Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
86f9c106 by Salvatore Bonaccorso at 2026-07-15T14:36:11+02:00
Process some NFUs

- - - - -
7f647a0d by Salvatore Bonaccorso at 2026-07-15T14:36:12+02:00
Add CVE-2026-54572/rclone

- - - - -
bba8bca1 by Salvatore Bonaccorso at 2026-07-15T14:36:12+02:00
Add one more pillow issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -61,9 +61,9 @@ CVE-2026-60118 (Hi.Events before 1.11.0 contains a missing 
server-side visibilit
 CVE-2026-60114 (Sustainable Irrigation Platform (SIP) through version 5.2.16 
contains  ...)
        NOT-FOR-US: Sustainable Irrigation Platform (SIP)
 CVE-2026-5270 (An authentication bypass vulnerability exists in certain 
releases of C ...)
-       TODO: check
+       NOT-FOR-US: Ciena
 CVE-2026-5269 (In Ciena's Navigator Network Control Suite (NCS) and Manage 
Control Pl ...)
-       TODO: check
+       NOT-FOR-US: Ciena
 CVE-2026-5040 (TP-Link Deco M5 v1 uses a weak password hashing mechanism to 
store use ...)
        NOT-FOR-US: TPLink
 CVE-2026-59891 (sigstore-js provides JavaScript libraries for interacting with 
Sigstor ...)
@@ -254,15 +254,15 @@ CVE-2026-58527 (Concurrent execution using shared 
resource with improper synchro
 CVE-2026-58526 (Use after free in Windows Storage allows an authorized 
attacker to ele ...)
        NOT-FOR-US: Microsoft
 CVE-2026-58479 (Sustainable Irrigation Platform (SIP) through version 5.2.16 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Sustainable Irrigation Platform (SIP)
 CVE-2026-58478 (Sustainable Irrigation Platform (SIP) through version 5.2.16 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Sustainable Irrigation Platform (SIP)
 CVE-2026-58477 (Sustainable Irrigation Platform (SIP) through version 5.2.16 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Sustainable Irrigation Platform (SIP)
 CVE-2026-58476 (Sustainable Irrigation Platform (SIP) through version 5.2.16 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Sustainable Irrigation Platform (SIP)
 CVE-2026-58475 (Sustainable Irrigation Platform (SIP) through version 5.2.16 
contains  ...)
-       TODO: check
+       NOT-FOR-US: Sustainable Irrigation Platform (SIP)
 CVE-2026-58461
        REJECTED
 CVE-2026-58279 (Missing authorization in Azure CycleCloud allows an authorized 
attacke ...)
@@ -270,7 +270,7 @@ CVE-2026-58279 (Missing authorization in Azure CycleCloud 
allows an authorized a
 CVE-2026-58277 (Improper authorization in Microsoft Office SharePoint allows 
an author ...)
        NOT-FOR-US: Microsoft
 CVE-2026-58229 (Allocation of resources without limits vulnerability in 
elixir-mint mi ...)
-       TODO: check
+       NOT-FOR-US: elixir-mint mint
 CVE-2026-57982 (Use of uninitialized resource in Windows RDP allows an 
authorized atta ...)
        NOT-FOR-US: Microsoft
 CVE-2026-57979 (Out-of-bounds read in Windows RDP allows an unauthorized 
attacker to d ...)
@@ -284,7 +284,7 @@ CVE-2026-57969 (Missing authentication for critical 
function in Azure CycleCloud
 CVE-2026-57968 (Buffer over-read in Windows Subsystem for Linux allows an 
authorized a ...)
        NOT-FOR-US: Microsoft
 CVE-2026-57898 (In Eclipse BaSyx Java Server SDK versions 2.0.0-milestone-05 
to 2.0.0- ...)
-       TODO: check
+       NOT-FOR-US: Eclipse BaSyx Java Server SDK
 CVE-2026-57108 (Access of resource using incompatible type ('type confusion') 
in .NET  ...)
        NOT-FOR-US: Microsoft
 CVE-2026-57107 (Improper authentication in Windows Admin Center allows an 
authorized a ...)
@@ -394,7 +394,7 @@ CVE-2026-56156 (Heap-based buffer overflow in Microsoft 
Office Excel allows an u
 CVE-2026-56155 (Insufficient granularity of access control in Active Directory 
Federat ...)
        NOT-FOR-US: Microsoft
 CVE-2026-55954 (Authentication Bypass by Spoofing vulnerability in ueberauth 
ueberauth ...)
-       TODO: check
+       NOT-FOR-US: ueberauth ueberauth_apple
 CVE-2026-55949 (Use of uninitialized resource in Microsoft Office Excel allows 
an unau ...)
        NOT-FOR-US: Microsoft
 CVE-2026-55948 (Use after free in Microsoft Office Excel allows an 
unauthorized attack ...)
@@ -408,7 +408,7 @@ CVE-2026-55899 (Stack-based buffer overflow in Microsoft 
Office Excel allows an
 CVE-2026-55898 (Out-of-bounds read in Microsoft Office Excel allows an 
unauthorized at ...)
        NOT-FOR-US: Microsoft
 CVE-2026-55651 (Easy!Appointments is a self hosted appointment scheduler. In 
version 1 ...)
