[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 24 08:47:43 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
40087809 by Salvatore Bonaccorso at 2026-09-24T09:43:10+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -11,7 +11,7 @@ CVE-2026-97152 (Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotel
CVE-2026-97151 (mammoth (aka mammoth.js) before 1.12.2 is vulnerable to prototype poll ...)
TODO: check
CVE-2026-97149 (In OpenStack Swift before 2.38.2, the tempurl middleware does not reje ...)
- - swift <unfixed>
+ - swift <unfixed> (bug #1148834)
NOTE: https://launchpad.net/bugs/2166876
NOTE: https://security.openstack.org/ossa/OSSA-2026-041.html
CVE-2026-97056 (SigNoz versions from v0.98.0 up to (but not including) v0.143.0, when ...)
@@ -873,7 +873,7 @@ CVE-2026-11744 (An input validation vulnerability exists in the PaperCut Hive em
CVE-2025-63564 (SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through ...)
TODO: check
CVE-2026-87022 (Improper handling of length parameter inconsistency vulnerability in A ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -881,7 +881,7 @@ CVE-2026-87022 (Improper handling of length parameter inconsistency vulnerabilit
NOTE: https://github.com/apache/tomcat/commit/567a85515b78d1cd6410a89844b88109fcc2306f (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/959a52a227cc35101b92dae35b722546167594d6 (9.0.122)
CVE-2026-86350 (Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Response ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -889,7 +889,7 @@ CVE-2026-86350 (Inconsistent interpretation of HTTP/2 requests ('HTTP Request/Re
NOTE: https://github.com/apache/tomcat/commit/259e938d3dedf07f3b24189fd5032adb95b01f2a (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/5adadc4ef413d5050f664d40800bbff74bd5d5ed (9.0.122)
CVE-2026-86248 (CLIENT_CERT authentication does not fail as expected for some scenario ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -897,7 +897,7 @@ CVE-2026-86248 (CLIENT_CERT authentication does not fail as expected for some sc
NOTE: https://github.com/apache/tomcat/commit/e5191b1e3292681097503f093b5432451ff5aa83 (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/fc41d82e0e383e4d6e88ad321d245dafdc17d26d (9.0.122)
CVE-2026-79677 (Missing release of resource after effective lifetime, Comparison using ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -905,7 +905,7 @@ CVE-2026-79677 (Missing release of resource after effective lifetime, Comparison
NOTE: https://github.com/apache/tomcat/commit/bb676e53cd0bdcbecfe9650841e99973a7693f7e (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/c8fa5430233bca5b209c593dd446f88fda9d543e (9.0.122)
CVE-2026-78437 (Incomplete cleanup vulnerability in Apache Tomcat allows a malformed r ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -913,7 +913,7 @@ CVE-2026-78437 (Incomplete cleanup vulnerability in Apache Tomcat allows a malfo
NOTE: https://github.com/apache/tomcat/commit/4ac5da0906c500f6042844d7f17e9fb174820758 (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/a28c35055ab11d35929ad564beb1a23a67b39546 (9.0.122)
CVE-2026-78383 (Allocation of resources without limits or throttling vulnerability in ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -921,7 +921,7 @@ CVE-2026-78383 (Allocation of resources without limits or throttling vulnerabili
NOTE: https://github.com/apache/tomcat/commit/2ed6d18ebfe4b085ef050dd0a0f4f20aff3bc48d (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/265bdc0a58b1447ff5d8f8b96ea81de58cb74c8c (9.0.122)
