Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
8abb10fd by Utkarsh Gupta at 2026-07-11T04:09:12+05:30
lts: golang-1.15 not-affected in bullseye (CVE-2026-39822, CVE-2026-42505)
- - - - -
083d7a8c by Utkarsh Gupta at 2026-07-11T04:09:33+05:30
lts: buildah not-affected (CVE-2026-44517)
- - - - -
d47ec90b by Utkarsh Gupta at 2026-07-11T04:18:47+05:30
lts: echo.v2 not-affected / echo.v3 postponed in bullseye (CVE-2026-55677)
- - - - -
4f0f33c1 by Utkarsh Gupta at 2026-07-11T04:18:57+05:30
lts: gobgp postponed (CVE-2026-49838 and bookworm triage for 7 more)
- - - - -
5fc6045f by Utkarsh Gupta at 2026-07-11T04:18:59+05:30
lts: golang-golang-x-image postponed (CVE-2026-46604, CVE-2026-46602,
CVE-2026-46601)
- - - - -
8ce4ef53 by Utkarsh Gupta at 2026-07-11T04:19:00+05:30
lts: dhcpcd5 postponed in bullseye (CVE-2026-56114, CVE-2025-70102)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2294,7 +2294,8 @@ CVE-2026-39822 (On Unix systems, opening a file in an
os.Root improperly follows
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- - golang-1.15 <removed>
+ - golang-1.15 <not-affected> (Vulnerable code introduced later)
+ NOTE: golang-1.15: os.Root API introduced in Go 1.24
(go.dev/doc/go1.24); absent in 1.15
NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
NOTE: https://github.com/golang/go/issues/79005
NOTE: Fixed by:
https://github.com/golang/go/commit/f9ef7f55988f03afeb3b8354367d0fa8d053683d
(go1.26.5)
@@ -2306,7 +2307,8 @@ CVE-2026-42505 (Handshakes which used Encrypted Client
Hello could be de-anonymi
- golang-1.24 <removed>
[trixie] - golang-1.24 <no-dsa> (Minor issue)
- golang-1.19 <removed>
- - golang-1.15 <removed>
+ - golang-1.15 <not-affected> (Vulnerable code introduced later)
+ NOTE: golang-1.15: crypto/tls client Encrypted Client Hello introduced
in Go 1.23 (issue #63369); absent in 1.15
NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
NOTE: https://github.com/golang/go/issues/79282
NOTE: Fixed by:
https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0
(go1.26.5)
@@ -4083,6 +4085,8 @@ CVE-2026-12996
CVE-2026-49838
- gobgp 4.7.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
+ [bookworm] - gobgp <postponed> (Minor issue, DoS via empty AS_PATH in
confed eBGP validation)
+ [bullseye] - gobgp <postponed> (Limited support, follow bookworm
security updates)
NOTE:
https://github.com/osrg/gobgp/security/advisories/GHSA-frrj-87jh-2772
NOTE:
https://github.com/osrg/gobgp/commit/4a319a6c25630fb3cdbda3e9ccfe56e702bdaaa0
(v4.7.0)
CVE-2026-9834 (The WP Database Backup \u2013 Unlimited Database & Files Backup
by Bac ...)
@@ -8833,6 +8837,8 @@ CVE-2026-46710 (Notepad++ is a free and open-source
source code editor. From 8.9
CVE-2026-46604 (The TIFF decoder can panic when decoding an invalid image with
an out- ...)
- golang-golang-x-image <unfixed> (bug #1140919)
[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-image <postponed> (Limited support, minor
issue, DoS on 32-bit)
+ [bullseye] - golang-golang-x-image <postponed> (Limited support, minor
issue, DoS on 32-bit)
NOTE: https://github.com/golang/go/issues/80122
NOTE: Fixed by:
https://github.com/golang/image/commit/7c04344368b6bcc71df693702522f4f03af45250
(v0.43.0)
CVE-2026-46386 (OpenProject is open-source, web-based project management
software. Pri ...)
@@ -9457,7 +9463,9 @@ CVE-2026-55677 (Echo is a Go web framework. Prior to
4.15.3 and 5.2.0, Echo's ro
- golang-github-labstack-echo <unfixed> (bug #1141444)
[trixie] - golang-github-labstack-echo <no-dsa> (Minor issue)
- golang-github-labstack-echo.v3 <removed>
+ [bullseye] - golang-github-labstack-echo.v3 <postponed> (Minor issue;
limited/case-by-case golang support, no upstream v3 fix)
- golang-github-labstack-echo.v2 <removed>
+ [bullseye] - golang-github-labstack-echo.v2 <not-affected> (static
handler does no url.PathUnescape; encoded-separator path absent)
NOTE:
https://github.com/labstack/echo/security/advisories/GHSA-vfp3-v2gw-7wfq
CVE-2026-55448 (mise manages dev tools like node, python, cmake, and
terraform. From 2 ...)
