[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sun Sep 20 12:05:23 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a530d81e by Moritz Muehlenhoff at 2026-09-20T13:02:52+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -293,12 +293,15 @@ CVE-2026-91847 (The Online Scheduling and Appointment Booking System WordPress
NOT-FOR-US: WordPress plugin
CVE-2026-91205 (A flaw was found in cockpit-files. A local unprivileged attacker can e ...)
- cockpit-files <unfixed> (bug #1148476)
+ [trixie] - cockpit-files <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2466442
CVE-2026-91203 (A flaw was found in cockpit-files. This vulnerability allows a local a ...)
- cockpit-files <unfixed> (bug #1148475)
+ [trixie] - cockpit-files <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2465632
CVE-2026-91202 (A flaw was found in cockpit-files. A low-privileged local user can exp ...)
- cockpit-files <unfixed> (bug #1148474)
+ [trixie] - cockpit-files <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2465834
CVE-2026-89334 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages & ...)
NOT-FOR-US: WordPress plugin
@@ -9728,6 +9731,8 @@ CVE-2026-92073 (Privilege escalation in the Enterprise Policies component. This
CVE-2026-92072 (Incorrect boundary conditions in the Safe Browsing component. This vul ...)
- firefox 156.0-1
- thunderbird 1:153.3.0esr-1
+ [trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+ [bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92072
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92072
CVE-2026-92071 (Sandbox escape due to incorrect boundary conditions in the Widget: Win ...)
@@ -9738,11 +9743,15 @@ CVE-2026-92071 (Sandbox escape due to incorrect boundary conditions in the Widge
CVE-2026-92070 (Information disclosure in the Networking component. This vulnerability ...)
- firefox 156.0-1
- thunderbird 1:153.3.0esr-1
+ [trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+ [bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92070
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92070
CVE-2026-92069 (Spoofing issue in the DOM: Navigation component. This vulnerability wa ...)
- firefox 156.0-1
- thunderbird 1:153.3.0esr-1
+ [trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+ [bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92069
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92069
CVE-2026-92068 (Site isolation issue in the Reader Mode component. This vulnerability ...)
@@ -9753,6 +9762,8 @@ CVE-2026-92068 (Site isolation issue in the Reader Mode component. This vulnerab
CVE-2026-92067 (Use-after-free in the Widget: Gtk component. This vulnerability was fi ...)
- firefox 156.0-1
- thunderbird 1:153.3.0esr-1
+ [trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+ [bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92067
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92067
CVE-2026-92066 (Sandbox escape in the Profile Backup component. This vulnerability was ...)
@@ -9774,6 +9785,8 @@ CVE-2026-92063 (Denial-of-service in the Audio/Video component. This vulnerabili
CVE-2026-92062 (Privilege escalation in the Session Restore component. This vulnerabil ...)
- firefox 156.0-1
- thunderbird 1:153.3.0esr-1
+ [trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+ [bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92062
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92062
CVE-2026-92061 (Incorrect boundary conditions in the Security: Process Sandboxing comp ...)
@@ -9782,11 +9795,15 @@ CVE-2026-92061 (Incorrect boundary conditions in the Security: Process Sandboxin
CVE-2026-92060 (Use-after-free in the Internationalization component. This vulnerabili ...)
- firefox 156.0-1
- thunderbird 1:153.3.0esr-1
+ [trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+ [bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92060
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92060
CVE-2026-92059 (Incorrect boundary conditions in the DOM: Editor component. This vulne ...)
- firefox 156.0-1
- thunderbird 1:153.3.0esr-1
+ [trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+ [bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92059
NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92059
CVE-2026-92058 (Use-after-free in the Graphics component. This vulnerability was fixed ...)
@@ -11494,6 +11511,7 @@ CVE-2026-55091 (flat-to-nested converts a hierarchy from a flat representation t
TODO: check
CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior to 70.0 ...)
- weasyprint <unfixed> (bug #1148178)
+ [trixie] - weasyprint <no-dsa> (Minor issue)
NOTE: https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jf6q-chmf-3h3v
NOTE: https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443 (v70.0)
CVE-2026-55072 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
@@ -16023,9 +16041,11 @@ CVE-2026-23855 (Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions
NOT-FOR-US: Dell / EMC
CVE-2026-22591 (eprosima Fast DDS is a C++ implementation of the DDS (Data Distributio ...)
- fastdds <unfixed>
+ [trixie] - fastdds <no-dsa> (Minor issue)
NOTE: https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7577-rf2r-j88m
CVE-2026-22590 (eprosima Fast DDS is a C++ implementation of the DDS (Data Distributio ...)
- fastdds <unfixed>
+ [trixie] - fastdds <no-dsa> (Minor issue)
NOTE: https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7r7h-hwfj-q626
CVE-2026-19778 (The WPMR Google Feed Manager for WooCommerce \u2013 Sell on Google Mer ...)
NOT-FOR-US: WordPress plugin
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a530d81eebda9825abf88e1f78fb1130ce9681a5
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a530d81eebda9825abf88e1f78fb1130ce9681a5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/49dbdc04/attachment.htm>
More information about the debian-security-tracker-commits
mailing list