[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 22 07:48:07 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
db527ed7 by Moritz Muehlenhoff at 2026-09-22T08:47:56+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -936,11 +936,13 @@ CVE-2026-93659 (Concrete CMS Community Store before 2.7.8 renders customer-suppl
 	NOT-FOR-US: Concrete CMS Community Store
 CVE-2026-93658 (uutils coreutils versions before 0.10.0 apply setuid or setgid mode to ...)
 	- rust-coreutils 0.10.0-1
+	[trixie] - rust-coreutils <no-dsa> (Minor issue)
 	NOTE: https://github.com/uutils/coreutils/security/advisories/GHSA-cgg3-923w-v53m
 	NOTE: https://github.com/uutils/coreutils/pull/13629
 	NOTE: Fixed by: https://github.com/uutils/coreutils/commit/7c87ab04fee8e52d989fb2625568a3eeda1b1f55 (0.10.0)
 CVE-2026-93657 (hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC ...)
 	- rust-hickory-resolver 0.26.3-1
+	[trixie] - rust-hickory-resolver <no-dsa> (Minor issue)
 	NOTE: https://github.com/hickory-dns/hickory-dns/security/advisories/GHSA-5j98-2g5x-46v6
 	NOTE: https://github.com/hickory-dns/hickory-dns/commit/30720f4fb22e5556ecbf26d2c8274ea4a9fdd238
 CVE-2026-93653 (A denial of service flaw was found in Poppler's Splash backend. A craf ...)
@@ -960,9 +962,11 @@ CVE-2026-93603 (vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a
 	NOT-FOR-US: Node.js vm2
 CVE-2026-93601 (rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101. ...)
 	- rust-rustls-webpki 0.103.13+ds-1
+	[trixie] - rust-rustls-webpki <no-dsa> (Minor issue)
 	NOTE: https://github.com/rustls/webpki/security/advisories/GHSA-xgp8-3hg3-c2mh
 CVE-2026-93600 (rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0. ...)
 	- rust-rustls-webpki 0.103.13+ds-1
+	[trixie] - rust-rustls-webpki <no-dsa> (Minor issue)
 	NOTE: https://github.com/rustls/webpki/security/advisories/GHSA-965h-392x-2mh5
 CVE-2026-93598 (ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1  ...)
 	NOT-FOR-US: ArcadeDB
@@ -1986,6 +1990,7 @@ CVE-2026-54716 (Valhalla is an open source routing engine and accompanying libra
 	NOT-FOR-US: Valhalla
 CVE-2026-54692 (SAIL is a cross-platform library for loading and saving images with su ...)
 	- sail 1.2.0-1
+	[trixie] - sail <no-dsa> (Minor issue)
 	NOTE: https://github.com/HappySeaFox/sail/security/advisories/GHSA-gp27-qv2x-55v5
 	NOTE: https://github.com/HappySeaFox/sail/commit/2991e18f806cf038038ee1ef9b08aa5d57480de1 (v1.0.0)
 CVE-2026-54671 (WeGIA is a web manager for charitable institutions. Prior to 3.8.5, We ...)
@@ -2021,10 +2026,12 @@ CVE-2026-54633 (PoDoFo is a C++17 PDF manipulation library. From version 1.0.0 u
 	NOTE: https://github.com/podofo/podofo/commit/999c519d285c4a65eba48409d9cd2da9d4743cca (1.1.1)
 CVE-2026-54627 (SAIL is a cross-platform library for loading and saving images with su ...)
 	- sail 1.2.0-1
+	[trixie] - sail <no-dsa> (Minor issue)
 	NOTE: https://github.com/HappySeaFox/sail/security/advisories/GHSA-ccqf-rv86-h3wm
 	NOTE: https://github.com/HappySeaFox/sail/commit/f44a8b779a1fc527fc6bc5caa71a66a8ed940d50 (v1.0.0)
 CVE-2026-54626 (SAIL is a cross-platform library for loading and saving images with su ...)
