[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 19 20:16:57 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
9eb6faca by Salvatore Bonaccorso at 2026-09-19T21:16:26+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1,5 +1,5 @@
 CVE-2026-82560
-	- perl <unfixed>
+	- perl <unfixed> (bug #1148455)
 	- podlators-perl <removed>
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43682367/
 	NOTE: Fixed by: https://github.com/rra/podlators/commit/70510174f69eb54aa6d617bde4e1402cd9b7c61f (release/v6.1.1)
@@ -1128,7 +1128,7 @@ CVE-2026-93455 (django-page-cms through 2.0.13 fails to properly validate page p
 CVE-2026-93454 (Aureus ERP through 1.6.0 stores the Payment Term note field unsanitize ...)
 	NOT-FOR-US: Aureus ERP
 CVE-2026-93453 (SOGo before 5.12.11 constructs password-reset links using the client-s ...)
-	- sogo <unfixed>
+	- sogo <unfixed> (bug #1148454)
 	NOTE: https://www.sogo.nu/news/2026/sogo-v51211-released.html
 	NOTE: Fixed by: https://github.com/Alinto/sogo/commit/382118a93b6925de2ce7f774abc1865ebea2dbba (SOGo-5.12.11)
 	NOTE: Fixed by: https://github.com/Alinto/sogo/commit/04a3e9823889acaf6c247b224f5f7a0108f8f829 (SOGo-5.12.11)
@@ -1802,12 +1802,12 @@ CVE-2026-86039 (libp2p is a JavaScript implementation of the libp2p networking s
 CVE-2026-86038 (libp2p is a JavaScript implementation of the libp2p networking stack.  ...)
 	NOT-FOR-US: Node libp2p
 CVE-2026-86000 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
-	- soupsieve <unfixed>
+	- soupsieve <unfixed> (bug #1148449)
 	[trixie] - soupsieve <no-dsa> (Minor issue)
 	NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-gjv8-xp57-g29c
 	NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/ce44e4996e6632871c18cdd7a7fb641be8ef34ef (2.9)
 CVE-2026-85999 (Soup Sieve is a CSS selector library designed to be used with Beautifu ...)
-	- soupsieve <unfixed>
+	- soupsieve <unfixed> (bug #1148449)
 	[trixie] - soupsieve <no-dsa> (Minor issue)
 	NOTE: https://github.com/facelessuser/soupsieve/security/advisories/GHSA-j934-xhv5-fg8f
 	NOTE: Fixed by: https://github.com/facelessuser/soupsieve/commit/cf198fcddc9230f06ed39f974eba0ce076b85cda (2.9)
@@ -4659,7 +4659,7 @@ CVE-2026-63225 (Redocly CLI makes OpenAPI validation, linting, and documentation
 CVE-2026-62997 (Kedro-Datasets provides data connectors for Kedro. From version 5.0.0  ...)
 	NOT-FOR-US: Kedro-Datasets
 CVE-2026-62949 (AsyncSSH is a Python package which provides an asynchronous client and ...)
-	- python-asyncssh <unfixed>
+	- python-asyncssh <unfixed> (bug #1148448)
 	[trixie] - python-asyncssh <no-dsa> (Minor issue)
 	NOTE: https://github.com/ronf/asyncssh/security/advisories/GHSA-rw4j-r22c-9gc3
 	NOTE: https://github.com/ronf/asyncssh/commit/9c354270c009285525e126721e8ed5fbed1f8a67 (v2.24.0)
@@ -10966,7 +10966,7 @@ CVE-2026-90693 (A flaw has been found in D-Link DIR-878 120B05. This impacts the
 CVE-2026-90692 (A vulnerability was detected in D-Link DIR-878 120B05. This affects th ...)
 	NOT-FOR-US: D-Link
 CVE-2026-90463 (A flaw was found in the sssd NSS responder. This input validation vuln ...)
-	- sssd <unfixed>
+	- sssd <unfixed> (bug #1148452)
 	[trixie] - sssd <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479268
 CVE-2026-8821 (Mattermost versions 11.9.x <= 11.9.0, 11.8.x <= 11.8.4, 11.7.x <= 11.7 ...)
@@ -11912,7 +11912,7 @@ CVE-2026-79300 (SEP sesam before 5.2.0.24 mishandles User Authorization with MFA
 CVE-2026-77773 (The Contact Form to Chat Apps | Click to Chat to Order  WordPress plug ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-90560 (zstd-jni versions 1.2.0 through 1.5.7-13 contain an out-of-bounds read ...)
-	- zstd-jni-java <unfixed>
+	- zstd-jni-java <unfixed> (bug #1148453)
 	[trixie] - zstd-jni-java <no-dsa> (Minor issue)
 	[bookworm] - zstd-jni-java <postponed> (Minor issue)
 	NOTE: https://github.com/luben/zstd-jni/issues/405
@@ -12008,7 +12008,7 @@ CVE-2026-90467 (aiosmtplib before 5.1.3 fails to properly validate email address
 	[bookworm] - aiosmtplib <postponed> (Minor issue)
 	NOTE: Fixed by: https://github.com/cole/aiosmtplib/commit/2e1b210714974ccc9efd0d09a8f846cb9aeaaec2 (v5.1.3)
 CVE-2026-90461 (OpenStack Ironic through 38.0.0 may send a username and password to an ...)
-	- ironic <unfixed>
+	- ironic <unfixed> (bug #1148451)
 	[trixie] - ironic <no-dsa> (Minor issue)
 	NOTE: https://bugs.launchpad.net/ironic/+bug/2162816
 CVE-2026-90460 (An issue was discovered in OpenStack Keystone before 29.0.3. Tokens ob ...)
@@ -176485,7 +176485,7 @@ CVE-2020-37184 (Allok Video Converter 4.6.1217 contains a stack overflow vulnera
 CVE-2020-37183 (Allok RM RMVB to AVI MPEG DVD Converter 3.6.1217 contains a stack over ...)
 	NOT-FOR-US: Allok RM RMVB to AVI MPEG DVD Converter
 CVE-2020-37182 (Redir 3.3 contains a stack overflow vulnerability in the doproxyconnec ...)
-	- redir <unfixed>
+	- redir <unfixed> (bug #1148417)
 	[trixie] - redir <no-dsa> (Minor issue)
 	[bookworm] - redir <postponed> (Minor issue; the overflowed connect_str is only ever set from the operator's own -x/--connect command line argument, never from network input)
 	[bullseye] - redir <postponed> (Minor issue; the overflowed connect_str is only ever set from the operator's own -x/--connect command line argument, never from network input)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9eb6faca0b3bed828f74d0c992edfedfd1584361

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/9eb6faca0b3bed828f74d0c992edfedfd1584361
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/4197e5ea/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list