[Git][security-tracker-team/security-tracker][master] 4 commits: node-undici: follow trixie triage (2)
Sylvain Beucler (@beuc)
gitlab at salsa.debian.org
Sat Sep 19 17:37:06 BST 2026
Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker
Commits:
8d90daef by Sylvain Beucler at 2026-09-19T18:36:45+02:00
node-undici: follow trixie triage (2)
- - - - -
a762e2d2 by Sylvain Beucler at 2026-09-19T18:36:48+02:00
rclone: bookworm postponed (8 more CVEs)
- - - - -
9f8be7bc by Sylvain Beucler at 2026-09-19T18:36:51+02:00
lts: add netcdf
- - - - -
94390c08 by Sylvain Beucler at 2026-09-19T18:36:53+02:00
python-jwcrypto: bookworm triage (3 CVEs)
CVE-2026-84185 introductory commit referenced in https://github.com/latchset/jwcrypto/security/advisories/GHSA-wwmx-rghj-gq83
- - - - -
2 changed files:
- data/CVE/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -5039,6 +5039,7 @@ CVE-2026-92114 (A vulnerability was identified in a2ui-project a2ui up to 0.10.6
NOT-FOR-US: a2ui-project a2ui
CVE-2026-92091 (A flaw was found in jwcrypto. The JWK.import_key() function validates ...)
- python-jwcrypto <unfixed> (bug #1148270)
+ [bookworm] - python-jwcrypto <postponed> (Minor issue, DoS)
NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-pwgw-f7xr-863h
NOTE: https://github.com/latchset/jwcrypto/pull/398
NOTE: https://github.com/latchset/jwcrypto/commit/21d2a2c20dbc1201ebe0b9b2621417629f37bfcd (v1.6.1)
@@ -21978,6 +21979,7 @@ CVE-2026-18175 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote attacker to ma
CVE-2026-18149 (undici's retry handler can leave an already-exposed response body pend ...)
- node-undici 8.10.2+dfsg+~cs3.2.2-1 (bug #1146745)
[trixie] - node-undici <no-dsa> (Minor issue)
+ [bookworm] - node-undici <postponed> (Minor issue)
NOTE: https://github.com/nodejs/undici/security/advisories/GHSA-pmjh-fq2x-6v4x
CVE-2026-18078 (IBM i 7.6, 7.5, 7.4, and 7.3 could allow a remote authenticated attack ...)
NOT-FOR-US: IBM
@@ -23006,9 +23008,11 @@ CVE-2026-85042 (Use after free in DevTools in Google Chrome prior to 152.0.7977.
CVE-2026-84185 (A flaw was found in the jwcrypto library, which is used for implementi ...)
- python-jwcrypto <unfixed> (bug #1146875)
[trixie] - python-jwcrypto <no-dsa> (Minor issue)
+ [bookworm] - python-jwcrypto <not-affected> (Vulnerable code introduced later)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2526729
NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-wwmx-rghj-gq83
NOTE: Fixed by: https://github.com/latchset/jwcrypto/commit/268f4bc5d46e05393fecbd2854074b11ab20cd65 (v1.6.0)
+ NOTE: Introduced by: https://github.com/latchset/jwcrypto/commit/e795a1375b948c06cf288ce64178997c2074d3c0 (v1.3.0)
CVE-2026-84146 (The Xpro Addons \u2014 140+ Widgets for Elementor WordPress plugin bef ...)
NOT-FOR-US: WordPress plugin
CVE-2026-84066 (The Directorist: AI-Powered Business Directory, Listings & Classified ...)
@@ -29741,7 +29745,7 @@ CVE-2026-80489 (Converting crafted EUC_JISX0213 input to UCS-4 or the internal w
CVE-2026-80179 (A flaw was found in jwcrypto. A remote attacker can send a specially c ...)
- python-jwcrypto <unfixed> (bug #1145983)
[trixie] - python-jwcrypto <no-dsa> (Minor issue)
- [bookworm] - python-jwcrypto <postponed> (Minor issue)
+ [bookworm] - python-jwcrypto <postponed> (Minor issue, DoS)
NOTE: https://github.com/latchset/jwcrypto/security/advisories/GHSA-96rv-c4vc-h4f4
CVE-2026-81501
- incus 7.0.1-3
@@ -33430,14 +33434,17 @@ CVE-2026-79778 (rclone before v1.75.0 contains a denial of service vulnerability
CVE-2026-79777 (rclone before v1.75.0 includes full Go stack traces in RC API error re ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-gwfq-86j8-7qhv
CVE-2026-79776 (rclone before 1.75.0 mounts the pprof debug handler as its own router ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-mfvx-7rcj-9m5g
CVE-2026-79775 (rclone versions >= v1.72.0 and <= v1.74.4 (fixed in v1.75.0) contain m ...)
- rclone <unfixed> (bug #1145670)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-6jcg-q3wp-x2f4
CVE-2026-79774 (Winter CMS versions before 1.2.13 contain an incomplete fix for a Twig ...)
