[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 20:29:59 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5ec5ef63 by Salvatore Bonaccorso at 2026-09-25T21:29:21+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2050,7 +2050,7 @@ CVE-2026-97225 (A flaw has been found in DbGate up to 7.2.5-beta.5. This affects
 CVE-2026-97224 (A vulnerability was detected in Excalidraw up to 0.18.1. The impacted  ...)
 	NOT-FOR-US: Excalidraw
 CVE-2026-97185 (A flaw was found in GIMP. When processing a specially crafted GIMPress ...)
-	- gimp <unfixed>
+	- gimp <unfixed> (bug #1148969)
 	[trixie] - gimp <no-dsa> (Minor issue)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16788
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/merge_requests/3016
@@ -2079,13 +2079,13 @@ CVE-2026-96873 (Improper neutralization of input during web page generation ('cr
 CVE-2026-96750 (MongoDB Compass can interpolate a database name without escaping into  ...)
 	NOT-FOR-US: mongodb-js (not same as node-mongodb)
 CVE-2026-96749 (An integer overflow in the BSON document encoding component of the Mon ...)
-	- pymongo <unfixed>
+	- pymongo <unfixed> (bug #1148967)
 	NOTE: https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-v4x9-3549-crwv
 CVE-2026-96748 (PyMongo's connection string parsing decodes percent-encoded characters ...)
-	- pymongo <unfixed>
+	- pymongo <unfixed> (bug #1148967)
 	NOTE: https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-vp6j-j7w5-5xjj
 CVE-2026-96747 (The client-side field level encryption support in the MongoDB Python D ...)
-	- pymongo <unfixed>
+	- pymongo <unfixed> (bug #1148967)
 	NOTE: https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-qx36-8mw2-4r3x
 CVE-2026-96746 (An out-of-bounds write in the connection-monitoring logic of the Mongo ...)
 	- mongo-c-driver 2.5.5-1
@@ -2094,7 +2094,7 @@ CVE-2026-96746 (An out-of-bounds write in the connection-monitoring logic of the
 	NOTE: https://github.com/mongodb/mongo-c-driver/commit/52352bfdea96506fafe0f53e222a1f61eebe54f2 (2.5.5)
 	NOTE: https://github.com/mongodb/mongo-c-driver/commit/59bcc756ad8f04af74b84b88ab747adfd2647b5b (1.30.12)
 CVE-2026-96745 (Deserialization of untrusted data in the command monitoring support of ...)
-	- php-mongodb <unfixed>
+	- php-mongodb <unfixed> (bug #1148966)
 	NOTE: https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c
 	NOTE: https://jira.mongodb.org/browse/PHPC-2743
 	NOTE: https://github.com/mongodb/mongo-php-driver/pull/2115
@@ -2127,31 +2127,31 @@ CVE-2026-94604
 CVE-2026-94416 (An authorization bypass was found in the Ansible Automation Platform ( ...)
 	NOT-FOR-US: Red Hat Ansible Automation Platform
 CVE-2026-94282
-	- libxi <unfixed>
+	- libxi <unfixed> (bug #1148965)
 	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-94281 (An out-of-bounds read in libXi's XListInputDevices() class parsing in  ...)
-	- libxi <unfixed>
+	- libxi <unfixed> (bug #1148965)
 	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93545 (An out-of-bounds read in libXi's XListInputDevices() in libXi before 1 ...)
-	- libxi <unfixed>
+	- libxi <unfixed> (bug #1148965)
 	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93544 (An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in li ...)
-	- libxi <unfixed>
+	- libxi <unfixed> (bug #1148965)
 	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93543 (An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8. ...)
-	- libxi <unfixed>
+	- libxi <unfixed> (bug #1148965)
 	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93542 (An out-of-bounds read in libXi's XI2 class parsing via size_classes()  ...)
-	- libxi <unfixed>
+	- libxi <unfixed> (bug #1148965)
 	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93541 (An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1 ...)
-	- libxi <unfixed>
+	- libxi <unfixed> (bug #1148965)
 	[trixie] - libxi <no-dsa> (Minor issue)
 	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93425 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
@@ -3368,7 +3368,7 @@ CVE-2026-97168
 CVE-2026-97155 (Fabasoft Folio Client before 2026, a locally installed component that  ...)
 	NOT-FOR-US: Fabasoft Folio Client
 CVE-2026-97152 (Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely expl ...)
-	- nanomsg <unfixed>
+	- nanomsg <unfixed> (bug #1148968)
 	NOTE: https://github.com/nanomsg/nanomsg/pull/1130
 	NOTE: Fixed by: https://github.com/nanomsg/nanomsg/commit/867c475cca52df0f705420dd7751da4ce5c2adfc (1.2.3)
 	NOTE: Fixed by: https://github.com/nanomsg/nanomsg/commit/6dac4ea9bd0f8cd215925aefd7fdcc62714f67d7 (1.2.3)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ec5ef632eabb3906ec0dba0915de565ed70a50e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ec5ef632eabb3906ec0dba0915de565ed70a50e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/ab440fdd/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list