[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 1 13:55:18 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eef7db4e by Moritz Muehlenhoff at 2026-09-01T14:55:08+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -370,22 +370,26 @@ CVE-2026-82855 (@hulumi/policies versions before 1.3.2 contain an evidence valid
 	NOT-FOR-US: Hulumi
 CVE-2026-82854 (Nodemailer before 8.0.4 is vulnerable to SMTP command injection throug ...)
 	- node-nodemailer 8.0.4+~7.0.11-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-c7w3-x93f-qmm8
 CVE-2026-82853 (Nodemailer versions before 8.0.5 contain an SMTP command injection vul ...)
 	- node-nodemailer 8.0.11+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-vvjj-xcjg-gr5g
 CVE-2026-82838 (The default docker image shipped for Venueless did not properly ensure ...)
 	NOT-FOR-US: rami.io products
 CVE-2026-82823
 	REJECTED
 CVE-2026-82821 (A vulnerability was determined in FLVMeta up to 1.2.2. Affected by thi ...)
-	- flvmeta <unfixed>
+	- flvmeta <unfixed> (unimportant)
 	NOTE: https://github.com/noirotm/flvmeta/issues/28
 	NOTE: Fixed by: https://github.com/noirotm/flvmeta/commit/52642f7dfb76ec7334016622dde60b1ae963d79b
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-82820 (A vulnerability was found in FLVMeta up to 1.2.2. Affected is the func ...)
-	- flvmeta <unfixed>
+	- flvmeta <unfixed> (unimportant)
 	NOTE: https://github.com/noirotm/flvmeta/issues/27
 	NOTE: Fixed by: https://github.com/noirotm/flvmeta/commit/f412a33b9a84c2d1a9dee145a868feddbf64879e
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-82818 (A vulnerability was determined in dibo-software diboot 3.8.0. This aff ...)
 	NOT-FOR-US: dibo-software diboot
 CVE-2026-82817 (A vulnerability was found in dibo-software diboot 3.8.0. Affected by t ...)
@@ -416,6 +420,7 @@ CVE-2026-82801 (A vulnerability was detected in NASA earthdata-search 1.0.0. Aff
 	NOT-FOR-US: NASA earthdata-search
 CVE-2026-82797 (Uncontrolled Recursion vulnerability in Samsung Open Source rlottie al ...)
 	- rlottie <unfixed>
+	[trixie] - rlottie <no-dsa> (Minor issue)
 	NOTE: https://github.com/Samsung/rlottie/pull/603
 CVE-2026-82703 (A security flaw has been discovered in Edimax BR-6214K 1.40. This vuln ...)
 	NOT-FOR-US: Edimax
@@ -913,6 +918,7 @@ CVE-2026-82592 (A vulnerability was detected in D-Link DIR-825M 1.1.8. This affe
 	NOT-FOR-US: D-Link
 CVE-2026-82591 (A security vulnerability has been detected in Open Asset Import Librar ...)
 	- assimp <unfixed>
+	[trixie] - assimp <no-dsa> (Minor issue)
 	NOTE: https://github.com/assimp/assimp/pull/6718
 	NOTE: Fixed by: https://github.com/assimp/assimp/commit/bf9dabb617c46e5133dac65cca6bff177917afcb
 CVE-2026-82590 (A weakness has been identified in Open5GS up to 2.7.7. The affected el ...)
@@ -1287,6 +1293,7 @@ CVE-2026-82456 (argocd-mcp 0.8.0 binds its HTTP transport to every network inter
 	NOT-FOR-US: Argo CD
 CVE-2026-82455 (RubyGems fails to re-validate path containment after filesystem symlin ...)
 	- rubygems <unfixed>
+	[trixie] - rubygems <no-dsa> (Minor issue)
 	NOTE: https://github.com/ruby/rubygems/pull/9493
 	NOTE: Fixed by (merge): https://github.com/ruby/rubygems/commit/103ca4230deacb31b9fcd813de109e83b5fc71ac
 CVE-2026-82454 (The Omnivore API (packages/api) before the fix in commit abf53d6 conta ...)
@@ -2920,6 +2927,7 @@ CVE-2026-81522 (A weakness in the MongoDB C++ Driver's handling of caller-suppli
 	NOTE: https://jira.mongodb.org/browse/CXX-3552
 CVE-2026-81521 (The MongoDB Go Driver's client-level bulk write operation may accept a ...)
 	- golang-mongodb-mongo-driver <unfixed>
+	[trixie] - golang-mongodb-mongo-driver <no-dsa> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/GODRIVER-4075
 CVE-2026-78618 (A business logic flaw in WatchGuard Dimension allows an authenticated  ...)
 	NOT-FOR-US: WatchGuard
@@ -6626,15 +6634,19 @@ CVE-2026-79773 (Winter CMS before 1.2.13 contains a local file inclusion vulnera
 	NOT-FOR-US: Winter CMS
 CVE-2026-79772 (Nokogiri versions before 1.19.1 fail to check the return value from xm ...)
 	- ruby-nokogiri 1.19.1+dfsg-1
+	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-wx95-c6cv-8532
 CVE-2026-79771 (Nokogiri versions before 1.19.3 contain a memory leak in the XSLT Styl ...)
 	- ruby-nokogiri 1.19.3+dfsg-1
+	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-v2fc-qm4h-8hqv
 CVE-2026-79770 (Nokogiri versions before 1.19.3 contain regular expression denial of s ...)
