[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 22 21:59:14 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5fa5af95 by Moritz Muehlenhoff at 2026-09-22T22:58:53+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -836,9 +836,11 @@ CVE-2026-88978 (Hatchet is a platform for orchestrating background tasks, AI age
 	NOT-FOR-US: Hatchet
 CVE-2026-88807 (A heap overflow in libXrender before 0.9.13 inRenderQueryPictFormats c ...)
 	- libxrender <unfixed> (bug #1148735)
+	[trixie] - libxrender <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19
 CVE-2026-88806 (A malicious X server could exploit a buffer overflow in libX11 before  ...)
 	- libx11 <unfixed> (bug #1148733)
+	[trixie] - libx11 <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309
 CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not sanitise and e ...)
 	NOT-FOR-US: WordPress plugin
@@ -1527,9 +1529,11 @@ CVE-2026-93988 (QloApps through 1.7.0 contains a path traversal vulnerability in
 	NOT-FOR-US: QloApps
 CVE-2026-93987 (rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnera ...)
 	- rclone <unfixed> (bug #1148669)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p6vx-hf7p-98j6
 CVE-2026-93986 (rclone before 1.75.1 fails to confine names from server and third-part ...)
 	- rclone <unfixed> (bug #1148669)
+	[trixie] - rclone <no-dsa> (Minor issue)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-3vxh-3pcx-9m8q
 CVE-2026-93985 (OpenPanel js-runtime through commit bad75bdd contains a sandbox escape ...)
 	NOT-FOR-US: OpenPanel
@@ -3144,6 +3148,7 @@ CVE-2026-77615 (Paella Player is a set of libraries to create a multi stream vid
 	NOT-FOR-US: Paella Player
 CVE-2026-77281 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
 	- caddy 2.11.4-1
+	[trixie] - caddy <no-dsa> (Minor issue)
 	NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9
 	NOTE: https://github.com/caddyserver/caddy/pull/7761
 	NOTE: Fixed by: https://github.com/caddyserver/caddy/commit/176b043b0104cee3f894023cd5a598ac29e404bb (v2.11.4)
@@ -12434,6 +12439,7 @@ CVE-2026-64701 (A permissions issue was addressed with additional restrictions.
 	NOT-FOR-US: Apple
 CVE-2026-55244 (ASTEVAL is an evaluator of Python expressions and statements. Prior to ...)
 	- python-asteval <unfixed> (bug #1148447)
+	[trixie] - python-asteval <no-dsa> (Minor issue)
 	NOTE: https://github.com/lmfit/asteval/security/advisories/GHSA-89v8-rhwq-hf77
 	NOTE: https://github.com/lmfit/asteval/pull/153
 	NOTE: Fixed by: https://github.com/lmfit/asteval/commit/9c625b3674f8d05f206708bb85afca17a87694a4 (1.0.9)
@@ -61901,19 +61907,19 @@ CVE-2026-71231 (IOTSmartHome's gui/login.php checkCookie function builds an auth
 	NOT-FOR-US: IOTSmartHome
 CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence an applic ...)
 	- libkcapi 1.5.1-1 (bug #1143974)
-	[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+	[trixie] - libkcapi <no-dsa> (Minor issue)
 	[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462867
 	NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/9a29cc2ce0fa87ec212d58118402eafe07db3f60 (v1.5.1)
 CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one ...)
 	- libkcapi 1.5.1-1 (bug #1143974)
-	[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+	[trixie] - libkcapi <no-dsa> (Minor issue)
 	[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462114
 	NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/cd966ffa08cf605ae5853d2f9a42fdd2b6df8bb4 (v1.5.1)
 CVE-2026-71225 (A flaw was found in libkcapi. When performing one-shot symmetric ciphe ...)
 	- libkcapi 1.5.1-1 (bug #1143974)
-	[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+	[trixie] - libkcapi <no-dsa> (Minor issue)
 	[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
 	NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/017adba8f54f36f92e1919687fb67a89c4d299c6 (v1.5.1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fa5af9535cef447d98abd9e8dbd8d1fc59bbe0d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fa5af9535cef447d98abd9e8dbd8d1fc59bbe0d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/9821bc9a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list