[Git][security-tracker-team/security-tracker][master] bugnums and drop ogmrip again for avilib copy

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Sep 19 23:35:35 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a4005ff0 by Moritz Muehlenhoff at 2026-09-20T00:34:58+02:00
bugnums and drop ogmrip again for avilib copy

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -74,13 +74,13 @@ CVE-2026-92099 (The WPGraphQL Smart Cache WordPress plugin before 2.3.2 does not
 CVE-2026-91847 (The Online Scheduling and Appointment Booking System  WordPress plugin ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-91205 (A flaw was found in cockpit-files. A local unprivileged attacker can e ...)
-	- cockpit-files <unfixed>
+	- cockpit-files <unfixed> (bug #1148476)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2466442
 CVE-2026-91203 (A flaw was found in cockpit-files. This vulnerability allows a local a ...)
-	- cockpit-files <unfixed>
+	- cockpit-files <unfixed> (bug #1148475)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2465632
 CVE-2026-91202 (A flaw was found in cockpit-files. A low-privileged local user can exp ...)
-	- cockpit-files <unfixed>
+	- cockpit-files <unfixed> (bug #1148474)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2465834
 CVE-2026-89334 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages &  ...)
 	NOT-FOR-US: WordPress plugin
@@ -710,7 +710,7 @@ CVE-2026-84992 (md-editor-v3 is a Markdown editor for Vue 3 developed in JSX and
 	NOT-FOR-US: md-editor-v3
 CVE-2026-84975 (PJSIP is a free and open source multimedia communication library writt ...)
 	- pjproject <removed>
-	- asterisk <unfixed>
+	- asterisk <unfixed> (bug #1148482)
 	NOTE: https://github.com/pjsip/pjproject/security/advisories/GHSA-382p-87mh-r3q8
 	NOTE: Fixed by: https://github.com/pjsip/pjproject/commit/43d3bd77bb6833eab4c493503b8d564a754ddfdd
 CVE-2026-84449 (libheif is a HEIF and AVIF file format decoder and encoder. Prior to 1 ...)
@@ -754,7 +754,7 @@ CVE-2026-81943 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmw
 CVE-2026-81942 (PLANET IGS-5225-8P2T4S industrial managed switch V1 and V2 firmware ve ...)
 	NOT-FOR-US: PLANET
 CVE-2026-81627 (A flaw was found in QEMU. The VAPIC setup hypercall in hw/i386/vapic.c ...)
-	- qemu <unfixed>
+	- qemu <unfixed> (bug #1148473)
 	[trixie] - qemu <no-dsa> (Minor issue)
 	NOTE: https://gitlab.com/qemu-project/qemu/-/work_items/4206
 	NOTE: Fixed by: https://gitlab.com/qemu-project/qemu/-/commit/d61c8a6fb7388486353aa267ba0d75b098f16662 (master)
@@ -820,7 +820,7 @@ CVE-2026-77239 (WACRM is a self-hostable CRM template for WhatsApp. In version 0
 CVE-2026-75961 (The NEX-Forms \u2013 Ultimate Forms Plugin for WordPress plugin for Wo ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75894 (In osmo-iuh from 0.1.0 through 1.8.0 a reachable assertion was found i ...)
-	- osmo-iuh <unfixed>
+	- osmo-iuh <unfixed> (bug #1148471)
 	[trixie] - osmo-iuh <no-dsa> (Minor issue)
 	NOTE: https://cgit.osmocom.org/osmo-iuh/commit/?id=f06967126f486bcb185ccf3d1a8f9bc02c4da1f6 (1.8.1)
 CVE-2026-75893 (In osmo-bsc from 1.0.1 through 1.14.1 a heap based buffer overflow iss ...)
@@ -8258,7 +8258,7 @@ CVE-2026-77860 (In NLnetLabs Unbound 1.20.0 up to and including 1.26.0, a vulner
 	- unbound 1.26.1-1
 	NOTE: https://nlnetlabs.nl/downloads/unbound/CVE-2026-77860.txt
 CVE-2026-92248 (A flaw was found in the file-psd plugin in GIMP. When generating a thu ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1148477)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16775
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3009
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/commit/6b1e668699ebebc35152ad6c3db4b445cd78b7df
@@ -10794,7 +10794,7 @@ CVE-2026-90957 (Affected versions of MISP serve uploaded SVG images inline witho
 CVE-2026-90955 (Affected versions of MISP\u2019s interactive CLI shell do not reliably ...)
 	- misp <itp> (bug #1144317)
 CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. When proc ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1148479)
 	[trixie] - gimp <not-affected> (Vulnerable code not present)
 	[bookworm] - gimp <not-affected> (Vulnerable code not present)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16753
@@ -10802,12 +10802,12 @@ CVE-2026-90949 (A flaw was found in GIMP's PSP (Paint Shop Pro) file loader. Whe
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/0ff8049449b00bdd906faad7fcea091de8aa00a5
 	NOTE: Introduced by: https://gitlab.gnome.org/GNOME/gimp/-/commit/680ebede22bf7f34f78e5342b4df207892559406 (GIMP_3_2_2)
 CVE-2026-90948 (A flaw was found in GIMP's ICO file loader. When processing an ICO fil ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1148480)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16742
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/123d6360b8d7e2a00a9d913889ee9cdca88e2380 (master)
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/07c8d365873dc748a11a2df19e7a9eeab1c10667 (gimp-3-2 branch)
 CVE-2026-90947 (A flaw was found in GIMP. When processing a specially crafted lighting ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1148481)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16682
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/2960
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8a680c38fe84d529255e6b2916951ae7c480ed2c (master)
@@ -11698,8 +11698,6 @@ CVE-2023-32778 (An issue was discovered in ILIAS 6.23, 7 before 7.22, and 8.1. A
 CVE-2026-90783 (MKVToolNix through 101.0 contains a heap buffer overflow in the bundle ...)
 	{DSA-6502-1}
 	- mkvtoolnix 101.0-2 (bug #1147621)
-	- ogmrip <unfixed>
-	[trixie] - ogmrip <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://codeberg.org/mbunkus/mkvtoolnix/commit/1495126138e086080f0163bee27fafbdf956a1d0
 	NOTE: Fixed by: https://codeberg.org/mbunkus/mkvtoolnix/commit/13fd81db3ae2b79d41536a9663719df11780797e
 CVE-2026-90782 (S2OPC through 1.7.3 contains a null pointer dereference in msg_subscri ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4005ff0cdcb2c253eddf475807c809ca0f58153

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a4005ff0cdcb2c253eddf475807c809ca0f58153
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/4dc5aa68/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list