[Git][security-tracker-team/security-tracker][master] new znuny issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 22 09:54:24 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
18917052 by Moritz Muehlenhoff at 2026-09-22T10:54:03+02:00
new znuny issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,11 @@
+CVE-2026-XXXX [ZSA-2026-15]
+ - znuny 6.5.25-1
+ [trixie] - znuny <no-dsa> (Non-free not supported)
+ NOTE: https://www.znuny.org/en/advisories/zsa-2026-15
+CVE-2026-XXXX [ZSA-2026-14]
+ - znuny 6.5.25-1
+ [trixie] - znuny <no-dsa> (Non-free not supported)
+ NOTE: https://www.znuny.org/en/advisories/zsa-2026-14
CVE-2026-94627 (vLLM Mooncake connector through 0.29.0 fails to properly manage GPU KV ...)
- vllm <itp> (bug #1095237)
CVE-2026-94626 (vLLM through 0.29.0 fails to validate the tp_size parameter in kv_tran ...)
@@ -102361,8 +102369,8 @@ CVE-2026-48937 (A flaw in Node.js HTTP/2 server API can cause servers to keep ac
NOTE: https://github.com/nodejs/node/commit/a1a5bb968303229d4a3a7c9e389dc3ece6237b4c (v22.23.0)
CVE-2026-48617 (A flaw in Node.js Permission Model enforcement allows Bypass via `proc ...)
- nodejs 24.17.0+dfsg+~cs24.13.2-1
- [bookworm] - nodejs <not-affected> ((Permission Model is a Node 20+ feature)
- [bullseye] - nodejs <not-affected> ((Permission Model is a Node 20+ feature)
+ [bookworm] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
+ [bullseye] - nodejs <not-affected> (Permission Model is a Node 20+ feature)
NOTE: https://nodejs.org/en/blog/vulnerability/june-2026-security-releases#permission-model-bypass-via-processreportwritereport-path-misvalidation-cve-2026-48617---low
NOTE: https://github.com/nodejs/node/commit/2f62693801a12bc8a485b3b7da3239ac522f607d (v22.23.0)
CVE-2026-47833 (setupBpmLogs follows symlink for bpm.log open and chown \u2014 contain ...)
@@ -114819,8 +114827,9 @@ CVE-2026-48190 (An incorrect handling of permissions in OTRS External Interface
CVE-2026-48189 (An improper Input Validation vulnerability in OTRS Customer Backend mo ...)
NOT-FOR-US: OTRS
CVE-2026-48188 (An improper Input Validation vulnerability in OTRS or ((OTRS)) Communi ...)
- NOT-FOR-US: OTRS
- NOTE: Could possibly affect Znuny, we'll let their security team figure it out
+ - znuny 6.5.25-1
+ [trixie] - znuny <no-dsa> (Non-free not supported)
+ NOTE: https://www.znuny.org/en/advisories/zsa-2026-13
CVE-2026-48187 (An uncontrolled allocation of resources without limits or throttling i ...)
NOT-FOR-US: OTRS
NOTE: Could possibly affect Znuny, we'll let their security team figure it out
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18917052cac8f00d7e19a06185ba91da285be62f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/18917052cac8f00d7e19a06185ba91da285be62f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/89c059bf/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list