CVE-2026-77791 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat durin ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -929,7 +929,7 @@ CVE-2026-77791 (Uncontrolled Resource Consumption vulnerability in Apache Tomcat
NOTE: https://github.com/apache/tomcat/commit/e896f73c868f66dfb2a93565fda4d13cd5909d2d (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/7a5945f1de1d3310214234dfbbd7c569af52d058 (9.0.122)
CVE-2026-77762 (Concurrent Execution using Shared Resource with Improper Synchronizati ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -937,7 +937,7 @@ CVE-2026-77762 (Concurrent Execution using Shared Resource with Improper Synchro
NOTE: https://github.com/apache/tomcat/commit/77d2d59347891eced52b0cb5a979fc33a8a2620c (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/71f27c2e84810930beda468b5ba732dcd0ef2652 (9.0.122)
CVE-2026-77756 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response S ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -945,7 +945,7 @@ CVE-2026-77756 (Inconsistent Interpretation of HTTP Requests ('HTTP Request/Resp
NOTE: https://github.com/apache/tomcat/commit/bf44bee23d97fbb1a64cbbbb213ff2b6506d26c4 (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/e590588ab7649c93d49b0eb7b3152700a977880d (9.0.122)
CVE-2026-76183 (Authentication Bypass by Alternate Name vulnerability in Apache Tomcat ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -953,7 +953,7 @@ CVE-2026-76183 (Authentication Bypass by Alternate Name vulnerability in Apache
NOTE: https://github.com/apache/tomcat/commit/5b48790abd13d94c2bd351027a39a671916b5ddf (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/a93a60a33f4cc202542eb6a0b87b7142d7db311c (9.0.122)
CVE-2026-75973 (Improper Authentication vulnerability in Apache Tomcat. When Jakarta A ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -961,7 +961,7 @@ CVE-2026-75973 (Improper Authentication vulnerability in Apache Tomcat. When Jak
NOTE: https://github.com/apache/tomcat/commit/f62c65768fdaa300e22e64ffa7b5118dce0571a1 (10.1.60)
NOTE: https://github.com/apache/tomcat/commit/043115414a39127cad015e9d285296e59c18bb41 (9.0.122)
CVE-2026-73581 (Improper Check for Certificate Revocation vulnerability in Apache Tomc ...)
- - tomcat11 <unfixed>
+ - tomcat11 <unfixed> (bug #1148824)
- tomcat10 10.1.60-1
- tomcat9 9.0.70-2
NOTE: Starting with 9.0.70-2 src:tomcat9 no longer ships the server stack, using that as the fixed version
@@ -1017,7 +1017,7 @@ CVE-2026-94422
- xdg-dbus-proxy 0.1.9-1 (bug #1148782)
NOTE: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-2cgv-pwcq-wvpq
CVE-2026-92709
- - rsyslog <unfixed>
+ - rsyslog <unfixed> (bug #1148832)
NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-xmp9-244p-5ggv
CVE-2026-93403 [Stack-based Buffer Overflow in mmpstrucdata rsyslog plugin]
- rsyslog 8.2606.0-4
@@ -1027,7 +1027,7 @@ CVE-2026-93403 [Stack-based Buffer Overflow in mmpstrucdata rsyslog plugin]
NOTE: https://github.com/rsyslog/rsyslog/pull/6991
NOTE: Fixed by: https://github.com/rsyslog/rsyslog/commit/bcda60a3692efdf0c8e44102528f5a0ebe0dec6d (v8.2606.0)
CVE-2026-93402 [mdtls discards the peer-identity verification result]
- - rsyslog <unfixed>
+ - rsyslog <unfixed> (bug #1148833)
NOTE: https://github.com/rsyslog/rsyslog/security/advisories/GHSA-8v8w-f8wf-475j
NOTE: https://github.com/rsyslog/rsyslog/pull/7617
NOTE: Fixed by: https://github.com/rsyslog/rsyslog/commit/ef9f77d709640ceb3d5e78118081a291f9e373c5
@@ -1381,12 +1381,12 @@ CVE-2026-92929 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 tru
CVE-2026-92928 (OpenEye Apex Network Video Recorder (NVR) firmware 3.2.9.376 contains ...)
