[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sun Sep 20 14:15:33 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bbb51d50 by Moritz Muehlenhoff at 2026-09-20T15:15:11+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -446,6 +446,7 @@ CVE-2026-76554 (The WP Import Export Lite WordPress plugin before 3.9.35 does no
 	NOT-FOR-US: WordPress plugin
 CVE-2026-75895 (In libsmpp35 from 0.1.0 through 1.8.0 out of bound read issue was foun ...)
 	- libsmpp34 <unfixed>
+	[trixie] - libsmpp34 <no-dsa> (Minor issue)
 	NOTE: https://cgit.osmocom.org/libsmpp34/commit/?id=af0e2912057551dab97bbe26e6a41f18a75f3bbb
 CVE-2026-75885 (A flaw was found in the OpenShift console. Unauthenticated access to t ...)
 	NOT-FOR-US: OpenShift
@@ -595,9 +596,11 @@ CVE-2017-20284 (Caucho Resin contains a path traversal vulnerability in the docu
 	NOT-FOR-US: Caucho Resin
 CVE-2026-93854 (In OpenStack Blazar before 17.0.1, the V2 lease API does not enforce o ...)
 	- blazar <unfixed> (bug #1148408)
+	[trixie] - blazar <no-dsa> (Minor issue)
 	NOTE: https://launchpad.net/bugs/2162719
 CVE-2026-93852 (In OpenStack Blazar before 17.0.1, the V2 lease listing operation (GET ...)
 	- blazar <unfixed> (bug #1148408)
+	[trixie] - blazar <no-dsa> (Minor issue)
 	NOTE: https://launchpad.net/bugs/2162719
 CVE-2026-93765 (Mongoid contains an unsafe reflection weakness in the document persist ...)
 	NOT-FOR-US: Mongoid
@@ -851,12 +854,15 @@ CVE-2026-92976 (A stored Cross-Site Scripting (XSS) vulnerability in the profile
 	NOT-FOR-US: T-Systems TAO
 CVE-2026-92768 (A flaw was found in cockpit-machines. This vulnerability allows a loca ...)
 	- cockpit-machines <unfixed>
+	[trixie] - cockpit-machines <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2469258
 CVE-2026-92747 (A flaw was found in `cockpit-machines`. This vulnerability allows a lo ...)
 	- cockpit-machines <unfixed>
+	[trixie] - cockpit-machines <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2469260
 CVE-2026-92745 (A flaw was found in cockpit-machines. This vulnerability allows a loca ...)
 	- cockpit-machines <unfixed>
+	[trixie] - cockpit-machines <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2476266
 CVE-2026-92702 (Cocos AI is a confidential computing system for running AI workloads i ...)
 	NOT-FOR-US: Cocos AI
@@ -1332,11 +1338,13 @@ CVE-2026-77874
 	NOT-FOR-US: Hibernate ORM
 CVE-2026-93019 (Imager versions before 1.036 for Perl exit the process reading a TGA w ...)
 	- libimager-perl 1.036+dfsg-1
+	[trixie] - libimager-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43654761/
 	NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-p4vw-rc54-p2c2
 	NOTE: Fixed by: https://github.com/tonycoz/imager/commit/74ed50e0625f9f51054e595bb4a8da92c1e0d571 (v1.036)
 CVE-2026-93018 (Imager versions before 1.036 for Perl disclose uninitialised heap memo ...)
 	- libimager-perl 1.036+dfsg-1
+	[trixie] - libimager-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43654795/
 	NOTE: https://github.com/tonycoz/imager/security/advisories/GHSA-j7v7-cm4g-vrgf
 	NOTE: Fixed by: https://github.com/tonycoz/imager/commit/dcf0a52e2732399d42ab44d98af6934658d068ee (v1.036)
@@ -4660,15 +4668,18 @@ CVE-2026-92599 (joi (npm package `joi`, hapi.js) versions >=17.2.0 <17.13.7 and
 	NOT-FOR-US: Node joi
 CVE-2026-92598 (Nodemailer before 9.1.0 fails to apply UTS-46 normalization when encod ...)
