[Git][security-tracker-team/security-tracker][master] automatic update
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 31 20:18:31 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7f0e07b3 by security tracker role at 2026-07-31T19:18:26+00:00
automatic update
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,265 @@
+CVE-2026-9611
+ REJECTED
+CVE-2026-68577
+ REJECTED
+CVE-2026-68576
+ REJECTED
+CVE-2026-68575
+ REJECTED
+CVE-2026-68574
+ REJECTED
+CVE-2026-67822 (Tenda W6-S 1.0.0.4(510) contains a stack-based buffer overflow vulnera ...)
+ TODO: check
+CVE-2026-67607 (LightFTP 2.3.1 contains a race condition vulnerability that allows rem ...)
+ TODO: check
+CVE-2026-67350 (Serendipity before 2.6.1 contains an open redirect vulnerability in ex ...)
+ TODO: check
+CVE-2026-65636 (Improper Neutralization of CRLF Sequences vulnerability in ufirstgroup ...)
+ TODO: check
+CVE-2026-65313 (A provisioning script used when installing HIPASE-250 (formerly 250 SC ...)
+ TODO: check
+CVE-2026-65311 (The HTTP server component of ANDRITZ HIPASE-250 (formerly 250 SCALA) i ...)
+ TODO: check
+CVE-2026-65310 (ANDRITZ HIPASE-250 (formerly 250 SCALA), in the default configuration ...)
+ TODO: check
+CVE-2026-65309 (ANDRITZ HIPASE-250 (formerly 250 SCALA) in affected versions stores an ...)
+ TODO: check
+CVE-2026-64607 (HttpClient based on the classic i/o model fails to correctly release t ...)
+ TODO: check
+CVE-2026-59232 (Cross-site Scripting in the lead index view in Roskus Prospero Flow CR ...)
+ TODO: check
+CVE-2026-59231 (Server-Side Request Forgery in the PDF export component in maalfer Pen ...)
+ TODO: check
+CVE-2026-58048 (Improper preservation of SQL mode when renaming databases in cPanel a ...)
+ TODO: check
+CVE-2026-58047 (HTTP Smuggling in cPanel allows potential leak of credentials.)
+ TODO: check
+CVE-2026-57232 (Contao is an Open Source CMS. From 5.3.35 through 5.3.47 and from 5.7. ...)
+ TODO: check
+CVE-2026-56571 (HCL iControl was affected by Improper Error Handling vulnerabilities. ...)
+ TODO: check
+CVE-2026-56570 (HCL iControl was affected by Auto complete Enabled vulnerabilities. It ...)
+ TODO: check
+CVE-2026-56569 (HCL iControl was affected by Sensitive Data Exposure vulnerabilities. ...)
+ TODO: check
+CVE-2026-56568 (HCL iControl was affected by Information Exposure Through Verbose Clie ...)
+ TODO: check
+CVE-2026-56567 (HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerab ...)
+ TODO: check
+CVE-2026-55824 (Contao is an Open Source CMS. In versions 4.13.40 through 5.3.46 and 5 ...)
+ TODO: check
+CVE-2026-55100 (hashi-vault-js is a Node.js module for interacting with the HashiCorp ...)
+ TODO: check
+CVE-2026-54737 (@phun-ky/defaults-deep is a library like lodash defaultsDeep with arra ...)
+ TODO: check
+CVE-2026-54729 (DSSRF is a Node.js library that provides a wide range of utilities and ...)
+ TODO: check
+CVE-2026-54725 (vault-secrets-webhook is a Kubernetes mutating webhook that makes dire ...)
+ TODO: check
+CVE-2026-53505 (Thumbor is an open-source photo thumbnail service by globo.com. Prior ...)
+ TODO: check
+CVE-2026-53504 (Thumbor is an open-source photo thumbnail service by globo.com. Prior ...)
+ TODO: check
+CVE-2026-53503 (Thumbor is an open-source photo thumbnail service by globo.com. Prior ...)
+ TODO: check
+CVE-2026-53502 (Thumbor is an open-source photo thumbnail service by globo.com. Prior ...)
+ TODO: check
+CVE-2026-53501 (Thumbor is an open-source photo thumbnail service by globo.com. Prior ...)
+ TODO: check
+CVE-2026-53500 (Thumbor is an open-source photo thumbnail service by globo.com. Prior ...)
+ TODO: check
+CVE-2026-52857 (Wings is the server control plane for Pterodactyl, a free, open-source ...)
+ TODO: check
+CVE-2026-52856 (Wings is the server control plane for Pterodactyl, a free, open-source ...)
+ TODO: check
+CVE-2026-52855 (Wings is the server control plane for Pterodactyl, a free, open-source ...)
