[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 22 18:48:20 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
d5e62ac2 by Moritz Muehlenhoff at 2026-09-22T19:48:10+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -576,6 +576,7 @@ CVE-2026-93433 (A flaw was found in libstoragemgmt. An attacker with control ove
NOT-FOR-US: libstoragemgmt
CVE-2026-94184 (A stack-based buffer overflow flaw was found in fetchmail when built w ...)
- fetchmail <unfixed>
+ [trixie] - fetchmail <no-dsa> (Minor issue)
NOTE: https://www.fetchmail.info/fetchmail-SA-2026-01.txt
NOTE: Fixed by: https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92 (6.6.7.rc1)
CVE-2026-94449 (A flaw was found in the SmallRye Fault Tolerance library, which is use ...)
@@ -927,6 +928,7 @@ CVE-2026-93963 (A security vulnerability has been detected in itsourcecode Leave
NOT-FOR-US: itsourcecode System
CVE-2026-93962 (A weakness has been identified in Kamailio up to 5.8.8/6.0.7/6.1.4/6.2 ...)
- kamailio <unfixed>
+ [trixie] - kamailio <postponed> (Minor issue, fix along with future DSA)
NOTE: https://github.com/kamailio/kamailio/issues/4876
NOTE: https://github.com/kamailio/kamailio/pull/4877
NOTE: Fixed by: https://github.com/kamailio/kamailio/commit/38711a3e788de0130d48cb485578c482b57d9351 (master)
@@ -5792,6 +5794,7 @@ CVE-2026-82561 (Apache NiFi 1.5.0 through 2.11.0 provide REST API methods that r
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-81872 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to v ...)
- golang-opentelemetry-otel <unfixed>
+ [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-hjf4-fphr-2h65
NOTE: https://github.com/open-telemetry/opentelemetry-go/issues/6797
NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/8620
@@ -5799,17 +5802,20 @@ CVE-2026-81872 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prio
NOTE: Fixed by: https://github.com/open-telemetry/opentelemetry-go/commit/ba71b09e6ed272e93a669aeaec1e98b1df4cc582 (v1.45.0)
CVE-2026-81871 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to v ...)
- golang-opentelemetry-otel <unfixed>
+ [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-w34q-cm8f-9c5x
NOTE: Introduced with: https://github.com/open-telemetry/opentelemetry-go/commit/d99c76fa32fbbcf3e1e0cee4c49a7f181b0697bb (v1.28.0)
NOTE: Fixed by: https://github.com/open-telemetry/opentelemetry-go/commit/c65d435b43e5e6b82310e6b18dd4cdcb8ac63a0c (v1.45.0)
CVE-2026-81870 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From versi ...)
- golang-opentelemetry-otel <unfixed>
+ [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-8wmf-6v46-5gfg
NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/8438
NOTE: Introduced with: https://github.com/open-telemetry/opentelemetry-go/commit/a1fff3c2588c783d1f3f6fd2315aa2660fc6d330 (v1.5.0)
NOTE: Fixed by: https://github.com/open-telemetry/opentelemetry-go/commit/3a1412d2b3bc4e4231fbeac2ed42117ae541bb38 (v1.45.0)
CVE-2026-81869 (OpenTelemetry-Go is the Go implementation of OpenTelemetry. From versi ...)
- golang-opentelemetry-otel 1.43.0-1
+ [trixie] - golang-opentelemetry-otel <no-dsa> (Minor issue)
NOTE: https://github.com/open-telemetry/opentelemetry-go/security/advisories/GHSA-p9f8-wvj8-2fg8
NOTE: https://github.com/open-telemetry/opentelemetry-go/issues/5996
NOTE: https://github.com/open-telemetry/opentelemetry-go/pull/5997
@@ -12336,6 +12342,7 @@ CVE-2026-85892 (Concurrent execution using shared resource with improper synchro
NOT-FOR-US: Microsoft
CVE-2026-84445 (gRPC-Go is the Go language implementation of gRPC. Prior to 1.82.2 and ...)
- golang-google-grpc <unfixed>
+ [trixie] - golang-google-grpc <no-dsa> (Minor issue)
[bookworm] - golang-google-grpc <postponed> (Limited support, minor issue; DoS, clean crash)
NOTE: https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj
NOTE: https://github.com/grpc/grpc-go/issues/9354
@@ -15146,9 +15153,12 @@ CVE-2026-89260 (MoguBlog through 6.2 contains an XML external entity injection v
NOT-FOR-US: MoguBlog
CVE-2026-89259 (Hugo is a static site generator. From v0.161.0, Hugo executes Node too ...)
- hugo 0.165.0-1
+ [trixie] - hugo <not-affected> (Incomplete fix for CVE-2026-44301 not shipped)
+ [bookworm] - hugo <not-affected> (Incomplete fix for CVE-2026-44301 not shipped)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-vrm6-x8vp-mv2r
CVE-2026-89258 (Hugo is a static site generator. In versions after v0.123.0 and before ...)
- hugo 0.165.0-1
+ [trixie] - hugo <no-dsa> (Minor issue)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-vrv5-r5rf-6v4j
CVE-2026-89257 (AVideo through 29.0 contains an insecure direct object reference (IDOR ...)
NOT-FOR-US: WWBN AVideo
@@ -127827,6 +127837,7 @@ CVE-2026-44301 (Hugo is a static site generator. From 0.43 to before 0.161.0, wh
[bookworm] - hugo <no-dsa> (Minor issue)
[bullseye] - hugo <no-dsa> (Minor issue)
NOTE: https://github.com/gohugoio/hugo/security/advisories/GHSA-x597-9fr4-5857
+ NOTE: When fixing in stable releases, CVE-2026-89259 is needed
CVE-2026-44296 (Deskflow is a keyboard and mouse sharing app. Prior to 1.26.0.167, a r ...)
- deskflow 1.26.0+dfsg-3
[trixie] - deskflow <no-dsa> (Minor issue)
=====================================
data/dsa-needed.txt
=====================================
@@ -40,6 +40,8 @@ erlang
--
exim4
--
+expat
+-
firebird3.0
--
firebird4.0
@@ -51,8 +53,13 @@ gegl (jmm)
--
ghostscript (carnil)
--
+graphicsmagick
+--
gst-plugins-good1.0
--
+hplip
+ security patches first need to be isolated
+--
jackson-databind
--
jetty9
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5e62ac24b6f297f19d33cd703b5b09197771f55
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5e62ac24b6f297f19d33cd703b5b09197771f55
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/f6f0a2b9/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list