[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 9 19:16:04 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a426e8ea by Moritz Muehlenhoff at 2026-09-09T20:15:13+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -1308,6 +1308,7 @@ CVE-2026-87049
 	NOT-FOR-US: operator-foundry
 CVE-2026-86564 (A flaw was found in DPDK lib/vhost. Missing length validation before r ...)
 	- dpdk <unfixed>
+	[trixie] - dpdk <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2529682
 CVE-2026-85630 (HTML::FormHandler versions before 0.410002 for Perl render field attri ...)
 	- libhtml-formhandler-perl <unfixed> (bug #1147198)
@@ -3940,6 +3941,7 @@ CVE-2026-0001 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver
 	NOT-FOR-US: ARM
 CVE-2026-18090 (A flaw was found in gdk-pixbuf. This vulnerability allows a remote att ...)
 	- gdk-pixbuf <unfixed>
+	[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517751
 CVE-2026-86544 (knowns versions before 0.30.0 contain an authorization bypass vulnerab ...)
 	NOT-FOR-US: knowns-dev/knowns
@@ -17049,18 +17051,23 @@ CVE-2026-79784 (Vocos instantiates a class named by a configuration file without
 	NOT-FOR-US: Vocos
 CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits when applyi ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-945v-v9p3-v5xw
 CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token header wh ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-gx4c-2hqx-cw2r
 CVE-2026-79781 (rclone serve s3 before 1.74.4 contains a path traversal vulnerability  ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8v25-v8p6-qf7v
 CVE-2026-79780 (rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE- ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8mxv-9xhp-86h4
 CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport downgrades in  ...)
 	- rclone <unfixed> (bug #1145670)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj
 CVE-2026-79778 (rclone before v1.75.0 contains a denial of service vulnerability in th ...)
 	- rclone <unfixed> (bug #1145670)


=====================================
data/dsa-needed.txt
=====================================
@@ -62,7 +62,7 @@ jq (aron)
 --
 jupyterlab
 --
-kamailio
+kamailio (jmm)
 --
 kitty
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a426e8ea1c57594cf7fa693520c04a18a8d9f547

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a426e8ea1c57594cf7fa693520c04a18a8d9f547
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/41d58e76/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list