[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 13 19:08:16 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c6bf67b8 by Moritz Muehlenhoff at 2026-09-13T20:08:06+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -66,12 +66,14 @@ CVE-2026-77773 (The Contact Form to Chat Apps | Click to Chat to Order  WordPres
 	NOT-FOR-US: WordPress plugin
 CVE-2026-90560 (zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read ...)
 	- zstd-jni-java <unfixed>
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/issues/405
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/b74ab242d640c40897e62aab4c744ddfad1f915f (v1.5.7-14)
 CVE-2026-90559 (snappy-java through 1.1.10.8 contains an out-of-bounds write vulnerabi ...)
 	NOT-FOR-US: snappy-java
 CVE-2026-90558 (sngrep through 1.8.4 contains stack buffer overflow vulnerabilities in ...)
 	- sngrep <unfixed>
+	[trixie] - sngrep <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/irontec/sngrep/commit/1ff74ee3ab5ff280e8ba976aa8c744dca57eb35b
 CVE-2026-90555 (vLLM versions before 0.28.0 fail to validate audio sample rate headers ...)
 	- vllm <itp> (bug #1095237)
@@ -153,6 +155,7 @@ CVE-2026-10148 (The Booking for Appointments and Events Calendar plugin for Word
 	NOT-FOR-US: WordPress plugin
 CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly validate email addresses sup ...)
 	- aiosmtplib 5.1.3-1 (bug #1147474)
+	[trixie] - aiosmtplib <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)
 CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and password to an ...)
 	- ironic <unfixed>
@@ -2022,8 +2025,8 @@ CVE-2026-89148 (AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 c
 	NOT-FOR-US: WWBN AVideo
 CVE-2026-89147 (Net-SNMP through 5.9.5.2 contains a denial of service vulnerability in ...)
 	- net-snmp <unfixed> (bug #1147442)
+	[trixie] - net-snmp <no-dsa> (Minor issue)
 	NOTE: https://gist.github.com/thesmartshadow/001cea595e75fed6aaea7389666dc9eb
-	TODO: check for upstream report
 CVE-2026-89146 (libp2p-rendezvous through 0.17.1 fails to validate registration TTL va ...)
 	NOT-FOR-US: libp2p-rendezvous
 CVE-2026-89099 (A race condition in the document value layer of MongoDB Server can all ...)
@@ -2068,10 +2071,12 @@ CVE-2026-87910 (When tarfile extracts a link on a system that doesn't support li
 	NOTE: https://github.com/python/cpython/commit/fb2f0bbc3b35264f09cc2cb2934b7987527a6bc2 (main)
 CVE-2026-87859 (morgan is an HTTP request logger middleware for Node.js. In versions b ...)
 	- node-morgan 1.12.1+~1.9.10-1 (bug #1147520)
+	[trixie] - node-morgan <no-dsa> (Minor issue)
 	NOTE: https://github.com/expressjs/morgan/security/advisories/GHSA-9f6g-j8ch-79g4
 	NOTE: Fixed by: https://github.com/expressjs/morgan/commit/4b695edf967ce179cdf4009fe8cddd184b7511ee (1.12.1)
 CVE-2026-87776 (compression is a Node.js and Express compression middleware. In versio ...)
 	- node-compression 1.8.2+~1.8.1-1 (bug #1147519)
+	[trixie] - node-compression <no-dsa> (Minor issue)
 	NOTE: https://github.com/expressjs/compression/security/advisories/GHSA-vc2v-76pw-4v95
 	NOTE: Fixed by: https://github.com/expressjs/compression/commit/151f63e91e1b64f8fb0b064e19321a4f28db6bff (v1.8.2)
 CVE-2026-87727 (a-blog cms Ver. 3.2.33 and earlier contains a path traversal vulnerabi ...)
@@ -2098,6 +2103,7 @@ CVE-2026-84390 (A inclusion of sensitive information in source code vulnerabilit
 	NOT-FOR-US: Fortinet
 CVE-2026-82617 (The two built-in name-finder patterns exposed by opennlp.tools.namefin ...)
 	- apache-opennlp <unfixed> (bug #1147511)
+	[trixie] - apache-opennlp <no-dsa> (Minor issue)
 	NOTE: https://lists.apache.org/thread/spzhcxxszqdpppg70m1zz2l3mv29mhl3
 CVE-2026-82583 (NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an au ...)