+ TODO: check
+CVE-2026-51301
+ REJECTED
+CVE-2026-51299
+ REJECTED
+CVE-2026-51289
+ REJECTED
+CVE-2026-51288
+ REJECTED
+CVE-2026-51287
+ REJECTED
+CVE-2026-51286
+ REJECTED
+CVE-2026-51285
+ REJECTED
+CVE-2026-51284
+ REJECTED
+CVE-2026-51283
+ REJECTED
+CVE-2026-51282
+ REJECTED
+CVE-2026-51281
+ REJECTED
+CVE-2026-51280
+ REJECTED
+CVE-2026-51279
+ REJECTED
+CVE-2026-51278
+ REJECTED
+CVE-2026-51277
+ REJECTED
+CVE-2026-51276
+ REJECTED
+CVE-2026-51265
+ REJECTED
+CVE-2026-51264
+ REJECTED
+CVE-2026-51262
+ REJECTED
+CVE-2026-51258
+ REJECTED
+CVE-2026-51257
+ REJECTED
+CVE-2026-51256
+ REJECTED
+CVE-2026-51255
+ REJECTED
+CVE-2026-51253
+ REJECTED
+CVE-2026-51250
+ REJECTED
+CVE-2026-51249
+ REJECTED
+CVE-2026-51248
+ REJECTED
+CVE-2026-51247
+ REJECTED
+CVE-2026-51246
+ REJECTED
+CVE-2026-51245
+ REJECTED
+CVE-2026-51243
+ REJECTED
+CVE-2026-51242
+ REJECTED
+CVE-2026-51241
+ REJECTED
+CVE-2026-51240
+ REJECTED
+CVE-2026-51239
+ REJECTED
+CVE-2026-51238
+ REJECTED
+CVE-2026-51237
+ REJECTED
+CVE-2026-51236
+ REJECTED
+CVE-2026-51234
+ REJECTED
+CVE-2026-51233
+ REJECTED
+CVE-2026-51232
+ REJECTED
+CVE-2026-51231
+ REJECTED
+CVE-2026-51230
+ REJECTED
+CVE-2026-51229
+ REJECTED
+CVE-2026-46594 (A reflected cross-site scripting (XSS) vulnerability has been identifi ...)
+ TODO: check
+CVE-2026-46593 (A SQL injection vulnerability has been identified in the PHP Jabbers - ...)
+ TODO: check
+CVE-2026-34497 (Improper neutralization of Script-Related HTML tags in a web page (bas ...)
+ TODO: check
+CVE-2026-34495 (Improper neutralization of input during web page generation ('cross-si ...)
+ TODO: check
+CVE-2026-34490 (Cleartext storage of sensitive information vulnerability in Johnson Co ...)
+ TODO: check
+CVE-2026-28145 (Insufficient Verification of Data Authenticity vulnerability in Stylem ...)
+ TODO: check
+CVE-2026-28144 (Insertion of Sensitive Information Into Sent Data vulnerability in Fli ...)
+ TODO: check
+CVE-2026-25552 (Ghost CLI before 1.30.1 contains an IP spoofing vulnerability that all ...)
+ TODO: check
+CVE-2026-21662 (Unrestricted upload of file with dangerous type vulnerability in Johns ...)
+ TODO: check
+CVE-2026-18481 (Stored cross-site scripting in the participant URL handling in AWS Ops ...)
+ TODO: check
+CVE-2026-18446 (fast-uri before 4.1.2, 3.1.5, and 2.4.4 requires a literal double forw ...)
+ TODO: check
+CVE-2026-18437 (The MailerPress \u2013 Newsletter, email marketing & AI automation plu ...)
+ TODO: check
+CVE-2026-18436 (The MailPress plugin for WordPress is vulnerable to unauthorized acces ...)
+ TODO: check
+CVE-2026-18358 (A flaw was found in gnome-remote-desktop as shipped in Red Hat Enterpr ...)
+ TODO: check
+CVE-2026-18321 (Buffer overflow in NTPsec's Zyfer refclock allows local attacker to cr ...)
+ TODO: check
+CVE-2026-18218 (A flaw was found in the TokenManager component of the Keycloak identit ...)
+ TODO: check
+CVE-2026-18217 (A flaw was found in the SAML protocol implementation of Keycloak, an o ...)
+ TODO: check
+CVE-2026-18215 (Keycloak provides a way to let users log in using Microsoft accounts w ...)
+ TODO: check
+CVE-2026-18214 (Keycloak allows users to log in using Google accounts and can be confi ...)
+ TODO: check
+CVE-2026-18211 (A flaw was found in the secure-client-uris client policy executor with ...)
+ TODO: check
+CVE-2026-18209 (A flaw was found in the keycloak-services component of Keycloak, which ...)
+ TODO: check
+CVE-2026-18208 (A flaw was found in the OIDC token introspection endpoint of the keycl ...)
+ TODO: check
+CVE-2026-18206 (A flaw was found in the keycloak-services component of Keycloak, which ...)
+ TODO: check
+CVE-2026-18203 (A flaw was found in the group policy evaluation logic of Keycloak, an ...)
+ TODO: check
+CVE-2026-18141 (A flaw was found in aap-gateway, a component of Ansible Automation Pla ...)
+ TODO: check
+CVE-2026-17592
+ REJECTED
+CVE-2026-17567 (The Fluent Forms \u2013 Customizable Contact Forms, Survey, Quiz, & Co ...)
+ TODO: check
+CVE-2026-17566 (pgAdmin 4's Import/Export Data tool builds a psql \copy (...) command ...)
+ TODO: check
+CVE-2026-17561 (Improper Control of Generation of Code ('Code Injection') vulnerabilit ...)
+ TODO: check
+CVE-2026-17351 (The fix for CVE-2026-12045 in pgAdmin 4 9.16 required the LLM-supplied ...)
+ TODO: check
+CVE-2026-17350 (The per-tool permission system (custom roles / role-based tool permiss ...)
+ TODO: check
+CVE-2026-17349 (/misc/workspace/adhoc_connect_server, part of the Workspaces feature i ...)
+ TODO: check
+CVE-2026-17348 (In SERVER mode, pgAdmin 4 enforces authentication per route via the @p ...)
+ TODO: check
+CVE-2026-17347 (The MASTER_PASSWORD_HOOK setting, introduced in pgAdmin 4 7.2, lets an ...)
+ TODO: check
+CVE-2026-17346 (The fix for CVE-2026-12044 in pgAdmin 4 9.16 hardened qtLiteral and sw ...)
