[Git][security-tracker-team/security-tracker][master] trixie triage
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Sat Sep 26 22:09:01 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
03b5fd0d by Moritz Muehlenhoff at 2026-09-26T23:03:03+02:00
trixie triage
- - - - -
2 changed files:
- data/CVE/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -756,9 +756,10 @@ CVE-2026-97324 (A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue
CVE-2026-97228 (Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a Grap ...)
NOT-FOR-US: Rapid7 Bulk Export MCP
CVE-2026-97222 (A heap use-after-free flaw was found in Gnumeric. When a user opens a ...)
- - gnumeric <unfixed>
+ - gnumeric <unfixed> (unimportant)
NOTE: https://gitlab.gnome.org/GNOME/gnumeric/-/issues/897
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gnumeric/-/commit/bc1dee29525933994181fb2307d6ad584de6040d
+ NOTE: Crash in GUI tool, no security impact
CVE-2026-97064 (X-SpringBoot through 6.0 ships with a hardcoded static master login ve ...)
NOT-FOR-US: X-SpringBoot
CVE-2026-97063 (X-SpringBoot through 6.0 returns login verification codes in HTTP resp ...)
@@ -901,6 +902,7 @@ CVE-2026-88387 (LibRaw 0.22.0 contains an incorrect numeric conversion vulnerabi
NOTE: Fixed by: https://github.com/LibRaw/LibRaw/commit/b41cbbd61951783e0440590dae55411a16185bdf (master)
CVE-2026-88386 (libsndfile 1.2.2 contains a misaligned memory access issue in psf_binh ...)
- libsndfile <unfixed> (bug #1149062)
+ [trixie] - libsndfile <no-dsa> (Minor issue)
NOTE: https://github.com/libsndfile/libsndfile/issues/1150
NOTE: Fixed by: https://github.com/libsndfile/libsndfile/commit/474e4d328b1e6240b93ec6ed14efb7c6a44bee57
CVE-2026-87722 (Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search ...)
@@ -2807,6 +2809,7 @@ CVE-2026-97061 (Black Candy through 3.2.1 fails to scope playlist search queries
NOT-FOR-US: Black Candy
CVE-2026-97059 (DCMTK through 3.7.0 contains a heap over-read vulnerability in Concate ...)
- dcmtk <unfixed>
+ [trixie] - dcmtk <no-dsa> (Minor issue)
NOTE: https://support.dcmtk.org/redmine/issues/1281
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/18379d5b8d234977cc30644e9e70d76d89c87285
NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/c33790827a192a598d20463af701a8b819f46ec1
@@ -2836,6 +2839,7 @@ CVE-2026-96746 (An out-of-bounds write in the connection-monitoring logic of the
NOTE: https://github.com/mongodb/mongo-c-driver/commit/59bcc756ad8f04af74b84b88ab747adfd2647b5b (1.30.12)
CVE-2026-96745 (Deserialization of untrusted data in the command monitoring support of ...)
- php-mongodb <unfixed> (bug #1148966)
+ [trixie] - php-mongodb <no-dsa> (Minor issue)
NOTE: https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c
NOTE: https://jira.mongodb.org/browse/PHPC-2743
NOTE: https://github.com/mongodb/mongo-php-driver/pull/2115
@@ -2939,6 +2943,7 @@ CVE-2026-88390 (An out-of-bounds write vulnerability in jslGetTokenValueAsString
NOT-FOR-US: Espruino
CVE-2026-88385 (Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data( ...)
- mxml 4.0.6-2
+ [trixie] - mxml <no-dsa> (Minor issue)
NOTE: https://github.com/michaelrsweet/mxml/issues/356
NOTE: Fixed by: https://github.com/michaelrsweet/mxml/commit/83ef80ae3c5413b73f501edb59ee74e31ce399d0 (v4.0.6)
CVE-2026-88384 (OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribut ...)
@@ -2947,11 +2952,12 @@ CVE-2026-88384 (OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ at
NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2615
NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/e782bcc1ffe1cc9edfaa5dbad4f28e866eaf9bbb (v3.5.0-rc)
CVE-2026-88383 (libical 4.0.6 contains an incompatible function pointer in icalparamet ...)
- - libical3 <unfixed> (bug #1149060)
+ - libical3 <unfixed> (bug #1149060; unimportant)
- libical <removed>
NOTE: https://github.com/libical/libical/issues/1361
NOTE: https://github.com/libical/libical/pull/1363
NOTE: Fixed by: https://github.com/libical/libical/commit/1fc946aaa91e5995dee593092723ba67d7113846 (4.0 branch)
+ NOTE: Negligible security impact
CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory a ...)
- hiredis <unfixed> (bug #1149059)
[trixie] - hiredis <no-dsa> (Minor issue)
@@ -2975,8 +2981,9 @@ CVE-2026-88372 (libsndfile 1.2.2 contains an integer overflow vulnerability in m
[trixie] - libsndfile <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://github.com/libsndfile/libsndfile/issues/1151
CVE-2026-88371 (ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in t ...)
