[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Sep 7 09:01:08 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0457abb0 by Moritz Muehlenhoff at 2026-09-07T10:00:34+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -226,6 +226,7 @@ CVE-2020-37277 (PocketMine-MP versions before 3.15.4 contain a denial of service
NOT-FOR-US: PocketMine-MP
CVE-2026-86219 (Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept ...)
- libauthen-sasl-perl 2.2000-2
+ [trixie] - libauthen-sasl-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43326063/
NOTE: Fixed by: https://github.com/perl-authen-sasl/perl-authen-sasl/commit/94337367030612842924f697cead29964a96448d (v2.2100)
CVE-2026-XXXX [CSS declaration smuggling via un-encoded ampersand emission]
@@ -809,7 +810,9 @@ CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper neutralization of input
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...)
- libsoup3 <unfixed> (bug #1146877)
+ [trixie] - libsoup3 <no-dsa> (Minor issue)
- libsoup2.4 <removed>
+ [trixie] - libsoup2.4 <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/552
CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
NOT-FOR-US: fastify/middie
@@ -2972,6 +2975,7 @@ CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path d
NOT-FOR-US: Rancher
CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The metadata w ...)
- gfs2-utils <unfixed> (bug #1146712)
+ [trixie] - gfs2-utils <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511397
TODO: check upstream details
CVE-2026-71223
@@ -2980,18 +2984,22 @@ CVE-2026-71223
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511400
CVE-2026-71222 (A heap out-of-bounds read vulnerability was found in gfs2-utils. The e ...)
- gfs2-utils <unfixed> (bug #1146712)
+ [trixie] - gfs2-utils <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511399
TODO: check upstream details
CVE-2026-71221 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In ...)
- gfs2-utils <unfixed> (bug #1146712)
+ [trixie] - gfs2-utils <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511396
TODO: check upstream details
CVE-2026-71220 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In ...)
- gfs2-utils <unfixed> (bug #1146712)
+ [trixie] - gfs2-utils <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511398
TODO: check upstream details
CVE-2026-71219 (A stack overflow vulnerability was found in gfs2-utils. The hash table ...)
- gfs2-utils <unfixed> (bug #1146712)
+ [trixie] - gfs2-utils <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2507750
TODO: check upstream details
CVE-2026-6071 (A remote code execution security issue exists in the affected products ...)
@@ -3050,10 +3058,14 @@ CVE-2025-12737 (The administrative operations within the Carbon Console do not a
NOT-FOR-US: WSO2
CVE-2026-XXXX [Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and Double Free in libde265]
- libde265 1.1.2-1
+ [trixie] - libde265 <no-dsa> (Minor issue)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-xp3h-6f5r-8cxp
+ NOTE: https://github.com/strukturag/libde265/commit/eb346780796055d9f9aac62d725d3170aa60c7b4 (v1.1.2)
CVE-2026-XXXX [heap-use-after-free in decoder_context::reset() via dangling previous_slice_header]
- libde265 1.1.2-1
+ [trixie] - libde265 <no-dsa> (Minor issue)
NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-mm7m-v26f-wf8x
+ NOTE: https://github.com/strukturag/libde265/commit/07bc500d45f781a7e2915afb7eebc2d6d9a541c9 (v1.1.2)
CVE-2026-56855 (Previously, after a channel has been established, a malicious peer cou ...)
- golang-go.crypto 1:0.56.0-1
[bookworm] - golang-go.crypto <postponed> (Limited support)
@@ -21228,6 +21240,7 @@ CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for mach
NOTE: Fixed by: https://github.com/onnx/onnx/commit/e9c74f596eaa0250f89e52a54160a25bbcb25b66 (v1.22.0)
CVE-2026-63337 (The RabbitMQ Java client library allows Java and JVM-based application ...)
- rabbitmq-java-client <unfixed> (bug #1144958)
+ [trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-6g32-pxv4-2wfj
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2000
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/9f8e7efd0c648f235dc0e96232ae7efa75ea4fa8 (main)
@@ -21235,6 +21248,7 @@ CVE-2026-63337 (The RabbitMQ Java client library allows Java and JVM-based appli
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/0032f75f9dc3df847f94b2b85a16119250bf63cb (v5.33.0)
CVE-2026-63336 (The RabbitMQ Java client library allows Java and JVM-based application ...)
- rabbitmq-java-client <unfixed> (bug #1144958)
+ [trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5m9f-rphj-c435
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1999
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/a4bf571dd368765baaa9cecfae68ce09f1bdcc01 (main)
@@ -21242,6 +21256,7 @@ CVE-2026-63336 (The RabbitMQ Java client library allows Java and JVM-based appli
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/1e7deb2e6020c9793a81385a53ea378ec63b9339 (v5.33.0)
CVE-2026-63335 (The RabbitMQ Java client library allows Java and JVM-based application ...)
- rabbitmq-java-client <unfixed> (bug #1144958)
+ [trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-qx7j-jv8m-fppr
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1959
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/31735344d9f9dfc53740b67f06e560e8846b9322 (main)
@@ -21257,6 +21272,7 @@ CVE-2026-61696 (Forem is open source software for building communities. In versi
NOT-FOR-US: Forem
CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
- rabbitmq-java-client <unfixed> (bug #1144958)
+ [trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1994
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591 (main)
@@ -38144,22 +38160,27 @@ CVE-2026-71314 (Nuxt is an open-source web development framework for Vue.js. Fro
NOT-FOR-US: Nuxt
CVE-2026-71313 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-7p4m-qxvv-g567
NOTE: Fixed by: https://github.com/rclone/rclone/commit/6a69713864b1d8f6edbc03d8af735f9624576d6e (v1.75.0)
CVE-2026-71312 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-2m8m-jhrm-w6j2
NOTE: Fixed by: https://github.com/rclone/rclone/commit/e122fba1a57641b63a580aa26c026903a84e2e88 (v1.75.0)
CVE-2026-71311 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8c48-q9wj-3w37
NOTE: Fixed by: https://github.com/rclone/rclone/commit/1df2b70753286c1dfe8366078cbedfdf7f96472c (v1.75.0)
CVE-2026-71310 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-xhf4-832v-7xcr
NOTE: Fixed by: https://github.com/rclone/rclone/commit/21d8cd3b92cd81d987f485051d454ea675d91a2b (v1.75.0)
CVE-2026-71309 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-45pq-889g-fcgh
NOTE: Fixed by: https://github.com/rclone/rclone/commit/cc5a189f00efe68ed0ddb32d3237b42549a9f264 (v1.75.0)
CVE-2026-70618 (Spacebar Server before commit 51da17c contains a missing authorization ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -122,6 +122,8 @@ rails
--
redis
--
+roundcube
+--
rsync
for regression fixes and new batch of CVEs, Samuel Henrique working on updates, likely to move to 3.5.0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0457abb0b368af3fca1e83bd859501204fb17238
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0457abb0b368af3fca1e83bd859501204fb17238
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260907/64d6bd2b/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list