Utkarsh Gupta pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
8abb10fd by Utkarsh Gupta at 2026-07-11T04:09:12+05:30
lts: golang-1.15 not-affected in bullseye (CVE-2026-39822, CVE-2026-42505)

- - - - -
083d7a8c by Utkarsh Gupta at 2026-07-11T04:09:33+05:30
lts: buildah not-affected (CVE-2026-44517)

- - - - -
d47ec90b by Utkarsh Gupta at 2026-07-11T04:18:47+05:30
lts: echo.v2 not-affected / echo.v3 postponed in bullseye (CVE-2026-55677)

- - - - -
4f0f33c1 by Utkarsh Gupta at 2026-07-11T04:18:57+05:30
lts: gobgp postponed (CVE-2026-49838 and bookworm triage for 7 more)

- - - - -
5fc6045f by Utkarsh Gupta at 2026-07-11T04:18:59+05:30
lts: golang-golang-x-image postponed (CVE-2026-46604, CVE-2026-46602, 
CVE-2026-46601)

- - - - -
8ce4ef53 by Utkarsh Gupta at 2026-07-11T04:19:00+05:30
lts: dhcpcd5 postponed in bullseye (CVE-2026-56114, CVE-2025-70102)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2294,7 +2294,8 @@ CVE-2026-39822 (On Unix systems, opening a file in an 
os.Root improperly follows
        - golang-1.24 <removed>
        [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
-       - golang-1.15 <removed>
+       - golang-1.15 <not-affected> (Vulnerable code introduced later)
+       NOTE: golang-1.15: os.Root API introduced in Go 1.24 
(go.dev/doc/go1.24); absent in 1.15
        NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
        NOTE: https://github.com/golang/go/issues/79005
        NOTE: Fixed by: 
https://github.com/golang/go/commit/f9ef7f55988f03afeb3b8354367d0fa8d053683d 
(go1.26.5)
@@ -2306,7 +2307,8 @@ CVE-2026-42505 (Handshakes which used Encrypted Client 
Hello could be de-anonymi
        - golang-1.24 <removed>
        [trixie] - golang-1.24 <no-dsa> (Minor issue)
        - golang-1.19 <removed>
-       - golang-1.15 <removed>
+       - golang-1.15 <not-affected> (Vulnerable code introduced later)
+       NOTE: golang-1.15: crypto/tls client Encrypted Client Hello introduced 
in Go 1.23 (issue #63369); absent in 1.15
        NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
        NOTE: https://github.com/golang/go/issues/79282
        NOTE: Fixed by: 
https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0 
(go1.26.5)
@@ -4083,6 +4085,8 @@ CVE-2026-12996
 CVE-2026-49838
        - gobgp 4.7.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
+       [bookworm] - gobgp <postponed> (Minor issue, DoS via empty AS_PATH in 
confed eBGP validation)
+       [bullseye] - gobgp <postponed> (Limited support, follow bookworm 
security updates)
        NOTE: 
https://github.com/osrg/gobgp/security/advisories/GHSA-frrj-87jh-2772
        NOTE: 
https://github.com/osrg/gobgp/commit/4a319a6c25630fb3cdbda3e9ccfe56e702bdaaa0 
(v4.7.0)
 CVE-2026-9834 (The WP Database Backup \u2013 Unlimited Database & Files Backup 
by Bac ...)
@@ -8833,6 +8837,8 @@ CVE-2026-46710 (Notepad++ is a free and open-source 
source code editor. From 8.9
 CVE-2026-46604 (The TIFF decoder can panic when decoding an invalid image with 
an out- ...)
        - golang-golang-x-image <unfixed> (bug #1140919)
        [trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-image <postponed> (Limited support, minor 
issue, DoS on 32-bit)
+       [bullseye] - golang-golang-x-image <postponed> (Limited support, minor 
issue, DoS on 32-bit)
        NOTE: https://github.com/golang/go/issues/80122
        NOTE: Fixed by: 
https://github.com/golang/image/commit/7c04344368b6bcc71df693702522f4f03af45250 
(v0.43.0)
 CVE-2026-46386 (OpenProject is open-source, web-based project management 
software. Pri ...)
@@ -9457,7 +9463,9 @@ CVE-2026-55677 (Echo is a Go web framework. Prior to 
4.15.3 and 5.2.0, Echo's ro
        - golang-github-labstack-echo <unfixed> (bug #1141444)
        [trixie] - golang-github-labstack-echo <no-dsa> (Minor issue)
        - golang-github-labstack-echo.v3 <removed>
+       [bullseye] - golang-github-labstack-echo.v3 <postponed> (Minor issue; 
limited/case-by-case golang support, no upstream v3 fix)
        - golang-github-labstack-echo.v2 <removed>
+       [bullseye] - golang-github-labstack-echo.v2 <not-affected> (static 
handler does no url.PathUnescape; encoded-separator path absent)
