[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 6 17:19:42 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a634b8b0 by Salvatore Bonaccorso at 2026-09-06T18:19:07+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -301,7 +301,7 @@ CVE-2026-86137 (In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-b
 CVE-2026-86100 (Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect ta ...)
 	NOT-FOR-US: Camaleon CMS
 CVE-2026-86098 (ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerabi ...)
-	- ndpi <unfixed>
+	- ndpi <unfixed> (bug #1146882)
 	NOTE: Fixed by: https://github.com/ntop/nDPI/commit/94e82c1de12323d992895830231865736a8abf2c (6.0)
 CVE-2026-86097 (PX4 Autopilot through 1.17.0 contains a null pointer dereference vulne ...)
 	NOT-FOR-US: PX4 Autopilot
@@ -321,7 +321,7 @@ CVE-2026-85786 (Improper handling of highly compressed data in Amazon ion-java b
 CVE-2026-85781 (Unverified ownership of a storage access point in the volume deletion  ...)
 	NOT-FOR-US: Amazon
 CVE-2026-85769 (A flaw was found in libtpms, a library that provides software TPM 2.0  ...)
-	- libtpms <unfixed>
+	- libtpms <unfixed> (bug #1146880)
 	[trixie] - libtpms <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2528538
 	NOTE: https://github.com/stefanberger/libtpms/issues/614
@@ -535,7 +535,7 @@ CVE-2026-85540 (DreamMaker developed by Interinfo has a SQL Injection vulnerabil
 CVE-2026-85538 (An incorrect authorization vulnerability in MISP allowed authenticated ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-85534 (A flaw was found in libsoup. When a client sends an HTTP/2 request bod ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1146878)
 	[trixie] - libsoup3 <no-dsa> (Minor issue)
 	- libsoup2.4 <removed>
 	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
@@ -548,7 +548,7 @@ CVE-2026-85528 (Improper input validation of the auto-configuration account iden
 CVE-2026-85525 (Improper OCSP response validation in the Snowflake Python, Go, JDBC, a ...)
 	NOT-FOR-US: Snowflake Drivers
 CVE-2026-85522 (A vulnerability was detected in valkey-io valkey up to 9.5.4/9.1.0. Af ...)
-	- valkey <unfixed>
+	- valkey <unfixed> (bug #1146879)
 	NOTE: https://github.com/valkey-io/valkey/issues/4207
 	NOTE: https://github.com/valkey-io/valkey/pull/4210
 	NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/8f9f19d311bbbaf916ef620a37440c96f726b2b7 (9.1.2)
@@ -567,7 +567,7 @@ CVE-2026-85311 (Missing Authorization vulnerability in Kings Plugins MarketKing
 CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper neutralization of input during ...)
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...)
-	- libsoup3 <unfixed>
+	- libsoup3 <unfixed> (bug #1146877)
 	- libsoup2.4 <removed>
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/552
 CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
@@ -675,11 +675,11 @@ CVE-2026-81859 (CP4BA - IBM Enterprise Records could allow a local attacker to o
 CVE-2026-81832 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1.0 thr ...)
 	NOT-FOR-US: IBM
 CVE-2026-81666 (An integer overflow was found in Corosync's handling of membership com ...)
-	- corosync <unfixed>
+	- corosync <unfixed> (bug #1146872)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524923
 	NOTE: Fixed by: https://github.com/corosync/corosync/commit/83920f2e36b5f1acd7dcf033c0820043cc29f82a
 CVE-2026-81665 (A heap-based buffer overflow was found in Corosync's Totem Process Gro ...)
-	- corosync <unfixed>
+	- corosync <unfixed> (bug #1146872)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524910
 	NOTE: Fixed by: https://github.com/corosync/corosync/commit/5148bf07dffa61bcfa92ca2c058e7d0f0a981cf3
 CVE-2026-81424 (The Accept Stripe Payments WordPress plugin before 2.1.4 does not veri ...)
@@ -1989,7 +1989,7 @@ CVE-2026-85042 (Use after free in DevTools in Google Chrome prior to 152.0.7977.
 	{DSA-6484-1}
 	- chromium 152.0.7977.82-1
 CVE-2026-84185 (A flaw was found in the jwcrypto library, which is used for implementi ...)
-	- python-jwcrypto <unfixed>
+	- python-jwcrypto <unfixed> (bug #1146875)
 	[trixie] - python-jwcrypto <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2526729
 	NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-wwmx-rghj-gq83
@@ -3184,7 +3184,7 @@ CVE-2026-82955 (In the current development version of Eclipse aeriOS, which has
 CVE-2026-82884 (The All in One SEO WordPress plugin before 5.0.0.1 does not sanitise a ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-82522 (libjxl before 0.12 contains an integer underflow vulnerability in the  ...)
-	- jpeg-xl <unfixed>
+	- jpeg-xl <unfixed> (bug #1146874)
 	NOTE: https://github.com/libjxl/libjxl/pull/4885
 	NOTE: https://github.com/libjxl/libjxl/commit/22ad80af1454f0444ea34115e49ed40517147d68 (v0.12.0)
 CVE-2026-82404 (TOON is a compact, human-readable serialization of JSON data for LLM p ...)
@@ -8493,7 +8493,7 @@ CVE-2026-81727 (NLTK versions before 3.10.3 contain a filesystem containment byp
 	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-f794-5jv7-7672
 CVE-2026-81726 (NLTK through 3.10.3 contains a path traversal vulnerability in model-a ...)
-	- nltk <unfixed>
+	- nltk <unfixed> (bug #1146873)
 	[trixie] - nltk <no-dsa> (Minor issue)
 	[bookworm] - nltk <postponed> (Minor issue)
 	NOTE: https://github.com/nltk/nltk/security/advisories/GHSA-8mgp-746c-j5xp



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a634b8b00cec590513e194b64269ee7bcef51ca5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a634b8b00cec590513e194b64269ee7bcef51ca5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260906/a4390695/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list