 	- node-nodemailer 10.0.0+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-wmmp-3585-3rmp
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/259c32d7d266301e3377a212776c3fff993c0148 (v9.1.0)
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/b212ac4e27bce8182478044fcb8d1642ccdad46e (v9.1.0)
 CVE-2026-92597 (Nodemailer versions >= 6.9.16 and < 9.1.0 mis-parse RFC 5322 comments  ...)
 	- node-nodemailer 10.0.0+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-cc9r-2j5m-2m83
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/902b63e935435c30f4025901c0902dce64cd8880 (v9.1.0)
 CVE-2026-92596 (Nodemailer before 9.1.0 contains a quadratic time complexity vulnerabi ...)
 	- node-nodemailer 10.0.0+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-2x7j-588g-ccc2
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/9116da9528c6524cefaed75185602a7e85d20434 (v9.1.0)
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/7cc38af418ffa6fc7e86085195ca5ca681694b3e (v9.1.0)
@@ -4676,6 +4687,7 @@ CVE-2026-92596 (Nodemailer before 9.1.0 contains a quadratic time complexity vul
 	NOTE: Fixed by: https://github.com/nodemailer/nodemailer/commit/83b8c48cbdb8b3116f2e1ba84af755b2c5661c0f (v9.1.0)
 CVE-2026-92595 (Nodemailer (npm package `nodemailer`) versions 9.1.0 and earlier do no ...)
 	- node-nodemailer 10.0.0+~8.0.1-1
+	[trixie] - node-nodemailer <no-dsa> (Minor issue)
 	NOTE: https://github.com/nodemailer/nodemailer/security/advisories/GHSA-8m3c-c648-2xjj
 CVE-2026-92594 (Craft CMS 5.0.0-RC1 through versions before 5.11.0 incorrectly authori ...)
 	NOT-FOR-US: Craft CMS or plugin for Craft CMS
@@ -8802,6 +8814,7 @@ CVE-2026-91987 (atomic-agents-stack before 1.1.0 contains a cost-guardrail bypas
 	NOT-FOR-US: atomic-agents-stack
 CVE-2026-91986 (gitoxide gix-transport before 0.59.2 fails to filter control character ...)
 	- rust-gix-transport <unfixed> (bug #1148173)
+	[trixie] - rust-gix-transport <no-dsa> (Minor issue)
 	NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-rc7h-wp5f-w3g5
 CVE-2026-91985 (Vikunja before 2.6.0 fails to properly restrict access to the link-sha ...)
 	NOT-FOR-US: Vikunja
@@ -9565,6 +9578,7 @@ CVE-2026-19780 (Koha Eval Code Injection Remote Code Execution Vulnerability. Th
 	- koha <itp> (bug #702134)
 CVE-2026-19774 (BlueZ A2DP Stack-based Buffer Overflow Remote Code Execution Vulnerabi ...)
 	- bluez 5.87-1
+	[trixie] - bluez <no-dsa> (Minor issue)
 	NOTE: https://www.zerodayinitiative.com/advisories/ZDI-26-589/
 	NOTE: https://github.com/bluez/bluez/pull/2251
 	NOTE: Fixed by: https://github.com/bluez/bluez/commit/912f5efb0dd9bb08e408d33371a57182c5678aef (5.87)
@@ -9701,31 +9715,43 @@ CVE-2026-92079 (Mitigation bypass in the Widget: Win32 component. This vulnerabi
 CVE-2026-92078 (Denial-of-service in the Security component. This vulnerability was fi ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92078
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92078
 CVE-2026-92077 (Denial-of-service in the SVG component. This vulnerability was fixed i ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92077
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92077
 CVE-2026-92076 (Incorrect boundary conditions in the Networking component. This vulner ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92076
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92076
 CVE-2026-92075 (Mitigation bypass in the Networking component. This vulnerability was  ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92075
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92075
 CVE-2026-92074 (Mitigation bypass in the Popup Blocker component. This vulnerability w ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92074
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92074
 CVE-2026-92073 (Privilege escalation in the Enterprise Policies component. This vulner ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92073
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92073
 CVE-2026-92072 (Incorrect boundary conditions in the Safe Browsing component. This vul ...)
@@ -9757,6 +9783,8 @@ CVE-2026-92069 (Spoofing issue in the DOM: Navigation component. This vulnerabil
 CVE-2026-92068 (Site isolation issue in the Reader Mode component. This vulnerability  ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92068
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92068
 CVE-2026-92067 (Use-after-free in the Widget: Gtk component. This vulnerability was fi ...)
