[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 4 18:49:34 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
288a1044 by Moritz Muehlenhoff at 2026-09-04T19:49:16+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -343,12 +343,15 @@ CVE-2026-81738
 	- openvpn <not-affected> (Only affects OpenVPN on Windows)
 CVE-2026-71198
 	- glance 2:32.0.0-4 (bug #1146594)
+	[trixie] - glance <no-dsa> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-71197
 	- glance 2:32.0.0-4 (bug #1146594)
+	[trixie] - glance <no-dsa> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-71196
 	- glance 2:32.0.0-4 (bug #1146594)
+	[trixie] - glance <no-dsa> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users having acc ...)
 	NOT-FOR-US: Hitachi Energy
@@ -564,6 +567,7 @@ CVE-2026-84970 (A numeric truncation weakness exists in the JSON parsing compone
 	NOTE: https://jira.mongodb.org/browse/CXX-3547
 CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers of the  ...)
 	- mongo-c-driver 2.5.2-1
+	[trixie] - mongo-c-driver <no-dsa> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/CDRIVER-6410
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/4229afa3bb4d0842edd5ee8da0f5143bd563e0bd (2.5.2)
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/08d0cfaaf08a54d7e87a5e5fa8d38251bf0eeca6 (1.30.9)
@@ -578,14 +582,17 @@ CVE-2026-84966 (An incorrect numeric type conversion in the BSON document buildi
 	NOTE: https://jira.mongodb.org/browse/CXX-3548
 CVE-2026-84965 (An integer wraparound in an allocation size calculation in the BSON li ...)
 	- mongo-c-driver 2.5.2-1
+	[trixie] - mongo-c-driver <no-dsa> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/CDRIVER-6405
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/8a4c4416a171b66a3eb0b136f844c62ca9e36025 (2.5.2)
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/aba72444f8e8950b8a57636b1ad72a5a853f8264 (1.30.9)
 CVE-2026-84964 (A double free in the OpenSSL-based TLS certificate revocation checking ...)
 	- mongo-c-driver 2.5.2-1
+	[trixie] - mongo-c-driver <no-dsa> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/CDRIVER-6409
 CVE-2026-84963 (An incorrect numeric conversion in the JSON parsing component of the M ...)
 	- mongo-c-driver 2.5.2-1
+	[trixie] - mongo-c-driver <no-dsa> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/CDRIVER-6407
 CVE-2026-84962 (An unauthorized user with key vault write access may cause an authoriz ...)
 	- libmongocrypt 1.20.2-1
@@ -1732,6 +1739,7 @@ CVE-2026-84309 (pypdf is a free and open-source pure-python PDF library. Prior t
 CVE-2026-84308 (phpseclib is a PHP secure communications library. Prior to 3.0.57 and  ...)
 	- php-phpseclib4 4.0.1-1
 	- php-phpseclib3 3.0.57-1
+	[trixie] - php-phpseclib3 <no-dsa> (Minor issue)
 	- php-phpseclib <not-affected> (Vulnerable code not present)
 	- phpseclib <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/phpseclib/phpseclib/security/advisories/GHSA-q97c-8qh3-fpc6
@@ -2212,6 +2220,7 @@ CVE-2026-73553
 	- envoyproxy <itp> (bug #987544)
 CVE-2026-16658
 	- ansible <unfixed> (bug #1146701)
+	[trixie] - ansible <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2506209
 CVE-2026-84353 (Use after free in Shared Tab Groups in Google Chrome on on Android pri ...)
 	{DSA-6482-1}
@@ -2317,6 +2326,7 @@ CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery vuln
 	NOT-FOR-US: Wyoming
 CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
 	- sqlparse <unfixed> (bug #1146628)
+	[trixie] - sqlparse <no-dsa> (Minor issue)
 	NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
 	NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b (0.6.0)
 CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
@@ -5077,6 +5087,7 @@ CVE-2026-76581 (The WPMU DEV Dashboard plugin for WordPress is vulnerable to Aut
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75758 (Uncontrolled Recursion vulnerability in the Elixir standard library al ...)
 	- elixir-lang <unfixed> (bug #1146626)
+	[trixie] - elixir-lang <no-dsa> (Minor issue)
 	[bookworm] - elixir-lang <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/elixir-lang/elixir/security/advisories/GHSA-jf5q-v438-665c
 	NOTE: https://cna.erlef.org/cves/CVE-2026-75758.html


=====================================
data/dsa-needed.txt
=====================================
@@ -152,6 +152,8 @@ sabnzbdplus
 --
 shaarli
 --
+slurm-wlm
+--
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/288a1044518efa98669ea5ba257da697ca7caec7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/288a1044518efa98669ea5ba257da697ca7caec7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260904/5b509e91/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list