[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 13 19:08:16 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c6bf67b8 by Moritz Muehlenhoff at 2026-09-13T20:08:06+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -66,12 +66,14 @@ CVE-2026-77773 (The Contact Form to Chat Apps | Click to Chat to Order WordPres
NOT-FOR-US: WordPress plugin
CVE-2026-90560 (zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read ...)
- zstd-jni-java <unfixed>
+ [trixie] - zstd-jni-java <no-dsa> (Minor issue)
NOTE: https://github.com/luben/zstd-jni/issues/405
NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f (v1.5.7-14)
CVE-2026-90559 (snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerabi ...)
NOT-FOR-US: snappy-java
CVE-2026-90558 (sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in ...)
- sngrep <unfixed>
+ [trixie] - sngrep <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b
CVE-2026-90555 (vLLM versions before 0.28.0 fail to validate audio sample rate headers ...)
- vllm <itp> (bug #1095237)
@@ -153,6 +155,7 @@ CVE-2026-10148 (The Booking for Appointments and Events Calendar plugin for Word
NOT-FOR-US: WordPress plugin
CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly validate email addresses sup ...)
- aiosmtplib 5.1.3-1 (bug #1147474)
+ [trixie] - aiosmtplib <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)
CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and password to an ...)
- ironic <unfixed>
@@ -2022,8 +2025,8 @@ CVE-2026-89148 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 c
NOT-FOR-US: WWBN AVideo
CVE-2026-89147 (Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in ...)
- net-snmp <unfixed> (bug #1147442)
+ [trixie] - net-snmp <no-dsa> (Minor issue)
NOTE: https://gist.github.com/thesmartshadow/001cea595e75fed6aaea7389666dc9eb
- TODO: check for upstream report
CVE-2026-89146 (libp2p-rendezvous through 0.17.1 fails to validate registration TTL va ...)
NOT-FOR-US: libp2p-rendezvous
CVE-2026-89099 (A race condition in the document value layer of MongoDB Server can all ...)
@@ -2068,10 +2071,12 @@ CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support li
NOTE: https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2 (main)
CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
- node-morgan 1.12.1+~1.9.10-1 (bug #1147520)
+ [trixie] - node-morgan <no-dsa> (Minor issue)
NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
NOTE: Fixed by: https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee (1.12.1)
CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
- node-compression 1.8.2+~1.8.1-1 (bug #1147519)
+ [trixie] - node-compression <no-dsa> (Minor issue)
NOTE: https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95
NOTE: Fixed by: https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff (v1.8.2)
CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)
@@ -2098,6 +2103,7 @@ CVE-2026-84390 (A inclusion of sensitive information in source code vulnerabilit
NOT-FOR-US: Fortinet
CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
- apache-opennlp <unfixed> (bug #1147511)
+ [trixie] - apache-opennlp <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3
CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
NOT-FOR-US: NextGen Connect (Mirth Connect)
@@ -2186,6 +2192,7 @@ CVE-2026-68497 (jackson-databind binds a JSON string to a javax.xml.datatype.Dur
NOTE: Fixed by: https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd (jackson-databind-2.18.10)
CVE-2026-67211 (OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP S ...)
- apache-opennlp <not-affected> (Vulnerable code not present)
+ [trixie] - apache-opennlp <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/gnobdsj640c60xl76q8g9o73c7jsybjm
CVE-2026-62140 (Unauthenticated Insecure Direct Object References (IDOR) in Quiz And S ...)
NOT-FOR-US: WordPress plugin or theme
@@ -2311,6 +2318,7 @@ CVE-2026-89089 (A SQL injection vulnerability exists in the JasperReports-based
NOT-FOR-US: OpenNMS
CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
- ocaml-cstruct <unfixed> (bug #1147522)
+ [trixie] - ocaml-cstruct <no-dsa> (Minor issue)
NOTE: https://osv.dev/vulnerability/OSEC-2026-20
NOTE: https://github.com/mirage/ocaml-cstruct/pull/324 (v6.3.0)
CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to validate ...)
@@ -2887,6 +2895,7 @@ CVE-2026-88030 (Improper neutralization of special elements in data query logic
NOTE: Fixed by: https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d (v2.26.0)
CVE-2026-88029 (Improper neutralization of special elements in data query logic in the ...)
- pymongo <unfixed> (bug #1147408)
+ [trixie] - pymongo <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/PYTHON-5994
NOTE: Fixed by: https://github.com/mongodb/mongo-python-driver/commit/fa676586ba4b399168a4d1d41c30dc2166cc44fd (v4.18.1)
CVE-2026-88028 (Improper neutralization of special elements in data query logic in the ...)
@@ -3212,6 +3221,7 @@ CVE-2026-85645 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop Conta
NOT-FOR-US: WordPress plugin
CVE-2026-84939 (Path traversal vulnerability in Apache FreeMarker template loading mec ...)
- libfreemarker-java <unfixed> (bug #1147516)
+ [trixie] - libfreemarker-java <no-dsa> (Minor issue)
NOTE: https://lists.apache.org/thread/hrd7o2ylwkkswdyhyzllgqt0f80kyd5y
CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted u ...)
