[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Fri Sep 25 13:01:42 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4e25df9c by Moritz Muehlenhoff at 2026-09-25T14:01:12+02:00
trixie triage

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -275,6 +275,7 @@ CVE-2026-88376 (Bento4 1.6.0.0 contains an integer underflow vulnerability in AP
 	NOT-FOR-US: Bento4
 CVE-2026-88373 (libde265 commit 4d45a6b contains a NULL pointer dereference vulnerabil ...)
 	- libde265 1.1.2-1
+	[trixie] - libde265 <no-dsa> (Minor issue)
 	NOTE: https://github.com/strukturag/libde265/issues/534
 	NOTE: Fixed by: https://github.com/strukturag/libde265/commit/f8d324914e43d92af23614f22959cf9eee7bf9ea (v1.1.2)
 CVE-2026-88372 (libsndfile 1.2.2 contains an integer overflow vulnerability in mat4_re ...)
@@ -298,6 +299,7 @@ CVE-2026-88365 (minimp3 commit ea99364f contains an integer overflow vulnerabili
 	NOT-FOR-US: minimp3
 CVE-2026-88362 (MuJS e892c9fdb contains an incorrect numeric conversion vulnerability  ...)
 	- mujs <unfixed>
+	[trixie] - mujs <no-dsa> (Minor issue)
 	NOTE: https://bugs.ghostscript.com/show_bug.cgi?id=709636
 	NOTE: Fixed by: https://cgit.ghostscript.com/cgi-bin/cgit.cgi/mujs.git/commit/?id=8a32c397b28fe45747ac4e9e4f3dca049825eda7
 CVE-2026-88361 (SumatraPDF 3.6.1 contains an integer overflow vulnerability in EngineM ...)
@@ -1854,12 +1856,14 @@ CVE-2026-88843 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.
 	NOT-FOR-US: WordPress plugin
 CVE-2026-88840 (BusyBox TLS get_client_hello() reads past the end of the input buffer  ...)
 	- busybox <unfixed>
+	[trixie] - busybox <not-affected> (Vulnerable code not present)
+	[bookworm] - busybox <not-affected> (Vulnerable code not present)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531354
-	TODO: check
+	NOTE: Introduced by: 657fbcd62c6cb1e15692ad471bc94cfe6efd8a5f (1_38_0)
 CVE-2026-88839 (BusyBox passwd/group tokenize() references a stale endpoint pointer af ...)
 	- busybox <unfixed>
+	[trixie] - busybox <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531353
-	TODO: check
 CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as plaintext durin ...)
 	- busybox <unfixed>
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
@@ -6147,6 +6151,7 @@ CVE-2026-63199 (Perses is an open-source dashboard and visualization project for
 	NOT-FOR-US: Perses
 CVE-2026-62943 (btrbk is a tool for creating snapshots and remote backups of Btrfs sub ...)
 	- btrbk <unfixed> (bug #1148559)
+	[trixie] - btrbk <no-dsa> (Minor issue)
 	NOTE: https://github.com/digint/btrbk/security/advisories/GHSA-pf45-7g54-65h5
 	NOTE: Introduced with: https://github.com/digint/btrbk/commit/8d0d7edda7cc775b87fd450266b756885f1eaa80 (v0.29.0)
 	NOTE: Fixed by: https://github.com/digint/btrbk/commit/29ca3c093205395bdeb9dd98677ab4139c458aec (v0.32.7)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e25df9c0e39ba0d2bff4e484daed0d1b4ec1db2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4e25df9c0e39ba0d2bff4e484daed0d1b4ec1db2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/281ac996/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list