[Git][security-tracker-team/security-tracker][master] 5 commits: nova: follow trixie triage
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Sat Sep 19 14:45:02 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
83e05a1f by Sylvain Beucler at 2026-09-19T15:44:36+02:00
nova: follow trixie triage
- - - - -
87e3bc85 by Sylvain Beucler at 2026-09-19T15:44:39+02:00
CVE-2026-86219/libauthen-sasl-perl: bookworm postponed
- - - - -
ed6a9a10 by Sylvain Beucler at 2026-09-19T15:44:42+02:00
CVE-2026-17495/node-moment: bookworm postponed
- - - - -
a5bbaa3e by Sylvain Beucler at 2026-09-19T15:44:44+02:00
CVE-2026-84305/sqlparse: bookworm postponed
- - - - -
fb0bf6de by Sylvain Beucler at 2026-09-19T15:44:47+02:00
CVE-2026-0799,CVE-2026-6244,CVE-2026-6554,CVE-2026-31911,CVE-2026-31912/libpcap: bookworm postponed
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10573,6 +10573,7 @@ CVE-2026-17628 (IBM Langflow OSS 1.0.0 through 1.10.2 could allow a remote authe
CVE-2026-17495 (moment is a JavaScript date library for parsing, validating, manipulat ...)
- node-moment 2.31.0+ds1-1 (bug #1148182)
[trixie] - node-moment <no-dsa> (Minor issue)
+ [bookworm] - node-moment <postponed> (Minor issue, requires passing a complex object directly to moment.locale())
NOTE: https://github.com/moment/moment/security/advisories/GHSA-4p3w-j4w9-5jqw
CVE-2026-17467 (IBM Cloud Pak for Data System (Yosemite 1.0) 3.0.5.2 could allow a rem ...)
NOT-FOR-US: IBM
@@ -20815,6 +20816,7 @@ CVE-2020-37277 (PocketMine-MP versions before 3.15.4 contain a denial of service
CVE-2026-86219 (Authen::SASL::Perl::DIGEST_MD5 versions before 2.2100 for Perl accept ...)
- libauthen-sasl-perl 2.2000-2
[trixie] - libauthen-sasl-perl <no-dsa> (Minor issue)
+ [bookworm] - libauthen-sasl-perl <postponed> (Minor issue, requires MiTM, historic DIGEST-MD5 mech)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43326063/
NOTE: Fixed by: https://github.com/perl-authen-sasl/perl-authen-sasl/commit/94337367030612842924f697cead29964a96448d (v2.2100)
CVE-2026-XXXX [CSS declaration smuggling via un-encoded ampersand emission]
@@ -21037,21 +21039,25 @@ CVE-2026-75018 (The Custom Contact Forms plugin for WordPress is vulnerable to a
CVE-2026-6554 (libpcap BPF interpreter treats the offset in the 'ja L' BPF instructio ...)
- libpcap 1.10.7-1 (bug #1146825)
[trixie] - libpcap <no-dsa> (Minor issue)
+ [bookworm] - libpcap <postponed> (Minor issue, requires running a malicious BPF program)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce (libpcap-1.10.7)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/09/2
CVE-2026-6244 (libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions ...)
- libpcap 1.10.7-1 (bug #1146825)
[trixie] - libpcap <no-dsa> (Minor issue)
+ [bookworm] - libpcap <postponed> (Minor issue, requires running a malicious BPF program)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19 (libpcap-1.10.7)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/09/2
CVE-2026-31912 (libpcap BPF interpreter detects neither reaching the end of the filter ...)
- libpcap 1.10.7-1 (bug #1146825)
[trixie] - libpcap <no-dsa> (Minor issue)
+ [bookworm] - libpcap <postponed> (Minor issue, requires running a malicious BPF program)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 (libpcap-1.10.7)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/09/2
CVE-2026-31911 (libpcap BPF interpreter calls abort() if it encounters a BPF instructi ...)
- libpcap 1.10.7-1 (bug #1146825)
[trixie] - libpcap <no-dsa> (Minor issue)
+ [bookworm] - libpcap <postponed> (Minor issue, requires running a malicious BPF program)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 (libpcap-1.10.7)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/09/2
CVE-2026-18313 (rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_ ...)
