[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Sep 24 20:04:52 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
de8a6391 by Salvatore Bonaccorso at 2026-09-24T21:04:29+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -878,10 +878,10 @@ CVE-2026-96678 (A security vulnerability has been detected in weiqingwen spring-
CVE-2026-96676 (A vulnerability was identified in Fast FAC1900R 20190827_2.0.2. The im ...)
NOT-FOR-US: Fast FAC1900R
CVE-2026-96675 (alsa-lib through 1.2.16.1 contains a denial of service vulnerability i ...)
- - alsa-lib <unfixed>
+ - alsa-lib <unfixed> (bug #1148900)
NOTE: https://github.com/alsa-project/alsa-lib/pull/527
CVE-2026-96674 (alsa-lib through 1.2.16.1 computes combined topology element size usin ...)
- - alsa-lib <unfixed>
+ - alsa-lib <unfixed> (bug #1148896)
NOTE: https://github.com/alsa-project/alsa-lib/pull/527
CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection vulnerability in the ...)
NOT-FOR-US: Photoview
@@ -936,18 +936,18 @@ CVE-2026-96549 (A vulnerability has been found in sfturing hosp_order up to 627f
CVE-2026-96548 (A flaw has been found in sfturing hosp_order up to 627f426331da8086ce8 ...)
NOT-FOR-US: sfturing hosp_order
CVE-2026-96546 (A one-byte out-of-bounds heap read flaw was found in GIMP's uncompress ...)
- - gimp <unfixed> (unimportant)
+ - gimp <unfixed> (unimportant; bug #1148892)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16802
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/108c72aab28fe069129ad0e545d6b97de5c0ce2f
NOTE: Crash in GUI tool, no security impact
CVE-2026-96545 (An out-of-bounds heap read flaw was found in GIMP's TIM image loader. ...)
- - gimp <unfixed>
+ - gimp <unfixed> (bug #1148895)
[trixie] - gimp <not-affected> (Vulnerable code not present)
[bookworm] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16791
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/8d6825ba0074a40834d23c2ddecd1f50276fde52 (gimp-3-2 branch)
CVE-2026-96541 (A denial-of-service flaw was found in gnome-remote-desktop. An unauthe ...)
- - gnome-remote-desktop <unfixed>
+ - gnome-remote-desktop <unfixed> (bug #1148894)
[trixie] - gnome-remote-desktop <not-affected> (Incomplete fix for CVE-2025-5024 not applied)
[bookworm] - gnome-remote-desktop <not-affected> (Incomplete fix for CVE-2025-5024 not applied)
NOTE: https://gitlab.gnome.org/GNOME/gnome-remote-desktop/-/issues/356
@@ -958,7 +958,7 @@ CVE-2026-96514 (A weakness has been identified in Neethuharii CafeManagement. Im
CVE-2026-96513 (A security flaw has been discovered in Neethuharii CafeManagement. Thi ...)
NOT-FOR-US: Neethuharii CafeManagement
CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER ...)
- - sudo <unfixed>
+ - sudo <unfixed> (bug #1148890)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539327
NOTE: Fixed by: https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c
CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for a PIN b ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de8a63919e681ed33ccefc1d0d42d1bece54d6bc
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/de8a63919e681ed33ccefc1d0d42d1bece54d6bc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/69d62925/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list