[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 11 15:48:22 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eff56db7 by Moritz Muehlenhoff at 2026-09-11T16:44:13+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -497,34 +497,42 @@ CVE-2026-88055 (AnythingLLM is an application that turns pieces of content into
NOT-FOR-US: AnythingLLM
CVE-2026-88054 (Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-f6h7-cqr4-6fx4
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/552771236b0d80cbdb0c7dd856120fa21a4672e5
CVE-2026-88053 (Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-rphx-x795-5qjv
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/8b0574680f3b22f246ade6a4c8e3029104255c63
CVE-2026-88052 (Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-2hm8-q5c7-c373
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/2d04d640db2e8c7e3bab2369d599343b5a8b8443
CVE-2026-88051 (Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-88qp-4g94-3rf3
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/56e09ca12e751623fe796ce1554ce704bffd2ef0
CVE-2026-88050 (Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-7v9h-3q3m-w68g
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/c94a5532ee04db5a4919542832fd94caee5ea58f
CVE-2026-88049 (Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-jgq8-pprg-vc68
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/b494ac18925f9d9aff9ef5815475de9943ab19bf
CVE-2026-88048 (Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-q44c-23p6-5mw6
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/103dc134eb36411ddc6833ec20aa2c76795bd0ff
CVE-2026-88047 (Tesseract is an open source OCR engine. In version 5.5.3 and earlier, ...)
- tesseract <unfixed>
+ [trixie] - tesseract <no-dsa> (Minor issue)
NOTE: https://github.com/tesseract-ocr/tesseract/security/advisories/GHSA-5j2p-r5vc-q7f3
NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/1bda5079b1c8a7e25f523486837426903d29ce84
CVE-2026-88046 (rclone is a command-line program to sync files and directories to and ...)
@@ -561,12 +569,15 @@ CVE-2026-88034 (Improper neutralization of special elements in data query logic
NOTE: Fixed by: https://github.com/mongodb/mongo-cxx-driver/commit/5e52e715bf820d2d4efff01b8520eb8640c98b29 (r4.5.3)
CVE-2026-88033 (Improper neutralization of special elements in data query logic in the ...)
- mongo-java-driver <unfixed>
+ [trixie] - mongo-java-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/JAVA-6283
CVE-2026-88032 (A use-after-free in the reactive client-side encryption component of t ...)
- mongo-java-driver <unfixed>
+ [trixie] - mongo-java-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/JAVA-6276
CVE-2026-88031 (Improper neutralization of special elements in data query logic in the ...)
- golang-mongodb-mongo-driver <unfixed>
+ [trixie] - golang-mongodb-mongo-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/GODRIVER-4081
NOTE: Fixed by: https://github.com/mongodb/mongo-go-driver/commit/806e132f9501a2665d05ebaba3b6f0d787ceaa96 (v1.17.10)
CVE-2026-88030 (Improper neutralization of special elements in data query logic in the ...)
@@ -1069,6 +1080,7 @@ CVE-2026-XXXX [GHSA-5qpq-xqfv-j9pg: Invalid write if a decoder is reinitialized
NOTE: https://github.com/tukaani-project/xz/security/advisories/GHSA-5qpq-xqfv-j9pg
CVE-2026-19816
- packagekit 1.4.0-1
+ [trixie] - packagekit <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2515940
NOTE: https://github.com/PackageKit/PackageKit/security/advisories/GHSA-g5gf-h68q-gxc8
NOTE: Fixed by: https://github.com/PackageKit/PackageKit/commit/33be77b3ecd3b566ca117358dc18c58c964e627b (v1.4.0)
@@ -1095,9 +1107,11 @@ CVE-2026-87875 (The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks
NOTE: https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq
CVE-2026-87874 (A flaw was found in the memcached cache plugin of the community.genera ...)
- ansible <unfixed>
+ [trixie] - ansible <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530995
CVE-2026-87872 (A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of t ...)
- ansible <unfixed>
+ [trixie] - ansible <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530988 (private)
CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The eval_acces ...)
- sssd <unfixed>
@@ -1654,24 +1668,29 @@ CVE-2026-87747 (The Enterprise Cloud Database developed by Ragic has an Arbitrar
NOT-FOR-US: Ragic
CVE-2026-87737 (An issue was discovered in the mirage-crypto-ec package before 2.4.0 f ...)
- ocaml-mirage-crypto 2.4.0-1
+ [trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
NOTE: https://osv.dev/vulnerability/OSEC-2026-17
NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/1a61aeee7f593ec067612df1739ec905eab0450f (v2.4.0)
CVE-2026-87736 (An issue was discovered in the mirage-crypto-ec package before 2.3.0 f ...)
- ocaml-mirage-crypto 2.3.0-1
+ [trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
NOTE: https://osv.dev/vulnerability/OSEC-2026-15
NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/1f0bf67044e67cf6e46911fcd77a0ff706b6c3e7 (v2.3.0)
CVE-2026-87735 (An issue was discovered in the mirage-crypto-pk package before 2.3.0 f ...)