NOT-FOR-US: mise
@@ -9766,11 +9774,15 @@ CVE-2026-50176 (The WebSocket Application Programming
Interface lacks restrictio
CVE-2026-46602 (The TIFF decoder does not set a limit on the size of tiles in
tiled im ...)
- golang-golang-x-image <unfixed> (bug #1140919)
[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-image <postponed> (Limited support, minor
issue, DoS)
+ [bullseye] - golang-golang-x-image <postponed> (Limited support, minor
issue, DoS)
NOTE: https://github.com/golang/go/issues/79905
NOTE: Fixed by:
https://github.com/golang/image/commit/304d4cc4ee82f96f864f1a4c9a3ae30a4016c9ce
(v0.43.0)
CVE-2026-46601 (The webp decoder can panic when processing a VP8 chunk with
dimensions ...)
- golang-golang-x-image <unfixed> (bug #1140919)
[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-image <postponed> (Limited support, minor
issue, DoS)
+ [bullseye] - golang-golang-x-image <postponed> (Limited support, minor
issue, DoS)
NOTE: https://github.com/golang/go/issues/79869
NOTE: Fixed by:
https://github.com/golang/image/commit/c5511df3ee92e86ce3fa383fdd247080019257c7
(v0.43.0)
CVE-2026-44622 (Charging station authentication identifiers are publicly
accessible vi ...)
@@ -13648,6 +13660,7 @@ CVE-2026-56114 (dhcpcd through 10.3.2, fixed in commit
2f00c7b, contains a one-b
[trixie] - dhcpcd <no-dsa> (Minor issue)
- dhcpcd5 <removed>
[bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point
release)
+ [bullseye] - dhcpcd5 <postponed> (Minor issue; needs non-default IA_PD
config + adjacent DHCPv6 server; 1-byte OOB, availability-only)
NOTE: Fixed by:
https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029
CVE-2026-56113 (dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a
heap use-af ...)
- dhcpcd 1:10.3.2-4 (bug #1140767)
@@ -13957,6 +13970,9 @@ CVE-2023-54365 (Traefik before 2.10.5 and 3.0.0-beta4
is affected by a denial-of
CVE-2026-44517
- golang-github-containers-buildah 1.43.2+ds1-1 (bug #1140619)
[trixie] - golang-github-containers-buildah <no-dsa> (Minor issue)
+ [bookworm] - golang-github-containers-buildah <not-affected>
(Vulnerable build-context URL refactor introduced in 1.38.1; 1.28.2 predates it)
+ [bullseye] - golang-github-containers-buildah <not-affected>
(Vulnerable build-context URL refactor introduced in 1.38.1; 1.19.6 predates it)
+ NOTE: GHSA-49p4-px3h-rq49 affects >= 1.38.1, < 1.43.2 (TempDirForURL
download-subdir path traversal); absent in bookworm 1.28.2 and bullseye 1.19.6.
Fixed by 54459cf8.
NOTE:
https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
NOTE: Fixed by:
https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
(v1.43.2)
CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar' filter could be
bypasse ...)
@@ -18652,6 +18668,7 @@ CVE-2025-70102 (A NULL pointer dereference occurs in
Roy Marples NetworkConfigur
[trixie] - dhcpcd <no-dsa> (Minor issue)
- dhcpcd5 <removed>
[bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point
release)
+ [bullseye] - dhcpcd5 <postponed> (Minor issue; NULL deref only via
malformed local dhcpcd.conf; not network-reachable)
NOTE: https://github.com/NetworkConfiguration/dhcpcd/issues/567
NOTE: Fixed by:
https://github.com/NetworkConfiguration/dhcpcd/commit/117742d755b591764036dd4218f314f748a3d2b7
(v10.3.1)
CVE-2025-69332 (Subscriber Broken Access Control in Bookify <= 1.1.1 versions.)
@@ -25826,7 +25843,9 @@ CVE-2026-50593 (Graphite before 1.3.15 has an integer
underflow and resultant ou
CVE-2026-49837
- gobgp 4.6.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
+ [bookworm] - gobgp <postponed> (Minor issue, OPEN capability length
under-enforcement)
[bullseye] - gobgp <postponed> (Limited support)
+ NOTE: GHSA scopes affected to v4 <= 4.5.0, but the CapLen-ignoring read
is present in 3.10.0 (bookworm) and 2.25.0 (bullseye):
CapFourOctetASNumber.DecodeFromBytes reads data[0:4] past the 2-byte header.
