[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 12 16:38:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
aa961736 by Salvatore Bonaccorso at 2026-09-12T17:37:45+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1783,7 +1783,7 @@ CVE-2026-8303 (Incorrect privilege assignment vulnerability in TUBITAK BILGEM So
 CVE-2026-8301 (Improper neutralization of special elements used in an OS command ('OS ...)
 	NOT-FOR-US: Pardus Boot Repair
 CVE-2026-89329 (A flaw was found in `multipathd`. A local attacker with access to the  ...)
-	- multipath-tools <unfixed>
+	- multipath-tools <unfixed> (bug #1147523)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470013
 	NOTE: https://github.com/opensvc/multipath-tools/security/advisories/GHSA-hmcm-9cq4-r2xm
 CVE-2026-89298 (A flaw was found in the Dynamic Client Registration service of Keycloa ...)
@@ -1909,11 +1909,11 @@ CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support li
 	NOTE: https://github.com/python/cpython/pull/157266
 	NOTE: https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2 (main)
 CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
-	- node-morgan <unfixed>
+	- node-morgan <unfixed> (bug #1147520)
 	NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
 	NOTE: Fixed by: https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee (1.12.1)
 CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
-	- node-compression <unfixed>
+	- node-compression <unfixed> (bug #1147519)
 	NOTE: https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95
 	NOTE: Fixed by: https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff (v1.8.2)
 CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)
@@ -1939,7 +1939,7 @@ CVE-2026-85083 (The ANJIA AJL33PC0801 IP camera uses a hard-coded credential for
 CVE-2026-84390 (A inclusion of sensitive information in source code vulnerability in F ...)
 	NOT-FOR-US: Fortinet
 CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
-	- apache-opennlp <unfixed>
+	- apache-opennlp <unfixed> (bug #1147511)
 	NOTE: https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3
 CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
 	NOT-FOR-US: NextGen Connect (Mirth Connect)
@@ -1978,7 +1978,7 @@ CVE-2026-79393 (A heap-based buffer overflow vulnerability in the WS-Addressing
 CVE-2026-79362 (Certain Woltlab products are affected by RCE via Cache Poisoning. WCF  ...)
 	NOT-FOR-US: Woltlab
 CVE-2026-78807 (An issue in wpa_supplicant all versions before v.2.12 allows a local a ...)
-	- wpa <unfixed>
+	- wpa <unfixed> (bug #1147510)
 	NOTE: https://w1.fi/security/2026-2/missing-network-context-validation-for-pmksa-caching.txt
 	NOTE: Fixed by: https://git.w1.fi/cgit/hostap/commit/?id=de5e73a03c34d83568afb3183b2b28c8d7641a30
 CVE-2026-78224 (The XSLT Transformer Step builds a bare TransformerFactory without the ...)
@@ -2021,7 +2021,7 @@ CVE-2026-6640 (The Media Library Assistant plugin for WordPress is vulnerable to
 CVE-2026-68528 (Concrete CMS RSS Displayer block below version 9.5.3  rendered remote  ...)
 	NOT-FOR-US: Concrete CMS
 CVE-2026-68497 (jackson-databind binds a JSON string to a javax.xml.datatype.Duration  ...)
-	- jackson-databind <unfixed>
+	- jackson-databind <unfixed> (bug #1147507)
 	NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-q4xh-88c3-wmh7
 	NOTE: https://github.com/FasterXML/jackson-databind/pull/6127
 	NOTE: Fixed by: https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd (jackson-databind-2.18.10)
@@ -2151,7 +2151,7 @@ CVE-2026-89094 (Forgejo before 16.0.4 allows remote code execution via a crafted
 CVE-2026-89089 (A SQL injection vulnerability exists in the JasperReports-based report ...)
 	NOT-FOR-US: OpenNMS
 CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
-	- ocaml-cstruct <unfixed>
+	- ocaml-cstruct <unfixed> (bug #1147522)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-20
 	NOTE: https://github.com/mirage/ocaml-cstruct/pull/324 (v6.3.0)
 CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to validate ...)
@@ -2818,7 +2818,7 @@ CVE-2026-85228 (An integer overflow in the tensor buffer validation component in
 CVE-2026-85217 (A maliciously crafted add-in, when installed and executed in Autodesk  ...)
 	NOT-FOR-US: Autodesk
 CVE-2026-84828 (A flaw was found in PCS (Pacemaker Configuration System). A local atta ...)