- ocaml-mirage-crypto 2.3.0-1
+ [trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
NOTE: https://osv.dev/vulnerability/OSEC-2026-14
NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/a0f59a0c90eb067505b55a03d3bb104eacd6dd33 (v2.3.0)
CVE-2026-87734 (An issue was discovered in the utcp package before 0.0.6 for OCaml. Ou ...)
NOT-FOR-US: utcp package for OCaml
CVE-2026-87733 (An issue was discovered in the mirage-crypto-ec function before 2.2.0 ...)
- ocaml-mirage-crypto 2.2.0-1
+ [trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
NOTE: https://osv.dev/vulnerability/OSEC-2026-13
NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/ca84f5ee8ede80bd1dd2aa4cd7cc90197752184e (v2.2.0)
CVE-2026-87732 (An issue was discovered in the mirage-crypto package before 2.2.0 for ...)
- ocaml-mirage-crypto 2.2.0-1
+ [trixie] - ocaml-mirage-crypto <no-dsa> (Minor issue)
NOTE: https://osv.dev/vulnerability/OSEC-2026-12
NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/25e7570aec91e092b347561c23f84b6ec39e7163 (v2.2.0)
CVE-2026-87724 (Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_ ...)
@@ -3358,12 +3377,15 @@ CVE-2026-79605
NOTE: https://xenbits.xen.org/xsa/advisory-513.html
CVE-2026-79604
- xen <unfixed>
+ [trixie] - xen <postponed> (Minor issue, fix along with future DSA)
NOTE: https://xenbits.xen.org/xsa/advisory-512.html
CVE-2026-79603 (x86 PV guests can free memory pages while still keeping a stale TLB en ...)
- xen <unfixed>
+ [trixie] - xen <postponed> (Minor issue, fix along with future DSA)
NOTE: https://xenbits.xen.org/xsa/advisory-511.html
CVE-2026-79602 (A guest with a PCI device assigned that has at least a BAR on the IO p ...)
- xen <unfixed>
+ [trixie] - xen <postponed> (Minor issue, fix along with future DSA)
NOTE: https://xenbits.xen.org/xsa/advisory-510.html
CVE-2026-79577 (An issue in the /cas/login component of sso-master v1.0.0 allows attac ...)
NOT-FOR-US: sso-master
@@ -5205,6 +5227,7 @@ CVE-2026-62645 (A vulnerability has been identified in Reyrolle 7SR5 (All versio
NOT-FOR-US: Siemens
CVE-2026-62437 (When guests are terminated, various pieces of cleanup need carrying ou ...)
- xen <unfixed>
+ [trixie] - xen <postponed> (Minor issue, fix along with future DSA)
NOTE: https://xenbits.xen.org/xsa/advisory-509.html
CVE-2026-61517 (Netis NX10 firmware V4.0.1.5808 and V3.0.0.4142 contain an OS command ...)
NOT-FOR-US: Netis
@@ -6034,6 +6057,7 @@ CVE-2022-51010 (PocketMine-MP versions before 4.4.2 fail to properly validate it
NOT-FOR-US: PocketMine-MP
CVE-2026-78254 (The ftp and scp tasks of Apache Ant can download files from a remote s ...)
- ant <unfixed>
+ [trixie] - ant <no-dsa> (Minor issue)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/06/2
NOTE: https://github.com/apache/ant/commit/07ee9c418e3bd3e7d0287fc9aaba3011e88f0dc2 (ANT_1.10.18_RC1)
NOTE: https://github.com/apache/ant/commit/9252566cab812c59a5695679ba11f497e85aabb0 (ANT_1.10.18_RC1)
@@ -8744,6 +8768,7 @@ CVE-2026-85154 (WWBN AVideo contains an authentication failure vulnerability whe
NOT-FOR-US: WWBN AVideo
CVE-2026-85150 (A NULL pointer dereference flaw was found in GStreamer's RTSP support ...)
- gst-plugins-base1.0 1.28.7-1
+ [trixie] - gst-plugins-base1.0 <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527936
NOTE: https://gstreamer.freedesktop.org/security/sa-2026-0082.html
NOTE: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/merge_requests/85150
@@ -10725,6 +10750,7 @@ CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b (0.6.0)
CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
- golang-google-grpc <unfixed> (bug #1146639)
+ [trixie] - golang-google-grpc <no-dsa> (Minor issue)
[bookworm] - golang-google-grpc <postponed> (Limited support)
NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-vp52-pcj8-j9qc
NOTE: https://github.com/grpc/grpc-go/pull/9331
@@ -10733,6 +10759,7 @@ CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83
NOTE: Fixed by: https://github.com/grpc/grpc-go/commit/8cfeca0e1ee5ea0980dcc320e20240fa1079ec77 (v1.83.1)
CVE-2026-84303 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, th ...)
- golang-google-grpc <unfixed> (bug #1146639)
+ [trixie] - golang-google-grpc <no-dsa> (Minor issue)
[bookworm] - golang-google-grpc <postponed> (Limited support)
NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-qc2q-p7wx-3px3
NOTE: https://github.com/grpc/grpc-go/pull/9332
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eff56db728e82de8ddc72cb1963bf609f6cc8c7e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eff56db728e82de8ddc72cb1963bf609f6cc8c7e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/3e0efda0/attachment.htm>
More information about the debian-security-tracker-commits
mailing list