Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
ce338bea by Salvatore Bonaccorso at 2026-06-28T13:08:43+02:00
Process some NFUs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,7 +7,7 @@ CVE-2026-58058 (Nmap through 7.99 does not keep the IPv6
extension-header walk w
CVE-2026-58057 (Flowise before 3.1.3 validates Custom MCP stdio environment
variables ...)
NOT-FOR-US: Flowise
CVE-2026-58056 (RustDesk gates incoming control messages on per-capability
flags rathe ...)
- TODO: check
+ NOT-FOR-US: RustDesk
CVE-2026-58055 (nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1
Upgrade re ...)
- nghttp2 <unfixed>
NOTE:
https://github.com/bikini/exploitarium/tree/main/nghttp2-nghttpx-upgrade-queue-poison-poc
@@ -27,9 +27,9 @@ CVE-2026-58050 (libssh2 through 1.11.1 reads an
attacker-controlled 32-bit attri
CVE-2026-58049 (FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c)
perform ...)
TODO: check
CVE-2026-13483 (A flaw has been found in arc53 DocsGPT up to 0.18.0. The
affected elem ...)
- TODO: check
+ NOT-FOR-US: arc53 DocsGPT
CVE-2026-13482 (A vulnerability was detected in skypilot-org skypilot up to
0.12.0. Im ...)
- TODO: check
+ NOT-FOR-US: skypilot-org skypilot
CVE-2026-10646 (Zephyr's BSD-sockets getaddrinfo() implementation
(subsys/net/lib/sock ...)
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-10644 (The Microchip SERCOM-G1 UART driver
(drivers/serial/uart_mchp_sercom_g ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ce338bea29058d148ccecfa1909671c32b652d83
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ce338bea29058d148ccecfa1909671c32b652d83
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits