[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 8 10:13:15 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5f134322 by Moritz Muehlenhoff at 2026-09-08T11:12:03+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -235,16 +235,19 @@ CVE-2026-86426 (LibreNMS before 26.8.0 contains an authentication bypass vulnera
NOT-FOR-US: LibreNMS
CVE-2026-86425 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)
- imagemagick <unfixed>
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-chf5-8rv9-gjqr
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/5bff96a5c8d0b3dafa4ad4fa7916db4cae72a11d (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/e006a69e03f3aff34e9a7af90a0793ec6d879b48 (6.9.13-55)
CVE-2026-86424 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a time-of-check-tim ...)
- imagemagick <unfixed>
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-9x6f-98x9-rx6g
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/a44ef50cc494253f7d9f0229bb25c064a8e2ae69 (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/0b47fb7e3d5650b2be88fd3a8c15096765970ce3 (6.9.13-55)
CVE-2026-86423 (ImageMagick before 7.1.2-30 and 6.9.x before 6.9.13-55 contains a heap ...)
- imagemagick <unfixed>
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-5m9j-96ff-j6qc
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/1d3e98913f6a8fa34b5a4180eadb9ed195b918a8 (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/ed44f0ba6e2ab57983a6d030c868d009514dc470 (6.9.13-55)
@@ -253,11 +256,13 @@ CVE-2026-86422 (ImageMagick before 7.1.2-30 contains a time-of-check-time-of-use
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-x8g2-7r3w-h44p
CVE-2026-86421 (ImageMagick before 7.1.2-30 and 6.9.13-55 contains a memory leak in th ...)
- imagemagick <unfixed>
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4jv7-q6xw-6f4x
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/c83153dfc128de8e7c538f879c532c7d36a75abb (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/d56cab9f2253373e57c2e77809ab12abbbbdd680 (6.9.13-55)
CVE-2026-86420 (ImageMagick before 7.1.2-30 and 6.9.13-55 fails to properly lower the ...)
- imagemagick <unfixed>
+ [trixie] - imagemagick <no-dsa> (Minor issue)
NOTE: https://github.com/ImageMagick/ImageMagick/security/advisories/GHSA-4mwf-mggw-29vp
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick/commit/6ac07556a93b2de00c845cd535ca256f45a47154 (7.1.2-30)
NOTE: Fixed by: https://github.com/ImageMagick/ImageMagick6/commit/29f17f3fe5008fc56f00c1fbc96adf46169db245 (6.9.13-55)
@@ -4126,7 +4131,9 @@ CVE-2026-79754 (Nuclio is a "Serverless" framework for Real-Time Events and Data
NOT-FOR-US: Nuclio
CVE-2026-78689 (Description NGINX JavaScript (njs) has a vulnerability in the XML mo ...)
- libnginx-mod-js 1.0.1-1
+ [trixie] - libnginx-mod-js <no-dsa> (Minor issue)
NOTE: https://my.f5.com/manage/s/article/K000162602
+ NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
CVE-2026-78609 (Incorrect Authorization (CWE-863) in Elastic Cloud on Kubernetes (ECK) ...)
NOT-FOR-US: Elastic Cloud on Kubernetes (ECK)
CVE-2026-78604 (Incorrect Permission Assignment for Critical Resource (CWE-732) in Ela ...)
@@ -4169,7 +4176,10 @@ CVE-2026-78408 (The nsenter --join-cgroup option opens the target cgroup.procs f
NOTE: https://github.com/util-linux/util-linux/security/advisories/GHSA-55fx-f4gg-cfhj
CVE-2026-78222 (A vulnerability exists in NGINX JavaScript where a malformed HTTP resp ...)
- libnginx-mod-js 1.0.1-1
+ [trixie] - libnginx-mod-js <no-dsa> (Minor issue)
NOTE: https://my.f5.com/manage/s/article/K000162603
+ NOTE: https://github.com/nginx/njs/commit/a62feb4831e75c75c446298ca4a23862dcfcbab4 (1.0.1)
+ NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
CVE-2026-78153 (The Restrict User Access WordPress plugin before 2.8.1 does not normal ...)
NOT-FOR-US: WordPress plugin
CVE-2026-77794 (The RegistrationMagic WordPress plugin before 6.0.9.9 does not validat ...)
@@ -4328,7 +4338,11 @@ CVE-2026-18672 (In Progress\xae Telerik\xae UI for AJAX prior to v2026.3.812, in
NOT-FOR-US: Progress Software
CVE-2026-18329 (Description NGINX JavaScript (njs)and QuickJS (qjs) engineshave a vul ...)
- libnginx-mod-js 1.0.1-1
+ [trixie] - libnginx-mod-js <not-affected> (Vulnerable code not present, only affects 0.9.9 and later)
+ [bookworm] - libnginx-mod-js <not-affected> (Vulnerable code not present, only affects 0.9.9 and later)
NOTE: https://my.f5.com/manage/s/article/K000162599
+ NOTE: https://github.com/nginx/njs/commit/6898f7c9f844ca30af2aed9e8b1fe10f393644a5 (1.0.1)
+ NOTE: https://github.com/nginx/njs/releases/tag/1.0.1
CVE-2026-18058 (The mobile Smart Connect dashboard UI was subject to manipulation by 3 ...)
NOT-FOR-US: Lenovo
CVE-2026-17563 (The User Frontend WordPress plugin before 4.3.11 does not enforce its ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f1343224b39a670dc05d64e59b40b26fa719202
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5f1343224b39a670dc05d64e59b40b26fa719202
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/476f3a85/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list