[Git][security-tracker-team/security-tracker][master] 2 commits: glance,keystone: follow trixie triage
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Sat Sep 19 11:07:59 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4d3dbeef by Sylvain Beucler at 2026-09-19T12:07:48+02:00
glance,keystone: follow trixie triage
- - - - -
eb7a9dda by Sylvain Beucler at 2026-09-19T12:07:51+02:00
CVE-2026-85013/modules: bookworm postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11949,6 +11949,7 @@ CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and password
CVE-2026-90460 (An issue was discovered in OpenStack Keystone before 29.0.3. Tokens ob ...)
- keystone <unfixed>
[trixie] - keystone <no-dsa> (Minor issue)
+ [bookworm] - keystone <postponed> (Minor issue)
NOTE: https://bugs.launchpad.net/keystone/+bug/2159643
NOTE: https://bugs.launchpad.net/keystone/+bug/2158931
NOTE: https://review.opendev.org/c/openstack/keystone/+/1002330
@@ -20710,6 +20711,7 @@ CVE-2026-16876 (An authentication bypass vulnerability exists in the WebGUI of S
CVE-2026-85013 (A flaw was found in environment-modules. A local attacker can exploit ...)
- modules 5.6.1-3
[trixie] - modules <no-dsa> (Minor issue; will be fixed via point release)
+ [bookworm] - modules <postponed> (Minor issue, requires access to trusted local directory))
NOTE: Fixed by: https://github.com/envmodules/modules/commit/d401b76a863386f9064637c71b66837805f82881 (v5.6.2)
CVE-2026-86304 (MojoX::Authentication versions before 0.006 for Perl allow SAML authen ...)
NOT-FOR-US: MojoX::Authentication Perl module
@@ -23094,14 +23096,17 @@ CVE-2026-81738 (OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 dr
CVE-2026-71198 (In OpenStack Glance before 32.0.1, the location API does not validate ...)
- glance 2:32.0.0-4 (bug #1146594)
[trixie] - glance <no-dsa> (Minor issue)
+ [bookworm] - glance <postponed> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-71197
- glance 2:32.0.0-4 (bug #1146594)
[trixie] - glance <no-dsa> (Minor issue)
+ [bookworm] - glance <postponed> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-71196
- glance 2:32.0.0-4 (bug #1146594)
[trixie] - glance <no-dsa> (Minor issue)
+ [bookworm] - glance <postponed> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users having acc ...)
NOT-FOR-US: Hitachi Energy
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/abc953c38c9a7c727be62218a520a7dd4c315277...eb7a9dda6da1ed854f3ae4906a3676c7e271954b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/abc953c38c9a7c727be62218a520a7dd4c315277...eb7a9dda6da1ed854f3ae4906a3676c7e271954b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/fea57c82/attachment.htm>
More information about the debian-security-tracker-commits
mailing list