 	- ruby-nokogiri 1.19.3+dfsg-1
+	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-c4rq-3m3g-8wgx
 CVE-2026-79769 (Nokogiri versions before 1.19.4 contain a possible invalid (out-of-bou ...)
 	- ruby-nokogiri 1.19.4+dfsg-1
+	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-g9g8-vgvw-g3vf
 CVE-2026-79717 (A server-side request forgery (SSRF) vulnerability was found in galaxy ...)
 	NOT-FOR-US: Ansible Galaxy server plugin for Pulp
@@ -7523,6 +7535,7 @@ CVE-2026-52490 (An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 all
 	NOTE: Fixed by: https://gitlab.com/libtiff/libtiff/-/commit/b04e935cb6242f22cc8b63c99a372cf3ea825e4e (v4.7.2rc2)
 CVE-2026-45404 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From versi ...)
 	- golang-opentelemetry-otel <unfixed>
+	[trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
 	NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-42cj-99w8-cp2p
 CVE-2026-34968 (Adminer before 5.4.3 contains an arbitrary file deletion vulnerability ...)
 	- adminer 5.4.3+dfsg-1
@@ -15291,6 +15304,7 @@ CVE-2026-70415 (Dell PowerStore SDNAS contains a Buffer Copy without Checking Si
 	NOT-FOR-US: Dell / EMC
 CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
+	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-93j5-89vc-pph4
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/09af76fce136f3136931654a0a1d43095c80e2f0 (main)
@@ -15298,6 +15312,7 @@ CVE-2026-69220 (The RabbitMQ Java client library allows Java and JVM-based appli
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/db89e34809fbc6ba4e946615f297f3684ccd0acc (v5.33.1)
 CVE-2026-69219 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
+	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-68mj-5wr7-6fgg
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2007
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/6a87a8dcdc8b4cc4b961a7cdd388276446e5dfb2 (main)
@@ -15463,6 +15478,7 @@ CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kript
 	NOT-FOR-US: Cryptosim
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
 	- lz4-java 1.11.2+ds1-1 (bug #1145019)
+	[trixie] - lz4-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
 	NOTE: Fixed by: https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da (v1.11.1)
 CVE-2026-59940 (Seroval facilitates JS value stringification, including complex struct ...)
@@ -22000,6 +22016,7 @@ CVE-2026-13196 (Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write v
 	NOT-FOR-US: KUNBUS
 CVE-2026-13002 (A flow has been identified into dnssec.c library, causing an infinite  ...)
 	- dnsmasq <unfixed> (bug #1144649)
+	[trixie] - dnsmasq <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2486360
 CVE-2026-12366 (Zephyr's dynamic kernel-object disposal path unref_check() in kernel/u ...)
 	NOT-FOR-US: Zephyr, different from src:zephyr
@@ -30811,9 +30828,10 @@ CVE-2026-19079 (A TOCTOU (Time-of-Check-Time-of-Use) race condition vulnerabilit
 	[trixie] - policycoreutils <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/SELinuxProject/selinux/commit/a556538c2d5d2583273e025b45c02651fef47679
 CVE-2026-18497 (A heap-buffer-overflow vulnerability exists in the nothings stb TrueTy ...)
-	- libstb <unfixed>
+	- libstb <unfixed> (unimportant)
 	NOTE: https://www.kb.cert.org/vuls/id/987105
 	NOTE: https://github.com/nothings/stb/issues/1905
+	NOTE: truetype parser only supported for trusted font files
 CVE-2026-17603 (Nexus Repository 3 did not sufficiently restrict which HikariCP connec ...)
 	NOT-FOR-US: Sonatype
 CVE-2026-17601 (A user holding a permission to update privilege definitions could modi ...)
@@ -36031,6 +36049,7 @@ CVE-2026-54722 (DSSRF is a Node.js library that provides a wide range of utiliti
 	NOT-FOR-US: DSSRF
 CVE-2026-54522 (MessagePack for Ruby is an implementation of the MessagePack binary se ...)
 	- ruby-msgpack 1.8.3-1
+	[trixie] - ruby-msgpack <no-dsa> (Minor issue)
 	[bookworm] - ruby-msgpack <postponed> (minor issue)
 	[bullseye] - ruby-msgpack <postponed> (minor issue)
 	NOTE: https://github.com/msgpack/msgpack-ruby/security/advisories/GHSA-4mrv-5p47-p938
@@ -51352,6 +51371,7 @@ CVE-2026-54171 (Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0,
 	NOTE: Fixed by: https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 (v1.5.0)
 CVE-2026-54163 (secure_headers manages application of security headers with many safe  ...)
 	- ruby-secure-headers 7.3.0-1
+	[trixie] - ruby-secure-headers <no-dsa> (Minor issue)
 	NOTE: https://github.com/github/secure_headers/security/advisories/GHSA-rqq5-2gf9-4w4q
 	NOTE: Fixed by: https://github.com/github/secure_headers/commit/286a79dea80c6a9be4ca93e0f284c923cf77e539 (7.3.0)
 CVE-2026-54159 (PrestaShop ps_facetedsearch is a module that adds layered navigation f ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -55,6 +55,8 @@ jetty9
 --
 jetty12
 --
+jpeg-xl (jmm)
+--
 jq (aron)
   For regression in #1144075
 --
@@ -72,6 +74,8 @@ libde265 (jmm)
 --
 libevent
 --
+libheif
+--
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
   releases to more 6.12.y versions



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eef7db4e362174dc2453e6045587bf5d9cd76cb0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eef7db4e362174dc2453e6045587bf5d9cd76cb0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260901/bfc230fc/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list