[Git][security-tracker-team/security-tracker][master] lts: follow no-dsa triage for low-priority packages + tidy some triage

Sylvain Beucler (@beuc) gitlab at salsa.debian.org
Sat Sep 19 19:57:17 BST 2026



Sylvain Beucler pushed to branch master at Debian Security Tracker / security-tracker


Commits:
038c33ab by Sylvain Beucler at 2026-09-19T20:57:10+02:00
lts: follow no-dsa triage for low-priority packages + tidy some triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -277,36 +277,43 @@ CVE-2026-63446 (Suricata is a network Intrusion Detection System, Intrusion Prev
 CVE-2026-61822 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
 	- pg-partman 5.5.0-1
 	[trixie] - pg-partman <no-dsa> (Minor issue)
+	[bookworm] - pg-partman <postponed> (Minor issue)
 	NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-9m6c-hw23-c6h2
 	NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
 CVE-2026-61821 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
 	- pg-partman 5.5.0-1
 	[trixie] - pg-partman <no-dsa> (Minor issue)
+	[bookworm] - pg-partman <postponed> (Minor issue)
 	NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-pxp2-x8cf-rfhc
 	NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
 CVE-2026-61820 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
 	- pg-partman 5.5.0-1
 	[trixie] - pg-partman <no-dsa> (Minor issue)
+	[bookworm] - pg-partman <postponed> (Minor issue)
 	NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-xqxh-6hh3-974m
 	NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
 CVE-2026-61819 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
 	- pg-partman 5.5.0-1
 	[trixie] - pg-partman <no-dsa> (Minor issue)
+	[bookworm] - pg-partman <postponed> (Minor issue)
 	NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-gv5h-j2cm-rhc3
 	NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
 CVE-2026-61818 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
 	- pg-partman 5.5.0-1
 	[trixie] - pg-partman <no-dsa> (Minor issue)
+	[bookworm] - pg-partman <postponed> (Minor issue)
 	NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-fm3m-9fh7-mqfc
 	NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
 CVE-2026-61817 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
 	- pg-partman 5.5.0-1
 	[trixie] - pg-partman <no-dsa> (Minor issue)
+	[bookworm] - pg-partman <postponed> (Minor issue)
 	NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-gmw2-52wc-258g
 	NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
 CVE-2026-61781 (pg_partman is a PostgreSQL extension that manages partitioned tables b ...)
 	- pg-partman 5.5.0-1
 	[trixie] - pg-partman <no-dsa> (Minor issue)
+	[bookworm] - pg-partman <postponed> (Minor issue)
 	NOTE: https://github.com/pgpartman/pg_partman/security/advisories/GHSA-742w-3j7c-qwvp
 	NOTE: Fixed by: https://github.com/pgpartman/pg_partman/commit/ba9405542acf24dd881845b935cab8b165854361 (v5.5.0)
 CVE-2026-61670 (microsandbox is an easy, fast, local-first microVM runtime and library ...)
@@ -384,6 +391,7 @@ CVE-2026-93758 (An insecure direct object reference in the nested attributes han
 CVE-2026-93753 (deepmerge through 4.3.1 contains a prototype poisoning vulnerability i ...)
 	- node-deepmerge <unfixed> (bug #1148407)
 	[trixie] - node-deepmerge <no-dsa> (Minor issue)
+	[bookworm] - node-deepmerge <postponed> (Minor issue)
 	NOTE: https://github.com/TehShrike/deepmerge/issues/273
 CVE-2026-93752 (CSSOM through 0.5.0 contains a denial of service vulnerability in CSSS ...)
 	NOT-FOR-US: CSSOM
@@ -651,6 +659,7 @@ CVE-2026-89059 (A flaw was found in RESTEasy's IIOImageProvider, which decodes a
 	- resteasy <unfixed>
 	- resteasy3.0 <unfixed>
 	[trixie] - resteasy3.0 <no-dsa> (Minor issue)
+	[bookworm] - resteasy3.0 <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519756
 	NOTE: https://github.com/resteasy/resteasy/security/advisories/GHSA-m4pc-7gc7-9vw2
 	NOTE: https://redhat.atlassian.net/browse/RESTEASY-3793
@@ -659,6 +668,7 @@ CVE-2026-89058 (A flaw was found in RESTEasy's CorsFilter, which, when configure
 	- resteasy <unfixed>
 	- resteasy3.0 <unfixed>
 	[trixie] - resteasy3.0 <no-dsa> (Minor issue)
+	[bookworm] - resteasy3.0 <postponed> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519775
 	NOTE: https://github.com/resteasy/resteasy/security/advisories/GHSA-972r-f3fv-whm3
 	NOTE: https://redhat.atlassian.net/browse/RESTEASY-3796
@@ -1555,6 +1565,7 @@ CVE-2024-27123 (A cross-site scripting (XSS) vulnerability has been reported to
 CVE-2026-XXXX [OSSA-2026-039]
 	- octavia 18.0.0-4 (bug #1148175)
 	[trixie] - octavia <no-dsa> (Minor issue)
+	[bookworm] - octavia <postponed> (Minor issue)
 	NOTE: https://bugs.launchpad.net/octavia/+bug/2162101
 	NOTE: https://bugs.launchpad.net/octavia/+bug/2162103
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-039.html
@@ -7129,8 +7140,10 @@ CVE-2026-19535 (Nozomi Networks Labs identified a CWE-352: Cross-Site Request Fo
 CVE-2026-19248 (QDomDocument XML parsing is vulnerable to a remotely-triggerable denia ...)
 	- qt6-base <unfixed> (bug #1148271)
 	[trixie] - qt6-base <no-dsa> (Minor issue)
+	[bookworm] - qt6-base <postponed> (Minor issue, DoS)
 	- qtbase-opensource-src <unfixed> (bug #1148272)
 	[trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
+	[bookworm] - qtbase-opensource-src <postponed> (Minor issue, DoS)
 	NOTE: https://qt-project.atlassian.net/browse/QTBUG-147191
 	NOTE: https://github.com/qt/qtbase/commit/1303f05b33bb777626644729dd3b1330f60ecb7f (6.10)
 CVE-2026-18595 (The WP-Lister Lite for eBay plugin for WordPress is vulnerable to Stor ...)
@@ -21609,6 +21622,7 @@ CVE-2026-81666 (An integer overflow was found in Corosync's handling of membersh
 CVE-2026-81665 (A heap-based buffer overflow was found in Corosync's Totem Process Gro ...)
 	- corosync <unfixed> (bug #1146872)
 	[trixie] - corosync <no-dsa> (Minor issue)
+	[bookworm] - corosync <postponed> (Minor issue, DoS when assert(3) is enabled)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2524910
 	NOTE: Fixed by: https://github.com/corosync/corosync/commit/5148bf07dffa61bcfa92ca2c058e7d0f0a981cf3
 CVE-2026-81424 (The Accept Stripe Payments WordPress plugin before 2.1.4 does not veri ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/038c33ab31e0e82f8456f5d8bf194b7971f9d093

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/038c33ab31e0e82f8456f5d8bf194b7971f9d093
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/8ee74c45/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list