[Git][security-tracker-team/security-tracker][master] trixie triage

Moritz Muehlenhoff (@jmm) jmm at debian.org
Sat Sep 26 22:09:01 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
03b5fd0d by Moritz Muehlenhoff at 2026-09-26T23:03:03+02:00
trixie triage

- - - - -


2 changed files:

- data/CVE/list
- data/dsa-needed.txt


Changes:

=====================================
data/CVE/list
=====================================
@@ -756,9 +756,10 @@ CVE-2026-97324 (A vulnerability was identified in YunaiV/zhijiantianya ruoyi-vue
 CVE-2026-97228 (Rapid7 Bulk Export MCP versions 0.2.5 through 0.6.1 suffer from a Grap ...)
 	NOT-FOR-US: Rapid7 Bulk Export MCP
 CVE-2026-97222 (A heap use-after-free flaw was found in Gnumeric. When a user opens a  ...)
-	- gnumeric <unfixed>
+	- gnumeric <unfixed> (unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/gnumeric/-/issues/897
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gnumeric/-/commit/bc1dee29525933994181fb2307d6ad584de6040d
+	NOTE: Crash in GUI tool, no security impact
 CVE-2026-97064 (X-SpringBoot through 6.0 ships with a hardcoded static master login ve ...)
 	NOT-FOR-US: X-SpringBoot
 CVE-2026-97063 (X-SpringBoot through 6.0 returns login verification codes in HTTP resp ...)
@@ -901,6 +902,7 @@ CVE-2026-88387 (LibRaw 0.22.0 contains an incorrect numeric conversion vulnerabi
 	NOTE: Fixed by: https://github.com/LibRaw/LibRaw/commit/b41cbbd61951783e0440590dae55411a16185bdf (master)
 CVE-2026-88386 (libsndfile 1.2.2 contains a misaligned memory access issue in psf_binh ...)
 	- libsndfile <unfixed> (bug #1149062)
+	[trixie] - libsndfile <no-dsa> (Minor issue)
 	NOTE: https://github.com/libsndfile/libsndfile/issues/1150
 	NOTE: Fixed by: https://github.com/libsndfile/libsndfile/commit/474e4d328b1e6240b93ec6ed14efb7c6a44bee57
 CVE-2026-87722 (Uncontrolled Resource Consumption (CWE-400 / CWE-1333) in regex search ...)
@@ -2807,6 +2809,7 @@ CVE-2026-97061 (Black Candy through 3.2.1 fails to scope playlist search queries
 	NOT-FOR-US: Black Candy
 CVE-2026-97059 (DCMTK through 3.7.0 contains a heap over-read vulnerability in Concate ...)
 	- dcmtk <unfixed>
+	[trixie] - dcmtk <no-dsa> (Minor issue)
 	NOTE: https://support.dcmtk.org/redmine/issues/1281
 	NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/18379d5b8d234977cc30644e9e70d76d89c87285
 	NOTE: Fixed by: https://github.com/DCMTK/dcmtk/commit/c33790827a192a598d20463af701a8b819f46ec1
@@ -2836,6 +2839,7 @@ CVE-2026-96746 (An out-of-bounds write in the connection-monitoring logic of the
 	NOTE: https://github.com/mongodb/mongo-c-driver/commit/59bcc756ad8f04af74b84b88ab747adfd2647b5b (1.30.12)
 CVE-2026-96745 (Deserialization of untrusted data in the command monitoring support of ...)
 	- php-mongodb <unfixed> (bug #1148966)
+	[trixie] - php-mongodb <no-dsa> (Minor issue)
 	NOTE: https://github.com/mongodb/mongo-php-driver/security/advisories/GHSA-cmvj-vxvq-rh2c
 	NOTE: https://jira.mongodb.org/browse/PHPC-2743
 	NOTE: https://github.com/mongodb/mongo-php-driver/pull/2115
@@ -2939,6 +2943,7 @@ CVE-2026-88390 (An out-of-bounds write vulnerability in jslGetTokenValueAsString
 	NOT-FOR-US: Espruino