@@ -9809,6 +9837,8 @@ CVE-2026-92059 (Incorrect boundary conditions in the DOM: Editor component. This
 CVE-2026-92058 (Use-after-free in the Graphics component. This vulnerability was fixed ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92058
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92058
 CVE-2026-92032 (Sandbox escape due to invalid pointer in the Graphics component. This  ...)
@@ -9830,31 +9860,43 @@ CVE-2026-92031 (Information disclosure in the Graphics: ImageLib component. This
 CVE-2026-92057 (Mitigation bypass in the Enterprise Policies component. This vulnerabi ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92057
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92057
 CVE-2026-92056 (Use-after-free in the Graphics: Text component. This vulnerability was ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92056
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92056
 CVE-2026-92055 (Privilege escalation in the DevTools component. This vulnerability was ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92055
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92055
 CVE-2026-92054 (Privilege escalation in the Memory component. This vulnerability was f ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92054
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92054
 CVE-2026-92053 (Privilege escalation in the Graphics: CanvasWebGL component. This vuln ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92053
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92053
 CVE-2026-92052 (Privilege escalation due to uninitialized memory in the Graphics: Canv ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92052
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92052
 CVE-2026-92051 (Spoofing issue due to invalid pointer in the Graphics component. This  ...)
@@ -9876,11 +9918,15 @@ CVE-2026-92048 (Sandbox escape due to incorrect boundary conditions in the Widge
 CVE-2026-92047 (Privilege escalation in the Crash Reporting component. This vulnerabil ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92047
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92047
 CVE-2026-92046 (Use-after-free in the Graphics component. This vulnerability was fixed ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92046
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92046
 CVE-2026-92030 (Mitigation bypass in the DOM: Copy & Paste and Drag & Drop component.  ...)
@@ -9894,26 +9940,36 @@ CVE-2026-92030 (Mitigation bypass in the DOM: Copy & Paste and Drag & Drop compo
 CVE-2026-92045 (Sandbox escape due to incorrect boundary conditions in the WebRTC comp ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92045
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92045
 CVE-2026-92044 (Information disclosure in the Networking: HTTP component. This vulnera ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92044
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92044
 CVE-2026-92043 (Privilege escalation due to incorrect boundary conditions in the Audio ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92043
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92043
 CVE-2026-92042 (Race condition in the DOM: Content Processes component. This vulnerabi ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92042
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92042
 CVE-2026-92041 (Mitigation bypass in the DOM: Networking component. This vulnerability ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92041
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92041
 CVE-2026-92040 (Use-after-free in the JavaScript: WebAssembly component. This vulnerab ...)
@@ -9922,11 +9978,15 @@ CVE-2026-92040 (Use-after-free in the JavaScript: WebAssembly component. This vu
 CVE-2026-92039 (Mitigation bypass in the DOM: Notifications component. This vulnerabil ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92039
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92039
 CVE-2026-92038 (Mitigation bypass in the Remote Settings Client component. This vulner ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92038
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92038
 CVE-2026-92037 (Incorrect boundary conditions in the DOM: Animation component. This vu ...)
@@ -10042,6 +10102,8 @@ CVE-2026-92016 (Use-after-free in the Disability Access APIs component. This vul
 CVE-2026-92035 (Sandbox escape due to incorrect boundary conditions in the Graphics co ...)
 	- firefox 156.0-1
 	- thunderbird 1:153.3.0esr-1
+	[trixie] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
+	[bookworm] - thunderbird <not-affected> (Vulnerable code not present, doesn't affect ESR140)
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-90/#CVE-2026-92035
 	NOTE: https://www.mozilla.org/en-US/security/advisories/mfsa2026-96/#CVE-2026-92035
 CVE-2026-92034 (Site isolation issue in the Graphics component. This vulnerability was ...)


=====================================
data/dsa-needed.txt
=====================================
@@ -38,6 +38,8 @@ emacs (jmm)
 --
 erlang
 --
+exim4
+--
 firebird3.0
 --
 firebird4.0



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbb51d50a0f5f8d437572261cfcf44ef30e9ce76

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbb51d50a0f5f8d437572261cfcf44ef30e9ce76
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260920/f4453cdb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list