[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 19:58:28 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f979a8ef by Salvatore Bonaccorso at 2026-09-18T20:57:54+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -57,7 +57,7 @@ CVE-2026-93394 (A flaw in libmongoc's SCRAM authentication implementation caused
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/6b27da3e0384170ac0efc75321556bd37a2ae03f (2.4.0)
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/0b9bbbff0b949dcddb97e518e7fdb5950e187be3 (1.30.11)
 CVE-2026-93393 (A heap-based buffer overflow exists in the TLS transport layer of the  ...)
-	- mongo-c-driver <unfixed>
+	- mongo-c-driver <unfixed> (bug #1148331)
 	NOTE: https://jira.mongodb.org/browse/CDRIVER-6417
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/5536089200aeb837f27f39465d89506eeff689e1 (2.5.4)
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/01b1cf32fbe78044676c2fb163ba4f561a8d3ee3 (1.30.11)
@@ -521,7 +521,7 @@ CVE-2026-92983 (InternLM LMDeploy through 0.17.0 in DistServe prefill/decode dis
 CVE-2026-92980 (HortusFox-Web prior to version 6.1 contains a remote code execution vu ...)
 	NOT-FOR-US: HortusFox-Web
 CVE-2026-92973 (ansi2html versions 1.7.0a0 through 1.9.3 contain a cross-site scriptin ...)
-	- python-ansi2html <unfixed>
+	- python-ansi2html <unfixed> (bug #1148327)
 	NOTE: https://github.com/pycontribs/ansi2html/commit/89d1c231c60ac52005f3b21bbba551c786c554fc (v1.9.4)
 CVE-2026-92972 (SGLang through 0.5.19 in prefill/decode disaggregation mode contains a ...)
 	NOT-FOR-US: SGLang
@@ -7335,15 +7335,15 @@ CVE-2026-91994 (Semaphore UI through 2.19.12 exempts GET and HEAD requests from
 CVE-2026-91993 (Jpom through 2.11.12 fails to validate workspace ownership when resolv ...)
 	NOT-FOR-US: Jpom
 CVE-2026-91992 (Tornado before 6.5.7 contains a credential leak vulnerability in CurlA ...)
-	- python-tornado <unfixed>
+	- python-tornado <unfixed> (bug #1148323)
 	NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-pw6j-qg29-8w7f
 CVE-2026-91991 (Tornado before 6.5.8 contains an incomplete fix for cookie attribute i ...)
-	- python-tornado <unfixed>
+	- python-tornado <unfixed> (bug #1148323)
 	[trixie] - python-tornado <not-affected> (Incomplete fix for CVE-2026-35536 not applied)
 	NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-wwv5-g3v4-889x
 	NOTE: CVE exists because of an incomplete fix for CVE-2026-35536
 CVE-2026-91990 (Tornado before 6.5.8 contains a memory amplification vulnerability in  ...)
-	- python-tornado <unfixed>
+	- python-tornado <unfixed> (bug #1148323)
 	NOTE: https://github.com/tornadoweb/tornado/security/advisories/GHSA-8423-8fgw-73vq
 CVE-2026-91989 (atomic-agents-stack before 1.1.0 contains a path traversal vulnerabili ...)
 	NOT-FOR-US: atomic-agents-stack
@@ -9596,15 +9596,15 @@ CVE-2026-91079 (Huly Platform through 0.7.426 contains a server-side request for
 CVE-2026-91021 (Trilium Notes, version v0.103.0 and earlier, contains a stored cross-s ...)
 	NOT-FOR-US: Trilium Notes
 CVE-2026-90996 (A flaw was found in sssd. A local unprivileged user could send a speci ...)
-	- sssd <unfixed>
+	- sssd <unfixed> (bug #1148326)
 	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2478986
 CVE-2026-90995 (A flaw was found in SSSD (System Security Services Daemon). A local at ...)
-	- sssd <unfixed>
+	- sssd <unfixed> (bug #1148325)
 	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479464
 CVE-2026-90994 (A flaw was found in sssd, specifically within the PAM (Pluggable Authe ...)
-	- sssd <unfixed>
+	- sssd <unfixed> (bug #1148324)
 	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479455
 CVE-2026-90961 (The LdapAuth and LinOTPAuth authentication plugins in MISP contain an  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f979a8ef9da467970801a416f6dabb0a20ffe179

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f979a8ef9da467970801a416f6dabb0a20ffe179
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/bed0df63/attachment.htm>


More information about the debian-security-tracker-commits mailing list