[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 20 12:05:23 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a530d81e by Moritz Muehlenhoff at 2026-09-20T13:02:52+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -293,12 +293,15 @@ CVE-2026-91847 (The Online Scheduling and Appointment Booking System  WordPress
 	NOT-FOR-US: WordPress plugin
 CVE-2026-91205 (A flaw was found in cockpit-files. A local unprivileged attacker can e ...)
 	- cockpit-files <unfixed> (bug #1148476)
+	[trixie] - cockpit-files <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2466442
 CVE-2026-91203 (A flaw was found in cockpit-files. This vulnerability allows a local a ...)
 	- cockpit-files <unfixed> (bug #1148475)
+	[trixie] - cockpit-files <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2465632
 CVE-2026-91202 (A flaw was found in cockpit-files. A low-privileged local user can exp ...)
 	- cockpit-files <unfixed> (bug #1148474)
+	[trixie] - cockpit-files <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2465834
 CVE-2026-89334 (The Better Messages \u2013 Chat Rooms, Group Chat, Private Messages &  ...)
 	NOT-FOR-US: WordPress plugin
@@ -9728,6 +9731,8 @@ CVE-2026-92073 (Privilege escalation in the Enterprise Policies component. This
 CVE-2026-92072 (Incorrect boundary conditions in the Safe Browsing component. This vul ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92072
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92072
 CVE-2026-92071 (Sandbox escape due to incorrect boundary conditions in the Widget: Win ...)
@@ -9738,11 +9743,15 @@ CVE-2026-92071 (Sandbox escape due to incorrect boundary conditions in the Widge
 CVE-2026-92070 (Information disclosure in the Networking component. This vulnerability ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92070
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92070
 CVE-2026-92069 (Spoofing issue in the DOM: Navigation component. This vulnerability wa ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92069
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92069
 CVE-2026-92068 (Site isolation issue in the Reader Mode component. This vulnerability  ...)
@@ -9753,6 +9762,8 @@ CVE-2026-92068 (Site isolation issue in the Reader Mode component. This vulnerab
 CVE-2026-92067 (Use-after-free in the Widget: Gtk component. This vulnerability was fi ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92067
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92067
 CVE-2026-92066 (Sandbox escape in the Profile Backup component. This vulnerability was ...)
@@ -9774,6 +9785,8 @@ CVE-2026-92063 (Denial-of-service in the Audio/Video component. This vulnerabili
 CVE-2026-92062 (Privilege escalation in the Session Restore component. This vulnerabil ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92062
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92062
 CVE-2026-92061 (Incorrect boundary conditions in the Security: Process Sandboxing comp ...)
@@ -9782,11 +9795,15 @@ CVE-2026-92061 (Incorrect boundary conditions in the Security: Process Sandboxin
 CVE-2026-92060 (Use-after-free in the Internationalization component. This vulnerabili ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92060
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92060
 CVE-2026-92059 (Incorrect boundary conditions in the DOM: Editor component. This vulne ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92059
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92059
 CVE-2026-92058 (Use-after-free in the Graphics component. This vulnerability was fixed ...)
@@ -11494,6 +11511,7 @@ CVE-2026-55091 (flat-to-nested converts a hierarchy from a flat representation t
 	TODO: check
 CVE-2026-55073 (WeasyPrint helps web developers to create PDF documents. Prior to 70.0 ...)
 	- weasyprint <unfixed> (bug #1148178)
+	[trixie] - weasyprint <no-dsa> (Minor issue)
 	NOTE: https://github.com/Kozea/WeasyPrint/security/advisories/GHSA-jf6q-chmf-3h3v
 	NOTE: https://github.com/Kozea/WeasyPrint/commit/289e278439b017cd9263b4cd4727026987f86443 (v70.0)
 CVE-2026-55072 (Pimcore is an Open Source Data & Experience Management Platform. Prior ...)
@@ -16023,9 +16041,11 @@ CVE-2026-23855 (Dell iDRAC9, 14G versions prior to 7.00.00.184, 15G/16G versions
 	NOT-FOR-US: Dell / EMC
 CVE-2026-22591 (eprosima Fast DDS is a C++ implementation of the DDS (Data Distributio ...)
 	- fastdds <unfixed>
+	[trixie] - fastdds <no-dsa> (Minor issue)
 	NOTE: https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7577-rf2r-j88m
 CVE-2026-22590 (eprosima Fast DDS is a C++ implementation of the DDS (Data Distributio ...)
 	- fastdds <unfixed>
+	[trixie] - fastdds <no-dsa> (Minor issue)
 	NOTE: https://github.com/eProsima/Fast-DDS/security/advisories/GHSA-7r7h-hwfj-q626
 CVE-2026-19778 (The WPMR Google Feed Manager for WooCommerce \u2013 Sell on Google Mer ...)
 	NOT-FOR-US: WordPress plugin



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a530d81eebda9825abf88e1f78fb1130ce9681a5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a530d81eebda9825abf88e1f78fb1130ce9681a5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/49dbdc04/attachment.htm>


More information about the debian-security-tracker-commits mailing list