[Git][security-tracker-team/security-tracker][master] Process some NFUs

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Sep 14 15:53:08 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1819e6cd by Salvatore Bonaccorso at 2026-09-14T16:52:39+02:00
Process some NFUs

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -221,37 +221,37 @@ CVE-2026-52296 (FFmpeg before 9.0 has an out-of-bounds read because of missing r
 CVE-2026-49030
 	REJECTED
 CVE-2026-38924 (In Oraios AI Serena before 1.0.0, the listen address of the MCP server ...)
-	TODO: check
+	NOT-FOR-US: Oraios AI Serena
 CVE-2026-38332 (TinyEXIF before 1.1.0 has a heap-based buffer over-read in EntryParser ...)
-	TODO: check
+	NOT-FOR-US: TinyEXIF
 CVE-2026-37008 (CrewAI before fb2323b offers a Python blocklist approach that operates ...)
-	TODO: check
+	NOT-FOR-US: CrewAI
 CVE-2026-36989 (A SQL Injection vulnerability exists in LuxSoft LuxCal through 5.3.4L  ...)
-	TODO: check
+	NOT-FOR-US: LuxSoft LuxCal
 CVE-2026-36453 (Rhymix before 2.1.31 allows insecure direct object reference, aka RVE- ...)
-	TODO: check
+	NOT-FOR-US: Rhymix CMS
 CVE-2026-35867 (A Command Injection vulnerability exists in the bs_SetLimitCli_info fu ...)
-	TODO: check
+	NOT-FOR-US: libshare.so library of the LB-LINK router
 CVE-2026-33970 (An issue was discovered in NR RRC and L2 in Samsung Mobile Processor,  ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33968 (An issue was discovered in camera in Samsung Mobile Processor Exynos 1 ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33967 (An issue was discovered in camera in Samsung Mobile Processor Exynos 1 ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33966 (An issue was discovered in camera in Samsung Mobile Processor Exynos 1 ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33964 (An issue was discovered in camera in Samsung Mobile Processor Exynos 1 ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33963 (An issue was discovered in camera in Samsung Mobile Processor Exynos 1 ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33962 (An issue was discovered in Wi-Fi in Samsung Mobile Processor Exynos 85 ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33960 (An issue was discovered in Samsung Mobile Processor and Wearable Proce ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33957 (An issue was discovered in CustOS Driver in Samsung Mobile Processor E ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-33956 (An issue was discovered in camera in Samsung Mobile Processor Exynos 1 ...)
-	TODO: check
+	NOT-FOR-US: Samsung
 CVE-2026-31278 (An issue in the /api/v2/setting/adserversetting endpoint of Suprema Bi ...)
 	TODO: check
 CVE-2026-29812 (CyberPanel before 2.4.4 has no logging for actions that could potentia ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1819e6cd6d2a5584465f4c6c0f062b2d87f909cf

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1819e6cd6d2a5584465f4c6c0f062b2d87f909cf
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/03b5dc88/attachment.htm>


More information about the debian-security-tracker-commits mailing list