- - zbar <unfixed> (bug #1149058)
+ - zbar <unfixed> (bug #1149058; unimportant)
NOTE: https://github.com/mchehab/zbar/issues/336
+ NOTE: Negligible security impact
CVE-2026-88370 (libconfini 1.16.4 contains a heap out-of-bounds write condition involv ...)
NOT-FOR-US: libconfini
CVE-2026-88369 (zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example ...)
@@ -3005,6 +3012,7 @@ CVE-2026-88360 (libvips 8.19.0 contains a memory access vulnerability when proce
NOTE: Not considered a security issue by upstream
CVE-2026-88359 (libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_it ...)
- libfyaml <unfixed> (bug #1149055)
+ [trixie] - libfyaml <no-dsa> (Minor issue)
NOTE: https://github.com/pantoniou/libfyaml/issues/315
NOTE: Fixed by: https://github.com/pantoniou/libfyaml/commit/12d903a5c9163d15edf2ef9d7311bd0d1505d902 (v1.0.0-beta1)
CVE-2026-88358 (simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in ...)
@@ -3309,6 +3317,7 @@ CVE-2025-32000 (HCL Sametime is vulnerable to insufficient input sanitization. T
NOT-FOR-US: HCL
CVE-2026-97404 (In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Si ...)
- zaqar 23.0.0~rc1-3 (bug #1148897)
+ [trixie] - zaqar <no-dsa> (Minor issue)
NOTE: https://security.openstack.org/ossa/OSSA-2026-042.html
CVE-2026-88816 [Fix FetchHashKeyName on IV/NV]
- libdbi-perl <unfixed> (bug #1149042)
@@ -5029,6 +5038,7 @@ CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse m
NOTE: Fixed by: https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214 (v1.7.0)
CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, ...)
- python-hpack <unfixed> (bug #1148944)
+ [trixie] - python-hpack <no-dsa> (Minor issue)
NOTE: https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
NOTE: https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c (v4.2.0)
CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
@@ -5546,6 +5556,7 @@ CVE-2026-XXXX [GHSA-83g2-gf92-5c4g]
NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-83g2-gf92-5c4g
CVE-2026-95516
- zbar 0.23.93-10
+ [trixie] - zbar <no-dsa> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537756
CVE-2026-96273 (Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB. ...)
- ghidra <itp> (bug #923851)
@@ -5646,6 +5657,7 @@ CVE-2026-91024 (The Booking Manager WordPress plugin before 2.1.21 does not san
NOT-FOR-US: WordPress plugin
CVE-2026-91018 (lwIP (Lightweight IP)has a double free vulnerability, which could cras ...)
- lwip <unfixed> (bug #1148822)
+ [trixie] - lwip <no-dsa> (Minor issue)
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f873b6295933e4149a2132adf3e9a2d2a676a5ec
CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 do ...)
NOT-FOR-US: WordPress plugin
@@ -5704,6 +5716,7 @@ CVE-2026-87979 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does n
NOT-FOR-US: WordPress plugin
CVE-2026-87121 (lwIPTCP/IP Stack MQTTis vulnerable to an out-of-bounds write, which ma ...)
- lwip <unfixed> (bug #1148822)
+ [trixie] - lwip <no-dsa> (Minor issue)
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=68b2c1191886578d40342846db6ab9a0099c2f40
NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f89407ea711879c04d91c92b35d67be78bbaf0f1
CVE-2026-87074 (The Forminator Forms WordPress plugin before 1.57.2.1 does not bind i ...)
@@ -10250,6 +10263,7 @@ CVE-2026-61793 (Nuxt OG Image generates OG Images with Vue templates in Nuxt. Fr
NOT-FOR-US: Nuxt OG Image
CVE-2026-61700 (MariaDB Connector/J is used to connect applications developed in Java ...)
- mariadb-connector-java 2.7.15-1
+ [trixie] - mariadb-connector-java <no-dsa> (Minor issue)
NOTE: https://jira.mariadb.org/browse/CONJ-1318
NOTE: https://github.com/mariadb-corporation/mariadb-connector-j/security/advisories/GHSA-wxmm-q36w-r9xj
NOTE: Fixed by: https://github.com/mariadb-corporation/mariadb-connector-j/commit/0205d8be947918566cd9ce5a9db149541bbc8dee (3.5.9)
=====================================
data/dsa-needed.txt
=====================================
@@ -23,7 +23,7 @@ amd64-microcode (carnil)
bouncycastle
possibly move to 1.85 for trixie
--
-buildstream
+buildstream (jmm)
Maintainer can provide an update for review
--
cacti
@@ -116,6 +116,9 @@ pacemaker
pdfminer (carnil)
Required followup for CVE-2025-64512 as original fix was incomplete.
--
+pillow
+ more CVEs to come
+--
podman
--
prometheus
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03b5fd0d6bd463ae6c9aa1a0258e410cc583416c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03b5fd0d6bd463ae6c9aa1a0258e410cc583416c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/a28e7287/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list