        NOTE: 
https://github.com/labstack/echo/security/advisories/GHSA-vfp3-v2gw-7wfq
 CVE-2026-55448 (mise manages dev tools like node, python, cmake, and 
terraform. From 2 ...)
        NOT-FOR-US: mise
@@ -9766,11 +9774,15 @@ CVE-2026-50176 (The WebSocket Application Programming 
Interface lacks restrictio
 CVE-2026-46602 (The TIFF decoder does not set a limit on the size of tiles in 
tiled im ...)
        - golang-golang-x-image <unfixed> (bug #1140919)
        [trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-image <postponed> (Limited support, minor 
issue, DoS)
+       [bullseye] - golang-golang-x-image <postponed> (Limited support, minor 
issue, DoS)
        NOTE: https://github.com/golang/go/issues/79905
        NOTE: Fixed by: 
https://github.com/golang/image/commit/304d4cc4ee82f96f864f1a4c9a3ae30a4016c9ce 
(v0.43.0)
 CVE-2026-46601 (The webp decoder can panic when processing a VP8 chunk with 
dimensions ...)
        - golang-golang-x-image <unfixed> (bug #1140919)
        [trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+       [bookworm] - golang-golang-x-image <postponed> (Limited support, minor 
issue, DoS)
+       [bullseye] - golang-golang-x-image <postponed> (Limited support, minor 
issue, DoS)
        NOTE: https://github.com/golang/go/issues/79869
        NOTE: Fixed by: 
https://github.com/golang/image/commit/c5511df3ee92e86ce3fa383fdd247080019257c7 
(v0.43.0)
 CVE-2026-44622 (Charging station authentication identifiers are publicly 
accessible vi ...)
@@ -13648,6 +13660,7 @@ CVE-2026-56114 (dhcpcd through 10.3.2, fixed in commit 
2f00c7b, contains a one-b
        [trixie] - dhcpcd <no-dsa> (Minor issue)
        - dhcpcd5 <removed>
        [bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point 
release)
+       [bullseye] - dhcpcd5 <postponed> (Minor issue; needs non-default IA_PD 
config + adjacent DHCPv6 server; 1-byte OOB, availability-only)
        NOTE: Fixed by: 
https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029
 CVE-2026-56113 (dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a 
heap use-af ...)
        - dhcpcd 1:10.3.2-4 (bug #1140767)
@@ -13957,6 +13970,9 @@ CVE-2023-54365 (Traefik before 2.10.5 and 3.0.0-beta4 
is affected by a denial-of
 CVE-2026-44517
        - golang-github-containers-buildah 1.43.2+ds1-1 (bug #1140619)
        [trixie] - golang-github-containers-buildah <no-dsa> (Minor issue)
+       [bookworm] - golang-github-containers-buildah <not-affected> 
(Vulnerable build-context URL refactor introduced in 1.38.1; 1.28.2 predates it)
+       [bullseye] - golang-github-containers-buildah <not-affected> 
(Vulnerable build-context URL refactor introduced in 1.38.1; 1.19.6 predates it)
+       NOTE: GHSA-49p4-px3h-rq49 affects >= 1.38.1, < 1.43.2 (TempDirForURL 
download-subdir path traversal); absent in bookworm 1.28.2 and bullseye 1.19.6. 
Fixed by 54459cf8.
        NOTE: 
https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
        NOTE: Fixed by: 
https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
 (v1.43.2)
 CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar'  filter could be 
bypasse ...)
@@ -18652,6 +18668,7 @@ CVE-2025-70102 (A NULL pointer dereference occurs in 
Roy Marples NetworkConfigur
        [trixie] - dhcpcd <no-dsa> (Minor issue)
        - dhcpcd5 <removed>
        [bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point 
release)
+       [bullseye] - dhcpcd5 <postponed> (Minor issue; NULL deref only via 
malformed local dhcpcd.conf; not network-reachable)
        NOTE: https://github.com/NetworkConfiguration/dhcpcd/issues/567
        NOTE: Fixed by: 
https://github.com/NetworkConfiguration/dhcpcd/commit/117742d755b591764036dd4218f314f748a3d2b7
 (v10.3.1)
 CVE-2025-69332 (Subscriber Broken Access Control in Bookify <= 1.1.1 versions.)
@@ -25826,7 +25843,9 @@ CVE-2026-50593 (Graphite before 1.3.15 has an integer 
underflow and resultant ou
 CVE-2026-49837
        - gobgp 4.6.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
+       [bookworm] - gobgp <postponed> (Minor issue, OPEN capability length 
under-enforcement)
        [bullseye] - gobgp <postponed> (Limited support)
