Utkarsh Gupta pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b47064d3 by Utkarsh Gupta at 2026-07-11T06:12:37+05:30
lts: c-ares not-affected in bullseye/bookworm (CVE-2026-33630 +
GHSA-jv8r/GHSA-pjmc)
- - - - -
a23c750c by Utkarsh Gupta at 2026-07-11T06:12:38+05:30
lts: cifs-utils postponed in bullseye/bookworm (CVE-2026-12505)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2765,6 +2765,8 @@ CVE-2026-59089 (A flaw was found in GIMP. The PlayStation
TIM loader, responsibl
CVE-2026-XXXX [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via
unvalidated DNS header record counts]
- c-ares 1.34.7-1
[trixie] - c-ares <no-dsa> (Minor issue)
+ [bookworm] - c-ares <not-affected> (New DNS-record parser prealloc
(ares_dns_record_rr_prealloc/ares_array_set_size) not present; introduced in
the 1.20+ rewrite)
+ [bullseye] - c-ares <not-affected> (New DNS-record parser prealloc not
present; introduced in the 1.20+ rewrite)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/06/8
NOTE:
https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj
NOTE: Fixed by:
https://github.com/c-ares/c-ares/commit/eaded4cb200b2a5f8d73f11021ff7c8d6968aaab
(main)
@@ -2772,6 +2774,8 @@ CVE-2026-XXXX [GHSA-jv8r-gqr9-68wj: Memory-amplification
denial of service via u
CVE-2026-XXXX [GHSA-pjmc-gx33-gc76: CPU-exhaustion denial of service via
unbounded DNS name compression pointer chains]
- c-ares 1.34.7-1
[trixie] - c-ares <no-dsa> (Minor issue)
+ [bookworm] - c-ares <not-affected> (Vulnerable 1.34 DNS-name
decompression parser (src/lib/record/ares_dns_name.c, ares_buf) not present)
+ [bullseye] - c-ares <not-affected> (Vulnerable 1.34 DNS-name
decompression parser not present)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/06/8
NOTE:
https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76
NOTE: Fixed by:
https://github.com/c-ares/c-ares/commit/f1288bbc70e9a1e0a77134c2382157e52d326aea
(main)
@@ -2779,6 +2783,8 @@ CVE-2026-XXXX [GHSA-pjmc-gx33-gc76: CPU-exhaustion denial
of service via unbound
CVE-2026-33630
- c-ares 1.34.7-1
[trixie] - c-ares <no-dsa> (Minor issue)
+ [bookworm] - c-ares <not-affected> (Vulnerable event-loop code not
present; read_answers()/requeue/host_query re-entrancy introduced in the 1.20+
rewrite, cf. CVE-2025-31498)
+ [bullseye] - c-ares <not-affected> (Vulnerable event-loop code not
present; cf. CVE-2025-31498)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/06/8
NOTE:
https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542
NOTE: Fixed by:
https://github.com/c-ares/c-ares/commit/1fa3b86a0b8d18fe7b60f3228a01d770feb026bc
(main)
@@ -15894,6 +15900,8 @@ CVE-2026-12529 (A security vulnerability has been
detected in SourceCodester CET
CVE-2026-12505 (A flaw was found in the cifs-utils package where the
cifs.upcall helpe ...)
- cifs-utils <unfixed> (bug #1140422)
[trixie] - cifs-utils <no-dsa> (Minor issue)
+ [bookworm] - cifs-utils <postponed> (Minor issue; local privesc via
cifs.upcall getpwuid in caller ns)
+ [bullseye] - cifs-utils <postponed> (Minor issue; local privesc via
cifs.upcall getpwuid in caller ns)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2489805
NOTE:
https://git.samba.org/?p=cifs-utils.git;a=commit;h=972c5b5ff95e3e812bc8daa72d0383654ab0dba7
CVE-2026-12407 (The E2Pdf \u2013 Export Pdf Tool for WordPress plugin for
WordPress is ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8ce4ef53199677c3bfaecab3aaaff840bf20e577...a23c750c2ef4ec8ce8eef0615d73bf99233a50ab
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8ce4ef53199677c3bfaecab3aaaff840bf20e577...a23c750c2ef4ec8ce8eef0615d73bf99233a50ab
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits