[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 15 22:18:25 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
66b60d9b by Moritz Muehlenhoff at 2026-09-15T23:18:14+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1196,6 +1196,7 @@ CVE-2026-90854 (A security flaw has been discovered in SourceCodester/katojkalem
 	NOT-FOR-US: SourceCodester
 CVE-2026-90852 (A vulnerability has been found in luben zstd-jni up to 1.5.7-13. This  ...)
 	- zstd-jni-java <unfixed>
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/issues/404
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936 (1.5.7-14)
 CVE-2026-90851 (A flaw has been found in PHPGurukul Hostel Management System 3.0. This ...)
@@ -1205,8 +1206,9 @@ CVE-2026-90850 (A vulnerability was detected in PHPGurukul Hostel Management Sys
 CVE-2026-90849 (A security vulnerability has been detected in SourceCodester College N ...)
 	NOT-FOR-US: SourceCodester
 CVE-2026-90848 (A weakness has been identified in Governikus AusweisApp up to 2.5.4. A ...)
-	- ausweisapp2 2.5.5-1
+	- ausweisapp2 2.5.5-1 (unimportant)
 	NOTE: https://github.com/Governikus/AusweisApp/commit/6724c548f9ab5f50d674960b5e2a736318815089 (2.5.5)
+	NOTE: Negligible security impact
 CVE-2026-90847 (A vulnerability was determined in EFM ipTIME C200E 1.094. The impacted ...)
 	NOT-FOR-US: EFM ipTIME C200E
 CVE-2026-90846 (A vulnerability has been found in PHPGurukul Daily Expense Tracker Sys ...)
@@ -2627,11 +2629,13 @@ CVE-2026-90684 (A flaw has been found in GPAC up to f1219cde. Affected by this v
 CVE-2026-90683 (A vulnerability was detected in GPAC up to f1219cde. Affected is the f ...)
 	- gpac <removed>
 CVE-2026-90682 (A security vulnerability has been detected in Matthias-Wandel jhead up ...)
-	- jhead <unfixed>
+	- jhead <unfixed> (unimportant)
 	NOTE: https://github.com/Matthias-Wandel/jhead/issues/99
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-90681 (A weakness has been identified in Matthias-Wandel jhead up to 3.3. Thi ...)
-	- jhead <unfixed>
+	- jhead <unfixed> (unimportant)
 	NOTE: https://github.com/Matthias-Wandel/jhead/issues/98
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-90680 (A security flaw has been discovered in D-Link DIR-823G 1.0.2B05_201812 ...)
 	NOT-FOR-US: D-Link
 CVE-2026-90623 (A weakness has been identified in andreashappe cochise up to 0.4.1. Af ...)
@@ -5689,10 +5693,12 @@ CVE-2026-89049 (A server-side request forgery issue due to improper validation o
 	NOT-FOR-US: Amazon
 CVE-2026-89046 (zstd-jni versions 1.5.5-6 through 1.5.7-13 contain an out-of-bounds re ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-rm53-6wf5-f34m
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/dd08685ef913a32e76fb27f43470035c06758646 (v1.5.7-14)
 CVE-2026-89045 (zstd-jni versions 1.4.8-4 through 1.5.7-13 fail to validate negative l ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-9jx2-gfp9-phfm
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/dd08685ef913a32e76fb27f43470035c06758646 (v1.5.7-14)
 CVE-2026-89044 (Netty versions 4.1.133.Final through 4.1.137.Final and 4.2.13.Final th ...)
@@ -6503,6 +6509,7 @@ CVE-2026-87927 (MaxSite CMS through 109.6 contains a local file inclusion vulner
 	NOT-FOR-US: MaxSite CMS
 CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail to validate closed state in set ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-2jw3-mg7f-vw4q
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e (v1.5.7-14)
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555 (v1.5.7-14)
@@ -6532,15 +6539,18 @@ CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose a
 	NOT-FOR-US: KGUARD DVR devices
 CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-947w-pxjj-c7m9
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555 (v1.5.7-14)
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936 (v1.5.7-14)
 CVE-2026-87824 (zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-257p-3h6w-pg7h
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/bba6cfca2c0897f1fa004f4193247479f10da853 (v1.5.7-14)
 CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-jfr6-9xqw-2g2q
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/d7a1c99322d5e1fc71932e722c0b5bb2fc525d3f (v1.5.7-14)
 CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid means duri ...)
@@ -6582,6 +6592,7 @@ CVE-2026-87806 (Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 co
 	NOT-FOR-US: Parse Server
 CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...)
 	- zstd-jni-java <unfixed> (bug #1147397)
+	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
 	NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb (v1.5.7-14)
 CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnera ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66b60d9ba48d6abaa6c3c516f7b79d1bb79a13d7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/66b60d9ba48d6abaa6c3c516f7b79d1bb79a13d7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/6a406757/attachment.htm>


More information about the debian-security-tracker-commits mailing list