[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Mon Sep 14 11:34:41 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5caa9c79 by Moritz Muehlenhoff at 2026-09-14T12:34:31+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -312,6 +312,7 @@ CVE-2026-90782 (S2OPC through 1.7.3 contains a null pointer dereference in msg_s
NOT-FOR-US: Systerel S2OPC
CVE-2026-90781 (alsa-lib through 1.2.16.1 contains a stack buffer overflow in the __sn ...)
- alsa-lib <unfixed> (bug #1147619)
+ [trixie] - alsa-lib <no-dsa> (Minor issue)
NOTE: https://lore.kernel.org/alsa-devel/CACBQ=P2FhO3M6dkv3cWuKb6Qhs92ouV+FJ3SJZ_PVBSSdJWRAQ@mail.gmail.com/
NOTE: Fixed by: https://github.com/alsa-project/alsa-lib/commit/f84cd4ced7b36fddb8e4ee24404cf7c091d27020
CVE-2026-90780 (SIPp through 3.7.7 contains a buffer overflow vulnerability in the get ...)
@@ -324,16 +325,19 @@ CVE-2026-90777 (ESPnet before 202609 deserializes pretrained model checkpoints u
NOT-FOR-US: ESPnet
CVE-2026-90776 (Nodemailer versions 9.1.0 through 10.0.4 contain a quadratic time comp ...)
- node-nodemailer <unfixed> (bug #1147617)
+ [trixie] - node-nodemailer <no-dsa> (Minor issue)
NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-prgh-xp8r-p3m5
NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/c07f17518d25aca8ab2ad66968dcbca538c24b89 (v10.0.5)
CVE-2026-90775 (PostGIS address_standardizer through 3.7.0 fails to validate the Weigh ...)
- address-standardizer <unfixed> (bug #1147616)
+ [trixie] - address-standardizer <no-dsa> (Minor issue)
NOTE: https://github.com/postgis/address_standardizer/pull/6
NOTE: Fixed by: https://github.com/postgis/address_standardizer/commit/a5cb4b1360a040973092f13b1af97a718e7e104a
CVE-2026-90774 (rustypaste before 0.18.1 validates the destination path before applyin ...)
NOT-FOR-US: rustypaste
CVE-2026-90773 (procs through 0.14.12 fails to sanitize escape sequences in process co ...)
- rust-procs <unfixed> (bug #1147614)
+ [trixie] - rust-procs <no-dsa> (Minor issue)
NOTE: https://github.com/dalance/procs/issues/950
NOTE: Fixed by: https://github.com/dalance/procs/commit/2698608d43011acba088def62a2bd6653c302c44
CVE-2026-90772 (Amundsen frontend through 4.3.0 renders table, dashboard, and feature ...)
@@ -2908,6 +2912,7 @@ CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists i
NOTE: Fixed by: https://github.com/libxls/libxls/commit/881f6ec3dabb017af878949a6ed7167613bd7a69
CVE-2026-79590 (A NULL pointer dereference vulnerability exists in the Prism parser co ...)
- mruby <unfixed>
+ [trixie] - mruby <no-dsa> (Minor issue)
NOTE: https://github.com/mruby/mruby/issues/7032
NOTE: Fixed by: https://github.com/mruby/mruby/commit/c6866eed4ad5640b552ba79d16063e7ec70a0ac9 (4.1.0-rc)
CVE-2026-78575 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticat ...)
=====================================
data/dsa-needed.txt
=====================================
@@ -76,6 +76,8 @@ linux (carnil)
--
lxd
--
+mkvtoolnix (jmm)
+--
nagios4
--
nats-server
@@ -159,6 +161,9 @@ unbound
--
valkey
--
+vlc
+ wait for 3.0.24
+--
vim
some of the issues seem worth fixing
Lee Garrett is interested in contributing an update for stable
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5caa9c7958631cf462ddc6306e3b38e53ee2c6d9
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5caa9c7958631cf462ddc6306e3b38e53ee2c6d9
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/00069679/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list