[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Sep 12 18:46:29 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
81b0d837 by Moritz Muehlenhoff at 2026-09-12T19:46:09+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3,9 +3,11 @@ CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly validate email address
 	NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)
 CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and password to an ...)
 	- ironic <unfixed>
+	[trixie] - ironic <no-dsa> (Minor issue)
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2162816
 CVE-2026-90460 (An issue was discovered in OpenStack Keystone before 29.0.3. Tokens ob ...)
 	- keystone <unfixed>
+	[trixie] - keystone <no-dsa> (Minor issue)
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2159643
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2158931
 	NOTE: https://review.opendev.org/c/openstack/keystone/+/1002330
@@ -1985,6 +1987,7 @@ CVE-2026-78224 (The XSLT Transformer Step builds a bare TransformerFactory witho
 	NOT-FOR-US: NextGen Healthcare
 CVE-2026-77159 (A symlink-following flaw was found in libvirt's qemuTPMEmulatorPrepare ...)
 	- libvirt 12.7.0-1
+	[trixie] - libvirt <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/libvirt/libvirt/-/work_items/909
 	NOTE: Fixed by: https://gitlab.com/libvirt/libvirt/-/commit/68e03ee02ff4826827f23d67d6b9eae49d7b9fb1 (v12.7.0-rc1)
 CVE-2026-72710 (SPIP before 4.4.18 contains a remote code execution vulnerability in t ...)
@@ -2611,9 +2614,11 @@ CVE-2026-88268 (GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffe
 	NOT-FOR-US: GeoVision
 CVE-2026-88265 (A flaw was found in crun. After pivot_root, reopening /dev/null for st ...)
 	- crun <unfixed> (bug #1147401)
+	[trixie] - crun <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531224
 CVE-2026-88264 (A flaw was found in crun. When the container configuration does not gi ...)
 	- crun <unfixed> (bug #1147401)
+	[trixie] - crun <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531223
 CVE-2026-88060 (Angular is a development platform for building mobile and desktop web  ...)
 	- angular.js <unfixed>
@@ -3070,8 +3075,9 @@ CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function (stb_sprin
 	- libstb <unfixed>
 	NOTE: https://github.com/nothings/stb/issues/1963
 CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of nothings ...)
-	- libstb <unfixed>
+	- libstb <unfixed> (unimportant)
 	NOTE: https://github.com/nothings/stb/issues/1962
+	NOTE: truetype parser only supported for trusted font files
 CVE-2026-79514 (An out-of-bounds read in the gf_dm_data_received function (downloader. ...)
 	- gpac <removed>
 CVE-2026-79513 (A divide-by-zero vulnerability in the gf_dash_get_timeline_duration fu ...)
@@ -11451,11 +11457,13 @@ CVE-2026-XXXX [heap-use-after-free in decoder_context::reset() via dangling prev
 	NOTE: https://github.com/strukturag/libde265/commit/07bc500d45f781a7e2915afb7eebc2d6d9a541c9 (v1.1.2)
 CVE-2026-56855 (Previously, after a channel has been established, a malicious peer cou ...)
 	- golang-go.crypto 1:0.56.0-1
+	[trixie] - golang-go.crypto <no-dsa> (Minor issue)
 	[bookworm] - golang-go.crypto <postponed> (Limited support)
 	NOTE: https://github.com/golang/go/issues/81317
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/86efde54dc7069251a8b007026c500d28e4239ce (v0.56.0)
 CVE-2026-78662 (Previously, a channel registered in the mux's chanList is not usable u ...)
 	- golang-go.crypto 1:0.56.0-1
+	[trixie] - golang-go.crypto <no-dsa> (Minor issue)
 	[bookworm] - golang-go.crypto <postponed> (Limited support)
 	NOTE: https://github.com/golang/go/issues/81316
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/a6cdac60840750226b15617ac8858be44361b36b (v0.56.0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b0d83736d7557a3c362a3cf33d0abe16a982f9

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/81b0d83736d7557a3c362a3cf33d0abe16a982f9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260912/a64eb606/attachment.htm>


More information about the debian-security-tracker-commits mailing list