NOT-FOR-US: OpenEye Apex Network Video Recorder (NVR) firmware
CVE-2026-91777 (Forward-reference completion for @JsonIdentityInfo object IDs in Faste ...)
- - jackson-databind <unfixed>
+ - jackson-databind <unfixed> (bug #1148830)
NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-cxp5-3px4-pw24
NOTE: https://github.com/FasterXML/jackson-databind/pull/6204
NOTE: Fixed by: https://github.com/FasterXML/jackson-databind/commit/37ad9b81712cbb9fb62c2d2c1813593252a24b67 (jackson-databind-3.2.3, jackson-databind-3.1.7, jackson-databind-2.22.3, jackson-databind-2.21.7, jackson-databind-2.18.11)
CVE-2026-91776 (TypeDeserializerBase._findDeserializer() in FasterXML jackson-databind ...)
- - jackson-databind <unfixed>
+ - jackson-databind <unfixed> (bug #1148830)
NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wv8q-qhhj-9h54
NOTE: https://github.com/FasterXML/jackson-databind/pull/6203
NOTE: Fixed by: https://github.com/FasterXML/jackson-databind/commit/2870d1d6dc1b7e1c07ee11dd5b04ab71cddbb577 (jackson-databind-3.2.3, jackson-databind-3.1.7, jackson-databind-2.22.3, jackson-databind-2.21.7, jackson-databind-2.18.11)
@@ -1406,7 +1406,7 @@ CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 6.
CVE-2026-90951 (The Paid Membership Subscriptions WordPress plugin before 3.1.0 does ...)
NOT-FOR-US: WordPress plugin
CVE-2026-89425 (UTF8DataInputJsonParser._reportInvalidToken() in FasterXML jackson-cor ...)
- - jackson-core <unfixed>
+ - jackson-core <unfixed> (bug #1148826)
NOTE: https://github.com/FasterXML/jackson-core/security/advisories/GHSA-7hhh-6rmp-j9qf
NOTE: https://github.com/FasterXML/jackson-core/pull/1698
NOTE: Fixed by: https://github.com/FasterXML/jackson-core/commit/211cf2c5d91abbec38067f37efc1363cd4e88ee3 (jackson-core-3.2.3, jackson-core-3.1.7, jackson-core-2.22.3, jackson-core-2.21.7, jackson-core-2.18.11)
@@ -1439,11 +1439,11 @@ CVE-2026-88345 (An out-of-bounds read vulnerability exists in the schema lexer o
CVE-2026-88344 (An out-of-bounds read vulnerability exists in the schema lexer of flat ...)
NOT-FOR-US: Dvidelabs flatcc
CVE-2026-88341 (A reachable assertion vulnerability exists in YARA 4.5.8 when loading ...)
- - yara <unfixed>
+ - yara <unfixed> (bug #1148825)
NOTE: https://github.com/VirusTotal/yara/issues/2238
NOTE: Fixed by: https://github.com/NOUIY/yara/commit/0cdff36723cd260243bb2b330bda555693354760
CVE-2026-88340 (An invalid pointer release vulnerability exists in YARA 4.5.8 during d ...)
- - yara <unfixed>
+ - yara <unfixed> (bug #1148825)
NOTE: https://github.com/VirusTotal/yara/issues/2239
NOTE: https://github.com/VirusTotal/yara/pull/2244
CVE-2026-88339 (A NULL pointer dereference vulnerability exists in the gf_sg_vrml_fiel ...)
@@ -1988,13 +1988,13 @@ CVE-2026-95619 (A flaw was found in libstdc++. An integer overflow can occur whe
CVE-2026-95511
REJECTED
CVE-2026-95508 (A heap-based buffer overflow was found in the DHCPv6 and TFTP response ...)
- - libslirp <unfixed>
+ - libslirp <unfixed> (bug #1148836)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537748
NOTE: Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/97f2dd0afea0db8b31135f768ecafe0775722a25 (v4.9.5)
NOTE: Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/5815f119c334c26e6e7a14ac87eca12b69918627 (v4.9.5)
TODO: check if fixes complete, the TFTP part is missing yet in v4.9.5?
