[Git][security-tracker-team/security-tracker][master] Reference (proposed) patch for CVE-2025-6966

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Dec 10 05:30:25 GMT 2025



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0243ae5c by Salvatore Bonaccorso at 2025-12-10T06:29:29+01:00
Reference (proposed) patch for CVE-2025-6966

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2524,7 +2524,7 @@ CVE-2025-6966 (NULL pointer dereference in TagSection.keys() in python-apt on AP
 	[trixie] - python-apt <no-dsa> (Minor issue)
 	[bookworm] - python-apt <no-dsa> (Minor issue)
 	NOTE: https://bugs.launchpad.net/ubuntu/+source/python-apt/+bug/2091865
-	NOTE: https://git.launchpad.net/ubuntu/+source/python-apt/commit/?h=ubuntu/jammy-updates&id=f6886ae90818c043a2348ba552c29adfb0236c66
+	NOTE: https://launchpadlibrarian.net/764050984/0001-Fix-invalid-nullptr-dereference-in-TagSection.keys.patch
 CVE-2025-66644 (Array Networks ArrayOS AG before 9.4.5.9 allows command injection, as  ...)
 	NOT-FOR-US: Array Networks ArrayOS AG
 CVE-2025-66624 (BACnet Protocol Stack library provides a BACnet application layer, net ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0243ae5cd387635e6d9a34c16a9cc53475c193f8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0243ae5cd387635e6d9a34c16a9cc53475c193f8
You're receiving this email because of your account on salsa.debian.org.


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20251210/d38b8718/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list