[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Sep 12 18:46:29 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
81b0d837 by Moritz Muehlenhoff at 2026-09-12T19:46:09+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3,9 +3,11 @@ CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly validate email address
NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)
CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and password to an ...)
- ironic <unfixed>
+ [trixie] - ironic <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/ironic/+bug/2162816
CVE-2026-90460 (An issue was discovered in OpenStack Keystone before 29.0.3. Tokens ob ...)
- keystone <unfixed>
+ [trixie] - keystone <no-dsa> (Minor issue)
NOTE: https://bugs.launchpad.net/keystone/+bug/2159643
NOTE: https://bugs.launchpad.net/keystone/+bug/2158931
NOTE: https://review.opendev.org/c/openstack/keystone/+/1002330
@@ -1985,6 +1987,7 @@ CVE-2026-78224 (The XSLT Transformer Step builds a bare TransformerFactory witho
NOT-FOR-US: NextGen Healthcare
CVE-2026-77159 (A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepare ...)
- libvirt 12.7.0-1
+ [trixie] - libvirt <no-dsa> (Minor issue)
NOTE: https://gitlab.com/libvirt/libvirt/-/work_items/909
NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/68e03ee02ff4826827f23d67d6b9eae49d7b9fb1 (v12.7.0-rc1)
CVE-2026-72710 (SPIP before 4.4.18 contains a remote code execution vulnerability in t ...)
@@ -2611,9 +2614,11 @@ CVE-2026-88268 (GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffe
NOT-FOR-US: GeoVision
CVE-2026-88265 (A flaw was found in crun. After pivot_root, reopening /dev/null for st ...)
- crun <unfixed> (bug #1147401)
+ [trixie] - crun <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531224
CVE-2026-88264 (A flaw was found in crun. When the container configuration does not gi ...)
- crun <unfixed> (bug #1147401)
+ [trixie] - crun <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531223
CVE-2026-88060 (Angular is a development platform for building mobile and desktop web ...)
- angular.js <unfixed>
@@ -3070,8 +3075,9 @@ CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function (stb_sprin
- libstb <unfixed>
NOTE: https://github.com/nothings/stb/issues/1963
CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of nothings ...)
- - libstb <unfixed>
+ - libstb <unfixed> (unimportant)
NOTE: https://github.com/nothings/stb/issues/1962
+ NOTE: truetype parser only supported for trusted font files
CVE-2026-79514 (An out-of-bounds read in the gf_dm_data_received function (downloader. ...)
- gpac <removed>
CVE-2026-79513 (A divide-by-zero vulnerability in the gf_dash_get_timeline_duration fu ...)
@@ -11451,11 +11457,13 @@ CVE-2026-XXXX [heap-use-after-free in decoder_context::reset() via dangling prev
NOTE: https://github.com/strukturag/libde265/commit/07bc500d45f781a7e2915afb7eebc2d6d9a541c9 (v1.1.2)
CVE-2026-56855 (Previously, after a channel has been established, a malicious peer cou ...)
- golang-go.crypto 1:0.56.0-1
+ [trixie] - golang-go.crypto <no-dsa> (Minor issue)
[bookworm] - golang-go.crypto <postponed> (Limited support)
NOTE: https://github.com/golang/go/issues/81317
NOTE: Fixed by: https://github.com/golang/crypto/commit/86efde54dc7069251a8b007026c500d28e4239ce (v0.56.0)
CVE-2026-78662 (Previously, a channel registered in the mux's chanList is not usable u ...)
- golang-go.crypto 1:0.56.0-1
+ [trixie] - golang-go.crypto <no-dsa> (Minor issue)
[bookworm] - golang-go.crypto <postponed> (Limited support)
NOTE: https://github.com/golang/go/issues/81316
NOTE: Fixed by: https://github.com/golang/crypto/commit/a6cdac60840750226b15617ac8858be44361b36b (v0.56.0)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b0d83736d7557a3c362a3cf33d0abe16a982f9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b0d83736d7557a3c362a3cf33d0abe16a982f9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/a64eb606/attachment.htm>
More information about the debian-security-tracker-commits
mailing list