+ TODO: check
+CVE-2026-16843 (Some Hikvision Wireless Access Points are vulnerable to authenticated ...)
+ TODO: check
+CVE-2026-16504 (Deployment of the VPS.org one-click Zulip template deploys a hardcoded ...)
+ TODO: check
+CVE-2026-16503 (Deployment of the VPS.org one-click Supabase template deploys a Postgr ...)
+ TODO: check
+CVE-2026-16105 (A flaw was found in the RoleContainerResource component of Keycloak. T ...)
+ TODO: check
+CVE-2026-15722 (A stack buffer overflow flaw was found in 389 Directory Server (389-ds ...)
+ TODO: check
+CVE-2026-15227 (Missing authorization in Checkmk <2.5.0p10, <2.4.0p35, <2.3.0p49, and ...)
+ TODO: check
+CVE-2026-11770 (A flaw was found in 389 Directory Server. An unauthenticated remote at ...)
+ TODO: check
+CVE-2026-10686 (Zephyr's IPv6 forwarding path re-sent routed unicast packets without e ...)
+ TODO: check
+CVE-2026-10685 (The Zephyr Bluetooth GATT client CCC-write response handler gatt_write ...)
+ TODO: check
+CVE-2026-10079 (A flaw was found in Red Hat Advanced Cluster Security for Kubernetes ( ...)
+ TODO: check
+CVE-2025-67651 (A Cross-Site Request Forgery (CSRF) vulnerability has been identified ...)
+ TODO: check
+CVE-2025-67650 (An authenticated SQL injection vulnerability has been identified in mu ...)
+ TODO: check
+CVE-2025-67649 (A SQL injection vulnerability has been identified in PHP Jabbers -Car ...)
+ TODO: check
+CVE-2025-62347 (HCL iControl was affected by Improper Input Validation vulnerability. ...)
+ TODO: check
CVE-2026-XXXX [GHSA-6v6x-387m-rj4w: Project restriction bypass on network address sets]
- incus 7.0.1-2
[trixie] - incus <not-affected> (Vulnerable code not present)
@@ -428,19 +690,26 @@ CVE-2026-54363 (CentreStack before 17.5 contains a hardcoded cryptographic key v
NOT-FOR-US: CentreStack
CVE-2026-53431 (Authentication Bypass by Capture-replay vulnerability in malach-it Bor ...)
NOT-FOR-US: malach-it Boruta
-CVE-2026-51295 (SQLite 3.41 is vulnerable to use after free in the jsonExtractFunc fun ...)
+CVE-2026-51295
+ REJECTED
TODO: check
-CVE-2026-51294 (SQLite 3.41 is vulnerable to use after free in the jsonArrayLengthFunc ...)
+CVE-2026-51294
+ REJECTED
TODO: check
-CVE-2026-51293 (A use-after-free vulnerability exists in SQLite 3.41 when the jsonBlob ...)
+CVE-2026-51293
+ REJECTED
TODO: check
-CVE-2026-51292 (sqlite 3.41 has a use-after-free vulnerability in the memory buffer pr ...)
+CVE-2026-51292
+ REJECTED
TODO: check
-CVE-2026-51291 (sqlite 3.41 is vulnerable to use after free in the json.c jsonCacheIns ...)
+CVE-2026-51291
+ REJECTED
TODO: check
-CVE-2026-51290 (SQLite 3.41 has a use-after-free vulnerability in the shared cache loc ...)
+CVE-2026-51290
+ REJECTED
TODO: check
-CVE-2026-51272 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
+CVE-2026-51272
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-4978 (Improper neutralization of special elements used in an SQL command ('S ...)
NOT-FOR-US: Traffic Analysis System
@@ -2267,6 +2536,7 @@ CVE-2026-65100 (Apache Traffic Server updates the HTTP/2 HPACK dynamic table bef
- trafficserver <unfixed> (bug #1143062)
NOTE: https://lists.apache.org/thread/5prl9glcm9g2swnq9hqxvnokylm1gr6d
CVE-2026-64557 (In the Linux kernel, the following vulnerability has been resolved: B ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/6fef032af0092ed5ccb767239a9ac1bc38c08a40 (7.2-rc3)
CVE-2026-64556 (In the Linux kernel, the following vulnerability has been resolved: p ...)
@@ -2582,14 +2852,17 @@ CVE-2025-60931 (An Insecure Direct Object Reference (IDOR) in the Employee Compe
CVE-2025-10656 (The Spreadsheet Price Changer for WooCommerce and WP E-commerce \u2013 ...)
NOT-FOR-US: WordPress plugin
CVE-2026-64560 (In the Linux kernel, the following vulnerability has been resolved: p ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/920f893f735e92ba3a1cd9256899a186b161928d (7.2-rc3)
CVE-2026-64559 (In the Linux kernel, the following vulnerability has been resolved: s ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b3d4ab2d7df9426f7f1d3671d7e2108f2ca6e970 (7.2-rc1)
CVE-2026-64558 (In the Linux kernel, the following vulnerability has been resolved: s ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -3013,37 +3286,53 @@ CVE-2026-54332 (gopacket provides packet processing capabilities for Go. In vers
- gopacket <unfixed> (bug #1143055)
NOTE: https://github.com/gopacket/gopacket/security/advisories/GHSA-g6v3-7xmc-w563
NOTE: Fixed by: https://github.com/gopacket/gopacket/commit/76119086f5936aacd7088bdf97d565501bb6c4cc (v1.6.1)
-CVE-2026-51275 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in ...)
+CVE-2026-51275
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51274 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow in ...)
