[Git][security-tracker-team/security-tracker][master] 2 commits: lts: follow no-dsa triage for low-priority packages
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Thu Sep 17 11:33:03 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c1d37967 by Sylvain Beucler at 2026-09-17T12:29:02+02:00
lts: follow no-dsa triage for low-priority packages
- - - - -
bde37355 by Sylvain Beucler at 2026-09-17T12:29:34+02:00
CVE-2026-41608/thrift: bookworm postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -15720,6 +15720,7 @@ CVE-2026-18355 (A heap buffer overflow flaw was found in the SASL I/O layer of 3
CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion ...)
- libprotocol-http2-perl 1.14-1 (bug #1147222)
[trixie] - libprotocol-http2-perl <no-dsa> (Minor issue)
+ [bookworm] - libprotocol-http2-perl <postponed> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43351225/
NOTE: Fixed by: https://github.com/vlet/p5-Protocol-HTTP2/commit/27a488a34d74fd16f123e5e6186d4f677faa246f (1.14)
CVE-2026-14444 (The WP Fusion (Pro) plugin for WordPress is vulnerable to Privilege Es ...)
@@ -15890,6 +15891,7 @@ CVE-2026-86232 (A weakness has been identified in itsourcecode Sales and Invento
CVE-2026-86231 (A security flaw has been discovered in mwiede jsch up to 2.28.5. Affec ...)
- jsch <unfixed>
[trixie] - jsch <no-dsa> (Minor issue)
+ [bookworm] - jsch <postponed> (Minor issue)
NOTE: https://github.com/mwiede/jsch/issues/1091
NOTE: https://github.com/mwiede/jsch/pull/1098
NOTE: Fixed by: https://github.com/mwiede/jsch/commit/194a2f76a5c0f1c3f778565be3fd66bcafc42d23 (jsch-2.28.6)
@@ -62782,7 +62784,7 @@ CVE-2026-41608 (Improper Handling of Highly Compressed Data (Data Amplification)
[experimental] - thrift 0.24.0-1
- thrift 0.24.0-2
[trixie] - thrift <no-dsa> (Minor issue)
- [bullseye] - thrift <postponed> (Minor issue, DoS)
+ [bookworm] - thrift <postponed> (Minor issue, DoS)
NOTE: https://lists.apache.org/thread/vwsbcwqdpwdtp8qkjo11ol6rodbfm21f
CVE-2026-40000 (The Activity zte.com.cn.filer/zte.com.cn.filer.FilePreViewActivity wit ...)
NOT-FOR-US: ZTE
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cbcbecc0b3295b89aa06d5cbb580bb72fbc9ed70...bde373553419aad0e323792db45b893d2c02862f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/cbcbecc0b3295b89aa06d5cbb580bb72fbc9ed70...bde373553419aad0e323792db45b893d2c02862f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/3b4622ad/attachment.htm>
More information about the debian-security-tracker-commits
mailing list