[Git][security-tracker-team/security-tracker][master] 5 commits: CVE-2026-63435/ruby-mail: bookworm postponed

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Sat Sep 19 15:51:03 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5aeccaf6 by Sylvain Beucler at 2026-09-19T16:09:03+02:00
CVE-2026-63435/ruby-mail: bookworm postponed

- - - - -
891b1a34 by Sylvain Beucler at 2026-09-19T16:09:41+02:00
CVE-2026-54171/ruby-excon: bookworm postponed

- - - - -
8bd48642 by Sylvain Beucler at 2026-09-19T16:16:58+02:00
CVE-2026-85769/libtpms: bookworm postponed

- - - - -
38441e78 by Sylvain Beucler at 2026-09-19T16:47:34+02:00
CVE-2026-86469/glib2.0: bookworm postponed

- - - - -
71e7e3bb by Sylvain Beucler at 2026-09-19T16:50:27+02:00
mongo bindings: postponed (4 CVEs)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14698,11 +14698,14 @@ CVE-2026-88034 (Improper neutralization of special elements in data query logic
 CVE-2026-88033 (Improper neutralization of special elements in data query logic in the ...)
 	- mongo-java-driver <unfixed> (bug #1147406)
 	[trixie] - mongo-java-driver <no-dsa> (Minor issue)
+	[bookworm] - mongo-java-driver <postponed> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/JAVA-6283
 CVE-2026-88032 (A use-after-free in the reactive client-side encryption component of t ...)
 	- mongo-java-driver <unfixed> (bug #1147406)
 	[trixie] - mongo-java-driver <no-dsa> (Minor issue)
+	[bookworm] - mongo-java-driver <postponed> (Minor issue, DoS)
 	NOTE: https://jira.mongodb.org/browse/JAVA-6276
+	NOTE: https://github.com/mongodb/mongo-java-driver/security/advisories/GHSA-c4c8-c376-3p6c
 CVE-2026-88031 (Improper neutralization of special elements in data query logic in the ...)
 	- golang-mongodb-mongo-driver <unfixed> (bug #1147410)
 	[trixie] - golang-mongodb-mongo-driver <no-dsa> (Minor issue)
@@ -14718,6 +14721,7 @@ CVE-2026-88030 (Improper neutralization of special elements in data query logic
 CVE-2026-88029 (Improper neutralization of special elements in data query logic in the ...)
 	- pymongo 4.18.1-1 (bug #1147408)
 	[trixie] - pymongo <no-dsa> (Minor issue)
+	[bookworm] - pymongo <postponed> (Minor issue)
 	NOTE: https://jira.mongodb.org/browse/PYTHON-5994
 	NOTE: Fixed by: https://github.com/mongodb/mongo-python-driver/commit/fa676586ba4b399168a4d1d41c30dc2166cc44fd (v4.18.1)
 CVE-2026-88028 (Improper neutralization of special elements in data query logic in the ...)
@@ -20170,6 +20174,7 @@ CVE-2026-86478 (In JetBrains YouTrack before 2025.3.161254,  2026.1.14042 improp
 CVE-2026-86469 (A flaw was found in GLib2. When g_file_replace() is used with G_FILE_C ...)
 	- glib2.0 <unfixed> (bug #1147411)
 	[trixie] - glib2.0 <no-dsa> (Minor issue)
+	[bookworm] - glib2.0 <postponed> (Minor issue, require working in attacker-controlled directory)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2473839
 	NOTE: https://gitlab.gnome.org/GNOME/glib/-/work_items/4044
 CVE-2026-86452 (Affected versions of MISP permit unauthenticated or weakly constrained ...)
@@ -21178,6 +21183,7 @@ CVE-2026-85781 (Unverified ownership of a storage access point in the volume del
 CVE-2026-85769 (A flaw was found in libtpms, a library that provides software TPM 2.0  ...)
 	- libtpms <unfixed> (bug #1146880)
 	[trixie] - libtpms <no-dsa> (Minor issue)
+	[bookworm] - libtpms <postponed> (Minor issue, OOB read)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2528538
 	NOTE: https://github.com/stefanberger/libtpms/issues/614
 	NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/b1462888180d896af03cae0487e8d45009cc445e
@@ -23444,6 +23450,7 @@ CVE-2026-84969 (A memory-handling error in the BSON-to-JSON conversion helpers o
 CVE-2026-84968 (An out-of-bounds read in the BSON decoding component of the MongoDB PH ...)
 	- php-mongodb <unfixed>
 	[trixie] - php-mongodb <no-dsa> (Minor issue)
+	[bookworm] - php-mongodb <postponed> (Minor issue, infoleak)
 	NOTE: https://jira.mongodb.org/browse/PHPC-2744
 	NOTE: Fixed by: https://github.com/mongodb/mongo-php-driver/commit/44f68614e0a859a0d880811e3f93c2a02330c565 (2.5.1)
 CVE-2026-84967 (A component of the MongoDB extension for Visual Studio Code does not n ...)
@@ -24968,6 +24975,7 @@ CVE-2026-71981 (Cypht before 2.12.2 contains a PHP object injection vulnerabilit
 CVE-2026-63435 (Mail is an internet library for Ruby designed to handle email generati ...)
 	- ruby-mail 2.9.1-1
 	[trixie] - ruby-mail <no-dsa> (Minor issue)
+	[bookworm] - ruby-mail <postponed> (Minor issue)
 	NOTE: https://github.com/mikel/mail/security/advisories/GHSA-mvxr-6m87-mv2q
 	NOTE: https://github.com/mikel/mail/pull/1664
 	NOTE: Fixed by: https://github.com/mikel/mail/commit/f9d59c2e447af42e2c3dec5a56b1bb25c7292859 (2.9.1)
@@ -78604,6 +78612,7 @@ CVE-2026-54242 (Statamic is a Laravel and Git powered content management system
 CVE-2026-54171 (Excon is usable, fast, simple HTTP 1.1 for Ruby. Prior to 1.5.0, Excon ...)
 	- ruby-excon 1.5.0-1
 	[trixie] - ruby-excon <no-dsa> (Minor issue)
+	[bookworm] - ruby-excon <postponed> (Minor issue, infoleak)
 	NOTE: https://github.com/excon/excon/security/advisories/GHSA-48rx-c7pg-q66r
 	NOTE: https://github.com/excon/excon/pull/901
 	NOTE: Fixed by: https://github.com/excon/excon/commit/ea89a35308a12f4b791b6c50f2cbd33f94889fa3 (v1.5.0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fb0bf6dea10f1eb2145ad2bfab79bf073dcd2afb...71e7e3bbc62a57bed4c5ccdd9bbe03d7642ad03c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/fb0bf6dea10f1eb2145ad2bfab79bf073dcd2afb...71e7e3bbc62a57bed4c5ccdd9bbe03d7642ad03c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/dee85ef4/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list