+CVE-2026-51274
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51273 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
+CVE-2026-51273
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51271 (In schreibfaul1 ESP32-audioI2S 3.4.5, a heap-based buffer overflow vul ...)
+CVE-2026-51271
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51270 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+CVE-2026-51270
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51269 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+CVE-2026-51269
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51268 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+CVE-2026-51268
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51267 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+CVE-2026-51267
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51266 (schreibfaul1 ESP32-audioI2S 3.4.5 has a heap-based buffer overflow vul ...)
+CVE-2026-51266
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51263 (schreibfaul1 ESP32-audioI2S 3.4.5 is vulnerable to Buffer Overflow. Th ...)
+CVE-2026-51263
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51261 (Missing mutex synchronization in AudioBuffer::freeSpace() in schreibfa ...)
+CVE-2026-51261
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51260 (Unsafe fixed-size memcpy operation in AudioBuffer::writeSpace() of sch ...)
+CVE-2026-51260
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51259 (Unchecked unsigned integer overflow in buffer size calculation in schr ...)
+CVE-2026-51259
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51254 (schreibfaul1 ESP32-audioI2S v3.4.5 has an integer underflow vulnerabil ...)
+CVE-2026-51254
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51252 (schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability ...)
+CVE-2026-51252
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51251 (Schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability ...)
+CVE-2026-51251
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
CVE-2026-50738 (A use-after-free condition exists in pglogical's worker signaling code ...)
- pglogical 2.4.8-1
@@ -3715,65 +4004,84 @@ CVE-2026-12001 (A hardcoded credential vulnerability exists in the firmware of m
CVE-2025-63913 (An issue was discovered in OpenSBI 1.3 allowing attackers to cause a d ...)
TODO: check
CVE-2026-64555 (In the Linux kernel, the following vulnerability has been resolved: K ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/ff1022c3de46753eb7eba2f6efd990569e66ff95 (7.2-rc4)
CVE-2026-64554 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/86f3ce81dd2b4b0aa2c3016c989a943e4b1b643d (7.2-rc4)
CVE-2026-64553 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/aedd02af1f8b0bceb7f42f5a21c41634ca9ed390 (7.2-rc1)
CVE-2026-64552 (In the Linux kernel, the following vulnerability has been resolved: v ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/9e5ad06ea826322ce8c58b4a68442a96f600c3c4 (7.2-rc1)
CVE-2026-64551 (In the Linux kernel, the following vulnerability has been resolved: s ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/1cd23ca80784223fa2204e16203f754da4e821f8 (7.2-rc4)
CVE-2026-64550 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/f0f1887a9e30712a1df03e152dce6fb91344b1f3 (7.2-rc3)
CVE-2026-64549 (In the Linux kernel, the following vulnerability has been resolved: B ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/dd068ef044128db655f48323a4acfd5907e04903 (7.2-rc3)
CVE-2026-64548 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/0c0a8ed85349dae298712d79cb276acfeb794d82 (7.2-rc1)
CVE-2026-64547 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/03f384bc0cb8d4a1301d4f5b0baef2d980258383 (7.2-rc3)
CVE-2026-64546 (In the Linux kernel, the following vulnerability has been resolved: d ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/faaa1e1155833e7d4ce7e3cfaf64c0d636b190db (7.2-rc1)
CVE-2026-64545 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e82d8cc4321c373dc46e741cd2dfdaa7921fddb7 (7.2-rc1)
CVE-2026-64544 (In the Linux kernel, the following vulnerability has been resolved: c ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/f7dd32c5179d7755de18e21d5674b08f9e5cb180 (7.2-rc1)
CVE-2026-64543 (In the Linux kernel, the following vulnerability has been resolved: t ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/1579342d71133da7f00daa02c75cebec7372097b (7.2-rc1)
CVE-2026-64542 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/d186e942365acece7c56d39da05dd63bf95b280a (7.2-rc1)
CVE-2026-64541 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/9d160b35cc34a2ba8229d07651468a7848325135 (7.2-rc3)
CVE-2026-64540 (In the Linux kernel, the following vulnerability has been resolved: u ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/8ff7f2a6da4fccaa5cc9be7251a24e71e29fbd1a (7.2-rc2)
CVE-2026-64539 (In the Linux kernel, the following vulnerability has been resolved: B ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/6f5fb689fdf80bdd143f22a502f9eb1f3c85e286 (7.2-rc1)
CVE-2026-64538 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6405-1}
- linux 7.1.5-1
NOTE: https://git.kernel.org/linus/46c3b8191aad3d032776bf3bebf03efdf5f4b905 (7.2-rc1)
CVE-2026-64537 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f3e02edd8322b31b8e6517faa6ba053bf29d1e26 (7.2-rc1)
@@ -4068,23 +4376,32 @@ CVE-2026-54272 (ip-address is a library for parsing and manipulating IPv4 and IP
NOTE: https://github.com/beaugunderson/ip-address/security/advisories/GHSA-22jq-vg5j-6vgg
NOTE: The is* classification API was introduced for Address4 in 10.1.1 and extended to
NOTE: Address6 in 10.2.0.
-CVE-2026-51304 (sqlite 3.41 has a use-after-free (UAF) vulnerability in the ORDER BY c ...)
+CVE-2026-51304
+ REJECTED
TODO: check
-CVE-2026-51303 (A use-after-free (UAF) vulnerability was discovered in the core parsin ...)
+CVE-2026-51303
+ REJECTED
TODO: check
-CVE-2026-51302 (SQLite 3.41 has a use-after-free vulnerability exists in the expressio ...)
+CVE-2026-51302
+ REJECTED
TODO: check
-CVE-2026-51300 (A use-after-free vulnerability exists in the expression parsing and me ...)
+CVE-2026-51300
+ REJECTED
TODO: check
-CVE-2026-51298 (sqlite 3.41 is vulnerable to use after free in the JSON extraction fun ...)
+CVE-2026-51298
+ REJECTED
TODO: check
-CVE-2026-51297 (sqlite 3.41 has a use-after-free vulnerability in the JSON parsing log ...)
+CVE-2026-51297
+ REJECTED
TODO: check
-CVE-2026-51296 (SQLite 3.41 has a use-after-free vulnerability in jsonRemoveFunc of SQ ...)
+CVE-2026-51296
+ REJECTED
TODO: check
-CVE-2026-51244 (schreibfaul1 ESP32-audioI2S 3.4.5 has a buffer overflow vulnerability ...)
+CVE-2026-51244
+ REJECTED
NOT-FOR-US: schreibfaul1 ESP32-audioI2S
-CVE-2026-51235 (LibRaw 0.21 is vulnerable to Buffer Overflow in the stretch() function ...)
+CVE-2026-51235
+ REJECTED
TODO: check
CVE-2026-49158 (Improper Handling of Highly Compressed Data (Data Amplification) vulne ...)
- thrift <unfixed>
@@ -4303,20 +4620,25 @@ CVE-2026-64536 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/3bf39f711ff27c64be8680a8938bcc5001982e81 (7.2-rc3)
CVE-2026-64535 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/dbbd07d0a7020b80f6a7028e561908f7b83b3d5a (7.1-rc4)
CVE-2026-64534 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.3-1
NOTE: https://git.kernel.org/linus/4606467a75cfc16721937272ed29462a750b60c8 (7.1-rc2)
CVE-2026-64533 (In the Linux kernel, the following vulnerability has been resolved: f ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/6a4c53a2e26a865565bd6a460961e8d6fcb32329 (7.2-rc1)
CVE-2026-64532 (In the Linux kernel, the following vulnerability has been resolved: f ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/3e127829e57f5190f612412ece4541cb96d5ec7a (7.2-rc1)
CVE-2026-64531 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/3f1f755366687d051174739fb99f7d560202f60b (7.2-rc4)
@@ -4406,6 +4728,7 @@ CVE-2026-9238 [hw/9pfs: cap Treaddir allocation]
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d2a298f359477fd6fa30dd6aa7357115b596012d (v11.0.3)
NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/169537e616a894175cd7c876c83b4801fe099232 (v10.0.12)
CVE-2026-64530 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.5-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/a8a02897f2b479127db261de05cbf0c28b98d159 (7.2-rc1)
@@ -5039,18 +5362,22 @@ CVE-2026-64512 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/1b1acf2dada0cc3931bb2cb9ff8832edfbee46a1 (7.2-rc1)
CVE-2026-64510 (In the Linux kernel, the following vulnerability has been resolved: A ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/38bf27511ef41bffebd157ec3eba41fc89ba59cd (7.2-rc1)
CVE-2026-64509 (In the Linux kernel, the following vulnerability has been resolved: r ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/2957771379fa335103a4b539db57bb2271e12142 (7.2-rc1)
CVE-2026-64508 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/96cce16e26dd02a8678f1e87f88a4b5cdb63b995 (7.2-rc2)
CVE-2026-64507 (In the Linux kernel, the following vulnerability has been resolved: x ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/a3af84b0fa00ead01fcd0e28b5d773ff25990a0d (7.2-rc2)
@@ -5087,6 +5414,7 @@ CVE-2026-64494 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/38b72267b7e22768a1f26d9935de4e1752a1dc85 (7.2-rc3)
CVE-2026-64493 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -5097,6 +5425,7 @@ CVE-2026-64489 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e64d170346d00b580c0043de3e5ccb3e331c47d4 (7.2-rc1)
CVE-2026-64488 (In the Linux kernel, the following vulnerability has been resolved: A ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/8df560fefe6fed6a20b7e06720eeaeccec349ac0 (7.2-rc1)
CVE-2026-64487 (In the Linux kernel, the following vulnerability has been resolved: A ...)
@@ -5122,6 +5451,7 @@ CVE-2026-64482 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c7fa99d30c7a166a5e5db5a585ce7501ff68326b (7.2-rc1)
CVE-2026-64481 (In the Linux kernel, the following vulnerability has been resolved: A ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/b65020d5398f499c09498c9786dba6d67ae57664 (7.2-rc1)
@@ -5144,6 +5474,7 @@ CVE-2026-64475 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/daedde7f024ecf88bc8e832ed40cf2c795f0796a (7.2-rc2)
CVE-2026-64472 (In the Linux kernel, the following vulnerability has been resolved: v ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/f2365a63b02ddea32e7db78b742c2503ec7b81f1 (7.2-rc2)
@@ -5172,9 +5503,11 @@ CVE-2026-64463 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/e8da46d99d3710106e7c44db14566bf9b57386b5 (7.2-rc3)
CVE-2026-64462 (In the Linux kernel, the following vulnerability has been resolved: P ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/7a94138caeb27f3c49c1dbd93bf422098925bb28 (7.2-rc1)
CVE-2026-64461 (In the Linux kernel, the following vulnerability has been resolved: P ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/f865a57896bd92d7662eb2818d8f48872e2cbbc7 (7.2-rc1)
CVE-2026-64458 (In the Linux kernel, the following vulnerability has been resolved: m ...)