NOT-FOR-US: BurgerEditor
@@ -3231,6 +3241,7 @@ CVE-2026-79522 (An out-of-bounds read in the gf_dm_get_chunk_data function (src/
- gpac <removed>
CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h) ...)
- libstb <unfixed>
+ [trixie] - libstb <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/nothings/stb/issues/1963
CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of nothings ...)
- libstb <unfixed> (unimportant)
@@ -3421,6 +3432,7 @@ CVE-2026-87872 (A flaw was found in the OCAPI modules (ocapi_command, ocapi_info
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530988 (private)
CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The eval_acces ...)
- sssd <unfixed>
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530888
CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose a system ...)
NOT-FOR-US: KGUARD DVR devices
@@ -5025,8 +5037,6 @@ CVE-2026-41987 (Permission control vulnerability in the app management module. I
NOT-FOR-US: Huawei
CVE-2026-30754 (A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP ...)
- ffmpeg 7:8.0.1-2
- [trixie] - ffmpeg 7:7.1.3-0+deb13u1
- [bookworm] - ffmpeg 7:5.1.8-0+deb12u1
NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20746
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d03483bd265b68db00c9b90f6f48dcf61c5c300d (n8.1)
NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/8b42ed314af97390cd3269ecfcff79366acb9290 (n8.0.1)
@@ -789878,17 +789888,17 @@ CVE-2018-10113 (An issue was discovered in GEGL through 0.3.32. The process func
NOTE: https://bugzilla.gnome.org/show_bug.cgi?id=795248
NOTE: https://gitlab.gnome.org/GNOME/gegl/commit/c83b05d565a1e3392c9606a4ecaa560eb9a4ee29
CVE-2018-10112 (An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_ ...)
- - gegl <unfixed> (unimportant; bug #1014710)
NOTE: https://bugzilla.gnome.org/show_bug.cgi?id=795249
NOTE: https://gitlab.gnome.org/GNOME/gegl/issues/65
NOTE: https://github.com/xiaoqx/pocs/tree/master/gegl#4-gegl-outbound-write-2
- NOTE: Architectual API limitation, negligible security impact
+ NOTE: Architectual API limitation, negligible security impact and could not be
+ NOTE: reproduced with current releases by upstream. Was also tracked as #1014710
CVE-2018-10111 (An issue was discovered in GEGL through 0.3.32. The render_rectangle f ...)
- - gegl <unfixed> (unimportant; bug #1014710)
NOTE: https://bugzilla.gnome.org/show_bug.cgi?id=795249
NOTE: https://gitlab.gnome.org/GNOME/gegl/issues/65
NOTE: POC https://github.com/xiaoqx/pocs/tree/master/gegl#2-gegl-dos-1
- NOTE: Architectual API limitation, negligible security impact
+ NOTE: Architectual API limitation, negligible security impact and could not be
+ NOTE: reproduced with current releases by upstream. Was also tracked as #1014710
CVE-2018-10110 (D-Link DIR-615 T1 devices allow XSS via the Add User feature.)
NOT-FOR-US: D-Link
CVE-2018-10109 (Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has ...)
=====================================
data/DSA/list
=====================================
@@ -1413,7 +1413,7 @@
[bookworm] - chromium 143.0.7499.109-1~deb12u1
[trixie] - chromium 143.0.7499.109-1~deb13u1
[10 Dec 2025] DSA-6079-1 ffmpeg - security update
- {CVE-2024-36618 CVE-2025-1594 CVE-2025-63757}
+ {CVE-2024-36618 CVE-2025-1594 CVE-2025-63757 CVE-2026-30754}
[bookworm] - ffmpeg 7:5.1.8-0+deb12u1
[10 Dec 2025] DSA-6078-1 firefox-esr - security update
{CVE-2025-14321 CVE-2025-14322 CVE-2025-14323 CVE-2025-14324 CVE-2025-14325 CVE-2025-14328 CVE-2025-14329 CVE-2025-14330 CVE-2025-14331 CVE-2025-14333}
@@ -1434,7 +1434,7 @@
[bookworm] - webkit2gtk 2.50.3-1~deb12u1
[trixie] - webkit2gtk 2.50.3-1~deb13u1
[07 Dec 2025] DSA-6073-1 ffmpeg - security update
- {CVE-2025-25473 CVE-2025-63757}
+ {CVE-2025-25473 CVE-2025-63757 CVE-2026-30754}
[trixie] - ffmpeg 7:7.1.3-0+deb13u1
[04 Dec 2025] DSA-6072-1 chromium - security update
{CVE-2025-13630 CVE-2025-13631 CVE-2025-13632 CVE-2025-13633 CVE-2025-13634 CVE-2025-13635 CVE-2025-13636 CVE-2025-13637 CVE-2025-13638 CVE-2025-13639 CVE-2025-13640 CVE-2025-13720 CVE-2025-13721}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6bf67b8f4c4d18b2de247676b8e00bcfea55c61
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6bf67b8f4c4d18b2de247676b8e00bcfea55c61
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260913/29c4bf13/attachment.htm>
More information about the debian-security-tracker-commits
mailing list