+       NOTE: GHSA scopes affected to v4 <= 4.5.0, but the CapLen-ignoring read 
is present in 3.10.0 (bookworm) and 2.25.0 (bullseye): 
CapFourOctetASNumber.DecodeFromBytes reads data[0:4] past the 2-byte header. 
Minor (OPEN-time capability misparse).
        NOTE: 
https://github.com/osrg/gobgp/security/advisories/GHSA-gjrg-jjr3-56cm
 CVE-2026-8916 (Out-of-bounds write vulnerability in Samsung Open Source 
rlottie allow ...)
        {DLA-4675-1}
@@ -26423,6 +26442,7 @@ CVE-2026-39107 (A Cross Site Scripting vulnerability 
exists in the Kimi AI v1.0
 CVE-2026-37462 (An integer underflow in the BGPUpdate.DecodeFromBytes function 
(/bgp/b ...)
        - gobgp 4.4.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
+       [bookworm] - gobgp <postponed> (Minor issue, uint16 underflow in 
BGPUpdate.DecodeFromBytes)
        [bullseye] - gobgp <postponed> (Limited support)
        NOTE: 
https://github.com/osrg/gobgp/commit/9ce8936672ebc07df524da77fa4c6ae26d92be6d 
(v4.4.0)
 CVE-2026-37460 (Missing input validation in the rfapiRibBi2Ri() function 
(rfapi_rib.c) ...)
@@ -48224,6 +48244,7 @@ CVE-2026-38669 (wCMS v.1.4 is vulnerable to Cross Site 
Scripting (XSS) when crea
 CVE-2026-37461 (An out-of-bounds read in the ParseIP6Extended function 
(/bgp/bgp.go) o ...)
        - gobgp 4.4.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
+       [bookworm] - gobgp <postponed> (Minor issue, not exploitable in 
practice; caller guarantees >=20 bytes)
        [bullseye] - gobgp <postponed> (Limited support, follow bookworm 
security updates)
        NOTE: 
https://github.com/osrg/gobgp/commit/362cce3e325f56e7a4f792ccb9689b3bdda9e682 
(v4.4.0)
        NOTE: 
https://github.com/osrg/gobgp/commit/9ce8936672ebc07df524da77fa4c6ae26d92be6d 
(v4.4.0)
@@ -48424,21 +48445,25 @@ CVE-2026-7738 (A security flaw has been discovered in 
puchunjie doc-tools-mcp 1.
 CVE-2026-7737 (A vulnerability was identified in osrg GoBGP up to 4.3.0. 
Affected by  ...)
        - gobgp 4.4.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
+       [bookworm] - gobgp <postponed> (Minor issue, missing length check in 
BMP ParseBody)
        [bullseye] - gobgp <postponed> (Limited support, follow bookworm 
security updates)
        NOTE: Fixed by: 
https://github.com/osrg/gobgp/commit/bc77597d42335c78464bc8e15a471d887bbdf260 
(v4.4.0)
 CVE-2026-7736 (A vulnerability was determined in osrg GoBGP up to 4.3.0. 
Affected by  ...)
        - gobgp 4.4.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
+       [bookworm] - gobgp <postponed> (Minor issue, uint16 underflow in MRT 
RibEntry decode)
        [bullseye] - gobgp <postponed> (Limited support, follow bookworm 
security updates)
        NOTE: Fixed by: 
https://github.com/osrg/gobgp/commit/76d911046344a3923cbe573364197aa081944592 
(v4.4.0)
 CVE-2026-7735 (A vulnerability was found in osrg GoBGP up to 4.3.0. Affected 
is the f ...)
        - gobgp 4.4.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
+       [bookworm] - gobgp <postponed> (Minor issue, AIGP attr parser error 
handling)
        [bullseye] - gobgp <postponed> (Limited support, follow bookworm 
security updates)
        NOTE: Fixed by: 
https://github.com/osrg/gobgp/commit/51ad1ada06cb41ce47b7066799981816f50b7ced 
(v4.4.0)
 CVE-2026-7734 (A vulnerability has been found in osrg GoBGP up to 4.3.0. This 
impacts ...)
        - gobgp 4.4.0-1
        [trixie] - gobgp <no-dsa> (Minor issue)
+       [bookworm] - gobgp <postponed> (Minor issue, SRv6 prefix-SID unknown 
sub-TLV loop)
        [bullseye] - gobgp <postponed> (Limited support, follow bookworm 
security updates)
        NOTE: Fixed by: 
https://github.com/osrg/gobgp/commit/f9f7b55ec258e514be0264871fa645a2c3edad11 
(v4.4.0)
 CVE-2026-7733 (A flaw has been found in funadmin up to 7.1.0-rc6. This affects 
the fu ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1c3b68c99265d9a2ed9fe0cef1aa1070c4bd972f...8ce4ef53199677c3bfaecab3aaaff840bf20e577

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1c3b68c99265d9a2ed9fe0cef1aa1070c4bd972f...8ce4ef53199677c3bfaecab3aaaff840bf20e577
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to