 	- sail 1.2.0-1
+	[trixie] - sail <no-dsa> (Minor issue)
 	NOTE: https://github.com/HappySeaFox/sail/security/advisories/GHSA-744p-cqg2-m33h
 	NOTE: https://github.com/HappySeaFox/sail/commit/fa24bceb93958ad665dbc3cf6b49a1079ab12559 (v1.0.0)
 CVE-2026-54618 (Obsidian Web MCP is a secure remote MCP server for Obsidian vaults. Pr ...)
@@ -2705,6 +2712,7 @@ CVE-2026-52836 (OpenDDS is an open source C++ implementation of the Object Manag
 	NOT-FOR-US: OpenDDS
 CVE-2026-52727 (lxc-ci contains continuous integration and image-build scripts for LXC ...)
 	- lxc-ci <unfixed>
+	[trixie] - lxc-ci <no-dsa> (Minor issue)
 	NOTE: https://github.com/lxc/lxc-ci/security/advisories/GHSA-4h59-f67g-5qxp
 	NOTE: https://github.com/lxc/lxc-ci/commit/082cb34ea19791a0424feafd9da67b94881ea40a
 CVE-2026-50610 (A vulnerability has been identified in the Acer System Monitoring comp ...)
@@ -7390,7 +7398,9 @@ CVE-2026-76186 (Apache Airflow Keycloak provider: from Airflow 3.3 the Keycloak
 	NOT-FOR-US: Apache Airflow Keycloak provider
 CVE-2026-76151 (Out-of-bounds read (buffer over-read) in the HTTP Cache-Control respon ...)
 	- qt6-base 6.11.2+dfsg-5
+	[trixie] - qt6-base <no-dsa> (Minor issue)
 	- qtbase-opensource-src <unfixed> (bug #1148673)
+	[trixie] - qtbase-opensource-src <no-dsa> (Minor issue)
 	NOTE: https://codereview.qt-project.org/c/qt/qtbase/+/752129
 CVE-2026-76104 (Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorrect Per ...)
 	NOT-FOR-US: Dell / EMC
@@ -9368,6 +9378,7 @@ CVE-2026-86472 (fast-uri is a dependency-free RFC 3986 URI parser for Node.js, u
 	NOTE: https://github.com/fastify/fast-uri/security/advisories/GHSA-hrr3-gc8f-f4qj
 CVE-2026-85234 (A flaw was found in tftp-hpa. When the `in.tftpd` remap engine process ...)
 	- tftp-hpa 5.3+20251116-1
+	[trixie] - tftp-hpa <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2460997
 	NOTE: https://git.kernel.org/pub/scm/network/tftp/tftp-hpa.git/commit/?id=4b493532f5ce052a1c124acd0661233ec7918327 (tftp-hpa-5.4)
 CVE-2026-82837 (GitLab has remediated an issue in GitLab CE/EE affecting all versions  ...)
@@ -91460,7 +91471,7 @@ CVE-2025-36319 (IBM watsonx.data intelligence 5.2.0, 5.2.1, 5.2.2, 5.3.0 could a
 	NOT-FOR-US: IBM
 CVE-2025-15666 (A security vulnerability has been detected in Open Asset Import Librar ...)
 	- assimp <unfixed> (bug #1141389)
-	[trixie] - assimp <postponed> (Minor issue, revisit when fixed upstream)
+	[trixie] - assimp <no-dsa> (Minor issue)
 	[bookworm] - assimp <postponed> (Minor issue, revisit when fixed upstream)
 	[bullseye] - assimp <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/assimp/assimp/issues/6079


=====================================
data/dsa-needed.txt
=====================================
@@ -166,6 +166,8 @@ tomcat11
 --
 valkey (aron)
 --
+varnish
+--
 vlc
   wait for 3.0.24
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db527ed71c7bcdeca2bb64cafa519961ad44bf0f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/db527ed71c7bcdeca2bb64cafa519961ad44bf0f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/8dfdd13d/attachment.htm>


More information about the debian-security-tracker-commits mailing list