[Git][security-tracker-team/security-tracker][master] tor, mkvtoolnix, firefox-esr DSAs

Moritz Muehlenhoff (@jmm) jmm at debian.org
Wed Sep 16 18:22:23 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b238d171 by Moritz Mühlenhoff at 2026-09-16T19:21:49+02:00
tor, mkvtoolnix, firefox-esr DSAs

- - - - -


3 changed files:

- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -7393,6 +7393,7 @@ CVE-2026-80914 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/560bef609fa5992745929e8d7d458b9d88dd2830 (7.3-rc1)
 CVE-2026-XXXX [TROVE-2026-043]
 	- tor 0.4.9.12-2
+	[trixie] - tor 0.4.9.12-0+deb13u2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41341
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41336
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41326
@@ -7401,30 +7402,36 @@ CVE-2026-XXXX [TROVE-2026-043]
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/e71a9959ffb8f423289cecfe6c87e411caafc5d1 (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-034]
 	- tor 0.4.9.12-2
+	[trixie] - tor 0.4.9.12-0+deb13u2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41358
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/d8e9f7a3f723a6872ea9dbef1987b8161a95c2ff (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-036]
 	- tor 0.4.9.12-2
+	[trixie] - tor 0.4.9.12-0+deb13u2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41319
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/5589c25902c865e09887d09ecf567a78f2d730eb (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-042]
 	- tor 0.4.9.12-2
+	[trixie] - tor 0.4.9.12-0+deb13u2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41329
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/f2cd147f923e9a1d1b3b440642d0bf4bd2add17a (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-033]
 	- tor 0.4.9.12-2
+	[trixie] - tor 0.4.9.12-0+deb13u2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41348
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/fd74c4fedd909e68541c61f98a8027906bf4b619 (tor-0.4.9.12)
 CVE-2026-XXXX [TROVE-2026-035]
 	- tor 0.4.9.12-2
+	[trixie] - tor 0.4.9.12-0+deb13u2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41320
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 CVE-2026-XXXX [TROVE-2026-040]
 	- tor 0.4.9.12-2
+	[trixie] - tor 0.4.9.12-0+deb13u2
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/work_items/41325
 	NOTE: https://gitlab.torproject.org/tpo/core/tor/-/raw/release-0.4.9/ChangeLog?ref_type=heads
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/045b6729daf381e2684c7ead2dea97dcbd4cdd4d (tor-0.4.9.12)


=====================================
data/DSA/list
=====================================
@@ -1,3 +1,12 @@
+[16 Sep 2026] DSA-6502-1 mkvtoolnix - security update
+	{CVE-2026-90783}
+	[trixie] - mkvtoolnix 92.0-1+deb13u1
+[16 Sep 2026] DSA-6501-1 firefox-esr - security update
+	{CVE-2026-92005 CVE-2026-92006 CVE-2026-92007 CVE-2026-92008 CVE-2026-92009 CVE-2026-92010 CVE-2026-92011 CVE-2026-92012 CVE-2026-92013 CVE-2026-92014 CVE-2026-92015 CVE-2026-92016 CVE-2026-92017 CVE-2026-92018 CVE-2026-92019 CVE-2026-92020 CVE-2026-92021 CVE-2026-92022 CVE-2026-92023 CVE-2026-92024 CVE-2026-92025 CVE-2026-92026 CVE-2026-92027 CVE-2026-92028 CVE-2026-92029 CVE-2026-92030 CVE-2026-92031 CVE-2026-92032}
+	[trixie] - firefox-esr 140.16.0esr-1~deb13u1
+[16 Sep 2026] DSA-6500-1 tor - security update
+	{CVE-2026-87724}
+	[trixie] - tor 0.4.9.12-0+deb13u2
 [16 Sep 2026] DSA-6496-2 nginx - regression update
 	[trixie] - nginx 1.26.3-3+deb13u9
 [15 Sep 2026] DSA-6499-1 cjose - security update


=====================================
data/dsa-needed.txt
=====================================
@@ -44,8 +44,6 @@ firebird3.0
 --
 firebird4.0
 --
-firefox-esr (jmm)
---
 gegl (jmm)
   move to 0.4.72
 --
@@ -79,8 +77,6 @@ linux (carnil)
 --
 lxd
 --
-mkvtoolnix (jmm)
---
 nagios4
 --
 nats-server
@@ -157,8 +153,6 @@ tomcat10
 --
 tomcat11
 --
-tor
---
 unbound
   Michael Tokarev is working on rebasing to 1.25.2 (possibly 1.26.0)
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b238d171f68c049a3325a683ae76e3a6a7b17d67

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b238d171f68c049a3325a683ae76e3a6a7b17d67
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260916/a17418f2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list