[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 4 18:39:00 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a286e498 by Salvatore Bonaccorso at 2026-09-04T19:38:34+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6,7 +6,7 @@ CVE-2026-76594
 CVE-2026-76595
 	NOT-FOR-US: Red Hat Insights Advisor backend
 CVE-2026-71223
-	- gfs2-utils <unfixed>
+	- gfs2-utils <unfixed> (bug #1146712)
 	[trixie] - gfs2-utils <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511400
 CVE-2026-9745 (IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations t ...)
@@ -812,23 +812,23 @@ CVE-2026-71404 (A flaw was found in Rancher Manager. The GlobalRole controller d
 CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path did not ...)
 	NOT-FOR-US: Rancher
 CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The metadata w ...)
-	- gfs2-utils <unfixed>
+	- gfs2-utils <unfixed> (bug #1146712)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511397
 	TODO: check upstream details
 CVE-2026-71222 (A heap out-of-bounds read vulnerability was found in gfs2-utils. The e ...)
-	- gfs2-utils <unfixed>
+	- gfs2-utils <unfixed> (bug #1146712)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511399
 	TODO: check upstream details
 CVE-2026-71221 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In  ...)
-	- gfs2-utils <unfixed>
+	- gfs2-utils <unfixed> (bug #1146712)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511396
 	TODO: check upstream details
 CVE-2026-71220 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In  ...)
-	- gfs2-utils <unfixed>
+	- gfs2-utils <unfixed> (bug #1146712)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511398
 	TODO: check upstream details
 CVE-2026-71219 (A stack overflow vulnerability was found in gfs2-utils. The hash table ...)
-	- gfs2-utils <unfixed>
+	- gfs2-utils <unfixed> (bug #1146712)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2507750
 	TODO: check upstream details
 CVE-2026-6071 (A remote code execution security issue exists in the affected products ...)
@@ -2211,7 +2211,7 @@ CVE-2026-73552
 CVE-2026-73553
 	- envoyproxy <itp> (bug #987544)
 CVE-2026-16658
-	- ansible <unfixed>
+	- ansible <unfixed> (bug #1146701)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506209
 CVE-2026-84353 (Use after free in Shared Tab Groups in Google Chrome on on Android pri ...)
 	{DSA-6482-1}
@@ -7191,7 +7191,7 @@ CVE-2026-77990 (Joomla Extension - joomlaeventmanager.net - Attendee lists reada
 CVE-2026-77989 (Joomla Extension - joomlaeventmanager.net - Reflected XSS via the PDF  ...)
 	NOT-FOR-US: Joomla
 CVE-2026-77652 (A heap-based buffer overflow vulnerability exists in the Dia diagram e ...)
-	- dia <unfixed>
+	- dia <unfixed> (bug #1146702)
 	[trixie] - dia <no-dsa> (Minor issue)
 	[bookworm] - dia <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/580
@@ -7528,7 +7528,7 @@ CVE-2025-51675 (An issue was discovered in openRISC OR1200 commit 83ac6b. An ina
 CVE-2023-27503
 	REJECTED
 CVE-2026-80158 (A flaw was found in the ipa_getkeytab module of the community.general  ...)
-	- ansible <unfixed>
+	- ansible <unfixed> (bug #1146699)
 	[trixie] - ansible <no-dsa> (Minor issue)
 	[bookworm] - ansible <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524651
@@ -7966,7 +7966,7 @@ CVE-2026-78236 (An insecure PIN derivation mechanism in ABR allows a low-privile
 CVE-2026-77801 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
 	NOT-FOR-US: GitLab (used to be packaged in the Debian archive as src:gitlab, but never in a stable release)
 CVE-2026-77658 (A stack-based buffer overflow vulnerability exists in the Dia diagram  ...)
-	- dia <unfixed>
+	- dia <unfixed> (bug #1146703)
 	[trixie] - dia <no-dsa> (Minor issue)
 	[bookworm] - dia <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/dia/-/issues/581
@@ -44379,7 +44379,7 @@ CVE-2026-50149 (Contour is a Kubernetes ingress controller using Envoy proxy. In
 CVE-2026-47701
 	NOT-FOR-US: OpenTelemetry Operator
 CVE-2026-16566
-	- ansible <unfixed>
+	- ansible <unfixed> (bug #1146700)
 	[trixie] - ansible <no-dsa> (Minor issue)
 	[bookworm] - ansible <not-affected> (Vulnerable code not present)
 	[bullseye] - ansible <not-affected> (Vulnerable code not present)
@@ -64484,7 +64484,7 @@ CVE-2026-53359 (In the Linux kernel, the following vulnerability has been resolv
 CVE-2026-49297 (Apache Airflow's Google provider operators `GCSToSFTPOperator` and `GC ...)
 	NOT-FOR-US: Airflow provider
 CVE-2026-54161
-	- nut <unfixed>
+	- nut <unfixed> (bug #1146704)
 	[trixie] - nut <no-dsa> (Minor issue)
 	[bookworm] - nut <postponed> (Minor issue)
 	[bullseye] - nut <postponed> (Minor issue)
@@ -76498,7 +76498,7 @@ CVE-2026-12770 (A vulnerability was determined in BerriAI litellm up to 1.63.1.
 	NOT-FOR-US: LiteLLM
 CVE-2026-54604
 	[experimental] - openslide 4.0.1+dfsg-1~0exp2
-	- openslide <unfixed>
+	- openslide <unfixed> (bug #1146705)
 	[trixie] - openslide <ignored> (Minor issue; only an exploitable issue with behaviour change of libtiff in 4.7.1)
 	[bookworm] - openslide <ignored> (Minor issue; only exploitable with the libtiff 4.7.1 behaviour change)
 	[bullseye] - openslide <ignored> (Minor issue; only exploitable with the libtiff 4.7.1 behaviour change)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a286e498437545e8bb58c1ca02aac4f292799df1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a286e498437545e8bb58c1ca02aac4f292799df1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/71d63fdc/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list