[Git][security-tracker-team/security-tracker][master] mark CVE-2026-11310, CVE-2026-10592, CVE-2026-10512, CVE-2026-10098 and...

Thorsten Alteholz (@alteholz) alteholz at debian.org
Sun Aug 2 10:11:23 BST 2026



Thorsten Alteholz pushed to branch master at Debian Security Tracker / security-tracker


Commits:
39603967 by Thorsten Alteholz at 2026-08-02T11:11:04+02:00
mark CVE-2026-11310, CVE-2026-10592, CVE-2026-10512, CVE-2026-10098 and CVE-2026-10097 as EOL for Bookworm and postponed for Bullseye

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31818,6 +31818,8 @@ CVE-2026-11703 (Missing SNI/ALPN binding on stateful (session-ID) resumption, wh
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10489 (v5.9.2-stable)
 CVE-2026-11310 (X.509 trust-chain bypass in the OpenSSL compatibility certificate veri ...)
 	- wolfssl 5.9.2-1
+	[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+	[bullseye] - wolfssl <postponed> (Minor issue)
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10674 (v5.9.2-stable)
 CVE-2026-10835 (The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not prope ...)
 	NOT-FOR-US: WordPress plugin
@@ -31825,15 +31827,23 @@ CVE-2026-10823 (The YMC Filter WordPress plugin before 3.11.3 does not properly
 	NOT-FOR-US: WordPress plugin
 CVE-2026-10592 (Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA n ...)
 	- wolfssl 5.9.2-1
+	[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+	[bullseye] - wolfssl <postponed> (Minor issue)
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10549 (v5.9.2-stable)
 CVE-2026-10512 (The X25519 x86_64 assembly implementation fails to clear the most sign ...)
 	- wolfssl 5.9.2-1
+	[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+	[bullseye] - wolfssl <postponed> (Minor issue)
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10536 (v5.9.2-stable)
 CVE-2026-10098 (OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_s ...)
 	- wolfssl 5.9.2-1
+	[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+	[bullseye] - wolfssl <postponed> (Minor issue)
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10554 (v5.9.2-stable)
 CVE-2026-10097 (wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compar ...)
 	- wolfssl 5.9.2-1
+	[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
+	[bullseye] - wolfssl <postponed> (Minor issue)
 	NOTE: https://github.com/wolfSSL/wolfssl/pull/10430 (v5.9.2-stable)
 CVE-2025-71340 (picklescan through 0.0.26 fails to detect malicious pickle files that  ...)
 	NOT-FOR-US: picklescan



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/396039675b1801c721b5ece5b5f54f7781bcc9fa

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/396039675b1801c721b5ece5b5f54f7781bcc9fa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/d3a4edaa/attachment.htm>


More information about the debian-security-tracker-commits mailing list