[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 15 14:05:43 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7a0a8ba4 by Moritz Muehlenhoff at 2026-09-15T13:29:35+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -876,11 +876,11 @@ CVE-2026-12758 (IBM Cloud Pak for Business Automation could allow a remote attac
 CVE-2026-12756 (IBM Business Automation Workflow containers and traditional is vulnera ...)
 	NOT-FOR-US: IBM
 CVE-2026-82049 (In CPython 3.13 and earlier, the tarfilemodule's dataand tar extractio ...)
-	- python3.15 <unfixed>
-	- python3.14 <unfixed>
 	- python3.13 <unfixed>
+	[trixie] - python3.13 <no-dsa> (Minor issue)
 	- python3.11 <removed>
 	- pypy3 <unfixed>
+	[trixie] - pypy3 <no-dsa> (Minor issue)
 	NOTE: https://github.com/python/cpython/issues/157190
 	NOTE: https://github.com/python/cpython/pull/157191
 	NOTE: https://github.com/python/cpython/pull/157262 (3.15)
@@ -888,7 +888,7 @@ CVE-2026-82049 (In CPython 3.13 and earlier, the tarfilemodule's dataand tar ext
 	NOTE: https://github.com/python/cpython/pull/157192 (3.13)
 	NOTE: https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d (3.13 branch)
 	NOTE: https://github.com/python/cpython/pull/157454 (3.12)
-	TODO: check, only impacts 3.13 and below, but pull requests are open as well for newer versions
+	NOTE: Fixed by changes in Python 3.14, some followup changes for 3.15/3.16, but without security impact
 CVE-2026-9812 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
 	- mattermost-server <itp> (bug #823556)
 CVE-2026-91081 (Docs through 5.6.1 contains a server-side request forgery vulnerabilit ...)
@@ -916,9 +916,12 @@ CVE-2026-90955 (Affected versions of MISP\u2019s interactive CLI shell do not re
 	- misp <itp> (bug #1144317)
 CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When proc ...)
 	- gimp <unfixed>
+	[trixie] - gimp <not-affected> (Vulnerable code not present)
+	[bookworm] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16753
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2998
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0ff8049449b00bdd906faad7fcea091de8aa00a5
+	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/680ebede22bf7f34f78e5342b4df207892559406 (GIMP_3_2_2)
 CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an ICO fil ...)
 	- gimp <unfixed>
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16742
@@ -1175,6 +1178,7 @@ CVE-2026-82232 (Improper neutralization of special elements used in an SQL comma
 	NOT-FOR-US: Apache software not packaged in Debian
 CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path trave ...)
 	- pymupdf <unfixed>
+	[trixie] - pymupdf <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/pymupdf/PyMuPDF/commit/b2c8f3a859fed35c379a44df566f770dc3e18605
 CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a DOM-base ...)
 	NOT-FOR-US: TripleLift


=====================================
data/dsa-needed.txt
=====================================
@@ -49,6 +49,8 @@ firebird4.0
 gegl (jmm)
   move to 0.4.72
 --
+gimp (jmm)
+--
 gst-plugins-good1.0
 --
 jackson-databind



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/c4c31d29/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list