[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 6 11:54:15 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e2a99b6c by Moritz Muehlenhoff at 2026-09-06T12:53:16+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -277,6 +277,7 @@ CVE-2026-85781 (Unverified ownership of a storage access point in the volume del
 	NOT-FOR-US: Amazon
 CVE-2026-85769 (A flaw was found in libtpms, a library that provides software TPM 2.0  ...)
 	- libtpms <unfixed>
+	[trixie] - libtpms <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2528538
 	NOTE: https://github.com/stefanberger/libtpms/issues/614
 	NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/b1462888180d896af03cae0487e8d45009cc445e
@@ -490,7 +491,9 @@ CVE-2026-85538 (An incorrect authorization vulnerability in MISP allowed authent
 	- misp <itp> (bug #1144317)
 CVE-2026-85534 (A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...)
 	- libsoup3 <unfixed>
+	[trixie] - libsoup3 <no-dsa> (Minor issue)
 	- libsoup2.4 <removed>
+	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/551
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/merge_requests/561
 CVE-2026-85533 (An authorization flaw in MISP allowed an authenticated user to submit  ...)
@@ -5169,7 +5172,9 @@ CVE-2026-65643 (Eval injection in cPanel 11.138.0.0 and earlier allows remote au
 	NOT-FOR-US: cPanel
 CVE-2026-62993 (Smarty is a template engine for PHP, facilitating the separation of pr ...)
 	- smarty4 <unfixed>
+	[trixie] - smarty4 <no-dsa> (Minor issue)
 	- smarty3 <unfixed>
+	[trixie] - smarty3 <no-dsa> (Minor issue)
 	NOTE: https://github.com/smarty-php/smarty/security/advisories/GHSA-cq55-c7wv-pxmq
 	NOTE: https://github.com/smarty-php/smarty/pull/1194
 	NOTE: Fixed by: https://github.com/smarty-php/smarty/commit/31e06fc087a8b5a9b236c1e5dacc1c2850a2c115 (v5.8.2)
@@ -6849,13 +6854,17 @@ CVE-2026-82254 (gitoxide before 0.69.0 contains unchecked array indexing in delt
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-x494-mj8g-cj27
 CVE-2026-82253 (gitoxide (Rust crates gix <= 0.72.0 and gix-validate <= 0.10.0) contai ...)
 	- rust-gix 0.83.0-1
+	[trixie] - rust-gix <no-dsa> (Minor issue)
 	- rust-gix-validate 0.11.1-1
+	[trixie] - rust-gix-validate <no-dsa> (Minor issue)
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-p3hw-mv63-rf9w
 CVE-2026-82252 (gitoxide before 0.52.1 follows symlinks when reading the worktree .git ...)
 	- rust-gix 0.83.0-1
+	[trixie] - rust-gix <no-dsa> (Minor issue)
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-pg4w-g64p-qwhj
 CVE-2026-82251 (gitoxide before 0.52.1 fails to validate submodule names from .gitmodu ...)
 	- rust-gix 0.83.0-1
+	[trixie] - rust-gix <no-dsa> (Minor issue)
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-fr8x-3vfx-f45h
 CVE-2026-82250 (gitoxide gix-packetline versions before 0.21.5 contain a panic vulnera ...)
 	- rust-gix-packetline 0.22.0-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2a99b6c0a448c55ab047821e2cae69beaebd4b0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2a99b6c0a448c55ab047821e2cae69beaebd4b0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/da927a18/attachment.htm>


More information about the debian-security-tracker-commits mailing list