[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 6 11:54:15 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e2a99b6c by Moritz Muehlenhoff at 2026-09-06T12:53:16+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -277,6 +277,7 @@ CVE-2026-85781 (Unverified ownership of a storage access point in the volume del
NOT-FOR-US: Amazon
CVE-2026-85769 (A flaw was found in libtpms, a library that provides software TPM 2.0 ...)
- libtpms <unfixed>
+ [trixie] - libtpms <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2528538
NOTE: https://github.com/stefanberger/libtpms/issues/614
NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/b1462888180d896af03cae0487e8d45009cc445e
@@ -490,7 +491,9 @@ CVE-2026-85538 (An incorrect authorization vulnerability in MISP allowed authent
- misp <itp> (bug #1144317)
CVE-2026-85534 (A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...)
- libsoup3 <unfixed>
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/551
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/561
CVE-2026-85533 (An authorization flaw in MISP allowed an authenticated user to submit ...)
@@ -5169,7 +5172,9 @@ CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote au
NOT-FOR-US: cPanel
CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
- smarty4 <unfixed>
+ [trixie] - smarty4 <no-dsa> (Minor issue)
- smarty3 <unfixed>
+ [trixie] - smarty3 <no-dsa> (Minor issue)
NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-cq55-c7wv-pxmq
NOTE: https://github.com/smarty-php/smarty/pull/1194
NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/31e06fc087a8b5a9b236c1e5dacc1c2850a2c115 (v5.8.2)
@@ -6849,13 +6854,17 @@ CVE-2026-82254 (gitoxide before 0.69.0 contains unchecked array indexing in delt
NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-x494-mj8g-cj27
CVE-2026-82253 (gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contai ...)
- rust-gix 0.83.0-1
+ [trixie] - rust-gix <no-dsa> (Minor issue)
- rust-gix-validate 0.11.1-1
+ [trixie] - rust-gix-validate <no-dsa> (Minor issue)
NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-p3hw-mv63-rf9w
CVE-2026-82252 (gitoxide before 0.52.1 follows symlinks when reading the worktree .git ...)
- rust-gix 0.83.0-1
+ [trixie] - rust-gix <no-dsa> (Minor issue)
NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-pg4w-g64p-qwhj
CVE-2026-82251 (gitoxide before 0.52.1 fails to validate submodule names from .gitmodu ...)
- rust-gix 0.83.0-1
+ [trixie] - rust-gix <no-dsa> (Minor issue)
NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-fr8x-3vfx-f45h
CVE-2026-82250 (gitoxide gix-packetline versions before 0.21.5 contain a panic vulnera ...)
- rust-gix-packetline 0.22.0-1
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2a99b6c0a448c55ab047821e2cae69beaebd4b0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2a99b6c0a448c55ab047821e2cae69beaebd4b0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/da927a18/attachment.htm>
More information about the debian-security-tracker-commits
mailing list