Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
cb60331e by Salvatore Bonaccorso at 2026-09-10T15:15:14+02:00
Add CVE-2026-74860/libxml2
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2802,7 +2802,11 @@ CVE-2026-75156 (Apache Airflow FAB provider versions
3.7.3 through 3.8.0 do not
CVE-2026-75021 (fastify-cli starts the Node.js Inspector when a debug flag is
used, bu ...)
NOT-FOR-US: fastify-cli
CVE-2026-74860 (A flaw was found in libxml2 with Python bindings enabled. A
remote att ...)
- TODO: check
+ - libxml2 2.15.3+dfsg-1
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2529697
+ NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/work_items/1076
+ NOTE: https://gitlab.gnome.org/GNOME/libxml2/-/merge_requests/397
+ NOTE: Fixed by:
https://gitlab.gnome.org/GNOME/libxml2/-/commit/f41e1865781f74d1cadfe2fbdfeefed946026f12
(v2.15.3)
CVE-2026-74859 (The shell theme installer in gnome-tweaks extracts
user-supplied ZIP a ...)
TODO: check
CVE-2026-74239 (XenForo before 2.3.13 contains a path traversal vulnerability
in the s ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb60331ed27a3683d849c33370f43684b04292f6
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cb60331ed27a3683d849c33370f43684b04292f6
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits