[Git][security-tracker-team/security-tracker][master] Add new issues from XSAs from 2026-09-08

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 8 20:20:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1181981b by Salvatore Bonaccorso at 2026-09-08T21:20:03+02:00
Add new issues from XSAs from 2026-09-08

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -456,10 +456,21 @@ CVE-2026-79904 (Photoshop Mobile is affected by an Improper Limitation of a Path
 	NOT-FOR-US: Adobe
 CVE-2026-79721 (Code execution can occur in versions of the MLflow platform running ve ...)
 	NOT-FOR-US: mlflow
+CVE-2026-79606
+	NOT-FOR-US: Xen Tapdisk
+	NOTE: https://xenbits.xen.org/xsa/advisory-513.html
+CVE-2026-79605
+	NOT-FOR-US: Xen Tapdisk
+	NOTE: https://xenbits.xen.org/xsa/advisory-513.html
+CVE-2026-79604
+	- xen <unfixed>
+	NOTE: https://xenbits.xen.org/xsa/advisory-512.html
 CVE-2026-79603 (x86 PV guests can free memory pages while still keeping a stale TLB en ...)
-	TODO: check
+	- xen <unfixed>
+	NOTE: https://xenbits.xen.org/xsa/advisory-511.html
 CVE-2026-79602 (A guest with a PCI device assigned that has at least a BAR on the IO p ...)
-	TODO: check
+	- xen <unfixed>
+	NOTE: https://xenbits.xen.org/xsa/advisory-510.html
 CVE-2026-79577 (An issue in the /cas/login component of sso-master v1.0.0 allows attac ...)
 	TODO: check
 CVE-2026-79576 (An issue in the Single-Sign On (SSO) component of Digital-Infrastructu ...)
@@ -2293,7 +2304,8 @@ CVE-2026-62646 (A vulnerability has been identified in Reyrolle 7SR5 (All versio
 CVE-2026-62645 (A vulnerability has been identified in Reyrolle 7SR5 (All versions < V ...)
 	NOT-FOR-US: Siemens
 CVE-2026-62437 (When guests are terminated, various pieces of cleanup need carrying ou ...)
-	TODO: check
+	- xen <unfixed>
+	NOTE: https://xenbits.xen.org/xsa/advisory-509.html
 CVE-2026-61517 (Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command  ...)
 	TODO: check
 CVE-2026-61516 (Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1181981b6dde849d8ee729bcc0d88f782674d0e4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1181981b6dde849d8ee729bcc0d88f782674d0e4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/f6bca067/attachment.htm>


More information about the debian-security-tracker-commits mailing list