[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Sep 26 18:49:27 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
eacbc975 by Moritz Muehlenhoff at 2026-09-26T19:49:13+02:00
trixie triage
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2501,6 +2501,7 @@ CVE-2026-96747 (The client-side field level encryption support in the MongoDB Py
NOTE: https://github.com/mongodb/mongo-python-driver/security/advisories/GHSA-qx36-8mw2-4r3x
CVE-2026-96746 (An out-of-bounds write in the connection-monitoring logic of the Mongo ...)
- mongo-c-driver 2.5.5-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://github.com/mongodb/mongo-c-driver/security/advisories/GHSA-frjf-h5jg-4v46
NOTE: https://jira.mongodb.org/browse/CDRIVER-6404
NOTE: https://github.com/mongodb/mongo-c-driver/commit/52352bfdea96506fafe0f53e222a1f61eebe54f2 (2.5.5)
@@ -2684,9 +2685,10 @@ CVE-2026-88358 (simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerabil
NOTE: https://github.com/simdjson/simdjson/pull/2817
NOTE: Fixed by: https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577
CVE-2026-88357 (nDPI 5.1.0 contains a memory access issue in the DNS dissector and ser ...)
- - ndpi <unfixed> (bug #1149051)
+ - ndpi <unfixed> (unimportant; bug #1149051)
NOTE: https://github.com/ntop/nDPI/issues/3213
NOTE: https://github.com/ntop/nDPI/pull/3231
+ NOTE: Negligible security impact
CVE-2026-88355 (An incorrect buffer size calculation vulnerability exists in tinyexpr ...)
NOT-FOR-US: tinyexpr
CVE-2026-88351 (An integer overflow vulnerability exists in the MPack Node API in MPac ...)
@@ -2797,6 +2799,7 @@ CVE-2026-75907 (The door access control on a Norwegian Cruise Line asset grants
NOT-FOR-US: door access control on a Norwegian Cruise Line
CVE-2026-73064 (In Mbed TLS 3.2.0 though 3.6.6 and 4.0.0 through 4.1.0, an attacker wh ...)
- mbedtls 3.6.7-1
+ [trixie] - mbedtls <no-dsa> (Minor issue)
NOTE: https://mbed-tls.readthedocs.io/en/latest/security-advisories/mbedtls-security-advisory-2026-07-random-generator-fault-tls-integrity/
CVE-2026-71540 (Wazuh is an open-source security platform providing unified XDR and SI ...)
NOT-FOR-US: Wazuh
@@ -3801,6 +3804,7 @@ CVE-2026-97155 (Fabasoft Folio Client before 2026, a locally installed component
NOT-FOR-US: Fabasoft Folio Client
CVE-2026-97152 (Nanomsg versions 0.5-beta through 1.x before 1.2.3 has a remotely expl ...)
- nanomsg <unfixed> (bug #1148968)
+ [trixie] - nanomsg <no-dsa> (Minor issue)
NOTE: https://github.com/nanomsg/nanomsg/pull/1130
NOTE: Fixed by: https://github.com/nanomsg/nanomsg/commit/867c475cca52df0f705420dd7751da4ce5c2adfc (1.2.3)
NOTE: Fixed by: https://github.com/nanomsg/nanomsg/commit/6dac4ea9bd0f8cd215925aefd7fdcc62714f67d7 (1.2.3)
@@ -8968,11 +8972,13 @@ CVE-2026-93426 (SigNoz versions 0.87.0 before 0.142.0 fail to escape user-suppli
NOT-FOR-US: SigNoz
CVE-2026-93395 (A missing lower-bound validation in the bson_new_from_buffer() functio ...)
- mongo-c-driver 2.4.0-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6343
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/c9cfa4cb3b7e7af27a96c25c86ac39f86a16b90c (2.4.0)
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/cb88248de50c0bca20a4a7bbb91108afe2dbc988 (1.30.11)
CVE-2026-93394 (A flaw in libmongoc's SCRAM authentication implementation caused the c ...)
- mongo-c-driver 2.4.0-1
+ [trixie] - mongo-c-driver <no-dsa> (Minor issue)
NOTE: https://jira.mongodb.org/browse/CDRIVER-6315
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/6b27da3e0384170ac0efc75321556bd37a2ae03f (2.4.0)
NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/0b9bbbff0b949dcddb97e518e7fdb5950e187be3 (1.30.11)
@@ -58068,6 +58074,7 @@ CVE-2026-73570 (A remote code execution vulnerability exists in Zimbra Collabora
NOT-FOR-US: Zimbra
CVE-2026-73569 (fast-xml-parser allows users to process XML from JS object without C/C ...)
- node-webfont <unfixed> (bug #1147730)
+ [trixie] - node-webfont <no-dsa> (Minor issue)
NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/security/advisories/GHSA-8r6m-32jq-jx6q
NOTE: https://github.com/NaturalIntelligence/fast-xml-parser/commit/4e546e03987662de5495d050b5fba26bea65383f (v5.10.1)
NOTE: node-webfont provides node-fast-xml-parser
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eacbc975566368c2ba104e5f677eb3b59d82a397
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eacbc975566368c2ba104e5f677eb3b59d82a397
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/a7763669/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list