[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 17 11:40:44 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
03496362 by Moritz Muehlenhoff at 2026-09-17T12:38:19+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -3914,10 +3914,12 @@ CVE-2026-89774 (In the Linux kernel, the following vulnerability has been resolv
NOTE: https://git.kernel.org/linus/4e37f6452d586b95c346a9abdd2fb80b67794f39 (7.1-rc3)
CVE-2026-89085 [heap buffer overflow in _init_fats / fat_table_read]
- parted <unfixed>
+ [trixie] - parted <no-dsa> (Minor issue)
NOTE: https://alioth-lists.debian.net/pipermail/parted-devel/2026-September/006032.html
NOTE: Fixed by: https://gitweb.git.savannah.gnu.org/gitweb/?p=parted.git;a=commit;h=73301c6915781c2eee66d0b1cc9d41a70bf901d6 (v3.7.13)
CVE-2026-89088 [heap buffer overflow in duplicate_legacy_root_dir]
- parted <unfixed>
+ [trixie] - parted <no-dsa> (Minor issue)
NOTE: https://alioth-lists.debian.net/pipermail/parted-devel/2026-September/006032.html
NOTE: Fixed by: https://gitweb.git.savannah.gnu.org/gitweb/?p=parted.git;a=commit;h=73301c6915781c2eee66d0b1cc9d41a70bf901d6 (v3.7.13)
CVE-2026-82373
@@ -5450,6 +5452,7 @@ CVE-2026-90812 (A security vulnerability has been detected in cosmicstack-labs m
NOT-FOR-US: mercury-agent
CVE-2026-90711 (proxy-addr is a Node.js module that determines a request's client addr ...)
- node-proxy-addr 2.0.8+~cs2.3.7-1
+ [trixie] - node-proxy-addr <no-dsa> (Minor issue)
NOTE: https://github.com/jshttp/proxy-addr/security/advisories/GHSA-jqcg-44mw-7w3h
CVE-2026-89141 (The AI Engine \u2013 The Chatbot, AI Framework & MCP for WordPress plu ...)
NOT-FOR-US: WordPress plugin
@@ -6211,12 +6214,15 @@ CVE-2026-91021 (Trilium Notes, version v0.103.0 and earlier, contains a stored c
NOT-FOR-US: Trilium Notes
CVE-2026-90996 (A flaw was found in sssd. A local unprivileged user could send a speci ...)
- sssd <unfixed>
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478986
CVE-2026-90995 (A flaw was found in SSSD (System Security Services Daemon). A local at ...)
- sssd <unfixed>
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479464
CVE-2026-90994 (A flaw was found in sssd, specifically within the PAM (Pluggable Authe ...)
- sssd <unfixed>
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479455
CVE-2026-90961 (The LdapAuth and LinOTPAuth authentication plugins in MISP contain an ...)
- misp <itp> (bug #1144317)
@@ -6403,6 +6409,7 @@ CVE-2026-90692 (A vulnerability was detected in D-Link DIR-878 120B05. This affe
NOT-FOR-US: D-Link
CVE-2026-90463 (A flaw was found in the sssd NSS responder. This input validation vuln ...)
- sssd <unfixed>
+ [trixie] - sssd <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479268
CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
- mattermost-server <itp> (bug #823556)
=====================================
data/dsa-needed.txt
=====================================
@@ -88,7 +88,9 @@ netatalk
--
netty
--
-nodejs
+network-manager-iodine
+--
+nodejs (jmm)
Bastien Roucaries posted debdiff for review
--
node-dompurify
@@ -151,6 +153,8 @@ shaarli
sogo
Regression update for #1144734, new batch of issues from 5.12.10 release
--
+squid
+--
tomcat10
--
tomcat11
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03496362ac3d1ac058befd965d04bca659a3f960
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03496362ac3d1ac058befd965d04bca659a3f960
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/57c43f49/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list