[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Tue Sep 22 21:59:14 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5fa5af95 by Moritz Muehlenhoff at 2026-09-22T22:58:53+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -836,9 +836,11 @@ CVE-2026-88978 (Hatchet is a platform for orchestrating background tasks, AI age
NOT-FOR-US: Hatchet
CVE-2026-88807 (A heap overflow in libXrender before 0.9.13 inRenderQueryPictFormats c ...)
- libxrender <unfixed> (bug #1148735)
+ [trixie] - libxrender <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxrender/-/merge_requests/19
CVE-2026-88806 (A malicious X server could exploit a buffer overflow in libX11 before ...)
- libx11 <unfixed> (bug #1148733)
+ [trixie] - libx11 <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libx11/-/merge_requests/309
CVE-2026-88788 (The Text Styler WordPress plugin through 1.1.1 does not sanitise and e ...)
NOT-FOR-US: WordPress plugin
@@ -1527,9 +1529,11 @@ CVE-2026-93988 (QloApps through 1.7.0 contains a path traversal vulnerability in
NOT-FOR-US: QloApps
CVE-2026-93987 (rclone versions 1.56.0 through 1.75.0 contain a path traversal vulnera ...)
- rclone <unfixed> (bug #1148669)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p6vx-hf7p-98j6
CVE-2026-93986 (rclone before 1.75.1 fails to confine names from server and third-part ...)
- rclone <unfixed> (bug #1148669)
+ [trixie] - rclone <no-dsa> (Minor issue)
NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-3vxh-3pcx-9m8q
CVE-2026-93985 (OpenPanel js-runtime through commit bad75bdd contains a sandbox escape ...)
NOT-FOR-US: OpenPanel
@@ -3144,6 +3148,7 @@ CVE-2026-77615 (Paella Player is a set of libraries to create a multi stream vid
NOT-FOR-US: Paella Player
CVE-2026-77281 (Caddy is an extensible server platform that uses TLS by default. In ve ...)
- caddy 2.11.4-1
+ [trixie] - caddy <no-dsa> (Minor issue)
NOTE: https://github.com/caddyserver/caddy/security/advisories/GHSA-j8px-rmrx-76h9
NOTE: https://github.com/caddyserver/caddy/pull/7761
NOTE: Fixed by: https://github.com/caddyserver/caddy/commit/176b043b0104cee3f894023cd5a598ac29e404bb (v2.11.4)
@@ -12434,6 +12439,7 @@ CVE-2026-64701 (A permissions issue was addressed with additional restrictions.
NOT-FOR-US: Apple
CVE-2026-55244 (ASTEVAL is an evaluator of Python expressions and statements. Prior to ...)
- python-asteval <unfixed> (bug #1148447)
+ [trixie] - python-asteval <no-dsa> (Minor issue)
NOTE: https://github.com/lmfit/asteval/security/advisories/GHSA-89v8-rhwq-hf77
NOTE: https://github.com/lmfit/asteval/pull/153
NOTE: Fixed by: https://github.com/lmfit/asteval/commit/9c625b3674f8d05f206708bb85afca17a87694a4 (1.0.9)
@@ -61901,19 +61907,19 @@ CVE-2026-71231 (IOTSmartHome's gui/login.php checkCookie function builds an auth
NOT-FOR-US: IOTSmartHome
CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence an applic ...)
- libkcapi 1.5.1-1 (bug #1143974)
- [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+ [trixie] - libkcapi <no-dsa> (Minor issue)
[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462867
NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/9a29cc2ce0fa87ec212d58118402eafe07db3f60 (v1.5.1)
CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one ...)
- libkcapi 1.5.1-1 (bug #1143974)
- [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+ [trixie] - libkcapi <no-dsa> (Minor issue)
[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462114
NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/cd966ffa08cf605ae5853d2f9a42fdd2b6df8bb4 (v1.5.1)
CVE-2026-71225 (A flaw was found in libkcapi. When performing one-shot symmetric ciphe ...)
- libkcapi 1.5.1-1 (bug #1143974)
- [trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
+ [trixie] - libkcapi <no-dsa> (Minor issue)
[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/017adba8f54f36f92e1919687fb67a89c4d299c6 (v1.5.1)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fa5af9535cef447d98abd9e8dbd8d1fc59bbe0d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5fa5af9535cef447d98abd9e8dbd8d1fc59bbe0d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/9821bc9a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list