[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 17 21:30:58 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7c30c120 by Salvatore Bonaccorso at 2026-09-17T22:29:48+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -6792,7 +6792,7 @@ CVE-2026-91988 (atomic-agents-stack before 1.1.0 accepts cleartext HTTP schemes
CVE-2026-91987 (atomic-agents-stack before 1.1.0 contains a cost-guardrail bypass in t ...)
NOT-FOR-US: atomic-agents-stack
CVE-2026-91986 (gitoxide gix-transport before 0.59.2 fails to filter control character ...)
- - rust-gix-transport <unfixed>
+ - rust-gix-transport <unfixed> (bug #1148173)
NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-rc7h-wp5f-w3g5
CVE-2026-91985 (Vikunja before 2.6.0 fails to properly restrict access to the link-sha ...)
NOT-FOR-US: Vikunja
@@ -6857,7 +6857,7 @@ CVE-2026-91930 (Flowise before 3.1.4 fails to scope enterprise organization and
CVE-2026-91929 (Flowise versions before 3.1.4 contain cross-tenant authorization gaps ...)
NOT-FOR-US: Flowise
CVE-2026-91926 (A flaw was found in gss-ntlmssp. A memory leak occurs in the NTLM targ ...)
- - gss-ntlmssp <unfixed>
+ - gss-ntlmssp <unfixed> (bug #1148174)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2533698
CVE-2026-91925 (Polyaxon through 2.16.4 renders operation specification fields with an ...)
NOT-FOR-US: Polyaxon
@@ -6900,7 +6900,7 @@ CVE-2026-91825 (Affected versions of MISP fail to authorize a submitted sharing
CVE-2026-91819 (Affected versions of MISP rely on CakePHP request-method override proc ...)
- misp <itp> (bug #1144317)
CVE-2026-91786 (A flaw was found in GNOME Shell. When processing icons from a remote s ...)
- - gnome-shell <unfixed> (unimportant)
+ - gnome-shell <unfixed> (unimportant; bug #1148176)
NOTE: https://gitlab.gnome.org/GNOME/gnome-shell/-/issues/9365
NOTE: https://gitlab.gnome.org/GNOME/gnome-shell/-/merge_requests/4418
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gnome-shell/-/commit/8a3f208d0123b4831b1a4ba1040acc4f9091d465 (51.0)
@@ -325021,7 +325021,7 @@ CVE-2024-11738 (A flaw was found in Rustls 0.23.13 and related APIs. This vulner
NOTE: https://rustsec.org/advisories/RUSTSEC-2024-0399.html
NOTE: https://github.com/rustls/rustls/issues/2227
CVE-2026-XXXX [Incomplete fix for CVE-2024-53920]
- - emacs <unfixed>
+ - emacs <unfixed> (bug #1148177)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/14/1
CVE-2024-53920 (In elisp-mode.el in GNU Emacs before 30.1, a user who chooses to invok ...)
{DSA-5871-1 DLA-4069-1}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c30c1205e7e89cf4d28fe1e7ba5b8a191eff4c6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7c30c1205e7e89cf4d28fe1e7ba5b8a191eff4c6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/c48581be/attachment.htm>
More information about the debian-security-tracker-commits
mailing list