[Git][security-tracker-team/security-tracker][master] 4 commits: CVE-2026-93894/varnish: bookworm postponed
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Sat Sep 19 13:51:42 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8cca5946 by Sylvain Beucler at 2026-09-19T14:51:25+02:00
CVE-2026-93894/varnish: bookworm postponed
- - - - -
4caa44e8 by Sylvain Beucler at 2026-09-19T14:51:28+02:00
CVE-2026-88264,CVE-2026-88265/crun: bookworm postponed
- - - - -
abd57f32 by Sylvain Beucler at 2026-09-19T14:51:28+02:00
lts: add freeipmi
- - - - -
a40e7736 by Sylvain Beucler at 2026-09-19T14:51:31+02:00
CVE-2026-XXXX/ostree: bookworm postponed (2 vulnerabilities)
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -4248,6 +4248,7 @@ CVE-2026-90053 (In the Linux kernel, the following vulnerability has been resolv
CVE-2026-93894 [VSV00020]
- vinyl-cache <unfixed> (bug #1148187)
- varnish <removed>
+ [bookworm] - varnish <postponed> (Minor issue, DoS)
NOTE: https://vinyl-cache.org/security/VSV00020.html
NOTE: Fixed by: https://code.vinyl-cache.org/vinyl-cache/vinyl-cache/commit/90f5bacc14b2404e6cc349ba015f0f73b8515136 (vinyl-cache-9.1.0)
NOTE: Fixed by: https://code.vinyl-cache.org/vinyl-cache/vinyl-cache/commit/853d397f30753bce1587991fcf9193c63fb4d1eb (vinyl-cache-9.0.2)
@@ -14589,10 +14590,12 @@ CVE-2026-88268 (GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffe
CVE-2026-88265 (A flaw was found in crun. After pivot_root, reopening /dev/null for st ...)
- crun <unfixed> (bug #1147401)
[trixie] - crun <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - crun <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531224
CVE-2026-88264 (A flaw was found in crun. When the container configuration does not gi ...)
- crun <unfixed> (bug #1147401)
[trixie] - crun <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - crun <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531223
CVE-2026-88060 (Angular is a development platform for building mobile and desktop web ...)
- angular.js <unfixed>
@@ -54162,10 +54165,12 @@ CVE-2026-73154 [GHSA-5g48-xjmf-7p4q: StationData::setData stack overflow]
CVE-2026-XXXX [GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems]
- ostree 2026.3-1 (bug #1144106)
[trixie] - ostree <postponed> (Minor issue)
+ [bookworm] - ostree <postponed> (Minor issue, requires high privileges)
NOTE: https://github.com/ostreedev/ostree/security/advisories/GHSA-xppc-j946-vcj7
CVE-2026-XXXX [GHSA-7cgc-gp99-6jmm: resource exhaustion via LZMA decoding]
- ostree 2026.3-1 (bug #1144105)
[trixie] - ostree <postponed> (Minor issue)
+ [bookworm] - ostree <postponed> (Minor issue, DoS)
NOTE: https://github.com/ostreedev/ostree/security/advisories/GHSA-7cgc-gp99-6jmm
NOTE: Regression: https://bugs.debian.org/1144283
CVE-2026-8917 (Untrusted Pointer Dereference in ASUS GPU Tweak III, GPUTweakII, AI Su ...)
=====================================
data/dla-needed.txt
=====================================
@@ -197,6 +197,9 @@ fort-validator
freecad
NOTE: 20260821: Added by Front-Desk (lamby)
--
+freeipmi
+ NOTE: 20260919: Added by Front-Desk (Beuc)
+--
freerdp2
NOTE: 20260127: Added by Front-Desk (Beuc)
NOTE: 20260127: Many CVEs fixed in 3.20.1 and 3.21, but missing fix commits (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/7cf2076b91dadabd6d3395bf5cbfc7d617947e3a...a40e7736888e5b3596f8f21080d720edab12c171
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/7cf2076b91dadabd6d3395bf5cbfc7d617947e3a...a40e7736888e5b3596f8f21080d720edab12c171
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/a6f97092/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list