[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 22 20:09:25 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4d033e48 by Salvatore Bonaccorso at 2026-09-22T21:08:46+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,38 +7,38 @@ CVE-2026-86805
 	NOTE: https://sourceware.org/git/?p=glibc.git;a=blob;f=advisories/GLIBC-SA-2026-0022
 	NOTE: Fixed by: https://sourceware.org/git/?p=glibc.git;a=commit;h=ed0c137b97eb940b4b64981e84ed806d3276edd9
 CVE-2026-87082
-	- libnet-idn-encode-perl <unfixed>
+	- libnet-idn-encode-perl <unfixed> (bug #1148729)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753021/
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/0918fb4a951ed5f4494c4cf202419c2842507ea4 (v2.590-TRIAL)
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/59dc7f2c605a897bcbfe0ac5eb2b8dbe6792348d (v2.590-TRIAL)
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/accb6df57ad107ec0c4bfb27b21551eed97c700e (v2.590-TRIAL)
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/572af0183b3a6294e22c6b509268da09697cf77d (v2.590-TRIAL)
 CVE-2026-87081
-	- libnet-idn-encode-perl <unfixed>
+	- libnet-idn-encode-perl <unfixed> (bug #1148729)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753018/
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/5ac3315131264670efcd3a29857b651506dfee8e (v2.590-TRIAL)
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/ea34f812d7dc67f3b211f4d92e74c6a7e24d764a (v2.590-TRIAL)
 CVE-2026-87080
-	- libnet-idn-encode-perl <unfixed>
+	- libnet-idn-encode-perl <unfixed> (bug #1148729)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753025/
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/48436c7ad2c4d4c6398110e11133754fc476a783 (v2.590-TRIAL)
 CVE-2026-87079
-	- libnet-idn-encode-perl <unfixed>
+	- libnet-idn-encode-perl <unfixed> (bug #1148729)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753023/
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/00d723423b66810af26b88c552bedc61975b3078 (v2.590-TRIAL)
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/447c6b38ef5d4570329fa4f78690f4e14e09ba0c (v2.590-TRIAL)
 CVE-2026-87078
-	- libnet-idn-encode-perl <unfixed>
+	- libnet-idn-encode-perl <unfixed> (bug #1148729)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753020/
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/92572f726e48af5559de4cc8a831463b79dfb217 (v2.590-TRIAL)
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/edad63e0eeeeb18d93bc6dfe4d9dcdff9c244e1b (v2.590-TRIAL)
 CVE-2026-74766
-	- libnet-idn-encode-perl <unfixed>
+	- libnet-idn-encode-perl <unfixed> (bug #1148729)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753027/
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/259e74c5739175b063c5393a4ce4a0705678ba61 (v2.590-TRIAL)
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/2fbc71e4d8517ab65c5d5d35fda086371b735a3f (v2.590-TRIAL)
 CVE-2026-74765
-	- libnet-idn-encode-perl <unfixed>
+	- libnet-idn-encode-perl <unfixed> (bug #1148729)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43753029/
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/27a91ccdb6c9b41f75ba198f5ae154d14e225de2 (v2.590-TRIAL)
 	NOTE: Fixed by: https://github.com/robrwo/Net-IDN-Encode/commit/81c7f99fe7430bdc5116081508dffdb56f376861 (v2.590-TRIAL)
@@ -209,10 +209,10 @@ CVE-2026-89139 (Temporal Server compiles a Worker Controller Instance module int
 CVE-2026-88978 (Hatchet is a platform for orchestrating background tasks, AI agents, a ...)
 	NOT-FOR-US: Hatchet
 CVE-2026-88807 (A heap overflow in libXrender before 0.9.13 inRenderQueryPictFormats c ...)
-	- libxrender <unfixed>
+	- libxrender <unfixed> (bug #1148735)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19
 CVE-2026-88806 (A malicious X server could exploit a buffer overflow in libX11 before  ...)
-	- libx11 <unfixed>
+	- libx11 <unfixed> (bug #1148733)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309
 CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not sanitise and e ...)
