[Git][security-tracker-team/security-tracker][master] mark CVE-2026-11703 and CVE-2026-11999 as postponed for Bullseye

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sun Aug 2 10:08:36 BST 2026



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bbaf24ac by Thorsten Alteholz at 2026-08-02T11:08:19+02:00
mark CVE-2026-11703 and CVE-2026-11999 as postponed for Bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31814,6 +31814,7 @@ CVE-2026-11800 (A flaw was found in Keycloak. This JWT algorithm confusion vulne
 CVE-2026-11703 (Missing SNI/ALPN binding on stateful (session-ID) resumption, which pr ...)
 	- wolfssl 5.9.2-1
 	[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+	[bullseye] - wolfssl <postponed> (Minor issue)
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10489 (v5.9.2-stable)
 CVE-2026-11310 (X.509 trust-chain bypass in the OpenSSL compatibility certificate veri ...)
 	- wolfssl 5.9.2-1
@@ -32428,6 +32429,7 @@ CVE-2026-12755 (Improper input validation in the PAM AD discovery endpoints in
 CVE-2026-11999 (X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compat ...)
 	- wolfssl 5.9.2-1
 	[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+	[bullseye] - wolfssl <postponed> (Minor issue)
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10674 (v5.9.2-stable)
 CVE-2026-12844 (List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer o ...)
 	- liblist-someutils-xs-perl 0.59-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbaf24acd253f29729e37398a56c4432d853b887

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bbaf24acd253f29729e37398a56c4432d853b887
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/9dca0624/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list