[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Sep 14 17:41:49 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7ca99966 by Moritz Muehlenhoff at 2026-09-14T18:41:28+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,8 +1,10 @@
 CVE-2026-XXXX [GHSA-484h-v688-jq5j: Source URL scheme bypasses sandboxed mode protections across multiple source subtypes]
 	- flatpak-builder <unfixed> (bug #1147701)
+	[trixie] - flatpak-builder <no-dsa> (Minor issue)
 	NOTE: https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-484h-v688-jq5j
 CVE-2026-86320
 	- flatpak-builder <unfixed> (bug #1147700)
+	[trixie] - flatpak-builder <no-dsa> (Minor issue)
 	NOTE: https://github.com/flatpak/flatpak-builder/security/advisories/GHSA-j5p8-jgjc-f3xv
 CVE-2026-90691 (A security vulnerability has been detected in 0x4m4 HexStrike AI up to ...)
 	NOT-FOR-US: 0x4m4 HexStrike AI
@@ -326,6 +328,7 @@ CVE-2023-32778 (An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. A
 CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in the bundle ...)
 	- mkvtoolnix 101.0-2 (bug #1147621)
 	- ogmrip <unfixed>
+	[trixie] - ogmrip <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0
 	NOTE: Fixed by: https://codeberg.org/mbunkus/mkvtoolnix/commit/13fd81db3ae2b79d41536a9663719df11780797e
 CVE-2026-90782 (S2OPC through 1.7.3 contains a null pointer dereference in msg_subscri ...)
@@ -3321,16 +3324,19 @@ CVE-2026-88047 (Tesseract is an open source OCR engine. In version 5.5.3 and ear
 	NOTE: Fixed by: https://github.com/tesseract-ocr/tesseract/commit/1bda5079b1c8a7e25f523486837426903d29ce84
 CVE-2026-88046 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-38xv-hf3p-h7mq
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/57842c5ee4e1407eda06a414a36510cce2db4252 (v1.75.1)
 CVE-2026-88045 (rclone is a command-line program to sync files and directories to and  ...)
-	- rclone <unfixed> (bug #1147404)
+	- rclone <not-affected> (Only affects 1.75.0)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-2p48-j3qc-rx9f
 	NOTE: https://github.com/rclone/rclone/issues/9616
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/7c1dfd99f3e6a22fcefd8686cc478226a15e63a1 (v1.75.1)
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/ab1f458013aaf6356e4bdeca61f7cb9139f8eb86 (v1.75.1)
 CVE-2026-88044 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
+	[trixie] - rclone <not-affected> (Vulnerable code not present, affects 1.70 and later)
+	[bookworm] - rclone <not-affected> (Vulnerable code not present, affects 1.70 and later)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p569-5gjg-9cmj
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/739403963abf6f58003c2becd5f7c4ad0d644153 (v1.75.1)
 CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP cookies, use ...)
@@ -3369,6 +3375,7 @@ CVE-2026-88031 (Improper neutralization of special elements in data query logic
 	NOTE: Fixed by: https://github.com/mongodb/mongo-go-driver/commit/806e132f9501a2665d05ebaba3b6f0d787ceaa96 (v1.17.10)
 CVE-2026-88030 (Improper neutralization of special elements in data query logic in the ...)
 	- ruby-mongo <unfixed> (bug #1147409)
+	[trixie] - ruby-mongo <no-dsa> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/RUBY-3941
 	NOTE: Fixed by: https://github.com/mongodb/mongo-ruby-driver/commit/ed62bb56c2e24c79113709331862d0aa3da74c6d (v2.26.0)
 CVE-2026-88029 (Improper neutralization of special elements in data query logic in the ...)
@@ -3398,25 +3405,31 @@ CVE-2026-88018 (rclone is a command-line program to sync files and directories t
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/90595f34f27f569be6b27c57fe5ab65057d323bd (1.75.1)
 CVE-2026-88017 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
+	[trixie] - rclone <not-affected> (Vulnerable code not present, only affects 1.64 and later)
+	[bookworm] - rclone <not-affected> (Vulnerable code not present, only affects 1.64 and later)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-c476-6w5q-jw77
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/c6af0b57c2b4af848bc968c2b407354476184b99 (v1.75.1)
 CVE-2026-88016 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-f8g7-2xjc-7mfh
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/17b0c03338a857bcb0a68d2d4c82ddbdec3f7893 (v1.75.1)
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/a7ab39d3d1958afa1446982c1dc4e4a73a887e3e (v1.75.1)
 CVE-2026-88015 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9 (v1.75.1)
 CVE-2026-88014 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
+	[trixie] - rclone <not-affected> (Vulnerable code not present, only affects 1.72 and later)
+	[bookworm] - rclone <not-affected> (Vulnerable code not present, only affects 1.72 and later)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-66hp-wgxq-6f5q
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/5dae3adbf571a6cd9ba501eb47397a7e871e1ae0 (v1.75.1)
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/6507e13d5a83789f500af96d7188c302c9d74d98 (v1.75.1)
-	TODO: check, said to affect only 1.72.0 onwards
 CVE-2026-88013 (rclone is a command-line program to sync files and directories to and  ...)
