[Git][security-tracker-team/security-tracker][master] trixie triage / dovecot references
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Sep 24 21:54:18 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1a95becc by Moritz Muehlenhoff at 2026-09-24T22:52:55+02:00
trixie triage / dovecot references
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -11872,6 +11872,7 @@ CVE-2026-76852 (Netcore NR268 firmware version 1.7.121109 has an improper integr
NOT-FOR-US: Netcore
CVE-2026-76825 (RestrictedPython is a tool that helps define a subset of the Python la ...)
- restrictedpython 8.4-1
+ [trixie] - restrictedpython <no-dsa> (Minor issue)
NOTE: https://github.com/zopefoundation/RestrictedPython/security/advisories/GHSA-hp3v-5vw7-fx9w
NOTE: Fixed by: https://github.com/zopefoundation/RestrictedPython/commit/3b47440070b91f8807c2b2998aca99e94783639a (8.4)
CVE-2026-76821 (OpenCTI is an open source platform for managing cyber threat intellige ...)
@@ -33799,9 +33800,13 @@ CVE-2026-4246 (The ElementsKit Pro plugin for WordPress is vulnerable to Stored
CVE-2026-42395 (A host listed as a trusted proxy can send forwarding information conta ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42395-single-nul-byte-xclient-forward-payload-crashes
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/0a1adbe37e03e859681bab6186494600b1c708ac
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/991780f2a9d567f9c2f4b136d96b0b35e1d8e9e1
CVE-2026-42393 (The comparison used for the doveadm password and API key is not fully ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42393-doveadm-password-or-api-key-length-can-still-be-leaked-with-timing-comparisons
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/17212df02d002be8b310d41205b32e04da666a4b
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/647e76a865ba173f6182e211c57ec3c2942a6b04
CVE-2026-42392 (An attacker that has valid credentials can send an invalid IMAP URLFET ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42392-imap-urlauth-leaks-memory-into-user-visible-error-messages
@@ -33814,6 +33819,10 @@ CVE-2026-42391 (An unauthenticated attacker can send an IMAP ID command with a v
CVE-2026-42008 (Forwarding information received from a host listed as a trusted proxy ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42008-xclient-forward-bare-token-not-namespaced-allows-nopassword-injection-via-trusted-proxy
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/da832e63e91d640e9a4bc57189c488cd97d99477
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/bc04ca866cbdd9a3228816fbc302c2024d207995
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/335abc77650a69860ff522ba87e714173a4e6049
+ NOTE: Fixed by: https://github.com/dovecot/core/commit/7e60077cafabc3626a6bd7071b753e1c57415558
CVE-2026-42007 (An attacker that has valid credentials can use a Sieve script with the ...)
- dovecot 1:2.4.5+dfsg1-1 (bug #1146018)
NOTE: https://documentation.open-xchange.com/dovecot/security/advisories/html/2026/oxdc-adv-2026-0003.html#cve-2026-42007-sieve-editheader-rce
=====================================
data/dsa-needed.txt
=====================================
@@ -79,7 +79,7 @@ jupyterlab
--
kitty
--
-lemonldap-ng
+lemonldap-ng (jmm)
Maintainer is preparing updates
--
libheif (aron)
@@ -124,7 +124,7 @@ pacemaker
pdfminer (carnil)
Required followup for CVE-2025-64512 as original fix was incomplete.
--
-php8.4
+php8.4 (jmm)
--
podman
--
@@ -177,6 +177,8 @@ sogo
--
squid
--
+swift (jmm)
+--
tomcat10
Bastien Roucaries proposed an update for review
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1a95becc54a11b25e1e6c51b1a114a259cd5ec7d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1a95becc54a11b25e1e6c51b1a114a259cd5ec7d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/b6af09a7/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list