[Git][security-tracker-team/security-tracker][master] bugnums

Moritz Muehlenhoff (@jmm) jmm at debian.org
Mon Sep 14 19:23:05 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
62cda978 by Moritz Muehlenhoff at 2026-09-14T20:22:24+02:00
bugnums

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -689,7 +689,7 @@ CVE-2026-89268 (QloApps through 1.7.0 renders back-office list filter POST param
 CVE-2026-89267 (starlette-admin versions 0.16.1 through 0.17.1 fail to enforce the sea ...)
 	NOT-FOR-US: Starlette-Admin
 CVE-2026-89266 (stb_vorbis through 1.22 contains a heap buffer overflow in start_decod ...)
-	- libstb <unfixed>
+	- libstb <unfixed> (bug #1147728)
 	[trixie] - libstb <no-dsa> (Minor issue)
 	NOTE: https://github.com/nothings/stb/issues/1928
 	NOTE: https://github.com/nothings/stb/issues/1933
@@ -3737,7 +3737,7 @@ CVE-2026-81431 (The Registration Form for WooCommerce WordPress plugin before 1.
 CVE-2026-79522 (An out-of-bounds read in the gf_dm_get_chunk_data function (src/utils/ ...)
 	- gpac <removed>
 CVE-2026-79516 (An out-of-bounds read in the stbsp_vsnprintf function (stb_sprintf.h)  ...)
-	- libstb <unfixed>
+	- libstb <unfixed> (bug #1147725)
 	[trixie] - libstb <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/nothings/stb/issues/1963
 CVE-2026-79515 (An out-of-bounds read in the stbtt_GetGlyphShape component of nothings ...)
@@ -3924,7 +3924,7 @@ CVE-2026-87874 (A flaw was found in the memcached cache plugin of the community.
 	[trixie] - ansible <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530995
 CVE-2026-87872 (A flaw was found in the OCAPI modules (ocapi_command, ocapi_info) of t ...)
-	- ansible <unfixed>
+	- ansible <unfixed> (bug #1147729)
 	[trixie] - ansible <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2530988 (private)
 CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The eval_acces ...)
@@ -54345,7 +54345,7 @@ CVE-2026-6879 (`Element.findall()` and fully-consumed `Element.iterfind()` exhib
 	[bullseye] - python3.9 <postponed> (Minor issue)
 	- python2.7 <removed>
 	[bullseye] - python2.7 <end-of-life> (EOL in bullseye LTS)
-	- pypy3 <unfixed>
+	- pypy3 <unfixed> (bug #1147726)
 	[trixie] - pypy3 <no-dsa> (Minor issue)
 	[bookworm] - pypy3 <postponed> (Minor issue)
 	[bullseye] - pypy3 <postponed> (Minor issue)
@@ -113412,7 +113412,7 @@ CVE-2026-8466 (Allocation of Resources Without Limits or Throttling vulnerabilit
 CVE-2026-8369 (Improper Input Validation in the NAT64 translator in The OpenThread Au ...)
 	NOT-FOR-US: OpenThread
 CVE-2026-8367 (aria2c accepts a server certificate with incorrect Extended Key Usage  ...)
-	- aria2 <unfixed>
+	- aria2 <unfixed> (bug #1147724)
 	[trixie] - aria2 <postponed> (Minor issue, revisit when fixed upstream)
 	[bookworm] - aria2 <postponed> (Minor issue, revisit when fixed upstream)
 	[bullseye] - aria2 <postponed> (Minor issue, revisit when fixed upstream)
@@ -140133,7 +140133,7 @@ CVE-2026-5314 (A vulnerability was found in Nothings stb up to 1.26. Impacted is
 	- libstb <unfixed> (unimportant)
 	NOTE: truetype parser only supported for trusted font files
 CVE-2026-5313 (A vulnerability has been found in Nothings stb up to 2.30. This issue  ...)
-	- libstb <unfixed>
+	- libstb <unfixed> (bug #1147721)
 	[trixie] - libstb <no-dsa> (Minor issue)
 	[bookworm] - libstb <no-dsa> (Minor issue)
 	NOTE: https://vuldb.com/submit/780462
@@ -140753,7 +140753,7 @@ CVE-2026-5195 (A flaw has been found in code-projects Student Membership System
 CVE-2026-5190 (Out-of-bounds write in the streaming decoder component in aws-c-event- ...)
 	NOT-FOR-US: Amazon
 CVE-2026-5186 (A weakness has been identified in Nothings stb up to 2.30. This impact ...)
-	- libstb <unfixed>
+	- libstb <unfixed> (bug #1147722)
 	[trixie] - libstb <no-dsa> (Minor issue)
 	[bookworm] - libstb <no-dsa> (Minor issue)
 	NOTE: https://vuldb.com/submit/780395



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62cda97809c76be5d131dcf37b2926a8ffed6fcd

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/62cda97809c76be5d131dcf37b2926a8ffed6fcd
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260914/a1a37bcf/attachment.htm>


More information about the debian-security-tracker-commits mailing list