@@ -5232,6 +5565,7 @@ CVE-2026-64442 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/ef61d628dfad38fead1fd2e08979ae9126d011d5 (7.2-rc3)
CVE-2026-64441 (In the Linux kernel, the following vulnerability has been resolved: s ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/1463ca3ec6601cbb097d8d87dbf5dcf1cb86a344 (7.2-rc3)
CVE-2026-64440 (In the Linux kernel, the following vulnerability has been resolved: s ...)
@@ -5239,6 +5573,7 @@ CVE-2026-64440 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/f8001e1a516ba3b495728c65b61f799cbfad6bd0 (7.2-rc3)
CVE-2026-64438 (In the Linux kernel, the following vulnerability has been resolved: c ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/277281c10c63791067d24d421f7c43a15faa9096 (7.2-rc1)
CVE-2026-64437 (In the Linux kernel, the following vulnerability has been resolved: k ...)
@@ -5255,6 +5590,7 @@ CVE-2026-64435 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/c9a71daaecb2fb1d8c704545cc0b1c920b9bf5d7 (7.2-rc3)
CVE-2026-64434 (In the Linux kernel, the following vulnerability has been resolved: B ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/b66774b48dd98f07254951f74ea6f513efe7ff8b (7.2-rc1)
CVE-2026-64432 (In the Linux kernel, the following vulnerability has been resolved: f ...)
@@ -5272,6 +5608,7 @@ CVE-2026-64429 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/90f0109019e6817eb40a486671b7722d1544ae29 (7.2-rc1)
CVE-2026-64428 (In the Linux kernel, the following vulnerability has been resolved: g ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/286533cb14a3c8a8bd39ff64ea2fc8e1aa0f638b (7.2-rc1)
@@ -5292,6 +5629,7 @@ CVE-2026-64422 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/efb8763d7bbb40cff4cc55a6b62c3095a038149c (7.2-rc1)
CVE-2026-64421 (In the Linux kernel, the following vulnerability has been resolved: m ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -5311,11 +5649,13 @@ CVE-2026-64417 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e30453c61e185e914fde83c650e268067b140218 (7.2-rc3)
CVE-2026-64416 (In the Linux kernel, the following vulnerability has been resolved: m ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/63b02a9409cb5180398491b093e48bcb5315f5fb (7.2-rc1)
CVE-2026-64413 (In the Linux kernel, the following vulnerability has been resolved: n ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/cbfe53599eebffd188938ab6774cc41794f6f9d5 (7.2-rc3)
CVE-2026-64412 (In the Linux kernel, the following vulnerability has been resolved: n ...)
@@ -5340,6 +5680,7 @@ CVE-2026-64406 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/4bd0b274054f2679f28b70222b607bb0afc3ab9a (7.2-rc3)
CVE-2026-64405 (In the Linux kernel, the following vulnerability has been resolved: B ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux 6.1.119-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -5349,6 +5690,7 @@ CVE-2026-64403 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/687617555cedfb74c9e3cb85d759b908dcb17856 (7.2-rc3)
CVE-2026-64401 (In the Linux kernel, the following vulnerability has been resolved: s ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/ec457f9afe5ae9538bdcd58fd4cb442b9787e183 (7.2-rc1)
@@ -5402,6 +5744,7 @@ CVE-2026-64391 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/baa5e094886fffa7e6272edcb5e08be5ce28262c (7.2-rc1)
CVE-2026-64390 (In the Linux kernel, the following vulnerability has been resolved: k ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c1016dd1d8b2bcd1158bbaabe94a31bb7e7431fb (7.2-rc1)
@@ -5440,6 +5783,7 @@ CVE-2026-64376 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/896df22ee57648b0c505bd76ddbc6b2341834696 (7.2-rc1)
CVE-2026-64375 (In the Linux kernel, the following vulnerability has been resolved: p ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/6255da28d4bb5349fe18e84cb043ccd394eba75d (7.2-rc1)
CVE-2026-64374 (In the Linux kernel, the following vulnerability has been resolved: s ...)
@@ -5455,6 +5799,7 @@ CVE-2026-64372 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/266d3dd8b757b48a576e90f018b51f7b7563cc32 (7.2-rc1)
CVE-2026-64371 (In the Linux kernel, the following vulnerability has been resolved: p ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/6650527444dadc63d84aa939d14ecba4fadb2f69 (7.2-rc1)
CVE-2026-64370 (In the Linux kernel, the following vulnerability has been resolved: p ...)
@@ -5462,6 +5807,7 @@ CVE-2026-64370 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/87bd2ad568e15b90d5f7d4bcd70342d05dad649c (7.2-rc1)
CVE-2026-64369 (In the Linux kernel, the following vulnerability has been resolved: s ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -5472,9 +5818,11 @@ CVE-2026-64365 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/46c8beeccd8ab2c863827254a85ea877654a3534 (7.2-rc3)
CVE-2026-64364 (In the Linux kernel, the following vulnerability has been resolved: H ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/8813b0612275cc61fe9e6603d0ee019247ade6be (7.2-rc3)
CVE-2026-64363 (In the Linux kernel, the following vulnerability has been resolved: H ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/75fe87e19d8aff81eb2c64d15d244ab8da4de945 (7.2-rc3)
CVE-2026-64362 (In the Linux kernel, the following vulnerability has been resolved: H ...)
@@ -5482,6 +5830,7 @@ CVE-2026-64362 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/7705b4140d188ce22656f6e541ae7ef834c7e11a (7.2-rc3)
CVE-2026-64361 (In the Linux kernel, the following vulnerability has been resolved: h ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/966cb76fb2857a4242cab6ea2ea17acf818a3da7 (7.2-rc1)
CVE-2026-64360 (In the Linux kernel, the following vulnerability has been resolved: h ...)