 	NOT-FOR-US: NextGen Connect (Mirth Connect)
@@ -2186,6 +2192,7 @@ CVE-2026-68497 (jackson-databind binds a JSON string to a javax.xml.datatype.Dur
 	NOTE: Fixed by: https://github.com/FasterXML/jackson-databind/commit/a99b7e74c8928f43f6975773a8c862c8316178bd (jackson-databind-2.18.10)
 CVE-2026-67211 (OOM Denial of Service via Unbounded Map Pre-Sizing in Apache OpenNLP S ...)
 	- apache-opennlp <not-affected> (Vulnerable code not present)
+	[trixie] - apache-opennlp <no-dsa> (Minor issue)
 	NOTE: https://lists.apache.org/thread/gnobdsj640c60xl76q8g9o73c7jsybjm
 CVE-2026-62140 (Unauthenticated Insecure Direct Object References (IDOR) in Quiz And S ...)
 	NOT-FOR-US: WordPress plugin or theme
@@ -2311,6 +2318,7 @@ CVE-2026-89089 (A SQL injection vulnerability exists in the JasperReports-based
 	NOT-FOR-US: OpenNMS
 CVE-2026-89087 (The cstruct package before 6.3.0 for OCaml mishandles indexes.)
 	- ocaml-cstruct <unfixed> (bug #1147522)
+	[trixie] - ocaml-cstruct <no-dsa> (Minor issue)
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-20
 	NOTE: https://github.com/mirage/ocaml-cstruct/pull/324 (v6.3.0)
 CVE-2026-89086 (In the jose package before 0.11.0 for OCaml, library calls to validate ...)
@@ -2887,6 +2895,7 @@ CVE-2026-88030 (Improper neutralization of special elements in data query logic
 	NOTE: Fixed by: https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d (v2.26.0)
 CVE-2026-88029 (Improper neutralization of special elements in data query logic in the ...)
 	- pymongo <unfixed> (bug #1147408)
+	[trixie] - pymongo <no-dsa> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/PYTHON-5994
 	NOTE: Fixed by: https://github.com/mongodb/mongo-python-driver/commit/fa676586ba4b399168a4d1d41c30dc2166cc44fd (v4.18.1)
 CVE-2026-88028 (Improper neutralization of special elements in data query logic in the ...)
@@ -3212,6 +3221,7 @@ CVE-2026-85645 (The Form Maker by 10Web \u2013 Mobile-Friendly Drag & Drop Conta
 	NOT-FOR-US: WordPress plugin
 CVE-2026-84939 (Path traversal vulnerability in Apache FreeMarker template loading mec ...)
 	- libfreemarker-java <unfixed> (bug #1147516)
+	[trixie] - libfreemarker-java <no-dsa> (Minor issue)
 	NOTE: https://lists.apache.org/thread/hrd7o2ylwkkswdyhyzllgqt0f80kyd5y
 CVE-2026-84063 (BurgerEditor 3.2.0 through 3.4.0 contains an issue with unrestricted u ...)
 	NOT-FOR-US: BurgerEditor
@@ -3231,6 +3241,7 @@ CVE-2026-79522 (An out-of-bounds read in the gf_dm_get_chunk_data function (src/
 	- gpac <removed>
 CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h)  ...)
 	- libstb <unfixed>
+	[trixie] - libstb <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/nothings/stb/issues/1963
 CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of nothings ...)
 	- libstb <unfixed> (unimportant)
@@ -3421,6 +3432,7 @@ CVE-2026-87872 (A flaw was found in the OCAPI modules (ocapi_command, ocapi_info
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530988 (private)
 CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The eval_acces ...)
 	- sssd <unfixed>
+	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530888
 CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose a system ...)
 	NOT-FOR-US: KGUARD DVR devices
@@ -5025,8 +5037,6 @@ CVE-2026-41987 (Permission control vulnerability in the app management module. I
 	NOT-FOR-US: Huawei
 CVE-2026-30754 (A memory corruption vulnerability exists in FFmpeg before 8.1. The RTP ...)
