[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 07:48:25 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
30613d23 by Moritz Muehlenhoff at 2026-09-24T08:48:14+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -698,6 +698,7 @@ CVE-2026-62985 (request-filtering-agent is an http(s).Agent implementation that
 	NOT-FOR-US: Node request-filtering-agent
 CVE-2026-62364 (wlc is a Weblate command-line client using Weblate's REST API. Prior t ...)
 	- wlc <unfixed>
+	[trixie] - wlc <no-dsa> (Minor issue)
 	NOTE: https://github.com/WeblateOrg/wlc/security/advisories/GHSA-3mqq-hv9c-85hc
 	NOTE: https://github.com/WeblateOrg/wlc/pull/1500
 	NOTE: https://github.com/WeblateOrg/wlc/commit/055fd2d43d0f72418b459286245330f08176db62 (2.0.1)
@@ -2494,6 +2495,7 @@ CVE-2026-94107 (NivoCart through 2.4.0 contains a predictable password reset tok
 	NOT-FOR-US: NivoCart
 CVE-2026-94106 (getID3 before 1.9.26 contains an OS command injection vulnerability in ...)
 	- php-getid3 1.9.26+dfsg-1 (bug #1148666)
+	[trixie] - php-getid3 <no-dsa> (Minor issue)
 	NOTE: https://github.com/JamesHeinrich/getID3/security/advisories/GHSA-qf3m-pmjh-h6fx
 	NOTE: https://github.com/JamesHeinrich/getID3/issues/503
 	NOTE: https://github.com/JamesHeinrich/getID3/commit/ce598c4f3823441d878c5a7a2a9f2f703a3e10b6 (v1.9.26)


=====================================
data/dsa-needed.txt
=====================================
@@ -23,6 +23,8 @@ amd64-microcode (carnil)
 bouncycastle
   possibly move to 1.85 for trixie
 --
+buildstream
+--
 cacti
   probably best to move to 1.2.31
 --
@@ -80,7 +82,7 @@ kitty
 libheif (aron)
   Wait until new upstream release lands in sid
 --
-libreoffice
+libreoffice (jmm)
 --
 linux (carnil)
   Wait until more issues have piled up, though try to regulary rebase for point
@@ -105,6 +107,8 @@ network-manager-sstp
 network-manager-vpnc
   no upstream fix yet, if totally dead removal is an option
 --
+ntfs-3g
+--
 nodejs (jmm)
   Bastien Roucaries posted debdiff for review
 --
@@ -179,8 +183,7 @@ valkey (aron)
 --
 varnish
 --
-vlc
-  wait for 3.0.24
+vlc (jmm)
 --
 vim
   some of the issues seem worth fixing
@@ -199,3 +202,5 @@ xz-utils
 --
 zlib (carnil)
 --
+zookeeper
+--



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30613d2342336dd617c120db87cb07bcd46e33d0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30613d2342336dd617c120db87cb07bcd46e33d0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/c3054fbb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list