[Git][security-tracker-team/security-tracker][master] 3 commits: lts: xen status update
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Sat Sep 19 10:51:52 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8e4954f6 by Sylvain Beucler at 2026-09-19T11:51:42+02:00
lts: xen status update
- - - - -
c9545a55 by Sylvain Beucler at 2026-09-19T11:51:44+02:00
node-undici: follow trixie triage
- - - - -
29883521 by Sylvain Beucler at 2026-09-19T11:51:45+02:00
lts: add libvirt
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -21418,26 +21418,32 @@ CVE-2026-85184 (@fastify/middie versions >= 9.1.0 and before 9.3.4 decide whethe
CVE-2026-85152 (undici 8.10.0 omits the destination origin from the cache and request- ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-vp8m-p9jh-q5pm
CVE-2026-85024 (undici bundles a WebSocket client whose permessage-deflate size-limit ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3wwx-pv8p-q78v
CVE-2026-85014 (undici's experimental WebSocketStream client crashes the whole Node.js ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rx4f-c7p8-82vq
CVE-2026-85008 (undici's cache interceptor documents that only safe HTTP methods are c ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-8436-99hf-9mmv
CVE-2026-84961 (undici's BalancedPool constructor passes its entire options object thr ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-w293-vg96-wgc3
CVE-2026-84947 (undici's dump interceptor reads and discards a response body up to a c ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2gqq-gqf2-x968
CVE-2026-84937 (The Video Player for YouTube WordPress plugin before 2.1.0 does not p ...)
NOT-FOR-US: WordPress plugin
@@ -21450,6 +21456,7 @@ CVE-2026-84934 (The JCH Optimize WordPress plugin before 6.0.1 does not perform
CVE-2026-84933 (undici's cache interceptor does not handle the Set-Cookie response hea ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-2jfj-6hjv-fm6j
CVE-2026-84931 (The Joli Table Of Contents WordPress plugin before 3.0.3 does not sani ...)
NOT-FOR-US: WordPress plugin
@@ -21470,6 +21477,7 @@ CVE-2026-84896 (The King Addons for Elementor WordPress plugin before 51.1.77 d
CVE-2026-84890 (undici's decompress interceptor decompresses response bodies according ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-3xpg-4rpp-hhhm
CVE-2026-84745 (The Events Calendar WordPress plugin before 6.17.3.1 does not restrict ...)
NOT-FOR-US: WordPress plugin
@@ -21528,6 +21536,7 @@ CVE-2026-81832 (IBM App Connect Enterprise 13.0.1.0 through 13.0.8.1, and 12.0.1
CVE-2026-81666 (An integer overflow was found in Corosync's handling of membership com ...)
- corosync <unfixed> (bug #1146872)
[trixie] - corosync <no-dsa> (Minor issue)
+ [bookworm] - corosync <postponed> (Minor issue, DoS)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524923
NOTE: Fixed by: https://github.com/corosync/corosync/commit/83920f2e36b5f1acd7dcf033c0820043cc29f82a
CVE-2026-81665 (A heap-based buffer overflow was found in Corosync's Totem Process Gro ...)
@@ -21828,6 +21837,7 @@ CVE-2026-19645 (IBM MQ Agent CD: v1.0.0, v1.0.1, v2.0.0, v2.0.1 An authenticated
CVE-2026-19534 (undici's WebSocket client crashes the whole Node.js process during the ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-rfgv-xxqx-mfg5
CVE-2026-19306 (IBM Langflow OSS 1.0.0 through 1.11.2 allows an authenticated attacker ...)
NOT-FOR-US: IBM
@@ -21882,6 +21892,7 @@ CVE-2026-18567 (IBM Db2 Mirror for i 7.4, 7.5, and 7.6 could allow a local attac
CVE-2026-18540 (undici's retry interceptor can append the body of a ranged retry respo ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-r53p-7pc4-xj5r
CVE-2026-18489 (IBM ContextForge MCP Gateway - Translate utility <= 1.0.8 MCP Context ...)
NOT-FOR-US: IBM
=====================================
data/dla-needed.txt
=====================================
@@ -374,6 +374,9 @@ libsoup2.4
libssh
NOTE: 20260731: Added by Front-Desk (ta)
--
+libvirt
+ NOTE: 20260919: Added by Front-Desk (Beuc)
+--
libwebsockets
NOTE: 20260718: Added by Front-Desk (Beuc)
NOTE: 20260718: 2 CVEs fixed in both bullseye and trixie (Beuc/front-desk)
@@ -817,7 +820,7 @@ wordpress
xen
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie (Beuc/front-desk)
- NOTE: 20260918: Maintainers are preparing an update, please review and coordinate,
+ NOTE: 20260918: Maintainers prepared an update, please review and coordinate,
NOTE: 20260918: they need help with the upload and DLA process: (Beuc/front-desk)
NOTE: 20260918: https://lists.debian.org/debian-lts/2026/08/msg00028.html
NOTE: 20260918: https://lists.debian.org/debian-lts/2026/09/threads.html#00073
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d409b9101179b026cade45eeb9c482fb7ad768dd...2988352154cd5363e25c710a33410f87be5ef55f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/d409b9101179b026cade45eeb9c482fb7ad768dd...2988352154cd5363e25c710a33410f87be5ef55f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/1762196f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list