[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 25 11:40:55 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
1e877666 by Moritz Muehlenhoff at 2026-09-25T12:21:00+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -100,6 +100,7 @@ CVE-2026-97224 (A vulnerability was detected in Excalidraw up to 0.18.1. The imp
NOT-FOR-US: Excalidraw
CVE-2026-97185 (A flaw was found in GIMP. When processing a specially crafted GIMPress ...)
- gimp <unfixed>
+ [trixie] - gimp <no-dsa> (Minor issue)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16788
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3016
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/3b5e12f8eb2734f954559fbdaf27d03765cea2e5
@@ -154,9 +155,11 @@ CVE-2026-95985 (The file write tool in Amazon Kiro IDE versions before 1.0.242 m
NOT-FOR-US: Amazon
CVE-2026-95521 (A command injection flaw was found in rpm. Installing or rebuilding a ...)
- rpm <unfixed>
+ [trixie] - rpm <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537812
CVE-2026-95519 (A flaw was found in rpm. An attacker can supply a crafted manifest fil ...)
- rpm <unfixed>
+ [trixie] - rpm <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470977
CVE-2026-94613 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
NOT-FOR-US: authentik
@@ -174,24 +177,31 @@ CVE-2026-94416 (An authorization bypass was found in the Ansible Automation Plat
NOT-FOR-US: Red Hat Ansible Automation Platform
CVE-2026-94282
- libxi <unfixed>
+ [trixie] - libxi <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
CVE-2026-94281 (An out-of-bounds read in libXi's XListInputDevices() class parsing in ...)
- libxi <unfixed>
+ [trixie] - libxi <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
CVE-2026-93545 (An out-of-bounds read in libXi's XListInputDevices() in libXi before 1 ...)
- libxi <unfixed>
+ [trixie] - libxi <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
CVE-2026-93544 (An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in li ...)
- libxi <unfixed>
+ [trixie] - libxi <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
CVE-2026-93543 (An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8. ...)
- libxi <unfixed>
+ [trixie] - libxi <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
CVE-2026-93542 (An out-of-bounds read in libXi's XI2 class parsing via size_classes() ...)
- libxi <unfixed>
+ [trixie] - libxi <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
CVE-2026-93541 (An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1 ...)
- libxi <unfixed>
+ [trixie] - libxi <no-dsa> (Minor issue)
NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
CVE-2026-93425 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
NOT-FOR-US: Dokploy
@@ -252,6 +262,7 @@ CVE-2026-88383 (libical 4.0.6 contains an incompatible function pointer in icalp
NOTE: Fixed by: https://github.com/libical/libical/commit/1fc946aaa91e5995dee593092723ba67d7113846 (4.0 branch)
CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory a ...)
- hiredis <unfixed>
+ [trixie] - hiredis <no-dsa> (Minor issue)
NOTE: https://github.com/redis/hiredis/issues/1357
CVE-2026-88378 (QuickJS commit 04be24600 contains a heap out-of-bounds write condition ...)
- quickjs-ng <unfixed>
@@ -268,6 +279,7 @@ CVE-2026-88373 (libde265 commit 4d45a6b contains a NULL pointer dereference vuln
NOTE: Fixed by: https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea (v1.1.2)
CVE-2026-88372 (libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_re ...)
- libsndfile <unfixed>
+ [trixie] - libsndfile <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/libsndfile/libsndfile/issues/1151
CVE-2026-88371 (ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in t ...)
- zbar <unfixed>
@@ -1460,9 +1472,11 @@ CVE-2026-96676 (A vulnerability was identified in Fast FAC1900R 20190827_2.0.2.
NOT-FOR-US: Fast FAC1900R
CVE-2026-96675 (alsa-lib through 1.2.16.1 contains a denial of service vulnerability i ...)
- alsa-lib <unfixed> (bug #1148900)
+ [trixie] - alsa-lib <no-dsa> (Minor issue)
NOTE: https://github.com/alsa-project/alsa-lib/pull/527
CVE-2026-96674 (alsa-lib through 1.2.16.1 computes combined topology element size usin ...)
- alsa-lib <unfixed> (bug #1148896)
+ [trixie] - alsa-lib <no-dsa> (Minor issue)
NOTE: https://github.com/alsa-project/alsa-lib/pull/527
CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection vulnerability in the ...)
NOT-FOR-US: Photoview
@@ -1541,6 +1555,7 @@ CVE-2026-96513 (A security flaw has been discovered in Neethuharii CafeManagemen
NOT-FOR-US: Neethuharii CafeManagement
CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER ...)
- sudo <unfixed> (bug #1148890)
+ [trixie] - sudo <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539327
NOTE: Fixed by: https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c
CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for a PIN b ...)
@@ -1846,9 +1861,9 @@ CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as plaintext
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
TODO: check
CVE-2026-88835 (BusyBox dpkg read_package_field() steps past a NUL terminator on malfo ...)
- - busybox <unfixed>
+ - busybox <unfixed> (unimportant)
NOTE: ttps://bugzilla.redhat.com/show_bug.cgi?id=2531349
- TODO: check
+ NOTE: Crash in CLI tool, no security impact
CVE-2026-88832 (BusyBox romfs volume ID parsing uses unbounded strlen on attacker-cont ...)
- busybox <unfixed>
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531345
@@ -2907,10 +2922,12 @@ CVE-2026-88344 (An out-of-bounds read vulnerability exists in the schema lexer o
NOT-FOR-US: Dvidelabs flatcc
CVE-2026-88341 (A reachable assertion vulnerability exists in YARA 4.5.8 when loading ...)
- yara <unfixed> (bug #1148825)
+ [trixie] - yara <no-dsa> (Minor issue)
NOTE: https://github.com/VirusTotal/yara/issues/2238
NOTE: Fixed by: https://github.com/NOUIY/yara/commit/0cdff36723cd260243bb2b330bda555693354760
CVE-2026-88340 (An invalid pointer release vulnerability exists in YARA 4.5.8 during d ...)
- yara <unfixed> (bug #1148825)
+ [trixie] - yara <no-dsa> (Minor issue)
NOTE: https://github.com/VirusTotal/yara/issues/2239
NOTE: https://github.com/VirusTotal/yara/pull/2244
CVE-2026-88339 (A NULL pointer dereference vulnerability exists in the gf_sg_vrml_fiel ...)
@@ -5384,6 +5401,7 @@ CVE-2026-77820 (The WPComplete plugin for WordPress is vulnerable to Stored Cros
NOT-FOR-US: WordPress plugin
CVE-2026-77528 (Autobahn Python is a WebSocket and WAMP implementation for Python that ...)
- python-autobahn <unfixed>
+ [trixie] - python-autobahn <no-dsa> (Minor issue)
NOTE: https://github.com/crossbario/autobahn-python/security/advisories/GHSA-hxp9-w8x3-p566
NOTE: https://github.com/crossbario/autobahn-python/pull/1916
NOTE: Fixed by: https://github.com/crossbario/autobahn-python/commit/77d323a30b09b1828ad8be2ce6344e056970e613 (v26.7.1)
@@ -12121,6 +12139,7 @@ CVE-2026-76104 (Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorre
NOT-FOR-US: Dell / EMC
CVE-2026-75516 (The RabbitMQ Java client library allows Java and JVM-based application ...)
- rabbitmq-java-client <unfixed>
+ [trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-jh4v-gfqj-7rhx
NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2015
NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/6d7c2bfe89796ca34d3531098fb59dd657fea39e (main)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e87766645b05ac36954c68cea5e65b7b4142a2e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e87766645b05ac36954c68cea5e65b7b4142a2e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/f957d989/attachment.htm>
More information about the debian-security-tracker-commits
mailing list