[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Sep 7 09:01:08 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0457abb0 by Moritz Muehlenhoff at 2026-09-07T10:00:34+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -226,6 +226,7 @@ CVE-2020-37277 (PocketMine-MP versions before 3.15.4 contain a denial of service
 	NOT-FOR-US: PocketMine-MP
 CVE-2026-86219 (Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept  ...)
 	- libauthen-sasl-perl 2.2000-2
+	[trixie] - libauthen-sasl-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43326063/
 	NOTE: Fixed by: https://github.com/perl-authen-sasl/perl-authen-sasl/commit/94337367030612842924f697cead29964a96448d (v2.2100)
 CVE-2026-XXXX [CSS declaration smuggling via un-encoded ampersand emission]
@@ -809,7 +810,9 @@ CVE-2026-85229 (** UNSUPPORTED WHEN ASSIGNED **Improper neutralization of input
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-85197 (A flaw was found in libsoup. A malicious HTTP/2 server or a Man-in-the ...)
 	- libsoup3 <unfixed> (bug #1146877)
+	[trixie] - libsoup3 <no-dsa> (Minor issue)
 	- libsoup2.4 <removed>
+	[trixie] - libsoup2.4 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/libsoup/-/work_items/552
 CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whether to r ...)
 	NOT-FOR-US: fastify/middie
@@ -2972,6 +2975,7 @@ CVE-2026-71403 (A flaw was found in Rancher Manager. The /v3/users update path d
 	NOT-FOR-US: Rancher
 CVE-2026-71224 (A stack overflow vulnerability was found in gfs2-utils. The metadata w ...)
 	- gfs2-utils <unfixed> (bug #1146712)
+	[trixie] - gfs2-utils <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511397
 	TODO: check upstream details
 CVE-2026-71223
@@ -2980,18 +2984,22 @@ CVE-2026-71223
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511400
 CVE-2026-71222 (A heap out-of-bounds read vulnerability was found in gfs2-utils. The e ...)
 	- gfs2-utils <unfixed> (bug #1146712)
+	[trixie] - gfs2-utils <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511399
 	TODO: check upstream details
 CVE-2026-71221 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In  ...)
 	- gfs2-utils <unfixed> (bug #1146712)
+	[trixie] - gfs2-utils <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511396
 	TODO: check upstream details
 CVE-2026-71220 (A stack out-of-bounds write vulnerability was found in gfs2-utils. In  ...)
 	- gfs2-utils <unfixed> (bug #1146712)
+	[trixie] - gfs2-utils <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511398
 	TODO: check upstream details
 CVE-2026-71219 (A stack overflow vulnerability was found in gfs2-utils. The hash table ...)
 	- gfs2-utils <unfixed> (bug #1146712)
+	[trixie] - gfs2-utils <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2507750
 	TODO: check upstream details
 CVE-2026-6071 (A remote code execution security issue exists in the affected products ...)
@@ -3050,10 +3058,14 @@ CVE-2025-12737 (The administrative operations within the Carbon Console do not a
 	NOT-FOR-US: WSO2
 CVE-2026-XXXX [Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') and Use After Free and Double Free in libde265]
 	- libde265 1.1.2-1
+	[trixie] - libde265 <no-dsa> (Minor issue)
 	NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-xp3h-6f5r-8cxp
+	NOTE: https://github.com/strukturag/libde265/commit/eb346780796055d9f9aac62d725d3170aa60c7b4 (v1.1.2)
 CVE-2026-XXXX [heap-use-after-free in decoder_context::reset() via dangling previous_slice_header]
 	- libde265 1.1.2-1
+	[trixie] - libde265 <no-dsa> (Minor issue)
 	NOTE: https://github.com/strukturag/libde265/security/advisories/GHSA-mm7m-v26f-wf8x
+	NOTE: https://github.com/strukturag/libde265/commit/07bc500d45f781a7e2915afb7eebc2d6d9a541c9 (v1.1.2)
 CVE-2026-56855 (Previously, after a channel has been established, a malicious peer cou ...)
 	- golang-go.crypto 1:0.56.0-1
 	[bookworm] - golang-go.crypto <postponed> (Limited support)
@@ -21228,6 +21240,7 @@ CVE-2026-63632 (Open Neural Network Exchange (ONNX) is an open standard for mach
 	NOTE: Fixed by: https://github.com/onnx/onnx/commit/e9c74f596eaa0250f89e52a54160a25bbcb25b66 (v1.22.0)
 CVE-2026-63337 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
+	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-6g32-pxv4-2wfj
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2000
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/9f8e7efd0c648f235dc0e96232ae7efa75ea4fa8 (main)
@@ -21235,6 +21248,7 @@ CVE-2026-63337 (The RabbitMQ Java client library allows Java and JVM-based appli
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/0032f75f9dc3df847f94b2b85a16119250bf63cb (v5.33.0)
 CVE-2026-63336 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
+	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5m9f-rphj-c435
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1999
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/a4bf571dd368765baaa9cecfae68ce09f1bdcc01 (main)
@@ -21242,6 +21256,7 @@ CVE-2026-63336 (The RabbitMQ Java client library allows Java and JVM-based appli
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/1e7deb2e6020c9793a81385a53ea378ec63b9339 (v5.33.0)
 CVE-2026-63335 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
+	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-qx7j-jv8m-fppr
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1959
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/31735344d9f9dfc53740b67f06e560e8846b9322 (main)
@@ -21257,6 +21272,7 @@ CVE-2026-61696 (Forem is open source software for building communities. In versi
 	NOT-FOR-US: Forem
 CVE-2026-61634 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed> (bug #1144958)
+	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-5xwg-cfvj-gff5
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/1994
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/08790f09686173eb17b48d08a25edcb32e71a591 (main)
@@ -38144,22 +38160,27 @@ CVE-2026-71314 (Nuxt is an open-source web development framework for Vue.js. Fro
 	NOT-FOR-US: Nuxt
 CVE-2026-71313 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1143842)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-7p4m-qxvv-g567
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/6a69713864b1d8f6edbc03d8af735f9624576d6e (v1.75.0)
 CVE-2026-71312 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1143842)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-2m8m-jhrm-w6j2
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/e122fba1a57641b63a580aa26c026903a84e2e88 (v1.75.0)
 CVE-2026-71311 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1143842)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8c48-q9wj-3w37
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/1df2b70753286c1dfe8366078cbedfdf7f96472c (v1.75.0)
 CVE-2026-71310 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1143842)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-xhf4-832v-7xcr
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/21d8cd3b92cd81d987f485051d454ea675d91a2b (v1.75.0)
 CVE-2026-71309 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1143842)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-45pq-889g-fcgh
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/cc5a189f00efe68ed0ddb32d3237b42549a9f264 (v1.75.0)
 CVE-2026-70618 (Spacebar Server before commit 51da17c contains a missing authorization ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -122,6 +122,8 @@ rails
 --
 redis
 --
+roundcube
+--
 rsync
   for regression fixes and new batch of CVEs, Samuel Henrique working on updates, likely to move to 3.5.0
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0457abb0b368af3fca1e83bd859501204fb17238

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0457abb0b368af3fca1e83bd859501204fb17238
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260907/64d6bd2b/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list