[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 4 18:49:34 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
288a1044 by Moritz Muehlenhoff at 2026-09-04T19:49:16+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -343,12 +343,15 @@ CVE-2026-81738
- openvpn <not-affected> (Only affects OpenVPN on Windows)
CVE-2026-71198
- glance 2:32.0.0-4 (bug #1146594)
+ [trixie] - glance <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-71197
- glance 2:32.0.0-4 (bug #1146594)
+ [trixie] - glance <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-71196
- glance 2:32.0.0-4 (bug #1146594)
+ [trixie] - glance <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users having acc ...)
NOT-FOR-US: Hitachi Energy
@@ -564,6 +567,7 @@ CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing compone
NOTE: https://jira.mongodb.org/browse/CXX-3547
CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers of the ...)
- mongo-c-driver 2.5.2-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6410
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/4229afa3bb4d0842edd5ee8da0f5143bd563e0bd (2.5.2)
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6 (1.30.9)
@@ -578,14 +582,17 @@ CVE-2026-84966 (An incorrect numeric type conversion in the BSON document buildi
NOTE: https://jira.mongodb.org/browse/CXX-3548
CVE-2026-84965 (An integer wraparound in an allocation size calculation in the BSON li ...)
- mongo-c-driver 2.5.2-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6405
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/8a4c4416a171b66a3eb0b136f844c62ca9e36025 (2.5.2)
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/aba72444f8e8950b8a57636b1ad72a5a853f8264 (1.30.9)
CVE-2026-84964 (A double free in the OpenSSL-based TLS certificate revocation checking ...)
- mongo-c-driver 2.5.2-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6409
CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component of the M ...)
- mongo-c-driver 2.5.2-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6407
CVE-2026-84962 (An unauthorized user with key vault write access may cause an authoriz ...)
- libmongocrypt 1.20.2-1
@@ -1732,6 +1739,7 @@ CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior t
CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to 3.0.57 and ...)
- php-phpseclib4 4.0.1-1
- php-phpseclib3 3.0.57-1
+ [trixie] - php-phpseclib3 <no-dsa> (Minor issue)
- php-phpseclib <not-affected> (Vulnerable code not present)
- phpseclib <not-affected> (Vulnerable code not present)
NOTE: https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6
@@ -2212,6 +2220,7 @@ CVE-2026-73553
- envoyproxy <itp> (bug #987544)
CVE-2026-16658
- ansible <unfixed> (bug #1146701)
+ [trixie] - ansible <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506209
CVE-2026-84353 (Use after free in Shared Tab Groups in Google Chrome on on Android pri ...)
{DSA-6482-1}
@@ -2317,6 +2326,7 @@ CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery vuln
NOT-FOR-US: Wyoming
CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- sqlparse <unfixed> (bug #1146628)
+ [trixie] - sqlparse <no-dsa> (Minor issue)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b (0.6.0)
CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
@@ -5077,6 +5087,7 @@ CVE-2026-76581 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to Aut
NOT-FOR-US: WordPress plugin
CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard library al ...)
- elixir-lang <unfixed> (bug #1146626)
+ [trixie] - elixir-lang <no-dsa> (Minor issue)
[bookworm] - elixir-lang <not-affected> (Vulnerable code introduced later)
NOTE: https://github.com/elixir-lang/elixir/security/advisories/GHSA-jf5q-v438-665c
NOTE: https://cna.erlef.org/cves/CVE-2026-75758.html
=====================================
data/dsa-needed.txt
=====================================
@@ -152,6 +152,8 @@ sabnzbdplus
--
shaarli
--
+slurm-wlm
+--
sogo
Regression update for #1144734, new batch of issues from 5.12.10 release
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/288a1044518efa98669ea5ba257da697ca7caec7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/288a1044518efa98669ea5ba257da697ca7caec7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/5b509e91/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list