@@ -5498,6 +5847,7 @@ CVE-2026-64355 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/aa496720618f1a6054f1c870bf10b4f6c99bf656 (7.2-rc1)
CVE-2026-64352 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/2f884d371fafea137afea504d49ee4a7c8d7985b (7.2-rc1)
@@ -5540,6 +5890,7 @@ CVE-2026-64342 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/bc0e4f16c44e50daa0b1ea729934baa3b4815dee (7.2-rc3)
CVE-2026-64341 (In the Linux kernel, the following vulnerability has been resolved: U ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/c602254ba4c10f60a73cd99d147874f86a3f485c (7.2-rc3)
CVE-2026-64340 (In the Linux kernel, the following vulnerability has been resolved: U ...)
@@ -5639,6 +5990,7 @@ CVE-2026-64312 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.96-1
NOTE: https://git.kernel.org/linus/ed459fe319376e876de433d12b6c6772e612ca36 (7.2-rc1)
CVE-2026-64307 (In the Linux kernel, the following vulnerability has been resolved: c ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -5692,11 +6044,13 @@ CVE-2026-64290 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/172fc8b19825a0f5884c38f2289188284e2d45ee (7.2-rc1)
CVE-2026-64287 (In the Linux kernel, the following vulnerability has been resolved: K ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/8cc8bbbfab14c22c5551d0dd19b208a44b141c76 (7.2-rc1)
CVE-2026-64286 (In the Linux kernel, the following vulnerability has been resolved: K ...)
+ {DSA-6405-1}
- linux 7.1.4-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -6069,6 +6423,7 @@ CVE-2026-64228 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/e3adf69f8eb121a9128c2b0029efd050d3649153 (7.1-rc4)
CVE-2026-64227 (In the Linux kernel, the following vulnerability has been resolved: A ...)
+ {DSA-6405-1}
- linux 7.0.12-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -11722,6 +12077,7 @@ CVE-2026-64207 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/05ed733b65ab977dd931e7f7ac0f62fdb81205c2 (7.2-rc1)
CVE-2026-64206 (In the Linux kernel, the following vulnerability has been resolved: B ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/2641a9e0a1dd4af2e21995470a21d55dd35e5203 (7.2-rc3)
CVE-2026-64205 (In the Linux kernel, the following vulnerability has been resolved: i ...)
@@ -11730,6 +12086,7 @@ CVE-2026-64205 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/10dd1a736d557e310a77117832874729a0175d57 (7.2-rc1)
CVE-2026-64192 (In the Linux kernel, the following vulnerability has been resolved: b ...)
+ {DSA-6405-1}
- linux 7.1.4-1
NOTE: https://git.kernel.org/linus/a6f0643e4f63cfaa0d5d4a69de4f132eac4b8fe4 (7.2-rc2)
CVE-2026-64191 (In the Linux kernel, the following vulnerability has been resolved: i ...)
@@ -13638,6 +13995,7 @@ CVE-2026-63974 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/525daaea459fc215f432de1b8debbd9144bf97b0 (7.1-rc6)
CVE-2026-63970 (In the Linux kernel, the following vulnerability has been resolved: v ...)
+ {DSA-6405-1}
- linux 7.0.12-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -19139,6 +19497,7 @@ CVE-2026-57363 (Improper Neutralization of Input During Web Page Generation ('Cr
CVE-2026-55772 (CedarJava is an open source Java implementation of the Cedar policy la ...)
NOT-FOR-US: CedarJava
CVE-2026-53365 (In the Linux kernel, the following vulnerability has been resolved: v ...)
+ {DSA-6405-1}
- linux 7.0.12-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -31607,6 +31966,7 @@ CVE-2026-53262 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.94-1
NOTE: https://git.kernel.org/linus/a213a8950414c684999dcf03edeea6c46ede172e (7.1-rc7)
CVE-2026-53260 (In the Linux kernel, the following vulnerability has been resolved: t ...)
+ {DSA-6405-1}
- linux 7.0.13-1
[bookworm] - linux <not-affected> (Vulnerable code not present)
[bullseye] - linux <not-affected> (Vulnerable code not present)
@@ -33460,6 +33820,7 @@ CVE-2026-53006 (In the Linux kernel, the following vulnerability has been resolv
[trixie] - linux 6.12.94-1
NOTE: https://git.kernel.org/linus/f996edd7615e686ada141b7f3395025729ff8ccb (7.1-rc1)
CVE-2026-53005 (In the Linux kernel, the following vulnerability has been resolved: a ...)
+ {DSA-6405-1}
- linux 7.0.10-1
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/965dc93481d1b80d341bdd16c27b16fe197175ee (7.1-rc1)
@@ -40949,7 +41310,8 @@ CVE-2026-7250 (GitLab has remediated an issue in GitLab CE/EE affecting all vers
- gitlab <removed>
CVE-2026-6976 (GitLab has remediated an issue in GitLab CE/EE affecting all versions ...)
- gitlab <removed>
-CVE-2026-6552 (GitLab has remediated an issue in GitLab EE affecting all versions fro ...)
+CVE-2026-6552
+ REJECTED
- gitlab <not-affected> (Only affects Gitlab EE)
CVE-2026-6338 (A HTTP request smuggling and desynchronization vulnerability affects K ...)
NOT-FOR-US: Kong Gateway Enterprise
@@ -41735,13 +42097,13 @@ CVE-2025-10237 (During an internal security assessment, a potential vulnerabilit
NOT-FOR-US: Lenovo
CVE-2024-58350 (Ghidra before 11.2 contains a use after free vulnerability in the Slei ...)
