[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Sep 7 16:45:10 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
df747f43 by Moritz Muehlenhoff at 2026-09-07T17:44:33+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -4211,6 +4211,7 @@ CVE-2026-71981 (Cypht before 2.12.2 contains a PHP object injection vulnerabilit
 	NOT-FOR-US: Cypht
 CVE-2026-63435 (Mail is an internet library for Ruby designed to handle email generati ...)
 	- ruby-mail 2.9.1-1
+	[trixie] - ruby-mail <no-dsa> (Minor issue)
 	NOTE: https://github.com/mikel/mail/security/advisories/GHSA-mvxr-6m87-mv2q
 	NOTE: https://github.com/mikel/mail/pull/1664
 	NOTE: Fixed by: https://github.com/mikel/mail/commit/f9d59c2e447af42e2c3dec5a56b1bb25c7292859 (2.9.1)
@@ -12366,15 +12367,19 @@ CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport downgrad
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj
 CVE-2026-79778 (rclone before v1.75.0 contains a denial of service vulnerability in th ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-3x6r-wxxg-53vv
 CVE-2026-79777 (rclone before v1.75.0 includes full Go stack traces in RC API error re ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-gwfq-86j8-7qhv
 CVE-2026-79776 (rclone before 1.75.0 mounts the pprof debug handler as its own router  ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-mfvx-7rcj-9m5g
 CVE-2026-79775 (rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain m ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-6jcg-q3wp-x2f4
 CVE-2026-79774 (Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig ...)
 	NOT-FOR-US: Winter CMS
@@ -33054,9 +33059,11 @@ CVE-2026-73154 [GHSA-5g48-xjmf-7p4q: StationData::setData stack overflow]
 	NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-5g48-xjmf-7p4q
 CVE-2026-XXXX [GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems]
 	- ostree 2026.3-1 (bug #1144106)
+	[trixie] - ostree <postponed> (Minor issue)
 	NOTE: https://github.com/ostreedev/ostree/security/advisories/GHSA-xppc-j946-vcj7
 CVE-2026-XXXX [GHSA-7cgc-gp99-6jmm: resource exhaustion via LZMA decoding]
 	- ostree 2026.3-1 (bug #1144105)
+	[trixie] - ostree <postponed> (Minor issue)
 	NOTE: https://github.com/ostreedev/ostree/security/advisories/GHSA-7cgc-gp99-6jmm
 	NOTE: Regression: https://bugs.debian.org/1144283
 CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Su ...)
@@ -45132,6 +45139,7 @@ CVE-2026-54605 (OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, pr
 	NOTE: Fixed by: https://github.com/ruby-oauth/oauth/commit/d069dc8c4c9631947451215f07460d6cdf0caf3f (v1.1.6)
 CVE-2026-54603 (OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frame ...)
 	- ruby-oauth2 2.0.25-1 (bug #1143054)
+	[trixie] - ruby-oauth2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/ruby-oauth/oauth2/security/advisories/GHSA-pp92-crg2-gfv9
 	NOTE: Fixed by: https://github.com/ruby-oauth/oauth2/commit/0f0a474f1b38453e119e660c2daca742d4378ce9 (v2.0.22)
 CVE-2026-54593 (Pterodactyl is a free, open-source game server management panel. Prior ...)
@@ -93175,6 +93183,7 @@ CVE-2026-48527 (HAX CMS helps manage microsite universe with PHP or NodeJs backe
 	NOT-FOR-US: HAX CMS
 CVE-2026-48501 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Prior to  ...)
 	- gh <unfixed>
+	[trixie] - gh <no-dsa> (Minor issue)
 	NOTE: https://github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9
 CVE-2026-47745 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admi ...)
 	NOT-FOR-US: Shopper



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/df747f4394b2af47149af0d3e159e60cb86e265c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/df747f4394b2af47149af0d3e159e60cb86e265c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260907/935d9412/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list