 	NOT-FOR-US: WordPress plugin
@@ -575,7 +575,7 @@ CVE-2026-75939 (A flaw was found in openshift/oc-mirror. The tool incorrectly ve
 CVE-2026-93433 (A flaw was found in libstoragemgmt. An attacker with control over a lo ...)
 	NOT-FOR-US: libstoragemgmt
 CVE-2026-94184 (A stack-based buffer overflow flaw was found in fetchmail when built w ...)
-	- fetchmail <unfixed>
+	- fetchmail <unfixed> (bug #1148731)
 	[trixie] - fetchmail <no-dsa> (Minor issue)
 	NOTE: https://www.fetchmail.info/fetchmail-SA-2026-01.txt
 	NOTE: Fixed by: https://gitlab.com/fetchmail/fetchmail/-/commit/cb5be5c38471eec19e519ace0bc569176317ea92 (6.6.7.rc1)
@@ -584,32 +584,32 @@ CVE-2026-94449 (A flaw was found in the SmallRye Fault Tolerance library, which
 CVE-2026-94368 (A flaw was found in the signature verification logic of noobaa-core, t ...)
 	NOT-FOR-US: noobaa
 CVE-2026-94640
-	- rpcbind <unfixed>
+	- rpcbind <unfixed> (bug #1148730)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462960
 CVE-2026-15801 (A vulnerability was found in CRI-O related to the container checkpoint ...)
 	- cri-o <itp> (bug #979702)
 CVE-2026-93712 (Dancer2 versions from 2.1.0 before 2.2.0 for Perl serve files from out ...)
-	- libdancer2-perl <unfixed>
+	- libdancer2-perl <unfixed> (bug #1148732)
 	[trixie] - libdancer2-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742973/
 	NOTE: https://github.com/PerlDancer/Dancer2/security/advisories/GHSA-6xw8-v24c-m783
 	NOTE: Introduced with: https://github.com/PerlDancer/Dancer2/commit/d2f922bbf4ca18942a177d38fa62abcce05ed3f4 (v0.02)
 	NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/2446a09ffb83fef71cc75c327bd6e4b1f007b885 (v2.2.0)
 CVE-2026-93711 (Dancer2 versions before 2.2.0 for Perl do not strip CR and LF from res ...)
-	- libdancer2-perl <unfixed>
+	- libdancer2-perl <unfixed> (bug #1148732)
 	[trixie] - libdancer2-perl <no-dsa> (Minor issue)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742971/
 	NOTE: https://github.com/PerlDancer/Dancer2/issues/1822
 	NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/ff89ac12af7b8899812a79e9924dfea7a5d9833b (v2.2.0)
 CVE-2026-93710 (Dancer2 versions from 2.0.0 before 2.2.0 for Perl dispatch a route tha ...)
-	- libdancer2-perl <unfixed>
+	- libdancer2-perl <unfixed> (bug #1148732)
 	[trixie] - libdancer2-perl <not-affected> (Vulnerable code introduced later in 2.0.0)
 	[bookworm] - libdancer2-perl <not-affected> (Vulnerable code introduced later in 2.0.0)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742969/
 	NOTE: https://github.com/PerlDancer/Dancer2/security/advisories/GHSA-v527-r4px-7vx7
 	NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/8fd31a32798f9aa25e4fccbd6c7cb9dd3a0c1029 (v2.2.0)
 CVE-2026-93709 (Dancer2 versions before 2.2.0 for Perl serve a layout as a page when a ...)
-	- libdancer2-perl <unfixed> (unimportant)
+	- libdancer2-perl <unfixed> (unimportant; bug #1148732)
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43742968/
 	NOTE: https://github.com/PerlDancer/Dancer2/issues/1823
 	NOTE: Fixed by: https://github.com/PerlDancer/Dancer2/commit/293fce08812b0928f34ab2d7b9357450707c3630 (v2.2.0)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d033e4865d1dd4cd22cbcd652a43b89f025f2e2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d033e4865d1dd4cd22cbcd652a43b89f025f2e2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/abb851de/attachment.htm>


More information about the debian-security-tracker-commits mailing list