@@ -21073,6 +21079,7 @@ CVE-2026-10196 (The Mail Mint \u2013 Email Marketing, Newsletter, Email Automati
CVE-2026-0799 (In BPF instructions that load/store a value from/to a scratch memory r ...)
- libpcap 1.10.7-1 (bug #1146825)
[trixie] - libpcap <no-dsa> (Minor issue)
+ [bookworm] - libpcap <postponed> (Minor issue, requires running a malicious BPF program)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 (libpcap-1.10.7)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/09/2
CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress is vuln ...)
@@ -25258,6 +25265,7 @@ CVE-2026-8712 (Wyoming before 1.10.2 contains a server-side request forgery vuln
CVE-2026-84305 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- sqlparse <unfixed> (bug #1146628)
[trixie] - sqlparse <no-dsa> (Minor issue)
+ [bookworm] - sqlparse <postponed> (Minor issue, DoS)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-cfqr-cjx5-5jcm
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/a51df6d9e2d31b44be9adb6bc8732517db6bf96b (0.6.0)
CVE-2026-84304 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.83.1, in ...)
@@ -43191,7 +43199,7 @@ CVE-2026-71566 (FakeFish handles incoming credentials by passing them down to s
CVE-2026-71491 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- sqlparse <unfixed> (bug #1144932)
[trixie] - sqlparse <no-dsa> (Minor issue)
- [bookworm] - sqlparse <postponed> (Minor issue)
+ [bookworm] - sqlparse <postponed> (Minor issue, DoS)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-f2ff-p2ww-7p4p
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/ef2012a5eeb491e604dea2b00d516904a3830c87 (0.6.0)
CVE-2026-71479 (New API is a large language mode (LLM) gateway and artificial intellig ...)
@@ -43278,7 +43286,7 @@ CVE-2026-59894 (sqlparse is a non-validating SQL parser module for Python. Prior
CVE-2026-59893 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- sqlparse <unfixed> (bug #1144932)
[trixie] - sqlparse <no-dsa> (Minor issue)
- [bookworm] - sqlparse <postponed> (Minor issue)
+ [bookworm] - sqlparse <postponed> (Minor issue, DoS)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-prg7-hcfm-mfcr
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/d1d80602741f77ec78e5a04ce4719244cf32352e (0.6.0)
CVE-2026-59829 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -43302,7 +43310,7 @@ CVE-2026-55674 (Discourse is an open-source discussion platform. Prior to 2026.1
CVE-2026-54284 (sqlparse is a non-validating SQL parser module for Python. Prior to 0. ...)
- sqlparse <unfixed> (bug #1144932)
[trixie] - sqlparse <no-dsa> (Minor issue)
- [bookworm] - sqlparse <postponed> (Minor issue)
+ [bookworm] - sqlparse <postponed> (Minor issue, DoS)
NOTE: https://github.com/andialbrecht/sqlparse/security/advisories/GHSA-pwgv-4x5q-6m9f
NOTE: Fixed by: https://github.com/andialbrecht/sqlparse/commit/939b129e24c0ad5d51368b1aa72fffcaca76f06f (0.6.0)
CVE-2026-53960 (Discourse is an open-source discussion platform. Prior to 2026.1.6, 20 ...)
@@ -54499,6 +54507,7 @@ CVE-2026-19349 (Lemonldap::NG::Portal versions from 2.0.0 before 2.16.9, from 2.
CVE-2026-XXXX [Nova console WebSocket proxy Origin allow-list poisoning]
- nova 2:33.0.1-5 (bug #1142113)
[trixie] - nova <no-dsa> (Minor issue)
+ [bookworm] - nova <postponed> (Minor issue)
NOTE: https://wiki.openstack.org/wiki/OSSN/OSSN-0101
NOTE: https://review.opendev.org/c/openstack/nova/+/995870
CVE-2026-72900 (Metabase allows an authenticated, low-privileged attacker to read the ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9029f0b2f3e21cc4f551b65f47a2ba879d4ae0da...fb0bf6dea10f1eb2145ad2bfab79bf073dcd2afb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/9029f0b2f3e21cc4f551b65f47a2ba879d4ae0da...fb0bf6dea10f1eb2145ad2bfab79bf073dcd2afb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/2eca3d32/attachment.htm>
More information about the debian-security-tracker-commits
mailing list