[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 15 14:05:43 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7a0a8ba4 by Moritz Muehlenhoff at 2026-09-15T13:29:35+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -876,11 +876,11 @@ CVE-2026-12758 (IBM Cloud Pak for Business Automation could allow a remote attac
CVE-2026-12756 (IBM Business Automation Workflow containers and traditional is vulnera ...)
NOT-FOR-US: IBM
CVE-2026-82049 (In CPython 3.13 and earlier, the tarfilemodule's dataand tar extractio ...)
- - python3.15 <unfixed>
- - python3.14 <unfixed>
- python3.13 <unfixed>
+ [trixie] - python3.13 <no-dsa> (Minor issue)
- python3.11 <removed>
- pypy3 <unfixed>
+ [trixie] - pypy3 <no-dsa> (Minor issue)
NOTE: https://github.com/python/cpython/issues/157190
NOTE: https://github.com/python/cpython/pull/157191
NOTE: https://github.com/python/cpython/pull/157262 (3.15)
@@ -888,7 +888,7 @@ CVE-2026-82049 (In CPython 3.13 and earlier, the tarfilemodule's dataand tar ext
NOTE: https://github.com/python/cpython/pull/157192 (3.13)
NOTE: https://github.com/python/cpython/commit/b8f23e307097552eaea2604383a12ab280520d0d (3.13 branch)
NOTE: https://github.com/python/cpython/pull/157454 (3.12)
- TODO: check, only impacts 3.13 and below, but pull requests are open as well for newer versions
+ NOTE: Fixed by changes in Python 3.14, some followup changes for 3.15/3.16, but without security impact
CVE-2026-9812 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
- mattermost-server <itp> (bug #823556)
CVE-2026-91081 (Docs through 5.6.1 contains a server-side request forgery vulnerabilit ...)
@@ -916,9 +916,12 @@ CVE-2026-90955 (Affected versions of MISP\u2019s interactive CLI shell do not re
- misp <itp> (bug #1144317)
CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When proc ...)
- gimp <unfixed>
+ [trixie] - gimp <not-affected> (Vulnerable code not present)
+ [bookworm] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16753
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2998
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0ff8049449b00bdd906faad7fcea091de8aa00a5
+ NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/680ebede22bf7f34f78e5342b4df207892559406 (GIMP_3_2_2)
CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an ICO fil ...)
- gimp <unfixed>
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16742
@@ -1175,6 +1178,7 @@ CVE-2026-82232 (Improper neutralization of special elements used in an SQL comma
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-82035 (PyMuPDF through 1.28.2, fixed in commit b2c8f3a, contains a path trave ...)
- pymupdf <unfixed>
+ [trixie] - pymupdf <no-dsa> (Minor issue)
NOTE: Fixed by: https://github.com/pymupdf/PyMuPDF/commit/b2c8f3a859fed35c379a44df566f770dc3e18605
CVE-2026-82019 (TripleLift's ad rendering script (video-bundle.js) contains a DOM-base ...)
NOT-FOR-US: TripleLift
=====================================
data/dsa-needed.txt
=====================================
@@ -49,6 +49,8 @@ firebird4.0
gegl (jmm)
move to 0.4.72
--
+gimp (jmm)
+--
gst-plugins-good1.0
--
jackson-databind
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7a0a8ba4a1911f57ad5d445b6f6e7db4798ecb00
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/c4c31d29/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list