[Git][security-tracker-team/security-tracker][master] bugnums

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 11 18:07:30 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
21245c89 by Moritz Muehlenhoff at 2026-09-11T19:07:04+02:00
bugnums

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -155,12 +155,12 @@ CVE-2026-79724 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attac
 CVE-2026-79723 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticat ...)
 	NOT-FOR-US: IBM
 CVE-2026-79592 (An out-of-bounds read vulnerability exists in the xls_dumpSummary() fu ...)
-	- r-cran-readxl <unfixed>
+	- r-cran-readxl <unfixed> (bug #1147420)
 	[trixie] - r-cran-readxl <no-dsa> (Minor issue)
 	NOTE: https://github.com/libxls/libxls/issues/162
 	NOTE: https://github.com/libxls/libxls/pull/165/changes/6eed8bc1d51d6649faebab0184b21ab8768d8fa6
 CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists in the  ...)
-	- r-cran-readxl <unfixed>
+	- r-cran-readxl <unfixed> (bug #1147420)
 	[trixie] - r-cran-readxl <no-dsa> (Minor issue)
 	NOTE: https://github.com/libxls/libxls/issues/161
 	NOTE: https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c
@@ -6065,7 +6065,7 @@ CVE-2022-51011 (PocketMine-MP before 4.2.10 fails to validate the total length o
 CVE-2022-51010 (PocketMine-MP versions before 4.4.2 fail to properly validate item IDs ...)
 	NOT-FOR-US: PocketMine-MP
 CVE-2026-78254 (The ftp and scp tasks of Apache Ant can download files from a remote s ...)
-	- ant <unfixed>
+	- ant <unfixed> (bug #1147425)
 	[trixie] - ant <no-dsa> (Minor issue)
 	NOTE: https://www.openwall.com/lists/oss-security/2026/09/06/2
 	NOTE: https://github.com/apache/ant/commit/07ee9c418e3bd3e7d0287fc9aaba3011e88f0dc2 (ANT_1.10.18_RC1)
@@ -12072,7 +12072,7 @@ CVE-2026-82629 (A vulnerability was determined in jeecgboot jeewx-boot up to 641
 CVE-2026-82217 (In Eclipse Theia versions 1.73.0 up to but not including 1.75.0, the A ...)
 	NOT-FOR-US: Eclipse
 CVE-2026-81624 (Undertow is a flexible performant web server used in JBoss EAP and Wil ...)
-	- undertow <unfixed>
+	- undertow <unfixed> (bug #1147427)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524868
 CVE-2026-79750 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
 	NOT-FOR-US: MCPHub
@@ -13564,11 +13564,10 @@ CVE-2026-82328 (A flaw was found in the file-ico plugin in GIMP. When processing
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16585
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/f59f677d849d5a2e1e689008d675f720c72e516e
 CVE-2026-82327 (A flaw was found in libsolv, a dependency-resolution library used by R ...)
-	- libsolv <unfixed>
+	- libsolv <unfixed> (bug #1147424)
 	[trixie] - libsolv <no-dsa> (Minor issue)
 	[bookworm] - libsolv <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2525602
-	TODO: check upstream status, no references from Red Hat
 CVE-2026-82324 (A flaw was found in the file-iff (IFF/ILBM) plugin in GIMP. When proce ...)
 	- gimp <unfixed> (bug #1146132; unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16584
@@ -14653,7 +14652,7 @@ CVE-2026-82072 (Out of bounds read in V8 in Google Chrome prior to 151.0.7922.72
 	- chromium 151.0.7922.71-1
 	[bullseye] - chromium <end-of-life> (see #1061268)
 CVE-2026-81934 (Redis contains a use-after-free vulnerability in the 'tlsProcessPendin ...)
-	- redis <unfixed>
+	- redis <unfixed> (bug #1147423)
 	NOTE: https://github.com/redis/redis/commit/6d088c335d5c3ec49a6c28486140b498e70b7834 (8.8.2)
 CVE-2026-81931 (Unrestricted Upload of File with Dangerous Type in the product photo u ...)
 	NOT-FOR-US: Roskus Prospero Flow CRM
@@ -54869,7 +54868,7 @@ CVE-2026-64257 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/8986c932905ea508d66da421eb2eb6e676ace1fe (7.2-rc4)
 CVE-2026-66373 (Redis before 8.8.0, in the unusual case where an authenticated attacke ...)
 	{DLA-4722-1}
-	- redis <unfixed>
+	- redis <unfixed> (bug #1147422)
 	NOTE: Fixed by: https://github.com/redis/redis/commit/4f62a8bf15c634187d8a87d874f8988032f90b6c (8.6.5)
 	NOTE: Fixed by: https://github.com/redis/redis/commit/04292292f2f5c180322292007a599a700611ebaf (7.2.15)
 	NOTE: fixed by: https://github.com/redis/redis/commit/41a958720e64e03576dd652d224aa46d22c096c3 (6.2.23)
@@ -118863,7 +118862,7 @@ CVE-2026-25588 (RedisTimeSeries is a time-series module for Redis. In all versio
 CVE-2026-25243 (Redis is an in-memory data structure store. In versions of redis-serve ...)
 	{DLA-4682-1}
 	[experimental] - redis 5:8.6.3-1
-	- redis <unfixed>
+	- redis <unfixed> (bug #1147421)
 	[bullseye] - redis <not-affected> (Vulnerable code not present; checks for dups introduced later)
 	NOTE: https://github.com/redis/redis/security/advisories/GHSA-c8h9-259x-jff4
 	NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-25243-deep-dive
@@ -118872,7 +118871,7 @@ CVE-2026-25243 (Redis is an in-memory data structure store. In versions of redis
 CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of redis-s ...)
 	{DLA-4682-1}
 	[experimental] - redis 5:8.6.3-1
-	- redis <unfixed>
+	- redis <unfixed> (bug #1147421)
 	[bullseye] - redis <ignored> (Invasive to backport entire timedOut mechanism etc.)
 	NOTE: https://github.com/redis/redis/security/advisories/GHSA-8ghh-qpmp-7826
 	NOTE: https://www.zeroday.cloud/blog/redis-cve-2026-23631-dark-replica
@@ -118880,7 +118879,7 @@ CVE-2026-23631 (Redis is an in-memory data structure store. In all versions of r
 	TODO: check redict and valkey
 CVE-2026-23479 (Redis is an in-memory data structure store. In redis-server from 7.2.0 ...)
 	[experimental] - redis 5:8.6.3-1
-	- redis <unfixed>
+	- redis <unfixed> (bug #1147421)
 	[bookworm] - redis <not-affected> (Vulnerable code not present)
 	[bullseye] - redis <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/redis/redis/security/advisories/GHSA-93m2-935m-8rj3



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21245c89020fff8ab82455594ee90a0e77acb7c8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/21245c89020fff8ab82455594ee90a0e77acb7c8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/58e1b476/attachment.htm>


More information about the debian-security-tracker-commits mailing list