unfixed> (bug #1142985)
NOTE: https://github.com/erlang/otp/security/advisories/GHSA-c6cw-pr89-w882
NOTE: https://cna.erlef.org/cves/CVE-2026-55953.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55953
@@ -1443,7 +1443,7 @@ CVE-2026-55953 (The Erlang/OTP ssl TLS 1.2 (and earlier) and DTLS client does no
NOTE: Fixed by: https://github.com/erlang/otp/commit/0a82596d425abe43dc2e0b3d74aa1557ef74051c (OTP-28.5.0.4)
NOTE: Fixed by: https://github.com/erlang/otp/commit/064e236414614f9085cbbbd6eacf0e43c02d1b4b (OTP-29.0.4)
CVE-2026-55737 (Signed to Unsigned Conversion Error and Out-of-bounds Write vulnerabil ...)
- - erlang <unfixed>
+ - erlang <unfixed> (bug #1142985)
NOTE: https://github.com/erlang/otp/security/advisories/GHSA-446w-268v-9462
NOTE: https://cna.erlef.org/cves/CVE-2026-55737.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-55737
@@ -1454,7 +1454,7 @@ CVE-2026-55579 (Pheditor is a single-file editor and file manager written in PHP
CVE-2026-55578 (Pheditor is a single-file editor and file manager written in PHP. From ...)
NOT-FOR-US: Pheditor
CVE-2026-54890 (Integer Underflow (Wrap or Wraparound) vulnerability in erlang otp erl ...)
- - erlang <unfixed>
+ - erlang <unfixed> (bug #1142985)
NOTE: https://github.com/erlang/otp/security/advisories/GHSA-54pw-5645-jh86
NOTE: https://cna.erlef.org/cves/CVE-2026-54890.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-54890
@@ -1507,7 +1507,7 @@ CVE-2026-48051 (Papra is a minimalistic document management and archiving platfo
CVE-2026-48030 (Pheditor is a single-file editor and file manager written in PHP. From ...)
NOT-FOR-US: Pheditor
CVE-2026-47078 (Relative Path Traversal vulnerability in Erlang OTP (stdlib zip module ...)
- - erlang <unfixed>
+ - erlang <unfixed> (bug #1142985)
NOTE: https://github.com/erlang/otp/security/advisories/GHSA-rf72-wp7h-jg3x
NOTE: https://cna.erlef.org/cves/CVE-2026-47078.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-47078
@@ -1527,7 +1527,7 @@ CVE-2026-43871 (Loop with Unreachable Exit Condition ('Infinite Loop') vulnerabi
- thrift <unfixed>
NOTE: https://lists.apache.org/thread/l4dwf14zbyqsmkc28c99ojj3t3gg9qby
CVE-2026-42792 (Improper Handling of Exceptional Conditions vulnerability in Erlang OT ...)
- - erlang <unfixed>
+ - erlang <unfixed> (bug #1142985)
NOTE: https://github.com/erlang/otp/security/advisories/GHSA-h6f3-hx58-xhj6
NOTE: https://cna.erlef.org/cves/CVE-2026-42792.html
NOTE: https://osv.dev/vulnerability/EEF-CVE-2026-42792
@@ -1542,15 +1542,15 @@ CVE-2026-24252 (NVIDIA NeMo for Linux contains a vulnerability where an attacker
CVE-2026-17612 (Honeywell S35 Series 3M/5M/8M/PinHole Cameras, all versions prior to a ...)
NOT-FOR-US: Honeywell
CVE-2026-17574 (HDF5 contains a NULL pointer dereference vulnerability. Processing a c ...)
- - hdf5 <unfixed>
+ - hdf5 <unfixed> (bug #1143001)
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/3fa6ed6e9dfeebbc784e21d8c48e31e35a8042bc (2.2.0-rc1)
CVE-2026-17573 (A double free vulnerability was discovered in the HDF5 library. Proces ...)
- - hdf5 <unfixed>
+ - hdf5 <unfixed> (bug #1143000)
NOTE: https://github.com/HDFGroup/hdf5/issues/6124
NOTE: https://github.com/HDFGroup/hdf5/pull/6160
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/dd3080a58cc6bb86f3b34284399915da9e513262 (2.1.0)
CVE-2026-17572 (Heap-based buffer overflow in the SOHM list-index deserialization code ...)
- - hdf5 <unfixed>
+ - hdf5 <unfixed> (bug #1142999)
NOTE: https://github.com/HDFGroup/hdf5/issues/6501
NOTE: https://github.com/HDFGroup/hdf5/pull/6499
NOTE: Fixed by: https://github.com/HDFGroup/hdf5/commit/20f0b9564bc46154e60f8d35578720a599d41552 (2.2.0-rc1)
@@ -9056,14 +9056,14 @@ CVE-2026-27823 (A vulnerability has been identified in EGroupware that may lead
CVE-2026-26483 (Mettle SendPortal 3.0.1 and earlier contains a stored cross-site scrip ...)
NOT-FOR-US: Mettle SendPortal
CVE-2026-26199 (HDF5 is a high-performance library and a file format specification tha ...)
- - hdf5 <unfixed>
+ - hdf5 <unfixed> (bug #1143003)
[trixie] - hdf5 <no-dsa> (Minor issue)
[bookworm] - hdf5 <postponed> (Minor issue; H5G_get_name buffer underflow only when caller passes size=0 to H5Iget_name)
[bullseye] - hdf5 <postponed> (Minor issue; H5G_get_name buffer underflow only when caller passes size=0 to H5Iget_name)
NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-5c6x-jmgf-f5vc
TODO: isolate fixing commit
CVE-2026-26197 (HDF5 is a high-performance library and a file format specification tha ...)
- - hdf5 <unfixed>
+ - hdf5 <unfixed> (bug #1143002)
[bookworm] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
[bullseye] - hdf5 <postponed> (Minor issue; OOB read only via a maliciously altered file whose array datatype size, element count and element size disagree; hdf5 is limited-support, trusted content only)
NOTE: https://github.com/HDFGroup/hdf5/security/advisories/GHSA-gh44-7wpq-622f
@@ -35841,12 +35841,12 @@ CVE-2026-9507 (A session fixation vulnerability has been identified in osTicket
CVE-2026-9307 (A sensitive information disclosure security issue exists within the af ...)
NOT-FOR-US: Rockwell Automation
CVE-2026-8484 (A heap buffer overflow vulnerability exists in the Jansi JNI "ioctl()" ...)
- - jansi <unfixed>
+ - jansi <unfixed> (bug #1142997)
[trixie] - jansi <no-dsa> (Minor issue)
[bookworm] - jansi <postponed> (Minor issue)
[bullseye] - jansi <not-affected> (jansi 1.x ships no native code; the vulnerable JNI ioctl is in jansi-native)
- jansi1 <not-affected> (Vulnerable code for JNI ioctl() in src:jansi-native)
- - jansi-native <unfixed>
+ - jansi-native <unfixed> (bug #1142998)
[trixie] - jansi-native <no-dsa> (Minor issue)
[bookworm] - jansi-native <postponed> (Minor issue)
[bullseye] - jansi-native <postponed> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3dc4ceee67d27de71f77589baa2f46cb50e8b6f6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3dc4ceee67d27de71f77589baa2f46cb50e8b6f6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260729/47f89d43/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list