 	- ffmpeg 7:8.0.1-2
-	[trixie] - ffmpeg 7:7.1.3-0+deb13u1
-	[bookworm] - ffmpeg 7:5.1.8-0+deb12u1
 	NOTE: https://code.ffmpeg.org/FFmpeg/FFmpeg/pulls/20746
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/d03483bd265b68db00c9b90f6f48dcf61c5c300d (n8.1)
 	NOTE: Fixed by: https://code.ffmpeg.org/FFmpeg/FFmpeg/commit/8b42ed314af97390cd3269ecfcff79366acb9290 (n8.0.1)
@@ -789878,17 +789888,17 @@ CVE-2018-10113 (An issue was discovered in GEGL through 0.3.32. The process func
 	NOTE: https://bugzilla.gnome.org/show_bug.cgi?id=795248
 	NOTE: https://gitlab.gnome.org/GNOME/gegl/commit/c83b05d565a1e3392c9606a4ecaa560eb9a4ee29
 CVE-2018-10112 (An issue was discovered in GEGL through 0.3.32. The gegl_tile_backend_ ...)
-	- gegl <unfixed> (unimportant; bug #1014710)
 	NOTE: https://bugzilla.gnome.org/show_bug.cgi?id=795249
 	NOTE: https://gitlab.gnome.org/GNOME/gegl/issues/65
 	NOTE: https://github.com/xiaoqx/pocs/tree/master/gegl#4-gegl-outbound-write-2
-	NOTE: Architectual API limitation, negligible security impact
+	NOTE: Architectual API limitation, negligible security impact and could not be
+	NOTE: reproduced with current releases by upstream. Was also tracked as #1014710
 CVE-2018-10111 (An issue was discovered in GEGL through 0.3.32. The render_rectangle f ...)
-	- gegl <unfixed> (unimportant; bug #1014710)
 	NOTE: https://bugzilla.gnome.org/show_bug.cgi?id=795249
 	NOTE: https://gitlab.gnome.org/GNOME/gegl/issues/65
 	NOTE: POC https://github.com/xiaoqx/pocs/tree/master/gegl#2-gegl-dos-1
-	NOTE: Architectual API limitation, negligible security impact
+	NOTE: Architectual API limitation, negligible security impact and could not be
+	NOTE: reproduced with current releases by upstream. Was also tracked as #1014710
 CVE-2018-10110 (D-Link DIR-615 T1 devices allow XSS via the Add User feature.)
 	NOT-FOR-US: D-Link
 CVE-2018-10109 (Monstra CMS 3.0.4 has a stored XSS vulnerability when an attacker has  ...)


=====================================
data/DSA/list
=====================================
@@ -1413,7 +1413,7 @@
 	[bookworm] - chromium 143.0.7499.109-1~deb12u1
 	[trixie] - chromium 143.0.7499.109-1~deb13u1
 [10 Dec 2025] DSA-6079-1 ffmpeg - security update
-	{CVE-2024-36618 CVE-2025-1594 CVE-2025-63757}
+	{CVE-2024-36618 CVE-2025-1594 CVE-2025-63757 CVE-2026-30754}
 	[bookworm] - ffmpeg 7:5.1.8-0+deb12u1
 [10 Dec 2025] DSA-6078-1 firefox-esr - security update
 	{CVE-2025-14321 CVE-2025-14322 CVE-2025-14323 CVE-2025-14324 CVE-2025-14325 CVE-2025-14328 CVE-2025-14329 CVE-2025-14330 CVE-2025-14331 CVE-2025-14333}
@@ -1434,7 +1434,7 @@
 	[bookworm] - webkit2gtk 2.50.3-1~deb12u1
 	[trixie] - webkit2gtk 2.50.3-1~deb13u1
 [07 Dec 2025] DSA-6073-1 ffmpeg - security update
-	{CVE-2025-25473 CVE-2025-63757}
+	{CVE-2025-25473 CVE-2025-63757 CVE-2026-30754}
 	[trixie] - ffmpeg 7:7.1.3-0+deb13u1
 [04 Dec 2025] DSA-6072-1 chromium - security update
 	{CVE-2025-13630 CVE-2025-13631 CVE-2025-13632 CVE-2025-13633 CVE-2025-13634 CVE-2025-13635 CVE-2025-13636 CVE-2025-13637 CVE-2025-13638 CVE-2025-13639 CVE-2025-13640 CVE-2025-13720 CVE-2025-13721}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6bf67b8f4c4d18b2de247676b8e00bcfea55c61

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c6bf67b8f4c4d18b2de247676b8e00bcfea55c61
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260913/29c4bf13/attachment.htm>


More information about the debian-security-tracker-commits mailing list