[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Sep 7 21:26:06 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
86b4d760 by Moritz Muehlenhoff at 2026-09-07T22:23:18+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -892,13 +892,18 @@ CVE-2024-11080 (The Post Grid and Gutenberg Blocks \u2013 ComboBlocks plugin for
 	NOT-FOR-US: WordPress plugin
 CVE-2026-49275 [GHSA-hxph-pv7w-8649: Out of bounds read in CrwMap::decodeBasic]
 	- exiv2 0.28.9+dfsg-1
+	[trixie] - exiv2 <no-dsa> (Minor issue)
 	NOTE: https://github.com/Exiv2/exiv2/security/advisories/GHSA-hxph-pv7w-8649
+	NOTE: https://github.com/Exiv2/exiv2/pull/9308
+	NOTE: https://github.com/Exiv2/exiv2/commit/c798e33d5592f9b51295257b39a01f55b9dd1769 (v0.28.9)
 CVE-2026-68547 [GHSA-jcgh-p9v3-pw6j: Heap out-of-bounds read in RemoteIo when reading block-aligned remote CRW files]
-	- exiv2 0.28.9+dfsg-1
+	- exiv2 0.28.9+dfsg-1 (unimportant)
 	NOTE: https://github.com/Exiv2/exiv2/security/advisories/GHSA-jcgh-p9v3-pw6j
+	NOTE: RemoteIo/curl backend not enabled in Debian
 CVE-2026-68546 [GHSA-3695-mjv8-3r52: Heap out-of-bounds write in RemoteIo when reading from a malicious remote server (WebReady/Curl builds)]
-	- exiv2 0.28.9+dfsg-1
+	- exiv2 0.28.9+dfsg-1 (unimportant)
 	NOTE: https://github.com/Exiv2/exiv2/security/advisories/GHSA-3695-mjv8-3r52
+	NOTE: RemoteIo/curl backend not enabled in Debian
 CVE-2026-9317 (Nango before 0.71.6 contains a missing authentication vulnerability in ...)
 	NOT-FOR-US: Nango
 CVE-2026-9186 (IBM Langflow OSS 1.0.0 through 1.11.2 allows remote authenticated atta ...)
@@ -1330,10 +1335,12 @@ CVE-2026-81832 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1
 	NOT-FOR-US: IBM
 CVE-2026-81666 (An integer overflow was found in Corosync's handling of membership com ...)
 	- corosync <unfixed> (bug #1146872)
+	[trixie] - corosync <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524923
 	NOTE: Fixed by: https://github.com/corosync/corosync/commit/83920f2e36b5f1acd7dcf033c0820043cc29f82a
 CVE-2026-81665 (A heap-based buffer overflow was found in Corosync's Totem Process Gro ...)
 	- corosync <unfixed> (bug #1146872)
+	[trixie] - corosync <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524910
 	NOTE: Fixed by: https://github.com/corosync/corosync/commit/5148bf07dffa61bcfa92ca2c058e7d0f0a981cf3
 CVE-2026-81424 (The Accept Stripe Payments WordPress plugin before 2.1.4 does not veri ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -34,6 +34,10 @@ dovecot
 --
 dulwich
 --
+emacs (jmm)
+--
+erlang
+--
 firebird3.0
 --
 firebird4.0



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86b4d7607ad0090e1d38c2d68a6a1bf1e3ba8321

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/86b4d7607ad0090e1d38c2d68a6a1bf1e3ba8321
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260907/4eb719b8/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list