 	- rclone <unfixed> (bug #1147404)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-486v-q2wf-fp2r
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/22859b7e696cea3c563c6ba04c6b7f91f74456b4 (v1.75.1)
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/79fbc0842f74e02cb84f0e3e7261d169983c8831 (v1.75.1)
@@ -4079,6 +4092,7 @@ CVE-2026-85102 (Improper certificate trust validation during VPN negotiation in
 CVE-2026-83530 (A user could provide an expression whose string length is longer than  ...)
 	- golang-cel-cel-go 0.32.0+ds-1
 	- golang-github-google-cel-go <unfixed> (bug #1147513)
+	[trixie] - golang-github-google-cel-go <no-dsa> (Minor issue)
 	NOTE: https://github.com/cel-expr/cel-go/pull/1302
 	NOTE: Fixed by: https://github.com/cel-expr/cel-go/commit/2814acd9e1edc48811cbd88c6f60432638334e5a (v0.29.0)
 CVE-2026-82563 (An attacker could impersonate the camera and place themselves in a man ...)
@@ -16598,6 +16612,7 @@ CVE-2026-58106 (CVE-2025-40843 https://github.com/advisories/GHSA-5xf2-f6ch-6p8r
 	NOT-FOR-US: Ericsson
 CVE-2026-56854 (The source-address critical option in the Permissions returned by an a ...)
 	- golang-go.crypto 1:0.55.0-1
+	[trixie] - golang-go.crypto <no-dsa> (Minor issue)
 	[bookworm] - golang-go.crypto <postponed> (Limited support)
 	NOTE: https://github.com/golang/go/issues/80213
 	NOTE: Fixed by: https://github.com/golang/crypto/commit/e557b08ec2b4f5dd00f38356919fc7b051dd88f8 (v0.55.0)
@@ -17971,7 +17986,7 @@ CVE-2026-10036 (SpeechBrain before 1.1.1 contains an arbitrary code execution vu
 	NOT-FOR-US: SpeechBrain
 CVE-2026-81893 (A flaw was found in gdk-pixbuf. When loading a specially crafted JPEG  ...)
 	- gdk-pixbuf <unfixed> (bug #1145988)
-	[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
+	[trixie] - gdk-pixbuf <postponed> (Minor issue, revisit when/if a fix is available for the C-based legacy implementation)
 	[bookworm] - gdk-pixbuf <postponed> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/merge_requests/278
 	NOTE: Introduced with: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/commit/4af78023ce7d3b5e3cec422a59bb4f48fa4f5886 (2.43.4)
@@ -59135,7 +59150,7 @@ CVE-2026-24537 (Unauthenticated Cross Site Request Forgery (CSRF) in WP Accessib
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-16768 (A flaw was found in gdk-pixbuf. When parsing a specially crafted ICO f ...)
 	- gdk-pixbuf <unfixed> (bug #1143155)
-	[trixie] - gdk-pixbuf <no-dsa> (Minor issue)
+	[trixie] - gdk-pixbuf <postponed> (Minor issue, revisit when/if a fix is available for the C-based legacy implementation)
 	[bookworm] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the rendered image; unfixed upstream)
 	[bullseye] - gdk-pixbuf <postponed> (Minor issue; bounded OOB read in the ICO palette lookup in OneLine8()/OneLine4(), leaks heap bytes into the rendered image; unfixed upstream)
 	NOTE: https://gitlab.gnome.org/GNOME/gdk-pixbuf/-/issues/302
@@ -66757,6 +66772,7 @@ CVE-2026-54242 (Statamic is a Laravel and Git powered content management system
 	NOT-FOR-US: Statamic CMS
 CVE-2026-54171 (Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon ...)
 	- ruby-excon 1.5.0-1
+	[trixie] - ruby-excon <no-dsa> (Minor issue)
 	NOTE: https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r
 	NOTE: https://github.com/excon/excon/pull/901
 	NOTE: Fixed by: https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 (v1.5.0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ca999664c3a49ebb26538987bde091b805651b2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7ca999664c3a49ebb26538987bde091b805651b2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/129f8b6f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list