[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 31 06:46:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
88e47b73 by Salvatore Bonaccorso at 2026-07-31T07:41:03+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -37,7 +37,7 @@ CVE-2026-5582 (The FuseWP plugin for WordPress is vulnerable to Cross-Site Reque
 CVE-2026-5219 (Cross-Site request forgery (CSRF) vulnerability in Softtr Information  ...)
 	NOT-FOR-US: E-Commerce Pack
 CVE-2026-59881 (AIOHTTP is an asynchronous HTTP client/server framework for asyncio an ...)
-	- python-aiohttp <unfixed>
+	- python-aiohttp <unfixed> (bug #1143160)
 	[trixie] - python-aiohttp <no-dsa> (Minor issue)
 	NOTE: https://github.com/aio-libs/aiohttp/security/advisories/GHSA-mq44-7p77-q5h7
 	NOTE: https://github.com/aio-libs/aiohttp/pull/12978
@@ -47,7 +47,7 @@ CVE-2026-59310 (VMware vCenter contains a directory traversal vulnerability in t
 CVE-2026-59309 (VMware vCenter contains an authentication bypass vulnerability in the  ...)
 	NOT-FOR-US: VMware
 CVE-2026-57862 (Kanboard 1.2.52 and prior contains a server-side request forgery vulne ...)
-	- kanboard <unfixed>
+	- kanboard <unfixed> (bug #1143159)
 	NOTE: https://gist.github.com/sermikr0/67c8acfc395e465127e729dc309da3ae
 	TODO: check upstream report
 CVE-2026-57859 (e107 prior to version 2.3.8 contains a code execution vulnerability in ...)
@@ -1640,22 +1640,22 @@ CVE-2026-16610 (The Admin and Site Enhancements (ASE) Pro plugin for WordPress i
 CVE-2026-16553 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-16531 (An unauthenticated remote attacker can exploit a path traversal vulner ...)
-	- pcp <unfixed>
+	- pcp <unfixed> (bug #1143154)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506037
 CVE-2026-16530 (A flaw was found in the PCP (Performance Co-Pilot) `pmproxy` service.  ...)
-	- pcp <unfixed>
+	- pcp <unfixed> (bug #1143154)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506033
 CVE-2026-16529 (A signed integer overflow in the PCP __pmGetPDU() function can be expl ...)
-	- pcp <unfixed>
+	- pcp <unfixed> (bug #1143154)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506032
 CVE-2026-16527 (An unauthenticated remote attacker can bypass access controls by sendi ...)
-	- pcp <unfixed>
+	- pcp <unfixed> (bug #1143154)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506031
 CVE-2026-16526 (A flaw in the PCP linux_sockets module exposes an unsecured internal c ...)
-	- pcp <unfixed>
+	- pcp <unfixed> (bug #1143154)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506026
 CVE-2026-16524 (A command injection flaw in PCP's linux_sockets PMDA allows malicious  ...)
-	- pcp <unfixed>
+	- pcp <unfixed> (bug #1143154)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506023
 CVE-2026-16339
 	REJECTED
@@ -2042,12 +2042,12 @@ CVE-2026-57834 (Apache Traffic Server allows request smuggling if chunked messag
 	- trafficserver <unfixed> (bug #1143062)
 	NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
 CVE-2026-56390 (GNU Bison improperly handles grammar\u2011defined output paths. Gramma ...)
-	- bison <unfixed>
+	- bison <unfixed> (bug #1143158)
 	[trixie] - bison <no-dsa> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389/
 	NOTE: https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=8d101c19d4d9aaedf83a448c925513742d4efcf0
 CVE-2026-56389 (GNU Bison allows for an execution of an arbitrary program during HTML  ...)
-	- bison <unfixed>
+	- bison <unfixed> (bug #1143158)
 	[trixie] - bison <no-dsa> (Minor issue)
 	NOTE: https://cert.pl/en/posts/2026/07/CVE-2026-56389
 	NOTE: https://cgit.git.savannah.gnu.org/cgit/bison.git/commit/?id=3169c1e7a2c6acc4c59dfcf8b089896d6881925b
@@ -3820,10 +3820,10 @@ CVE-2026-17523 (A flaw was found in the Linux kernel in net/can/bcm.c in can: bc
 CVE-2026-17514 (A vulnerability was determined in ZJONSSON node-unzipper up to 0.12.3. ...)
 	NOT-FOR-US: ZJONSSON node-unzipper
 CVE-2026-17513 (A vulnerability was found in ggml-org whisper.cpp 95ea8f9b. Affected i ...)
-	- whisper.cpp <unfixed>
+	- whisper.cpp <unfixed> (bug #1143157)
 	NOTE: https://github.com/ggml-org/whisper.cpp/issues/3924
 CVE-2026-17512 (A vulnerability has been found in ggml-org whisper.cpp 1.8.4-58. This  ...)
-	- whisper.cpp <unfixed>
+	- whisper.cpp <unfixed> (bug #1143157)
 	NOTE: https://github.com/ggml-org/whisper.cpp/issues/3923
 	NOTE: https://github.com/ggml-org/whisper.cpp/pull/3925
 CVE-2026-17192 (A VCO feature does not sufficiently validate caller-supplied input, al ...)
@@ -3889,11 +3889,11 @@ CVE-2026-9830 (The bookingpress-appointment-booking-pro WordPress plugin before
 CVE-2026-66412 (Leantime 3.6.2 and prior contains a broken access control vulnerabilit ...)
 	NOT-FOR-US: Leantime
 CVE-2026-17501 (A flaw has been found in ggml-org llama.cpp e15efe0. This vulnerabilit ...)
-	- llama.cpp <unfixed>
+	- llama.cpp <unfixed> (bug #1143156)
 	NOTE: https://github.com/ggml-org/llama.cpp/issues/25283
 	NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
 CVE-2026-17500 (A vulnerability was detected in ggml-org llama.cpp d006858/e15efe0. Th ...)
-	- llama.cpp <unfixed>
+	- llama.cpp <unfixed> (bug #1143156)
 	NOTE: https://github.com/ggml-org/llama.cpp/issues/25284
 	NOTE: https://github.com/ggml-org/llama.cpp/pull/25308
 CVE-2026-15928 (XMLRPC-C Library versions 1.07 through 1.67.01 are vulnerable to a ref ...)
@@ -6775,7 +6775,7 @@ CVE-2026-24552 (Contributor SQL Injection in Create by Mediavine <= 2.5.3 versio
 CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessibility  ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO f ...)
-	- gdk-pixbuf <unfixed>
+	- gdk-pixbuf <unfixed> (bug #1143155)
 	[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
 	[bookworm] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the rendered image; unfixed upstream)
 	[bullseye] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the rendered image; unfixed upstream)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88e47b73d36f69b92d5eabe2632cdc88880f775e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88e47b73d36f69b92d5eabe2632cdc88880f775e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/cb55ef14/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list