[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 3 15:11:56 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4d7627ae by Moritz Muehlenhoff at 2026-09-03T15:56:37+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -33,9 +33,11 @@ CVE-2026-84839 (A vulnerability was determined in tsi-coop tsi-dpdp-cms up to 0.
 	NOT-FOR-US: tsi-coop tsi-dpdp-cms
 CVE-2026-84838 (A flaw was found in rpmuncompress. This command injection vulnerabilit ...)
 	- rpm <unfixed>
+	[trixie] - rpm <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462222
 CVE-2026-84837 (A flaw was found in rpm. An attacker can exploit a command injection v ...)
 	- rpm <unfixed>
+	[trixie] - rpm <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478408
 CVE-2026-84835 (Missing Authorization vulnerability in DimaFreund Rentsyst allows Expl ...)
 	NOT-FOR-US: WordPress plugin or theme
@@ -631,6 +633,7 @@ CVE-2026-84367 (joi is a schema description language and data validator for Java
 	NOT-FOR-US: Node joi
 CVE-2026-84366 (Scrapy is a high-level web crawling and scraping framework for Python. ...)
 	- python-scrapy 2.17.0-1
+	[trixie] - python-scrapy <no-dsa> (Minor issue)
 	NOTE: https://github.com/scrapy/scrapy/security/advisories/GHSA-76g3-c3x4-crvx
 	NOTE: Fixed by: https://github.com/scrapy/scrapy/commit/9523e1ec8c41fde265a26d14563d178b6f1ad04b (2.17.0)
 CVE-2026-84365 (Hono is a Web application framework that provides support for any Java ...)
@@ -647,6 +650,7 @@ CVE-2026-84361 (Composer is a dependency Manager for the PHP language. From 1.0
 	NOTE: Fixed by: https://github.com/composer/composer/commit/199ad81a9cc6a2a5164ad79a8da26b2e19e521af (2.2.30)
 CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
 	- pypdf <unfixed>
+	[trixie] - pypdf <no-dsa> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://github.com/py-pdf/pypdf/security/advisories/GHSA-jp53-mhqp-8xcg
 	NOTE: https://github.com/py-pdf/pypdf/pull/3964
@@ -1052,16 +1056,19 @@ CVE-2026-80229
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb (rc-8_22_0-3)
 CVE-2026-19931
 	- curl 8.22.0~rc2-1
+	[trixie] - curl <no-dsa> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-19931.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (rc-8_22_0-2)
 CVE-2026-18924
 	- curl 8.22.0~rc2-1
+	[trixie] - curl <no-dsa> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-18924.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/ea7134ac874a66107e54ff93657ac565cf2ec4aa (curl-7_44_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43 (rc-8_22_0-1)
 CVE-2026-13608
 	- curl 8.22.0~rc2-1
+	[trixie] - curl <no-dsa> (Minor issue)
 	NOTE: https://curl.se/docs/CVE-2026-13608.html
 	NOTE: Introduced with: https://github.com/curl/curl/commit/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 (curl-7_82_0)
 	NOTE: Fixed by: https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519 (rc-8_22_0-1)
@@ -1071,11 +1078,13 @@ CVE-2026-84373 (Vitest is a testing framework powered by Vite. From 2.1.0 until
 	NOT-FOR-US: Vitest
 CVE-2026-84311 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
 	- pypdf <unfixed> (bug #1146476)
+	[trixie] - pypdf <no-dsa> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527050
 	TODO: check upstream references
 CVE-2026-84310 (pypdf is a free and open-source pure-python PDF library. Prior to 6.16 ...)
 	- pypdf <unfixed> (bug #1146476)
+	[trixie] - pypdf <no-dsa> (Minor issue)
 	- pypdf2 <removed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527049
 	TODO: check upstream references
@@ -1919,6 +1928,7 @@ CVE-2026-83743 (A weakness has been identified in invoiceninja Invoice Ninja up
 	NOT-FOR-US: invoiceninja Invoice Ninja
 CVE-2026-83596 (A flaw was found in WebKitGTK. Processing malicious web content can ca ...)
 	- webkit2gtk <unfixed>
+	[trixie] - webkit2gtk <postponed> (Fix along with future DSA)
 	[bookworm] - webkit2gtk <end-of-life> (see DSA-6232-1)
 	- wpewebkit <unfixed>
 	[trixie] - wpewebkit <ignored> (wpewebkit not covered by security support in Trixie)


=====================================
data/dsa-needed.txt
=====================================
@@ -138,7 +138,7 @@ ruby3.3
 --
 ruby-oj
 --
-ruby-rack
+ruby-rack (jmm)
 --
 ruby-rack-session
 --
@@ -154,6 +154,8 @@ shaarli
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --
+spip
+--
 thunderbird (jmm)
 --
 tomcat10



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d7627ae8cabebc680ef290a62f96b6cde6532b7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d7627ae8cabebc680ef290a62f96b6cde6532b7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260903/53aedba9/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list