[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 22 20:09:25 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
4d033e48 by Salvatore Bonaccorso at 2026-09-22T21:08:46+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,38 +7,38 @@ CVE-2026-86805
NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0022
NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=ed0c137b97eb940b4b64981e84ed806d3276edd9
CVE-2026-87082
- - libnet-idn-encode-perl <unfixed>
+ - libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753021/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/0918fb4a951ed5f4494c4cf202419c2842507ea4 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/59dc7f2c605a897bcbfe0ac5eb2b8dbe6792348d (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/accb6df57ad107ec0c4bfb27b21551eed97c700e (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/572af0183b3a6294e22c6b509268da09697cf77d (v2.590-TRIAL)
CVE-2026-87081
- - libnet-idn-encode-perl <unfixed>
+ - libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753018/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/5ac3315131264670efcd3a29857b651506dfee8e (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/ea34f812d7dc67f3b211f4d92e74c6a7e24d764a (v2.590-TRIAL)
CVE-2026-87080
- - libnet-idn-encode-perl <unfixed>
+ - libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753025/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/48436c7ad2c4d4c6398110e11133754fc476a783 (v2.590-TRIAL)
CVE-2026-87079
- - libnet-idn-encode-perl <unfixed>
+ - libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753023/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/00d723423b66810af26b88c552bedc61975b3078 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/447c6b38ef5d4570329fa4f78690f4e14e09ba0c (v2.590-TRIAL)
CVE-2026-87078
- - libnet-idn-encode-perl <unfixed>
+ - libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753020/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/92572f726e48af5559de4cc8a831463b79dfb217 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/edad63e0eeeeb18d93bc6dfe4d9dcdff9c244e1b (v2.590-TRIAL)
CVE-2026-74766
- - libnet-idn-encode-perl <unfixed>
+ - libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753027/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/259e74c5739175b063c5393a4ce4a0705678ba61 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/2fbc71e4d8517ab65c5d5d35fda086371b735a3f (v2.590-TRIAL)
CVE-2026-74765
- - libnet-idn-encode-perl <unfixed>
+ - libnet-idn-encode-perl <unfixed> (bug #1148729)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753029/
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/27a91ccdb6c9b41f75ba198f5ae154d14e225de2 (v2.590-TRIAL)
NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/81c7f99fe7430bdc5116081508dffdb56f376861 (v2.590-TRIAL)
@@ -209,10 +209,10 @@ CVE-2026-89139 (Temporal Server compiles a Worker Controller Instance module int
CVE-2026-88978 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
NOT-FOR-US: Hatchet
CVE-2026-88807 (A heap overflow in libXrender before 0.9.13 inRenderQueryPictFormats c ...)
- - libxrender <unfixed>
+ - libxrender <unfixed> (bug #1148735)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19
CVE-2026-88806 (A malicious X server could exploit a buffer overflow in libX11 before ...)
- - libx11 <unfixed>
+ - libx11 <unfixed> (bug #1148733)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309
CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not sanitise and e ...)
NOT-FOR-US: WordPress plugin
@@ -575,7 +575,7 @@ CVE-2026-75939 (A flaw was found in openshift/oc-mirror. The tool incorrectly ve
CVE-2026-93433 (A flaw was found in libstoragemgmt. An attacker with control over a lo ...)
NOT-FOR-US: libstoragemgmt
CVE-2026-94184 (A stack-based buffer overflow flaw was found in fetchmail when built w ...)
- - fetchmail <unfixed>
+ - fetchmail <unfixed> (bug #1148731)
[trixie] - fetchmail <no-dsa> (Minor issue)
NOTE: https://www.fetchmail.info/fetchmail-SA-2026-01.txt
NOTE: Fixed by: https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92 (6.6.7.rc1)
@@ -584,32 +584,32 @@ CVE-2026-94449 (A flaw was found in the SmallRye Fault Tolerance library, which
CVE-2026-94368 (A flaw was found in the signature verification logic of noobaa-core, t ...)
NOT-FOR-US: noobaa
CVE-2026-94640
- - rpcbind <unfixed>
+ - rpcbind <unfixed> (bug #1148730)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462960
CVE-2026-15801 (A vulnerability was found in CRI-O related to the container checkpoint ...)
- cri-o <itp> (bug #979702)
CVE-2026-93712 (Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from out ...)
- - libdancer2-perl <unfixed>
+ - libdancer2-perl <unfixed> (bug #1148732)
[trixie] - libdancer2-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742973/
NOTE: https://github.com/PerlDancer/Dancer2/security/advisories/GHSA-6xw8-v24c-m783
NOTE: Introduced with: https://github.com/PerlDancer/Dancer2/commit/d2f922bbf4ca18942a177d38fa62abcce05ed3f4 (v0.02)
NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/2446a09ffb83fef71cc75c327bd6e4b1f007b885 (v2.2.0)
CVE-2026-93711 (Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from res ...)
- - libdancer2-perl <unfixed>
+ - libdancer2-perl <unfixed> (bug #1148732)
[trixie] - libdancer2-perl <no-dsa> (Minor issue)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742971/
NOTE: https://github.com/PerlDancer/Dancer2/issues/1822
NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/ff89ac12af7b8899812a79e9924dfea7a5d9833b (v2.2.0)
CVE-2026-93710 (Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route tha ...)
- - libdancer2-perl <unfixed>
+ - libdancer2-perl <unfixed> (bug #1148732)
[trixie] - libdancer2-perl <not-affected> (Vulnerable code introduced later in 2.0.0)
[bookworm] - libdancer2-perl <not-affected> (Vulnerable code introduced later in 2.0.0)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742969/
NOTE: https://github.com/PerlDancer/Dancer2/security/advisories/GHSA-v527-r4px-7vx7
NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/8fd31a32798f9aa25e4fccbd6c7cb9dd3a0c1029 (v2.2.0)
CVE-2026-93709 (Dancer2 versions before 2.2.0 for Perl serve a layout as a page when a ...)
- - libdancer2-perl <unfixed> (unimportant)
+ - libdancer2-perl <unfixed> (unimportant; bug #1148732)
NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742968/
NOTE: https://github.com/PerlDancer/Dancer2/issues/1823
NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/293fce08812b0928f34ab2d7b9357450707c3630 (v2.2.0)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d033e4865d1dd4cd22cbcd652a43b89f025f2e2
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d033e4865d1dd4cd22cbcd652a43b89f025f2e2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/abb851de/attachment.htm>
More information about the debian-security-tracker-commits
mailing list