[Git][security-tracker-team/security-tracker][master] Add Debian bug references for some issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Sep 13 22:09:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1470ca7d by Salvatore Bonaccorso at 2026-09-13T23:07:23+02:00
Add Debian bug references for some issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,10 +1,10 @@
 CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in the bundle ...)
-	- mkvtoolnix <unfixed>
+	- mkvtoolnix <unfixed> (bug #1147621)
 	NOTE: Fixed by: https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0
 CVE-2026-90782 (S2OPC through 1.7.3 contains a null pointer dereference in msg_subscri ...)
 	NOT-FOR-US: Systerel S2OPC
 CVE-2026-90781 (alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __sn ...)
-	- alsa-lib <unfixed>
+	- alsa-lib <unfixed> (bug #1147619)
 	NOTE: https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/
 	NOTE: Fixed by: https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020
 CVE-2026-90780 (SIPp through 3.7.7 contains a buffer overflow vulnerability in the get ...)
@@ -16,17 +16,17 @@ CVE-2026-90778 (SIPp through 3.7.7 contains a buffer overflow vulnerability in g
 CVE-2026-90777 (ESPnet before 202609 deserializes pretrained model checkpoints using t ...)
 	NOT-FOR-US: ESPnet
 CVE-2026-90776 (Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time comp ...)
-	- node-nodemailer <unfixed>
+	- node-nodemailer <unfixed> (bug #1147617)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-prgh-xp8r-p3m5
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/c07f17518d25aca8ab2ad66968dcbca538c24b89 (v10.0.5)
 CVE-2026-90775 (PostGIS address_standardizer through 3.7.0 fails to validate the Weigh ...)
-	- address-standardizer <unfixed>
+	- address-standardizer <unfixed> (bug #1147616)
 	NOTE: https://github.com/postgis/address_standardizer/pull/6
 	NOTE: Fixed by: https://github.com/postgis/address_standardizer/commit/a5cb4b1360a040973092f13b1af97a718e7e104a
 CVE-2026-90774 (rustypaste before 0.18.1 validates the destination path before applyin ...)
 	NOT-FOR-US: rustypaste
 CVE-2026-90773 (procs through 0.14.12 fails to sanitize escape sequences in process co ...)
-	- rust-procs <unfixed>
+	- rust-procs <unfixed> (bug #1147614)
 	NOTE: https://github.com/dalance/procs/issues/950
 	NOTE: Fixed by: https://github.com/dalance/procs/commit/2698608d43011acba088def62a2bd6653c302c44
 CVE-2026-90772 (Amundsen frontend through 4.3.0 renders table, dashboard, and feature  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1470ca7dd5d0e519f4e07e226c67a3fe321515b1

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1470ca7dd5d0e519f4e07e226c67a3fe321515b1
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260913/683a4a9c/attachment.htm>


More information about the debian-security-tracker-commits mailing list