[Git][security-tracker-team/security-tracker][master] 2 commits: glance,keystone: follow trixie triage

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Sat Sep 19 11:07:59 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4d3dbeef by Sylvain Beucler at 2026-09-19T12:07:48+02:00
glance,keystone: follow trixie triage

- - - - -
eb7a9dda by Sylvain Beucler at 2026-09-19T12:07:51+02:00
CVE-2026-85013/modules: bookworm postponed

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11949,6 +11949,7 @@ CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and password
 CVE-2026-90460 (An issue was discovered in OpenStack Keystone before 29.0.3. Tokens ob ...)
 	- keystone <unfixed>
 	[trixie] - keystone <no-dsa> (Minor issue)
+	[bookworm] - keystone <postponed> (Minor issue)
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2159643
 	NOTE: https://bugs.launchpad.net/keystone/+bug/2158931
 	NOTE: https://review.opendev.org/c/openstack/keystone/+/1002330
@@ -20710,6 +20711,7 @@ CVE-2026-16876 (An authentication bypass vulnerability exists in the WebGUI of S
 CVE-2026-85013 (A flaw was found in environment-modules. A local attacker can exploit  ...)
 	- modules 5.6.1-3
 	[trixie] - modules <no-dsa> (Minor issue; will be fixed via point release)
+	[bookworm] - modules <postponed> (Minor issue, requires access to trusted local directory))
 	NOTE: Fixed by: https://github.com/envmodules/modules/commit/d401b76a863386f9064637c71b66837805f82881 (v5.6.2)
 CVE-2026-86304 (MojoX::Authentication versions before 0.006 for Perl allow SAML authen ...)
 	NOT-FOR-US: MojoX::Authentication Perl module
@@ -23094,14 +23096,17 @@ CVE-2026-81738 (OpenVPN 2.5.0 through 2.7.6 on Windows using the tap-windows6 dr
 CVE-2026-71198 (In OpenStack Glance before 32.0.1, the location API does not validate  ...)
 	- glance 2:32.0.0-4 (bug #1146594)
 	[trixie] - glance <no-dsa> (Minor issue)
+	[bookworm] - glance <postponed> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-71197
 	- glance 2:32.0.0-4 (bug #1146594)
 	[trixie] - glance <no-dsa> (Minor issue)
+	[bookworm] - glance <postponed> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-71196
 	- glance 2:32.0.0-4 (bug #1146594)
 	[trixie] - glance <no-dsa> (Minor issue)
+	[bookworm] - glance <postponed> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-038.html
 CVE-2026-9854 (A vulnerability exists in SYS600 RBAC mechanism where users having acc ...)
 	NOT-FOR-US: Hitachi Energy



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/abc953c38c9a7c727be62218a520a7dd4c315277...eb7a9dda6da1ed854f3ae4906a3676c7e271954b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/abc953c38c9a7c727be62218a520a7dd4c315277...eb7a9dda6da1ed854f3ae4906a3676c7e271954b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/fea57c82/attachment.htm>


More information about the debian-security-tracker-commits mailing list