[Git][security-tracker-team/security-tracker][master] auto-nfu: extend nvidia rule

Moritz Muehlenhoff (@jmm) jmm at debian.org
Tue Sep 22 22:18:35 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
91e331f0 by Moritz Muehlenhoff at 2026-09-22T23:18:08+02:00
auto-nfu: extend nvidia rule

- - - - -


2 changed files:

- data/CVE/list
- data/packages/nfu.yaml


Changes:

=====================================
data/CVE/list
=====================================
@@ -489,39 +489,39 @@ CVE-2026-68956 (Allocation of Resources Without Limits or Throttling vulnerabili
 CVE-2026-65634 (Inefficient algorithmic complexity in the Erlang/OTP asn1 OBJECT IDENT ...)
 	TODO: check
 CVE-2026-65179 (NVIDIA NeMo contains a vulnerability in the TabularTokenizer class whe ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65178 (NVIDIA NeMo contains a vulnerability in its dataset-loading workflow w ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65130 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65129 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65128 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65127 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65126 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65125 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65124 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65121 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65118 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65117 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65115 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65114 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65113 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65112 (NVIDIA Infrastructure Controller for Linux contains a vulnerability wh ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-65111 (NVIDIA NeMo Speech for all platforms contains a vulnerability where ma ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-63386 (js-toml is a TOML parser for JavaScript. Prior to 1.1.3, load() does n ...)
 	TODO: check
 CVE-2026-63279 (LibreOffice can import PICT images, which may be embedded in documents ...)
@@ -578,9 +578,9 @@ CVE-2026-25255 (Exposed dangerous function lead to privilege escalation via gRPC
 CVE-2026-25254 (Improper authorization leads to Remote Code Execution via SocketIO int ...)
 	NOT-FOR-US: Qualcomm
 CVE-2026-24267 (NVIDIA NeMo Speech for all platforms contains a vulnerability in the s ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-24239 (NVIDIA NeMo Speech for all platforms contains a vulnerability where ma ...)
-	TODO: check
+	NOT-FOR-US: NVIDIA
 CVE-2026-1645 (The Hostel plugin for WordPress is vulnerable to Stored Cross-Site Scr ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19915 (A potential security vulnerability has been identified in the HP Suppo ...)


=====================================
data/packages/nfu.yaml
=====================================
@@ -643,6 +643,7 @@
       - product: DLS component of NVIDIA License System
       - product: Dynamo
       - product: FLARE SDK
+      - product: Infrastructure Controller
       - product: Isaac Lab
       - product: Isaac Launchable
       - product: KAI Scheduler
@@ -651,6 +652,7 @@
       - product: Megatron-Bridge
       - product: Megatron-LM
       - product: Merlin Transformers4Rec
+      - product: NeMo Speech
       - product: NSIGHT Graphics
       - product: NVApp
       - product: NVDebug tool



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/91e331f0b71d2c37a646e9a5f30a8eb7e33765f5

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/91e331f0b71d2c37a646e9a5f30a8eb7e33765f5
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260922/1da091dd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list