[Git][security-tracker-team/security-tracker][master] NFUs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 8 21:32:20 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
955ee8c9 by Moritz Muehlenhoff at 2026-09-08T22:32:05+02:00
NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -744,7 +744,7 @@ CVE-2026-76196 (Photoshop Mobile is affected by a Session Fixation vulnerability
 CVE-2026-76191 (Animate is affected by an Improper Control of Generation of Code ('Cod ...)
 	NOT-FOR-US: Adobe
 CVE-2026-75156 (Apache Airflow FAB provider versions 3.7.3 through 3.8.0 do not valida ...)
-	TODO: check
+	NOT-FOR-US: Apache Airflow provider
 CVE-2026-75021 (fastify-cli starts the Node.js Inspector when a debug flag is used, bu ...)
 	TODO: check
 CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remote att ...)
@@ -968,7 +968,7 @@ CVE-2026-72927 (Heap-based buffer overflow in Winsock allows an authorized attac
 CVE-2026-72926 (Use after free in Windows Internet Connection Sharing (ICS) allows an  ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-72923 (In Microsoft.OpenApi.YamlReader from 2.0.0-preview.11 until 2.12.0 and ...)
-	TODO: check
+	NOT-FOR-US: Microsoft
 CVE-2026-71377 (Command Argument Injection Vulnerability in Cosminexus Component Conta ...)
 	NOT-FOR-US: Hitachi
 CVE-2026-71376 (OS command injection vulnerability in Cosminexus Component Container.  ...)
@@ -2307,11 +2307,11 @@ CVE-2026-62437 (When guests are terminated, various pieces of cleanup need carry
 	- xen <unfixed>
 	NOTE: https://xenbits.xen.org/xsa/advisory-509.html
 CVE-2026-61517 (Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command  ...)
-	TODO: check
+	NOT-FOR-US: Netis
 CVE-2026-61516 (Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an information ...)
-	TODO: check
+	NOT-FOR-US: Netis
 CVE-2026-5729 (Use After Free vulnerability in Arm Ltd Valhall GPU Kernel Driver, Arm ...)
-	TODO: check
+	NOT-FOR-US: Arm
 CVE-2026-58941 (In multiple functions of iommu.c, there is a possible out of bounds re ...)
 	NOT-FOR-US: Android
 CVE-2026-58874 (In multiple functions of SmsController.java, there is a possible escal ...)
@@ -2349,7 +2349,7 @@ CVE-2026-56177 (Use after free in Windows Server allows an authorized attacker t
 CVE-2026-56172 (Use after free in Windows VHD miniport driver allows an authorized att ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-56101 (OpenBSD before commit 1ee99df contains an inverted comparison vulnerab ...)
-	TODO: check
+	NOT-FOR-US: OpenBSD
 CVE-2026-55294 (In ihevcd_get_tu_data_size of ihevcd_utils.c, there is a possible out  ...)
 	NOT-FOR-US: Android
 CVE-2026-55290 (In setTo of ResourceTypes.cpp, there is a possible out-of-bounds heap  ...)
@@ -2365,9 +2365,9 @@ CVE-2026-55256 (In parsePartHeaders of multiple files, there is a possible persi
 CVE-2026-55007 (Double free in Microsoft Exchange Server allows an unauthorized attack ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-54611 (InstantCMS is a free and open source content management system. Versio ...)
-	TODO: check
+	NOT-FOR-US: InstantCMS
 CVE-2026-52307 (An authenticated stored cross-site scripting (XSS) vulnerability in th ...)
-	TODO: check
+	NOT-FOR-US: ClassCMS
 CVE-2026-50349 (Concurrent execution using shared resource with improper synchronizati ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-50093 (A vulnerability has been identified in Siveillance Control Pro V3.0 (A ...)
@@ -2397,7 +2397,7 @@ CVE-2026-49879 (In multiple functions of rw_t3t.cc, there is a possible out of b
 CVE-2026-48888 (Allocation of Resources Without Limits or Throttling vulnerability in  ...)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-48707 (InstantCMS is a free and open source content management system. Versio ...)
-	TODO: check
+	NOT-FOR-US: InstantCMS
 CVE-2026-47625 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
 	NOT-FOR-US: NVIDIA
 CVE-2026-47297 (Deserialization of untrusted data in SQL Server allows an unauthorized ...)
@@ -2585,13 +2585,13 @@ CVE-2026-12645 (A Missing Authorization vulnerability in Ivanti Neurons for ITSM
 CVE-2026-12611 (A client may issue HTTP/2 requests to a Jetty server that result in bl ...)
 	TODO: check
 CVE-2026-12387 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm ...)
-	TODO: check
+	NOT-FOR-US: Arm
 CVE-2026-12285 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm ...)
-	TODO: check
+	NOT-FOR-US: Arm
 CVE-2026-12230 (The LearnPress \u2013 WordPress LMS Plugin for Create and Sell Online  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-11891 (Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Driver,  ...)
-	TODO: check
+	NOT-FOR-US: Arm
 CVE-2026-11573 (Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets ...)
 	TODO: check
 CVE-2026-0860 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/955ee8c937468281ad9e88ffc9cb6f40aa44df7a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/955ee8c937468281ad9e88ffc9cb6f40aa44df7a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/b6259e6c/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list