Minor (OPEN-time capability misparse).
NOTE:
https://github.com/osrg/gobgp/security/advisories/GHSA-gjrg-jjr3-56cm
CVE-2026-8916 (Out-of-bounds write vulnerability in Samsung Open Source
rlottie allow ...)
{DLA-4675-1}
@@ -26423,6 +26442,7 @@ CVE-2026-39107 (A Cross Site Scripting vulnerability
exists in the Kimi AI v1.0
CVE-2026-37462 (An integer underflow in the BGPUpdate.DecodeFromBytes function
(/bgp/b ...)
- gobgp 4.4.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
+ [bookworm] - gobgp <postponed> (Minor issue, uint16 underflow in
BGPUpdate.DecodeFromBytes)
[bullseye] - gobgp <postponed> (Limited support)
NOTE:
https://github.com/osrg/gobgp/commit/9ce8936672ebc07df524da77fa4c6ae26d92be6d
(v4.4.0)
CVE-2026-37460 (Missing input validation in the rfapiRibBi2Ri() function
(rfapi_rib.c) ...)
@@ -48224,6 +48244,7 @@ CVE-2026-38669 (wCMS v.1.4 is vulnerable to Cross Site
Scripting (XSS) when crea
CVE-2026-37461 (An out-of-bounds read in the ParseIP6Extended function
(/bgp/bgp.go) o ...)
- gobgp 4.4.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
+ [bookworm] - gobgp <postponed> (Minor issue, not exploitable in
practice; caller guarantees >=20 bytes)
[bullseye] - gobgp <postponed> (Limited support, follow bookworm
security updates)
NOTE:
https://github.com/osrg/gobgp/commit/362cce3e325f56e7a4f792ccb9689b3bdda9e682
(v4.4.0)
NOTE:
https://github.com/osrg/gobgp/commit/9ce8936672ebc07df524da77fa4c6ae26d92be6d
(v4.4.0)
@@ -48424,21 +48445,25 @@ CVE-2026-7738 (A security flaw has been discovered in
puchunjie doc-tools-mcp 1.
CVE-2026-7737 (A vulnerability was identified in osrg GoBGP up to 4.3.0.
Affected by ...)
- gobgp 4.4.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
+ [bookworm] - gobgp <postponed> (Minor issue, missing length check in
BMP ParseBody)
[bullseye] - gobgp <postponed> (Limited support, follow bookworm
security updates)
NOTE: Fixed by:
https://github.com/osrg/gobgp/commit/bc77597d42335c78464bc8e15a471d887bbdf260
(v4.4.0)
CVE-2026-7736 (A vulnerability was determined in osrg GoBGP up to 4.3.0.
Affected by ...)
- gobgp 4.4.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
+ [bookworm] - gobgp <postponed> (Minor issue, uint16 underflow in MRT
RibEntry decode)
[bullseye] - gobgp <postponed> (Limited support, follow bookworm
security updates)
NOTE: Fixed by:
https://github.com/osrg/gobgp/commit/76d911046344a3923cbe573364197aa081944592
(v4.4.0)
CVE-2026-7735 (A vulnerability was found in osrg GoBGP up to 4.3.0. Affected
is the f ...)
- gobgp 4.4.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
+ [bookworm] - gobgp <postponed> (Minor issue, AIGP attr parser error
handling)
[bullseye] - gobgp <postponed> (Limited support, follow bookworm
security updates)
NOTE: Fixed by:
https://github.com/osrg/gobgp/commit/51ad1ada06cb41ce47b7066799981816f50b7ced
(v4.4.0)
CVE-2026-7734 (A vulnerability has been found in osrg GoBGP up to 4.3.0. This
impacts ...)
- gobgp 4.4.0-1
[trixie] - gobgp <no-dsa> (Minor issue)
+ [bookworm] - gobgp <postponed> (Minor issue, SRv6 prefix-SID unknown
sub-TLV loop)
[bullseye] - gobgp <postponed> (Limited support, follow bookworm
security updates)
NOTE: Fixed by:
https://github.com/osrg/gobgp/commit/f9f7b55ec258e514be0264871fa645a2c3edad11
(v4.4.0)
CVE-2026-7733 (A flaw has been found in funadmin up to 7.1.0-rc6. This affects
the fu ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1c3b68c99265d9a2ed9fe0cef1aa1070c4bd972f...8ce4ef53199677c3bfaecab3aaaff840bf20e577
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1c3b68c99265d9a2ed9fe0cef1aa1070c4bd972f...8ce4ef53199677c3bfaecab3aaaff840bf20e577
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits