[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 25 11:40:55 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
1e877666 by Moritz Muehlenhoff at 2026-09-25T12:21:00+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -100,6 +100,7 @@ CVE-2026-97224 (A vulnerability was detected in Excalidraw up to 0.18.1. The imp
 	NOT-FOR-US: Excalidraw
 CVE-2026-97185 (A flaw was found in GIMP. When processing a specially crafted GIMPress ...)
 	- gimp <unfixed>
+	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16788
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3016
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/3b5e12f8eb2734f954559fbdaf27d03765cea2e5
@@ -154,9 +155,11 @@ CVE-2026-95985 (The file write tool in Amazon Kiro IDE versions before 1.0.242 m
 	NOT-FOR-US: Amazon
 CVE-2026-95521 (A command injection flaw was found in rpm. Installing or rebuilding a  ...)
 	- rpm <unfixed>
+	[trixie] - rpm <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537812
 CVE-2026-95519 (A flaw was found in rpm. An attacker can supply a crafted manifest fil ...)
 	- rpm <unfixed>
+	[trixie] - rpm <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2470977
 CVE-2026-94613 (authentik is an open-source identity provider. Prior to 2026.2.7, 2026 ...)
 	NOT-FOR-US: authentik
@@ -174,24 +177,31 @@ CVE-2026-94416 (An authorization bypass was found in the Ansible Automation Plat
 	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-94282
 	- libxi <unfixed>
+	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-94281 (An out-of-bounds read in libXi's XListInputDevices() class parsing in  ...)
 	- libxi <unfixed>
+	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93545 (An out-of-bounds read in libXi's XListInputDevices() in libXi before 1 ...)
 	- libxi <unfixed>
+	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93544 (An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in li ...)
 	- libxi <unfixed>
+	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93543 (An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8. ...)
 	- libxi <unfixed>
+	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93542 (An out-of-bounds read in libXi's XI2 class parsing via size_classes()  ...)
 	- libxi <unfixed>
+	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93541 (An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1 ...)
 	- libxi <unfixed>
+	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93425 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
 	NOT-FOR-US: Dokploy
@@ -252,6 +262,7 @@ CVE-2026-88383 (libical 4.0.6 contains an incompatible function pointer in icalp
 	NOTE: Fixed by: https://github.com/libical/libical/commit/1fc946aaa91e5995dee593092723ba67d7113846 (4.0 branch)
 CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory a ...)
 	- hiredis <unfixed>
+	[trixie] - hiredis <no-dsa> (Minor issue)
 	NOTE: https://github.com/redis/hiredis/issues/1357
 CVE-2026-88378 (QuickJS commit 04be24600 contains a heap out-of-bounds write condition ...)
 	- quickjs-ng <unfixed>
@@ -268,6 +279,7 @@ CVE-2026-88373 (libde265 commit 4d45a6b contains a NULL pointer dereference vuln
 	NOTE: Fixed by: https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea (v1.1.2)
 CVE-2026-88372 (libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_re ...)
 	- libsndfile <unfixed>
+	[trixie] - libsndfile <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/libsndfile/libsndfile/issues/1151
 CVE-2026-88371 (ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in t ...)
 	- zbar <unfixed>
@@ -1460,9 +1472,11 @@ CVE-2026-96676 (A vulnerability was identified in Fast FAC1900R 20190827_2.0.2.
 	NOT-FOR-US: Fast FAC1900R
 CVE-2026-96675 (alsa-lib through 1.2.16.1 contains a denial of service vulnerability i ...)
 	- alsa-lib <unfixed> (bug #1148900)
+	[trixie] - alsa-lib <no-dsa> (Minor issue)
 	NOTE: https://github.com/alsa-project/alsa-lib/pull/527
 CVE-2026-96674 (alsa-lib through 1.2.16.1 computes combined topology element size usin ...)
 	- alsa-lib <unfixed> (bug #1148896)
+	[trixie] - alsa-lib <no-dsa> (Minor issue)
 	NOTE: https://github.com/alsa-project/alsa-lib/pull/527
 CVE-2026-96673 (Photoview through 2.4.0 contains an SQL injection vulnerability in the ...)