 CVE-2026-88385 (Mini-XML 4.0.5 contains a memory leak vulnerability in mxml_load_data( ...)
 	- mxml 4.0.6-2
+	[trixie] - mxml <no-dsa> (Minor issue)
 	NOTE: https://github.com/michaelrsweet/mxml/issues/356
 	NOTE: Fixed by: https://github.com/michaelrsweet/mxml/commit/83ef80ae3c5413b73f501edb59ee74e31ce399d0 (v4.0.6)
 CVE-2026-88384 (OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ attribut ...)
@@ -2947,11 +2952,12 @@ CVE-2026-88384 (OpenEXR 3.4.14 contains a NULL Pointer Dereference in the C++ at
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/pull/2615
 	NOTE: https://github.com/AcademySoftwareFoundation/openexr/commit/e782bcc1ffe1cc9edfaa5dbad4f28e866eaf9bbb (v3.5.0-rc)
 CVE-2026-88383 (libical 4.0.6 contains an incompatible function pointer in icalparamet ...)
-	- libical3 <unfixed> (bug #1149060)
+	- libical3 <unfixed> (bug #1149060; unimportant)
 	- libical <removed>
 	NOTE: https://github.com/libical/libical/issues/1361
 	NOTE: https://github.com/libical/libical/pull/1363
 	NOTE: Fixed by: https://github.com/libical/libical/commit/1fc946aaa91e5995dee593092723ba67d7113846 (4.0 branch)
+	NOTE: Negligible security impact
 CVE-2026-88382 (hiredis commit 29ea279 (post-v1.5.0) contains an uncontrolled memory a ...)
 	- hiredis <unfixed> (bug #1149059)
 	[trixie] - hiredis <no-dsa> (Minor issue)
@@ -2975,8 +2981,9 @@ CVE-2026-88372 (libsndfile 1.2.2 contains an integer overflow vulnerability in m
 	[trixie] - libsndfile <postponed> (Minor issue, revisit when fixed upstream)
 	NOTE: https://github.com/libsndfile/libsndfile/issues/1151
 CVE-2026-88371 (ZBar commit 2ea2ca58 contains an undefined-behavior vulnerability in t ...)
-	- zbar <unfixed> (bug #1149058)
+	- zbar <unfixed> (bug #1149058; unimportant)
 	NOTE: https://github.com/mchehab/zbar/issues/336
+	NOTE: Negligible security impact
 CVE-2026-88370 (libconfini 1.16.4 contains a heap out-of-bounds write condition involv ...)
 	NOT-FOR-US: libconfini
 CVE-2026-88369 (zserge jsmn commit 25647e6 is vulnerable to Buffer Overflow in example ...)
@@ -3005,6 +3012,7 @@ CVE-2026-88360 (libvips 8.19.0 contains a memory access vulnerability when proce
 	NOTE: Not considered a security issue by upstream
 CVE-2026-88359 (libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_atom_it ...)
 	- libfyaml <unfixed> (bug #1149055)
+	[trixie] - libfyaml <no-dsa> (Minor issue)
 	NOTE: https://github.com/pantoniou/libfyaml/issues/315
 	NOTE: Fixed by: https://github.com/pantoniou/libfyaml/commit/12d903a5c9163d15edf2ef9d7311bd0d1505d902 (v1.0.0-beta1)
 CVE-2026-88358 (simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in ...)
@@ -3309,6 +3317,7 @@ CVE-2025-32000 (HCL Sametime is vulnerable to insufficient input sanitization. T
 	NOT-FOR-US: HCL
 CVE-2026-97404 (In OpenStack Zaqar before 22.0.2, WSGI transport mishandles the URL-Si ...)
 	- zaqar 23.0.0~rc1-3 (bug #1148897)
+	[trixie] - zaqar <no-dsa> (Minor issue)
 	NOTE: https://security.openstack.org/ossa/OSSA-2026-042.html
 CVE-2026-88816 [Fix FetchHashKeyName   on IV/NV]
 	- libdbi-perl <unfixed> (bug #1149042)
@@ -5029,6 +5038,7 @@ CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse m
 	NOTE: Fixed by: https://github.com/typelevel/jawn/commit/f6ace7e0db715de1a8c4618bed9378333a5c2214 (v1.7.0)
 CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, ...)
 	- python-hpack <unfixed> (bug #1148944)
+	[trixie] - python-hpack <no-dsa> (Minor issue)
 	NOTE: https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
 	NOTE: https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c (v4.2.0)
 CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
@@ -5546,6 +5556,7 @@ CVE-2026-XXXX [GHSA-83g2-gf92-5c4g]
 	NOTE: https://github.com/FreeRDP/FreeRDP/security/advisories/GHSA-83g2-gf92-5c4g
 CVE-2026-95516
 	- zbar 0.23.93-10
+	[trixie] - zbar <no-dsa> (Minor issue)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537756
 CVE-2026-96273 (Ghidra before 12.1.4 fails to validate the TYPE_COL byte in OptionsDB. ...)
 	- ghidra <itp> (bug #923851)
@@ -5646,6 +5657,7 @@ CVE-2026-91024 (The Booking Manager  WordPress plugin before 2.1.21 does not san
 	NOT-FOR-US: WordPress plugin
 CVE-2026-91018 (lwIP (Lightweight IP)has a double free vulnerability, which could cras ...)
 	- lwip <unfixed> (bug #1148822)
+	[trixie] - lwip <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f873b6295933e4149a2132adf3e9a2d2a676a5ec
 CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 do ...)
 	NOT-FOR-US: WordPress plugin
@@ -5704,6 +5716,7 @@ CVE-2026-87979 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does n
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87121 (lwIPTCP/IP Stack MQTTis vulnerable to an out-of-bounds write, which ma ...)
 	- lwip <unfixed> (bug #1148822)
+	[trixie] - lwip <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=68b2c1191886578d40342846db6ab9a0099c2f40
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f89407ea711879c04d91c92b35d67be78bbaf0f1
 CVE-2026-87074 (The Forminator Forms  WordPress plugin before 1.57.2.1 does not bind i ...)
@@ -10250,6 +10263,7 @@ CVE-2026-61793 (Nuxt OG Image generates OG Images with Vue templates in Nuxt. Fr
 	NOT-FOR-US: Nuxt OG Image
 CVE-2026-61700 (MariaDB Connector/J is used to connect applications developed in Java  ...)
 	- mariadb-connector-java 2.7.15-1
+	[trixie] - mariadb-connector-java <no-dsa> (Minor issue)
 	NOTE: https://jira.mariadb.org/browse/CONJ-1318
 	NOTE: https://github.com/mariadb-corporation/mariadb-connector-j/security/advisories/GHSA-wxmm-q36w-r9xj
 	NOTE: Fixed by: https://github.com/mariadb-corporation/mariadb-connector-j/commit/0205d8be947918566cd9ce5a9db149541bbc8dee (3.5.9)


=====================================
data/dsa-needed.txt
=====================================
@@ -23,7 +23,7 @@ amd64-microcode (carnil)
 bouncycastle
   possibly move to 1.85 for trixie
 --
-buildstream
+buildstream (jmm)
   Maintainer can provide an update for review
 --
 cacti
@@ -116,6 +116,9 @@ pacemaker
 pdfminer (carnil)
   Required followup for CVE-2025-64512 as original fix was incomplete.
 --
+pillow
+  more CVEs to come
+--
 podman
 --
 prometheus



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03b5fd0d6bd463ae6c9aa1a0258e410cc583416c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/03b5fd0d6bd463ae6c9aa1a0258e410cc583416c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/a28e7287/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list