[Git][security-tracker-team/security-tracker][master] 5 commits: CVE-2026-63435/ruby-mail: bookworm postponed
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Sat Sep 19 15:51:03 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5aeccaf6 by Sylvain Beucler at 2026-09-19T16:09:03+02:00
CVE-2026-63435/ruby-mail: bookworm postponed
- - - - -
891b1a34 by Sylvain Beucler at 2026-09-19T16:09:41+02:00
CVE-2026-54171/ruby-excon: bookworm postponed
- - - - -
8bd48642 by Sylvain Beucler at 2026-09-19T16:16:58+02:00
CVE-2026-85769/libtpms: bookworm postponed
- - - - -
38441e78 by Sylvain Beucler at 2026-09-19T16:47:34+02:00
CVE-2026-86469/glib2.0: bookworm postponed
- - - - -
71e7e3bb by Sylvain Beucler at 2026-09-19T16:50:27+02:00
mongo bindings: postponed (4 CVEs)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -14698,11 +14698,14 @@ CVE-2026-88034 (Improper neutralization of special elements in data query logic
CVE-2026-88033 (Improper neutralization of special elements in data query logic in the ...)
- mongo-java-driver <unfixed> (bug #1147406)
[trixie] - mongo-java-driver <no-dsa> (Minor issue)
+ [bookworm] - mongo-java-driver <postponed> (Minor issue)
NOTE: https://jira.mongodb.org/browse/JAVA-6283
CVE-2026-88032 (A use-after-free in the reactive client-side encryption component of t ...)
- mongo-java-driver <unfixed> (bug #1147406)
[trixie] - mongo-java-driver <no-dsa> (Minor issue)
+ [bookworm] - mongo-java-driver <postponed> (Minor issue, DoS)
NOTE: https://jira.mongodb.org/browse/JAVA-6276
+ NOTE: https://github.com/mongodb/mongo-java-driver/security/advisories/GHSA-c4c8-c376-3p6c
CVE-2026-88031 (Improper neutralization of special elements in data query logic in the ...)
- golang-mongodb-mongo-driver <unfixed> (bug #1147410)
[trixie] - golang-mongodb-mongo-driver <no-dsa> (Minor issue)
@@ -14718,6 +14721,7 @@ CVE-2026-88030 (Improper neutralization of special elements in data query logic
CVE-2026-88029 (Improper neutralization of special elements in data query logic in the ...)
- pymongo 4.18.1-1 (bug #1147408)
[trixie] - pymongo <no-dsa> (Minor issue)
+ [bookworm] - pymongo <postponed> (Minor issue)
NOTE: https://jira.mongodb.org/browse/PYTHON-5994
NOTE: Fixed by: https://github.com/mongodb/mongo-python-driver/commit/fa676586ba4b399168a4d1d41c30dc2166cc44fd (v4.18.1)
CVE-2026-88028 (Improper neutralization of special elements in data query logic in the ...)
@@ -20170,6 +20174,7 @@ CVE-2026-86478 (In JetBrains YouTrack before 2025.3.161254, 2026.1.14042 improp
CVE-2026-86469 (A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...)
- glib2.0 <unfixed> (bug #1147411)
[trixie] - glib2.0 <no-dsa> (Minor issue)
+ [bookworm] - glib2.0 <postponed> (Minor issue, require working in attacker-controlled directory)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2473839
NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/4044
CVE-2026-86452 (Affected versions of MISP permit unauthenticated or weakly constrained ...)
@@ -21178,6 +21183,7 @@ CVE-2026-85781 (Unverified ownership of a storage access point in the volume del
CVE-2026-85769 (A flaw was found in libtpms, a library that provides software TPM 2.0 ...)
- libtpms <unfixed> (bug #1146880)
[trixie] - libtpms <no-dsa> (Minor issue)
+ [bookworm] - libtpms <postponed> (Minor issue, OOB read)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2528538
NOTE: https://github.com/stefanberger/libtpms/issues/614
NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/b1462888180d896af03cae0487e8d45009cc445e
@@ -23444,6 +23450,7 @@ CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers o
CVE-2026-84968 (An out-of-bounds read in the BSON decoding component of the MongoDB PH ...)
- php-mongodb <unfixed>
[trixie] - php-mongodb <no-dsa> (Minor issue)
+ [bookworm] - php-mongodb <postponed> (Minor issue, infoleak)
NOTE: https://jira.mongodb.org/browse/PHPC-2744
NOTE: Fixed by: https://github.com/mongodb/mongo-php-driver/commit/44f68614e0a859a0d880811e3f93c2a02330c565 (2.5.1)
CVE-2026-84967 (A component of the MongoDB extension for Visual Studio Code does not n ...)
@@ -24968,6 +24975,7 @@ CVE-2026-71981 (Cypht before 2.12.2 contains a PHP object injection vulnerabilit
CVE-2026-63435 (Mail is an internet library for Ruby designed to handle email generati ...)
- ruby-mail 2.9.1-1
[trixie] - ruby-mail <no-dsa> (Minor issue)
+ [bookworm] - ruby-mail <postponed> (Minor issue)
NOTE: https://github.com/mikel/mail/security/advisories/GHSA-mvxr-6m87-mv2q
NOTE: https://github.com/mikel/mail/pull/1664
NOTE: Fixed by: https://github.com/mikel/mail/commit/f9d59c2e447af42e2c3dec5a56b1bb25c7292859 (2.9.1)
@@ -78604,6 +78612,7 @@ CVE-2026-54242 (Statamic is a Laravel and Git powered content management system
CVE-2026-54171 (Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon ...)
- ruby-excon 1.5.0-1
[trixie] - ruby-excon <no-dsa> (Minor issue)
+ [bookworm] - ruby-excon <postponed> (Minor issue, infoleak)
NOTE: https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r
NOTE: https://github.com/excon/excon/pull/901
NOTE: Fixed by: https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 (v1.5.0)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fb0bf6dea10f1eb2145ad2bfab79bf073dcd2afb...71e7e3bbc62a57bed4c5ccdd9bbe03d7642ad03c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fb0bf6dea10f1eb2145ad2bfab79bf073dcd2afb...71e7e3bbc62a57bed4c5ccdd9bbe03d7642ad03c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/dee85ef4/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list