[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Sep 9 19:16:04 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a426e8ea by Moritz Muehlenhoff at 2026-09-09T20:15:13+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1308,6 +1308,7 @@ CVE-2026-87049
NOT-FOR-US: operator-foundry
CVE-2026-86564 (A flaw was found in DPDK lib/vhost. Missing length validation before r ...)
- dpdk <unfixed>
+ [trixie] - dpdk <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2529682
CVE-2026-85630 (HTML::FormHandler versions before 0.410002 for Perl render field attri ...)
- libhtml-formhandler-perl <unfixed> (bug #1147198)
@@ -3940,6 +3941,7 @@ CVE-2026-0001 (Use After Free vulnerability in Arm Ltd Bifrost GPU Kernel Driver
NOT-FOR-US: ARM
CVE-2026-18090 (A flaw was found in gdk-pixbuf. This vulnerability allows a remote att ...)
- gdk-pixbuf <unfixed>
+ [trixie] - gdk-pixbuf <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2517751
CVE-2026-86544 (knowns versions before 0.30.0 contain an authorization bypass vulnerab ...)
NOT-FOR-US: knowns-dev/knowns
@@ -17049,18 +17051,23 @@ CVE-2026-79784 (Vocos instantiates a class named by a configuration file without
NOT-FOR-US: Vocos
CVE-2026-79783 (rclone before 1.74.4 fails to mask special permission bits when applyi ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-945v-v9p3-v5xw
CVE-2026-79782 (rclone before 1.74.4 fails to strip the X-Amz-Security-Token header wh ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-gx4c-2hqx-cw2r
CVE-2026-79781 (rclone serve s3 before 1.74.4 contains a path traversal vulnerability ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8v25-v8p6-qf7v
CVE-2026-79780 (rclone before v1.75.0 fails to sanitize IBM IAM bearer tokens and SSE- ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8mxv-9xhp-86h4
CVE-2026-79779 (rclone versions before v1.75.0 fail to reject transport downgrades in ...)
- rclone <unfixed> (bug #1145670)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-h4mf-4v27-hggj
CVE-2026-79778 (rclone before v1.75.0 contains a denial of service vulnerability in th ...)
- rclone <unfixed> (bug #1145670)
=====================================
data/dsa-needed.txt
=====================================
@@ -62,7 +62,7 @@ jq (aron)
--
jupyterlab
--
-kamailio
+kamailio (jmm)
--
kitty
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a426e8ea1c57594cf7fa693520c04a18a8d9f547
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a426e8ea1c57594cf7fa693520c04a18a8d9f547
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/41d58e76/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list