-       TODO: check
+       NOT-FOR-US: Easy!Appointments
 CVE-2026-55145 (Improper neutralization of special elements used in a command 
('comman ...)
        NOT-FOR-US: Microsoft
 CVE-2026-55144 (Missing cryptographic step in Windows CryptoAPI allows an 
authorized a ...)
@@ -602,7 +602,9 @@ CVE-2026-54982 (Integer underflow (wrap or wraparound) in 
Reliable Multicast Tra
 CVE-2026-54684 (jadx is a Dex to Java decompiler. From 1.5.2 to 1.5.5, a 
malicious .xa ...)
        TODO: check
 CVE-2026-54572 (Rclone is a command-line program to sync files and directories 
to and  ...)
-       TODO: check
+       - rclone <unfixed>
+       NOTE: 
https://github.com/rclone/rclone/security/advisories/GHSA-cf44-9pgv-m4xc
+       NOTE: Fixed by: 
https://github.com/rclone/rclone/commit/874a804f5289517defdd7de68b2a374837080265
 (v1.74.4)
 CVE-2026-54429 (A vulnerability has been identified in SIMATIC S7-PLCSIM 
Advanced (All ...)
        NOT-FOR-US: Siemens
 CVE-2026-54132 (Heap-based buffer overflow in Windows Kernel allows an 
unauthorized at ...)
@@ -648,29 +650,32 @@ CVE-2026-54108 (External control of file name or path in 
Microsoft Office ShareP
 CVE-2026-54107 (Concurrent execution using shared resource with improper 
synchronizati ...)
        NOT-FOR-US: Microsoft
 CVE-2026-54058 (Pillow is a Python imaging library. Prior to 12.3.0, when 
Pillow loads ...)
-       TODO: check
+       - pillow <unfixed>
+       NOTE: 
https://github.com/python-pillow/Pillow/security/advisories/GHSA-62p4-gmf7-7g93
+       NOTE: https://github.com/python-pillow/Pillow/pull/9719
+       NOTE: Fixed by: 
https://github.com/python-pillow/Pillow/commit/6a8de891fb00968e5ea79bfa84368ed90b3cfc1d
 (12.3.0)
 CVE-2026-53633 (Vitest is a testing framework powered by Vite. From 3.0.0 
until 3.2.5, ...)
-       TODO: check
+       NOT-FOR-US: Vitest
 CVE-2026-53566 (Out-of-bounds read vulnerability in Citrix Citrix Secure 
Access Client ...)
        NOT-FOR-US: Citrix
 CVE-2026-53565 (Improper Privilege Management vulnerability in Citrix Secure 
Access Cl ...)
        NOT-FOR-US: Citrix
 CVE-2026-53486 (The decompress package for Node.js extracts archives. Prior to 
10.2.1  ...)
-       TODO: check
+       NOT-FOR-US: Node decompress module
 CVE-2026-52841 (Easy!Appointments is a self hosted appointment scheduler. In 
versions  ...)
-       TODO: check
+       NOT-FOR-US: Easy!Appointments
 CVE-2026-52840 (Easy!Appointments is a self hosted appointment scheduler. In 
versions  ...)
-       TODO: check
+       NOT-FOR-US: Easy!Appointments
 CVE-2026-52839 (Easy!Appointments is a self hosted appointment scheduler. 
Versions pri ...)
-       TODO: check
+       NOT-FOR-US: Easy!Appointments
 CVE-2026-52838 (Easy!Appointments is a self hosted appointment scheduler. 
Versions pri ...)
-       TODO: check
+       NOT-FOR-US: Easy!Appointments
 CVE-2026-52837 (Easy!Appointments is a self hosted appointment scheduler. In 
versions  ...)
-       TODO: check
+       NOT-FOR-US: Easy!Appointments
 CVE-2026-52101 (An issue in andreimarcu linux-server v.1.0 through v.2.3.8 
allows a re ...)
-       TODO: check
+       NOT-FOR-US: andreimarcu linux-server
 CVE-2026-52100 (Cross Site Request Forgery vulnerability in andreimarcu 
linux-server v ...)
-       TODO: check
+       NOT-FOR-US: andreimarcu linux-server
 CVE-2026-51808 (Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before 
allows  ...)
        TODO: check
 CVE-2026-51807 (Buffer Overflow vulnerability in OpenHTJ2K v.0.18.4 and before 
allows  ...)
@@ -1906,7 +1911,7 @@ CVE-2026-62328 (9Router through version 0.4.41 contain an 
unauthenticated inform
 CVE-2026-62327 (9Router through version 0.4.41 contains an unauthenticated 
information ...)
        NOT-FOR-US: 9Router
 CVE-2026-62242 (Spring Boot Admin Server before 4.1.2 contains a server-side 
request f ...)
-       TODO: check
+       NOT-FOR-US: Spring Boot Admin Server
 CVE-2026-62240 (CrewAI before 1.15.1 contains a server-side request forgery 
vulnerabil ...)
        NOT-FOR-US: CrewAI
 CVE-2026-62239 (FlashAttention through 2.8.3.post1, fixed in commit 0816ef1, 
contains  ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ceac5da9c19783bffe49dccd7071505ecc3b9ddf...bba8bca1b0faf5ea763b0582a693b7e8813d2c60

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/ceac5da9c19783bffe49dccd7071505ecc3b9ddf...bba8bca1b0faf5ea763b0582a693b7e8813d2c60
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to