[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 9 07:10:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c986c524 by Salvatore Bonaccorso at 2026-09-09T08:09:47+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31,7 +31,7 @@ CVE-2026-9034 (Use After Free vulnerability in Arm Ltd Bifrost GPU Userspace Dri
 CVE-2026-86853 (A malicious webpage could repeatedly trigger external URL schemes, cau ...)
 	NOT-FOR-US: Firefox for iOS
 CVE-2026-86840 (The `vtoken-minting` and `slpx` pallets in Bifrost contain an improper ...)
-	TODO: check
+	NOT-FOR-US: Bifrost
 CVE-2026-86804 (A vulnerability was identified in seakee CPA-Manager-Plus up to 1.11.1 ...)
 	NOT-FOR-US: seakee CPA-Manager-Plus
 CVE-2026-86738 (Snipe-IT versions before 8.7.0 contain a CSS injection vulnerability i ...)
@@ -77,7 +77,7 @@ CVE-2026-86719 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf33
 CVE-2026-86718 (WWBN AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 co ...)
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-86716 (A vulnerability was determined in Cesanta mJS up to 1.26. Affected is  ...)
-	TODO: check
+	NOT-FOR-US: Cesanta mJS
 CVE-2026-86714 (PX4 Autopilot through 1.17.0 contains a stack buffer over-read vulnera ...)
 	NOT-FOR-US: PX4 Autopilot
 CVE-2026-86713 (PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability i ...)
@@ -109,11 +109,11 @@ CVE-2026-86665 (A vulnerability was identified in aircheng-org iWebShop-5 up to
 CVE-2026-86644 (A vulnerability was determined in star7th showdoc up to 3.9.1. This vu ...)
 	NOT-FOR-US: star7th showdoc
 CVE-2026-86600 (In affected Snowflake drivers, WORKLOAD_IDENTITY authentication reques ...)
-	TODO: check
+	NOT-FOR-US: Snowflake
 CVE-2026-86597 (Insertion of sensitive information into log files in the Snowflake Pyt ...)
-	TODO: check
+	NOT-FOR-US: Snowflake
 CVE-2026-86590 (In Eclipse Che versions 7.79.0 through 7.121.0, the dashboard backend' ...)
-	TODO: check
+	NOT-FOR-US: Eclipse Che
 CVE-2026-86550 (NuBrowser lacks protocol whitelist validation for the S.browser_fallba ...)
 	NOT-FOR-US: ZTE
 CVE-2026-86477
@@ -2565,7 +2565,7 @@ CVE-2026-26084 (A improper access control vulnerability in Fortinet FortiSandbox
 CVE-2026-22575 (An improper access control vulnerability in Fortinet FortiManager 7.6. ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-20293 (A vulnerability in the Unified Extensible Firmware Interface (UEFI) Sh ...)
-	TODO: check
+	NOT-FOR-US: Cisco
 CVE-2026-19614 (The API is prone to XML external entity (XXE) injection. By default, X ...)
 	TODO: check
 CVE-2026-19203 (A client may issue specially crafted HTTP/1.1 chunked requests to a Je ...)
@@ -2583,9 +2583,9 @@ CVE-2026-16502 (The Live Composer \u2013 Free WordPress Website Builder plugin f
 CVE-2026-16497 (NVIDIA Triton Inference Server for Linux contains a vulnerability wher ...)
 	NOT-FOR-US: NVIDIA
 CVE-2026-16037 (Observable timing discrepancy vulnerability in PayTR Payment and Elect ...)
-	TODO: check
+	NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
 CVE-2026-16025 (Improper validation of specified quantity in input vulnerability in Pa ...)
-	TODO: check
+	NOT-FOR-US: PayTR Virtual Pos iFrame API (v9x) WHMCS Module
 CVE-2026-12745 (A Deserialization of Untrusted Data vulnerability in Ivanti Neurons fo ...)
 	NOT-FOR-US: Ivanti
 CVE-2026-12744 (A Deserialization of Untrusted Data vulnerability in Ivanti Neurons fo ...)
@@ -2615,7 +2615,7 @@ CVE-2026-11891 (Use After Free vulnerability in Arm Ltd Valhall GPU Userspace Dr
 CVE-2026-11573 (Uncontrolled recursion in Qt's QDomDocument serialization (QtXml) lets ...)
 	TODO: check
 CVE-2026-0860 (Exposure of Sensitive Information to an Unauthorized Actor vulnerabili ...)
-	TODO: check
+	NOT-FOR-US: ARM
 CVE-2026-0084 (In multiple functions of HostEmulationManager.java, there is a possibl ...)
 	NOT-FOR-US: Android
 CVE-2026-0065 (In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessContro ...)
@@ -2623,7 +2623,7 @@ CVE-2026-0065 (In areBackgroundActivityStartsAllowed of BackgroundLaunchProcessC
 CVE-2026-0054 (In isCallerAllowed of WalletContextualLocationsService.kt, there is a  ...)
 	NOT-FOR-US: Android
 CVE-2026-0001 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver, Arm ...)
-	TODO: check
+	NOT-FOR-US: ARM
 CVE-2026-18090
 	- gdk-pixbuf <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517751



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c986c524a4af11cfa72170ef187b8621fbb7d714

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c986c524a4af11cfa72170ef187b8621fbb7d714
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/44f97e59/attachment.htm>


More information about the debian-security-tracker-commits mailing list