NOT-FOR-US: Winter CMS
@@ -59349,26 +59356,31 @@ CVE-2026-71314 (Nuxt is an open-source web development framework for Vue.js. Fro
CVE-2026-71313 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-7p4m-qxvv-g567
NOTE: Fixed by: https://github.com/rclone/rclone/commit/6a69713864b1d8f6edbc03d8af735f9624576d6e (v1.75.0)
CVE-2026-71312 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-2m8m-jhrm-w6j2
NOTE: Fixed by: https://github.com/rclone/rclone/commit/e122fba1a57641b63a580aa26c026903a84e2e88 (v1.75.0)
CVE-2026-71311 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-8c48-q9wj-3w37
NOTE: Fixed by: https://github.com/rclone/rclone/commit/1df2b70753286c1dfe8366078cbedfdf7f96472c (v1.75.0)
CVE-2026-71310 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-xhf4-832v-7xcr
NOTE: Fixed by: https://github.com/rclone/rclone/commit/21d8cd3b92cd81d987f485051d454ea675d91a2b (v1.75.0)
CVE-2026-71309 (rclone is a command-line program to sync files and directories to and ...)
- rclone <unfixed> (bug #1143842)
[trixie] - rclone <no-dsa> (Minor issue)
+ [bookworm] - rclone <postponed> (Limited support, minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-45pq-889g-fcgh
NOTE: Fixed by: https://github.com/rclone/rclone/commit/cc5a189f00efe68ed0ddb32d3237b42549a9f264 (v1.75.0)
CVE-2026-70618 (Spacebar Server before commit 51da17c contains a missing authorization ...)
@@ -197745,8 +197757,8 @@ CVE-2025-15044 (A vulnerability was detected in Tenda WH450 1.0.0.18. Impacted i
CVE-2025-14936 (NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow Remote ...)
- netcdf 1:4.10.1-1 (bug #1123960)
[trixie] - netcdf <no-dsa> (Minor issue)
- [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - netcdf <postponed> (Minor issue)
+ [bullseye] - netcdf <postponed> (Minor issue)
- netcdf-parallel 1:4.10.1-1 (bug #1123961)
[trixie] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
@@ -197757,8 +197769,8 @@ CVE-2025-14936 (NSF Unidata NetCDF-C Attribute Name Stack-based Buffer Overflow
CVE-2025-14935 (NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow Remote ...)
- netcdf 1:4.10.1-1 (bug #1123960)
[trixie] - netcdf <no-dsa> (Minor issue)
- [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - netcdf <postponed> (Minor issue)
+ [bullseye] - netcdf <postponed> (Minor issue)
- netcdf-parallel 1:4.10.1-1 (bug #1123961)
[trixie] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
@@ -197769,8 +197781,8 @@ CVE-2025-14935 (NSF Unidata NetCDF-C Dimension Name Heap-based Buffer Overflow R
CVE-2025-14934 (NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow Remote ...)
- netcdf 1:4.10.1-1 (bug #1123960)
[trixie] - netcdf <no-dsa> (Minor issue)
- [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - netcdf <postponed> (Minor issue)
+ [bullseye] - netcdf <postponed> (Minor issue)
- netcdf-parallel 1:4.10.1-1 (bug #1123961)
[trixie] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
@@ -197781,8 +197793,8 @@ CVE-2025-14934 (NSF Unidata NetCDF-C Variable Name Stack-based Buffer Overflow R
CVE-2025-14933 (NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Executio ...)
- netcdf 1:4.10.1-1 (bug #1123960)
[trixie] - netcdf <no-dsa> (Minor isuse)
- [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - netcdf <postponed> (Minor issue)
+ [bullseye] - netcdf <postponed> (Minor issue)
- netcdf-parallel 1:4.10.1-1 (bug #1123961)
[trixie] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
@@ -197793,8 +197805,8 @@ CVE-2025-14933 (NSF Unidata NetCDF-C NC Variable Integer Overflow Remote Code Ex
CVE-2025-14932 (NSF Unidata NetCDF-C Time Unit Stack-based Buffer Overflow Remote Code ...)
- netcdf 1:4.10.1-1 (bug #1123960)
[trixie] - netcdf <no-dsa> (Minor issue)
- [bookworm] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
- [bullseye] - netcdf <postponed> (Minor issue, revisit when fixed upstream)
+ [bookworm] - netcdf <postponed> (Minor issue)
+ [bullseye] - netcdf <postponed> (Minor issue)
- netcdf-parallel 1:4.10.1-1 (bug #1123961)
[trixie] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - netcdf-parallel <postponed> (Minor issue, revisit when fixed upstream)
=====================================
data/dla-needed.txt
=====================================
@@ -440,6 +440,9 @@ nats-server
NOTE: 20260715: Added by Front-Desk (Beuc)
NOTE: 20260715: Upcoming DSA (Beuc/front-desk)
--
+netcdf
+ NOTE: 20260919: Added by Front-Desk (Beuc)
+--
netty (rouca)
NOTE: 20250814: Added by Front-Desk (lamby)
NOTE: 20251115: Partial release for sid. Fix all CVEs except CVE-2025-58056 (rouca)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/57cd99c14ed1b9ff9d0210aeda2074eef279e164...94390c081c17b2b9a8d6b9bcf132bd7532b58886
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/57cd99c14ed1b9ff9d0210aeda2074eef279e164...94390c081c17b2b9a8d6b9bcf132bd7532b58886
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/5160549e/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list