-	- pcs <unfixed>
+	- pcs <unfixed> (bug #1147515)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2527320
 	NOTE: Introduced with: https://github.com/ClusterLabs/pcs/commit/9178b78d11baa70e700a5c0d9fc1c17f27d452fa (0.10.8)
 	NOTE: Fixed by: https://github.com/ClusterLabs/pcs/commit/b41eaf3c6e2ecfc575c42442fb02b8ef05b4dd6a
@@ -3048,7 +3048,7 @@ CVE-2026-87011 (Open WebUI is an extensible, feature-rich, and user-friendly sel
 CVE-2026-85645 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop Contact For ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-84939 (Path traversal vulnerability in Apache FreeMarker template loading mec ...)
-	- libfreemarker-java <unfixed>
+	- libfreemarker-java <unfixed> (bug #1147516)
 	NOTE: https://lists.apache.org/thread/hrd7o2ylwkkswdyhyzllgqt0f80kyd5y
 CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted u ...)
 	NOT-FOR-US: BurgerEditor
@@ -3242,10 +3242,10 @@ CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail to validate closed state
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e (v1.5.7-14)
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555 (v1.5.7-14)
 CVE-2026-87876 (Two case-insensitive comparisons on request-derived usernames outside  ...)
-	- cups <unfixed>
+	- cups <unfixed> (bug #1147521)
 	NOTE: https://github.com/OpenPrinting/cups/security/advisories/GHSA-r8jp-q6fh-g5r2
 CVE-2026-87875 (The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a sour ...)
-	- cups <unfixed>
+	- cups <unfixed> (bug #1147521)
 	NOTE: https://github.com/OpenPrinting/cups/security/advisories/GHSA-559w-7676-3xrq
 CVE-2026-87874 (A flaw was found in the memcached cache plugin of the community.genera ...)
 	- ansible <unfixed>
@@ -3424,7 +3424,7 @@ CVE-2026-85102 (Improper certificate trust validation during VPN negotiation in
 	NOT-FOR-US: Check Point
 CVE-2026-83530 (A user could provide an expression whose string length is longer than  ...)
 	- golang-cel-cel-go 0.32.0+ds-1
-	- golang-github-google-cel-go <unfixed>
+	- golang-github-google-cel-go <unfixed> (bug #1147513)
 	NOTE: https://github.com/cel-expr/cel-go/pull/1302
 	NOTE: Fixed by: https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a (v0.29.0)
 CVE-2026-82563 (An attacker could impersonate the camera and place themselves in a man ...)
@@ -5052,7 +5052,7 @@ CVE-2026-87050
 CVE-2026-87049
 	NOT-FOR-US: operator-foundry
 CVE-2026-86564 (A flaw was found in DPDK lib/vhost. Missing length validation before r ...)
-	- dpdk <unfixed>
+	- dpdk <unfixed> (bug #1147518)
 	[trixie] - dpdk <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2529682
 CVE-2026-85630 (HTML::FormHandler versions before 0.410002 for Perl render field attri ...)
@@ -5835,7 +5835,7 @@ CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A remo
 	NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/397
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/libxml2/-/commit/f41e1865781f74d1cadfe2fbdfeefed946026f12 (v2.15.3)
 CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts user-supplied ZIP a ...)
-	- gnome-tweaks <unfixed>
+	- gnome-tweaks <unfixed> (bug #1147509)
 	[trixie] - gnome-tweaks <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gnome-tweaks/-/issues/542
 CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability in the s ...)
@@ -8363,7 +8363,7 @@ CVE-2026-86231 (A security flaw has been discovered in mwiede jsch up to 2.28.5.
 CVE-2026-86228 (A security vulnerability has been detected in JeecgBoot up to 3.9.3. T ...)
 	NOT-FOR-US: JeecgBoot
 CVE-2026-86227 (A weakness has been identified in valkey-io valkey up to 9.0.5/9.1.1.  ...)
-	- valkey <unfixed>
+	- valkey <unfixed> (bug #1147517)
 	NOTE: https://github.com/valkey-io/valkey/issues/4222
 	NOTE: https://github.com/valkey-io/valkey/pull/4229
 	NOTE: Fixed by: https://github.com/valkey-io/valkey/commit/4691888e7fab3df128f0bde5750c9fde2ae552fa (unstable)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aa961736ae34cc770f97999966ccc1b31399f99b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/aa961736ae34cc770f97999966ccc1b31399f99b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/70dacb02/attachment.htm>


More information about the debian-security-tracker-commits mailing list