Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
3871661a by Salvatore Bonaccorso at 2026-08-12T07:03:52+02:00
Add CVE-2026-672{6,7} for libtpms
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -449,9 +449,19 @@ CVE-2026-70304 (Heap-based buffer overflow in Windows DNS
allows an authorized a
CVE-2026-70130 (Heap-based buffer overflow in Microsoft Office allows an
unauthorized ...)
NOT-FOR-US: Microsoft
CVE-2026-6727 (A timing side-channel vulnerability exists in the RSA OAEP
decryption ...)
- TODO: check
+ - libtpms <unfixed> (unimportant)
+ NOTE: Fixed by:
https://github.com/stefanberger/libtpms/commit/fd5b4174622032e131b70389b40ec6add4da3237
(stable-0.10 branch)
+ NOTE: Fixed by:
https://github.com/stefanberger/libtpms/commit/b26c0755e3ae37c41da9822027098878bdb5a196
(stable-0.9 branch)
+ NOTE: Debian binary packages not build with
--disable-use-openssl-functions or -DUSE_OPENSSL_FUNCTIONS_RSA=0
+ NOTE: https://groups.google.com/g/libtpms-announce/c/xB2PqSQRA_8
CVE-2026-6726 (An information leakage vulnerability was reported in the TCG
TPM 2.0 r ...)
- TODO: check
+ - libtpms 0.9.1-1
+ NOTE: Fixed by:
https://github.com/stefanberger/libtpms/commit/17255da54cf8354d02369f1323dc50cfb87e2bf4
(v0.9.0)
+ NOTE: Fixed by:
https://github.com/stefanberger/libtpms/commit/33a03986e0a09dde439985e0312d1c8fb3743aab
(v0.8.5)
+ NOTE: Fixed by:
https://github.com/stefanberger/libtpms/commit/1196ab8a3d55eaadb1c8093cd102c4057eb7d9a6
(stable-0.10 branch)
+ NOTE: Fixed by:
https://github.com/stefanberger/libtpms/commit/854f547769251a8c5673e7ec5018e0ef363f4dd3
(stable-0.9 branch)
+ NOTE: Consider already fixed with the changes applied in v0.8.5 and
v0.9.0
+ NOTE: https://groups.google.com/g/libtpms-announce/c/xB2PqSQRA_8
CVE-2026-69320 (Improper neutralization of special elements used in an os
command ('os ...)
NOT-FOR-US: Microsoft
CVE-2026-69306 (Not failing securely ('failing open') in Visual Studio Code
allows an ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3871661a27c6a15e1f4dae3a5aee909e18ffa9aa
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3871661a27c6a15e1f4dae3a5aee909e18ffa9aa
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits