[Git][security-tracker-team/security-tracker][master] trixie triage / dovecot references

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 21:54:18 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1a95becc by Moritz Muehlenhoff at 2026-09-24T22:52:55+02:00
trixie triage / dovecot references

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -11872,6 +11872,7 @@ CVE-2026-76852 (Netcore NR268 firmware version 1.7.121109 has an improper integr
 	NOT-FOR-US: Netcore
 CVE-2026-76825 (RestrictedPython is a tool that helps define a subset of the Python la ...)
 	- restrictedpython 8.4-1
+	[trixie] - restrictedpython <no-dsa> (Minor issue)
 	NOTE: https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-hp3v-5vw7-fx9w
 	NOTE: Fixed by: https://github.com/zopefoundation/RestrictedPython/commit/3b47440070b91f8807c2b2998aca99e94783639a (8.4)
 CVE-2026-76821 (OpenCTI is an open source platform for managing cyber threat intellige ...)
@@ -33799,9 +33800,13 @@ CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to Stored
 CVE-2026-42395 (A host listed as a trusted proxy can send forwarding information conta ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42395-single-nul-byte-xclient-forward-payload-crashes
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/0a1adbe37e03e859681bab6186494600b1c708ac
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/991780f2a9d567f9c2f4b136d96b0b35e1d8e9e1
 CVE-2026-42393 (The comparison used for the doveadm password and API key is not fully  ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42393-doveadm-password-or-api-key-length-can-still-be-leaked-with-timing-comparisons
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/17212df02d002be8b310d41205b32e04da666a4b
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/647e76a865ba173f6182e211c57ec3c2942a6b04
 CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP URLFET ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42392-imap-urlauth-leaks-memory-into-user-visible-error-messages
@@ -33814,6 +33819,10 @@ CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a v
 CVE-2026-42008 (Forwarding information received from a host listed as a trusted proxy  ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42008-xclient-forward-bare-token-not-namespaced-allows-nopassword-injection-via-trusted-proxy
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/da832e63e91d640e9a4bc57189c488cd97d99477
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/bc04ca866cbdd9a3228816fbc302c2024d207995
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/335abc77650a69860ff522ba87e714173a4e6049
+	NOTE: Fixed by: https://github.com/dovecot/core/commit/7e60077cafabc3626a6bd7071b753e1c57415558
 CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script with the ...)
 	- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
 	NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42007-sieve-editheader-rce


=====================================
data/dsa-needed.txt
=====================================
@@ -79,7 +79,7 @@ jupyterlab
 --
 kitty
 --
-lemonldap-ng
+lemonldap-ng (jmm)
   Maintainer is preparing updates
 --
 libheif (aron)
@@ -124,7 +124,7 @@ pacemaker
 pdfminer (carnil)
   Required followup for CVE-2025-64512 as original fix was incomplete.
 --
-php8.4
+php8.4 (jmm)
 --
 podman
 --
@@ -177,6 +177,8 @@ sogo
 --
 squid
 --
+swift (jmm)
+--
 tomcat10
   Bastien Roucaries proposed an update for review
 --



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1a95becc54a11b25e1e6c51b1a114a259cd5ec7d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1a95becc54a11b25e1e6c51b1a114a259cd5ec7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/b6af09a7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list