[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Sep 7 16:45:10 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
df747f43 by Moritz Muehlenhoff at 2026-09-07T17:44:33+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -4211,6 +4211,7 @@ CVE-2026-71981 (Cypht before 2.12.2 contains a PHP object injection vulnerabilit
NOT-FOR-US: Cypht
CVE-2026-63435 (Mail is an internet library for Ruby designed to handle email generati ...)
- ruby-mail 2.9.1-1
+ [trixie] - ruby-mail <no-dsa> (Minor issue)
NOTE: https://github.com/mikel/mail/security/advisories/GHSA-mvxr-6m87-mv2q
NOTE: https://github.com/mikel/mail/pull/1664
NOTE: Fixed by: https://github.com/mikel/mail/commit/f9d59c2e447af42e2c3dec5a56b1bb25c7292859 (2.9.1)
@@ -12366,15 +12367,19 @@ CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport downgrad
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj
CVE-2026-79778 (rclone before v1.75.0 contains a denial of service vulnerability in th ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-3x6r-wxxg-53vv
CVE-2026-79777 (rclone before v1.75.0 includes full Go stack traces in RC API error re ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-gwfq-86j8-7qhv
CVE-2026-79776 (rclone before 1.75.0 mounts the pprof debug handler as its own router ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-mfvx-7rcj-9m5g
CVE-2026-79775 (rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain m ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-6jcg-q3wp-x2f4
CVE-2026-79774 (Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig ...)
NOT-FOR-US: Winter CMS
@@ -33054,9 +33059,11 @@ CVE-2026-73154 [GHSA-5g48-xjmf-7p4q: StationData::setData stack overflow]
NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-5g48-xjmf-7p4q
CVE-2026-XXXX [GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems]
- ostree 2026.3-1 (bug #1144106)
+ [trixie] - ostree <postponed> (Minor issue)
NOTE: https://github.com/ostreedev/ostree/security/advisories/GHSA-xppc-j946-vcj7
CVE-2026-XXXX [GHSA-7cgc-gp99-6jmm: resource exhaustion via LZMA decoding]
- ostree 2026.3-1 (bug #1144105)
+ [trixie] - ostree <postponed> (Minor issue)
NOTE: https://github.com/ostreedev/ostree/security/advisories/GHSA-7cgc-gp99-6jmm
NOTE: Regression: https://bugs.debian.org/1144283
CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Su ...)
@@ -45132,6 +45139,7 @@ CVE-2026-54605 (OAuth is a Ruby wrapper for the OAuth 1.0 and 1.0a protocols, pr
NOTE: Fixed by: https://github.com/ruby-oauth/oauth/commit/d069dc8c4c9631947451215f07460d6cdf0caf3f (v1.1.6)
CVE-2026-54603 (OAuth2 is a Ruby wrapper for the OAuth 2.0 and 2.1 authorization frame ...)
- ruby-oauth2 2.0.25-1 (bug #1143054)
+ [trixie] - ruby-oauth2 <no-dsa> (Minor issue)
NOTE: https://github.com/ruby-oauth/oauth2/security/advisories/GHSA-pp92-crg2-gfv9
NOTE: Fixed by: https://github.com/ruby-oauth/oauth2/commit/0f0a474f1b38453e119e660c2daca742d4378ce9 (v2.0.22)
CVE-2026-54593 (Pterodactyl is a free, open-source game server management panel. Prior ...)
@@ -93175,6 +93183,7 @@ CVE-2026-48527 (HAX CMS helps manage microsite universe with PHP or NodeJs backe
NOT-FOR-US: HAX CMS
CVE-2026-48501 (GitHub CLI (gh) is GitHub\u2019s official command line tool. Prior to ...)
- gh <unfixed>
+ [trixie] - gh <no-dsa> (Minor issue)
NOTE: https://github.com/cli/cli/security/advisories/GHSA-8xvp-7hj6-mcj9
CVE-2026-47745 (Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admi ...)
NOT-FOR-US: Shopper
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/df747f4394b2af47149af0d3e159e60cb86e265c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/df747f4394b2af47149af0d3e159e60cb86e265c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260907/935d9412/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list