[Git][security-tracker-team/security-tracker][master] mark CVE-2026-11310, CVE-2026-10592, CVE-2026-10512, CVE-2026-10098 and...
Thorsten Alteholz (@alteholz)
alteholz at debian.org
Sun Aug 2 10:11:23 BST 2026
Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker
Commits:
39603967 by Thorsten Alteholz at 2026-08-02T11:11:04+02:00
mark CVE-2026-11310, CVE-2026-10592, CVE-2026-10512, CVE-2026-10098 and CVE-2026-10097 as EOL for Bookworm and postponed for Bullseye
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -31818,6 +31818,8 @@ CVE-2026-11703 (Missing SNI/ALPN binding on stateful (session-ID) resumption, wh
NOTE: https://github.com/wolfSSL/wolfssl/pull/10489 (v5.9.2-stable)
CVE-2026-11310 (X.509 trust-chain bypass in the OpenSSL compatibility certificate veri ...)
- wolfssl 5.9.2-1
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+ [bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10674 (v5.9.2-stable)
CVE-2026-10835 (The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not prope ...)
NOT-FOR-US: WordPress plugin
@@ -31825,15 +31827,23 @@ CVE-2026-10823 (The YMC Filter WordPress plugin before 3.11.3 does not properly
NOT-FOR-US: WordPress plugin
CVE-2026-10592 (Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA n ...)
- wolfssl 5.9.2-1
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+ [bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10549 (v5.9.2-stable)
CVE-2026-10512 (The X25519 x86_64 assembly implementation fails to clear the most sign ...)
- wolfssl 5.9.2-1
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+ [bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10536 (v5.9.2-stable)
CVE-2026-10098 (OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_s ...)
- wolfssl 5.9.2-1
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+ [bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10554 (v5.9.2-stable)
CVE-2026-10097 (wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compar ...)
- wolfssl 5.9.2-1
+ [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+ [bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10430 (v5.9.2-stable)
CVE-2025-71340 (picklescan through 0.0.26 fails to detect malicious pickle files that ...)
NOT-FOR-US: picklescan
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/396039675b1801c721b5ece5b5f54f7781bcc9fa
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/396039675b1801c721b5ece5b5f54f7781bcc9fa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/d3a4edaa/attachment.htm>
More information about the debian-security-tracker-commits
mailing list