CVE-2026-95507
- - libslirp <unfixed>
+ - libslirp <unfixed> (bug #1148835)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537747
NOTE: Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/b4b2b07812fcadd2754281e5ae8d9fe2bfb3c96a (v4.9.5)
CVE-2026-95503 (A flaw was found in the Kerberos federation provider of Keycloak, an o ...)
@@ -2072,7 +2072,7 @@ CVE-2026-90990 (Improper neutralization of newlines in filter values in the moni
CVE-2026-90882 (The open-vsx.org deployment returned Access-Control-Allow-Origin refle ...)
NOT-FOR-US: open-vsx.org
CVE-2026-90462 (A flaw was found in SSSD. When configured with the LDAP access provide ...)
- - sssd <unfixed>
+ - sssd <unfixed> (bug #1148827)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2479483
CVE-2026-8849 (Use After Free vulnerability in RTI Connext Professional (Security Plu ...)
NOT-FOR-US: RTI Connext
@@ -3348,7 +3348,7 @@ CVE-2026-90839
CVE-2026-82187 (The Web to Print Online Designer WordPress plugin before 2.15.0 does n ...)
NOT-FOR-US: WordPress plugin
CVE-2026-92382 (An out-of-bounds write flaw was found in usbredir. Starting an isochro ...)
- - usbredir <unfixed>
+ - usbredir <unfixed> (bug #1148831)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2535972
TODO: check details once Red Hat opens up bugzilla entry
CVE-2026-94113 (Frappe ERPNext versions before 15.121.0 and 16.x before 16.34.0 contai ...)
@@ -15940,10 +15940,10 @@ CVE-2026-90533 (Flowise before 3.1.4 contains a broken access control vulnerabil
CVE-2026-90474 (MCPHub before 1.0.32 contains an authentication bypass vulnerability i ...)
NOT-FOR-US: MCPHub
CVE-2026-90473 (msgpack-java through 0.9.12 contains an integer overflow vulnerability ...)
- - msgpack-java <unfixed>
+ - msgpack-java <unfixed> (bug #1148829)
NOTE: https://github.com/msgpack/msgpack-java/issues/1014
CVE-2026-90472 (msgpack-java through 0.9.12 contains a stack overflow vulnerability in ...)
- - msgpack-java <unfixed>
+ - msgpack-java <unfixed> (bug #1148828)
NOTE: https://github.com/msgpack/msgpack-java/issues/1015
CVE-2026-89172 (Improper protection of physical side channels vulnerability in Microch ...)
NOT-FOR-US: Microchip
@@ -30425,7 +30425,7 @@ CVE-2026-19796 (The Listdom: AI-powered Business Directory with Classifieds Ads
CVE-2026-19573 (The Affiliate Super Assistent plugin for WordPress is vulnerable to St ...)
NOT-FOR-US: WordPress plugin
CVE-2026-19032 (jackson-databind's deserializer for java.nio.file.Path resolves an att ...)
- - jackson-databind <unfixed>
+ - jackson-databind <unfixed> (bug #1148830)
NOTE: https://github.com/FasterXML/jackson-databind/security/advisories/GHSA-wjgm-6hv5-3cvf
NOTE: https://github.com/FasterXML/jackson-databind/pull/6129
NOTE: https://github.com/FasterXML/jackson-databind/commit/cc6756b61ed90b6b9227f670e0408d5d9bd48551 (jackson-databind-3.2.2, jackson-databind-3.1.6, jackson-databind-2.22.2, jackson-databind-2.21.6, jackson-databind-2.18.10)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/40087809c7516a4d468718f3ed19ddf9f8d55589
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/40087809c7516a4d468718f3ed19ddf9f8d55589
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/9e0346f5/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list