- ghidra <itp> (bug #923851)
-CVE-2026-54706 [OnionShare follows symlinks in shared directories, allowing unintended disclosure of local files]
+CVE-2026-54706 (OnionShare is an open source tool that lets you securely and anonymous ...)
- onionshare 2.6.4-1 (bug #1139717)
[trixie] - onionshare <no-dsa> (Minor issue)
[bookworm] - onionshare <postponed> (Minor issue; requires sharing a directory containing untrusted symlinks)
[bullseye] - onionshare <postponed> (Minor issue; requires sharing a directory containing untrusted symlinks)
NOTE: https://github.com/onionshare/onionshare/security/advisories/GHSA-22p9-r2f5-22mf
-CVE-2026-54707 [OnionShare Receive mode writes uploaded files even when file uploads are disabled]
+CVE-2026-54707 (OnionShare is an open source tool that lets you securely and anonymous ...)
- onionshare 2.6.4-1 (bug #1139716)
[trixie] - onionshare <no-dsa> (Minor issue)
[bookworm] - onionshare <postponed> (Minor issue; policy bypass by a peer who already holds the onion address and key)
@@ -44826,7 +45188,7 @@ CVE-2026-62393 (Improper Handling of Insufficient Permissions or Privileges vuln
NOT-FOR-US: Apache Kylin (different from Kylin desktop environment)
CVE-2026-62392 (Improper Neutralization of Special Elements used in an OS Command ('OS ...)
NOT-FOR-US: Apache Kylin (different from Kylin desktop environment)
-CVE-2026-62391
+CVE-2026-62391 (The security fix for CVE-2025-66518 is incomplete.Any client who can a ...)
NOT-FOR-US: Apache Kyuubi
CVE-2026-62390 (Improper Neutralization of Special Elements used in an SQL Command ('S ...)
NOT-FOR-US: Apache Kylin (different from Kylin desktop environment)
@@ -52487,6 +52849,7 @@ CVE-2026-44710 (pam_usb provides hardware authentication for Linux using ordinar
CVE-2026-44709 (pam_usb provides hardware authentication for Linux using ordinary remo ...)
NOT-FOR-US: pam_usb
CVE-2026-44681 (Authlib is a Python library which builds OAuth and OpenID Connect serv ...)
+ {DLA-4708-1}
- python-authlib 1.7.2-1
NOTE: https://github.com/authlib/authlib/security/advisories/GHSA-r95x-qfjj-fjj2
CVE-2026-44660 (UltraJSON is a fast JSON encoder and decoder written in pure C with bi ...)
@@ -54524,6 +54887,7 @@ CVE-2026-45945 (In the Linux kernel, the following vulnerability has been resolv
[bullseye] - linux <not-affected> (Vulnerable code not present)
NOTE: https://git.kernel.org/linus/c3b1edea3791fa91ab7032faa90355913ad9451b (7.0-rc1)
CVE-2026-45944 (In the Linux kernel, the following vulnerability has been resolved: i ...)
+ {DSA-6405-1}
- linux 6.18.14-1
NOTE: https://git.kernel.org/linus/c1e4f1dccbe9d7656d1c6872ebeadb5992d0aaa2 (7.0-rc1)
CVE-2026-45943 (In the Linux kernel, the following vulnerability has been resolved: e ...)
@@ -61786,7 +62150,7 @@ CVE-2026-44617 (LDAP filter injection vulnerability in Apache Zeppelin. LdapReal
NOT-FOR-US: Apache Zeppelin
CVE-2026-44616 (LDAP injection vulnerability in Apache Zeppelin. ActiveDirectoryGroupR ...)
NOT-FOR-US: Apache Zeppelin
-CVE-2026-44615
+CVE-2026-44615 (Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebo ...)
NOT-FOR-US: Apache Zeppelin
CVE-2026-44613 (Cross-Site Request Forgery (CSRF) vulnerability in Apache Zeppelin. Th ...)
NOT-FOR-US: Apache Zeppelin
@@ -209586,11 +209950,11 @@ CVE-2025-4530 (A vulnerability was found in feng_ha_ha/megagao ssm-erp and produ
NOT-FOR-US: feng_ha_ha/megagao ssm-erp production_ssm
CVE-2025-4529 (A vulnerability was found in Seeyon Zhiyuan OA Web Application System ...)
NOT-FOR-US: Seeyon Zhiyuan OA Web Application System
-CVE-2025-4528 (A weakness has been identified in D\xedgitro NGC Explorer up to 3.44.1 ...)
+CVE-2025-4528 (A weakness has been identified in D\xedgitro NGC Explorer up to 3.48.2 ...)
NOT-FOR-US: Digitro NGC Explorer
CVE-2025-4527 (A security flaw has been discovered in D\xedgitro NGC Explorer up to 3 ...)
NOT-FOR-US: Digitro NGC Explorer
-CVE-2025-4526 (A vulnerability was identified in D\xedgitro NGC Explorer up to 3.44.1 ...)
+CVE-2025-4526 (A vulnerability was identified in D\xedgitro NGC Explorer up to 3.48.2 ...)
NOT-FOR-US: Digitro NGC Explorer
CVE-2025-4525 (A vulnerability, which was classified as critical, has been found in D ...)
NOT-FOR-US: Discord
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f0e07b351a6301339b60d2416e4fb850d5ef7a4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7f0e07b351a6301339b60d2416e4fb850d5ef7a4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/b7d16c5a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list