[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 8 10:13:15 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5f134322 by Moritz Muehlenhoff at 2026-09-08T11:12:03+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -235,16 +235,19 @@ CVE-2026-86426 (LibreNMS before 26.8.0 contains an authentication bypass vulnera
 	NOT-FOR-US: LibreNMS
 CVE-2026-86425 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)
 	- imagemagick <unfixed>
+	[trixie] - imagemagick <no-dsa> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/5bff96a5c8d0b3dafa4ad4fa7916db4cae72a11d (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/e006a69e03f3aff34e9a7af90a0793ec6d879b48 (6.9.13-55)
 CVE-2026-86424 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ...)
 	- imagemagick <unfixed>
+	[trixie] - imagemagick <no-dsa> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/a44ef50cc494253f7d9f0229bb25c064a8e2ae69 (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/0b47fb7e3d5650b2be88fd3a8c15096765970ce3 (6.9.13-55)
 CVE-2026-86423 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)
 	- imagemagick <unfixed>
+	[trixie] - imagemagick <no-dsa> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5m9j-96ff-j6qc
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/1d3e98913f6a8fa34b5a4180eadb9ed195b918a8 (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ed44f0ba6e2ab57983a6d030c868d009514dc470 (6.9.13-55)
@@ -253,11 +256,13 @@ CVE-2026-86422 (ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x8g2-7r3w-h44p
 CVE-2026-86421 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in th ...)
 	- imagemagick <unfixed>
+	[trixie] - imagemagick <no-dsa> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/c83153dfc128de8e7c538f879c532c7d36a75abb (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/d56cab9f2253373e57c2e77809ab12abbbbdd680 (6.9.13-55)
 CVE-2026-86420 (ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the  ...)
 	- imagemagick <unfixed>
+	[trixie] - imagemagick <no-dsa> (Minor issue)
 	NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/6ac07556a93b2de00c845cd535ca256f45a47154 (7.1.2-30)
 	NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/29f17f3fe5008fc56f00c1fbc96adf46169db245 (6.9.13-55)
@@ -4126,7 +4131,9 @@ CVE-2026-79754 (Nuclio is a "Serverless" framework for Real-Time Events and Data
 	NOT-FOR-US: Nuclio
 CVE-2026-78689 (Description   NGINX JavaScript (njs) has a vulnerability in the XML mo ...)
 	- libnginx-mod-js 1.0.1-1
+	[trixie] - libnginx-mod-js <no-dsa> (Minor issue)
 	NOTE: https://my.f5.com/manage/s/article/K000162602
+	NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
 CVE-2026-78609 (Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) ...)
 	NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
 CVE-2026-78604 (Incorrect Permission Assignment for Critical Resource (CWE-732) in Ela ...)
@@ -4169,7 +4176,10 @@ CVE-2026-78408 (The nsenter --join-cgroup option opens the target cgroup.procs f
 	NOTE: https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj
 CVE-2026-78222 (A vulnerability exists in NGINX JavaScript where a malformed HTTP resp ...)
 	- libnginx-mod-js 1.0.1-1
+	[trixie] - libnginx-mod-js <no-dsa> (Minor issue)
 	NOTE: https://my.f5.com/manage/s/article/K000162603
+	NOTE: https://github.com/nginx/njs/commit/a62feb4831e75c75c446298ca4a23862dcfcbab4 (1.0.1)
+	NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
 CVE-2026-78153 (The Restrict User Access WordPress plugin before 2.8.1 does not normal ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77794 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not validat ...)
@@ -4328,7 +4338,11 @@ CVE-2026-18672 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812, in
 	NOT-FOR-US: Progress Software
 CVE-2026-18329 (Description  NGINX JavaScript (njs)and QuickJS (qjs) engineshave a vul ...)
 	- libnginx-mod-js 1.0.1-1
+	[trixie] - libnginx-mod-js <not-affected> (Vulnerable code not present, only affects 0.9.9 and later)
+	[bookworm] - libnginx-mod-js <not-affected> (Vulnerable code not present, only affects 0.9.9 and later)
 	NOTE: https://my.f5.com/manage/s/article/K000162599
+	NOTE: https://github.com/nginx/njs/commit/6898f7c9f844ca30af2aed9e8b1fe10f393644a5 (1.0.1)
+	NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
 CVE-2026-18058 (The mobile Smart Connect dashboard UI was subject to manipulation by 3 ...)
 	NOT-FOR-US: Lenovo
 CVE-2026-17563 (The User Frontend WordPress plugin before 4.3.11 does not enforce its  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f1343224b39a670dc05d64e59b40b26fa719202

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f1343224b39a670dc05d64e59b40b26fa719202
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/476f3a85/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list