 	NOT-FOR-US: Photoview
@@ -1541,6 +1555,7 @@ CVE-2026-96513 (A security flaw has been discovered in Neethuharii CafeManagemen
 	NOT-FOR-US: Neethuharii CafeManagement
 CVE-2026-96512 (A flaw was found in sudo. When sudoers rules use NOTBEFORE or NOTAFTER ...)
 	- sudo <unfixed> (bug #1148890)
+	[trixie] - sudo <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2539327
 	NOTE: Fixed by: https://github.com/sudo-project/sudo/commit/1820a349687522f51023d1ae5925125f59679a8c
 CVE-2026-96456 (The Reachy Mini Bluetooth service asks a connecting device for a PIN b ...)
@@ -1846,9 +1861,9 @@ CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as plaintext
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
 	TODO: check
 CVE-2026-88835 (BusyBox dpkg read_package_field() steps past a NUL terminator on malfo ...)
-	- busybox <unfixed>
+	- busybox <unfixed> (unimportant)
 	NOTE: ttps://bugzilla.redhat.com/show_bug.cgi?id=2531349
-	TODO: check
+	NOTE: Crash in CLI tool, no security impact
 CVE-2026-88832 (BusyBox romfs volume ID parsing uses unbounded strlen on attacker-cont ...)
 	- busybox <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531345
@@ -2907,10 +2922,12 @@ CVE-2026-88344 (An out-of-bounds read vulnerability exists in the schema lexer o
 	NOT-FOR-US: Dvidelabs flatcc
 CVE-2026-88341 (A reachable assertion vulnerability exists in YARA 4.5.8 when loading  ...)
 	- yara <unfixed> (bug #1148825)
+	[trixie] - yara <no-dsa> (Minor issue)
 	NOTE: https://github.com/VirusTotal/yara/issues/2238
 	NOTE: Fixed by: https://github.com/NOUIY/yara/commit/0cdff36723cd260243bb2b330bda555693354760
 CVE-2026-88340 (An invalid pointer release vulnerability exists in YARA 4.5.8 during d ...)
 	- yara <unfixed> (bug #1148825)
+	[trixie] - yara <no-dsa> (Minor issue)
 	NOTE: https://github.com/VirusTotal/yara/issues/2239
 	NOTE: https://github.com/VirusTotal/yara/pull/2244
 CVE-2026-88339 (A NULL pointer dereference vulnerability exists in the gf_sg_vrml_fiel ...)
@@ -5384,6 +5401,7 @@ CVE-2026-77820 (The WPComplete plugin for WordPress is vulnerable to Stored Cros
 	NOT-FOR-US: WordPress plugin
 CVE-2026-77528 (Autobahn Python is a WebSocket and WAMP implementation for Python that ...)
 	- python-autobahn <unfixed>
+	[trixie] - python-autobahn <no-dsa> (Minor issue)
 	NOTE: https://github.com/crossbario/autobahn-python/security/advisories/GHSA-hxp9-w8x3-p566
 	NOTE: https://github.com/crossbario/autobahn-python/pull/1916
 	NOTE: Fixed by: https://github.com/crossbario/autobahn-python/commit/77d323a30b09b1828ad8be2ce6344e056970e613 (v26.7.1)
@@ -12121,6 +12139,7 @@ CVE-2026-76104 (Dell ObjectScale, versions prior to 4.4.0.0, contains an Incorre
 	NOT-FOR-US: Dell / EMC
 CVE-2026-75516 (The RabbitMQ Java client library allows Java and JVM-based application ...)
 	- rabbitmq-java-client <unfixed>
+	[trixie] - rabbitmq-java-client <no-dsa> (Minor issue)
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/security/advisories/GHSA-jh4v-gfqj-7rhx
 	NOTE: https://github.com/rabbitmq/rabbitmq-java-client/pull/2015
 	NOTE: Fixed by: https://github.com/rabbitmq/rabbitmq-java-client/commit/6d7c2bfe89796ca34d3531098fb59dd657fea39e (main)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e87766645b05ac36954c68cea5e65b7b4142a2e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/1e87766645b05ac36954c68cea5e65b7b4142a2e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/f957d989/attachment.htm>


More information about the debian-security-tracker-commits mailing list