[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 17 11:40:44 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
03496362 by Moritz Muehlenhoff at 2026-09-17T12:38:19+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -3914,10 +3914,12 @@ CVE-2026-89774 (In the Linux kernel, the following vulnerability has been resolv
 	NOTE: https://git.kernel.org/linus/4e37f6452d586b95c346a9abdd2fb80b67794f39 (7.1-rc3)
 CVE-2026-89085 [heap buffer overflow in _init_fats / fat_table_read]
 	- parted <unfixed>
+	[trixie] - parted <no-dsa> (Minor issue)
 	NOTE: https://alioth-lists.debian.net/pipermail/parted-devel/2026-September/006032.html
 	NOTE: Fixed by: https://gitweb.git.savannah.gnu.org/gitweb/?p=parted.git;a=commit;h=73301c6915781c2eee66d0b1cc9d41a70bf901d6 (v3.7.13)
 CVE-2026-89088 [heap buffer overflow in duplicate_legacy_root_dir]
 	- parted <unfixed>
+	[trixie] - parted <no-dsa> (Minor issue)
 	NOTE: https://alioth-lists.debian.net/pipermail/parted-devel/2026-September/006032.html
 	NOTE: Fixed by: https://gitweb.git.savannah.gnu.org/gitweb/?p=parted.git;a=commit;h=73301c6915781c2eee66d0b1cc9d41a70bf901d6 (v3.7.13)
 CVE-2026-82373
@@ -5450,6 +5452,7 @@ CVE-2026-90812 (A security vulnerability has been detected in cosmicstack-labs m
 	NOT-FOR-US: mercury-agent
 CVE-2026-90711 (proxy-addr is a Node.js module that determines a request's client addr ...)
 	- node-proxy-addr 2.0.8+~cs2.3.7-1
+	[trixie] - node-proxy-addr <no-dsa> (Minor issue)
 	NOTE: https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h
 CVE-2026-89141 (The AI Engine \u2013 The Chatbot, AI Framework & MCP for WordPress plu ...)
 	NOT-FOR-US: WordPress plugin
@@ -6211,12 +6214,15 @@ CVE-2026-91021 (Trilium Notes, version v0.103.0 and earlier, contains a stored c
 	NOT-FOR-US: Trilium Notes
 CVE-2026-90996 (A flaw was found in sssd. A local unprivileged user could send a speci ...)
 	- sssd <unfixed>
+	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478986
 CVE-2026-90995 (A flaw was found in SSSD (System Security Services Daemon). A local at ...)
 	- sssd <unfixed>
+	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479464
 CVE-2026-90994 (A flaw was found in sssd, specifically within the PAM (Pluggable Authe ...)
 	- sssd <unfixed>
+	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479455
 CVE-2026-90961 (The LdapAuth and LinOTPAuth authentication plugins in MISP contain an  ...)
 	- misp <itp> (bug #1144317)
@@ -6403,6 +6409,7 @@ CVE-2026-90692 (A vulnerability was detected in D-Link DIR-878 120B05. This affe
 	NOT-FOR-US: D-Link
 CVE-2026-90463 (A flaw was found in the sssd NSS responder. This input validation vuln ...)
 	- sssd <unfixed>
+	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479268
 CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
 	- mattermost-server <itp> (bug #823556)


=====================================
data/dsa-needed.txt
=====================================
@@ -88,7 +88,9 @@ netatalk
 --
 netty
 --
-nodejs
+network-manager-iodine
+--
+nodejs (jmm)
   Bastien Roucaries posted debdiff for review
 --
 node-dompurify
@@ -151,6 +153,8 @@ shaarli
 sogo
   Regression update for #1144734, new batch of issues from 5.12.10 release
 --
+squid
+--
 tomcat10
 --
 tomcat11



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03496362ac3d1ac058befd965d04bca659a3f960

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03496362ac3d1ac058befd965d04bca659a3f960
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/57c43f49/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list