[Git][security-tracker-team/security-tracker][master] Mark wolfssl issues as no-dsa for trixie
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sun Aug 2 20:10:04 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
0e5b6c77 by Salvatore Bonaccorso at 2026-08-02T21:09:19+02:00
Mark wolfssl issues as no-dsa for trixie
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -31854,11 +31854,13 @@ CVE-2026-11800 (A flaw was found in Keycloak. This JWT algorithm confusion vulne
- keycloak <itp> (bug #1088287)
CVE-2026-11703 (Missing SNI/ALPN binding on stateful (session-ID) resumption, which pr ...)
- wolfssl 5.9.2-1
+ [trixie] - wolfssl <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10489 (v5.9.2-stable)
CVE-2026-11310 (X.509 trust-chain bypass in the OpenSSL compatibility certificate veri ...)
- wolfssl 5.9.2-1
+ [trixie] - wolfssl <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10674 (v5.9.2-stable)
@@ -31868,21 +31870,25 @@ CVE-2026-10823 (The YMC Filter WordPress plugin before 3.11.3 does not properly
NOT-FOR-US: WordPress plugin
CVE-2026-10592 (Certificates with wildcard DNS SANs (e.g. *.example.com) bypassed CA n ...)
- wolfssl 5.9.2-1
+ [trixie] - wolfssl <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10549 (v5.9.2-stable)
CVE-2026-10512 (The X25519 x86_64 assembly implementation fails to clear the most sign ...)
- wolfssl 5.9.2-1
+ [trixie] - wolfssl <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10536 (v5.9.2-stable)
CVE-2026-10098 (OCSP CertID serial-number length-confusion in wolfSSL_OCSP_resp_find_s ...)
- wolfssl 5.9.2-1
+ [trixie] - wolfssl <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10554 (v5.9.2-stable)
CVE-2026-10097 (wolfSSL's AVX2-optimized ML-KEM implementation (mlkem_cmp_avx2) compar ...)
- wolfssl 5.9.2-1
+ [trixie] - wolfssl <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10430 (v5.9.2-stable)
@@ -32479,6 +32485,7 @@ CVE-2026-12755 (Improper input validation in the PAM AD discovery endpoints in
NOT-FOR-US: Devolutions
CVE-2026-11999 (X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compat ...)
- wolfssl 5.9.2-1
+ [trixie] - wolfssl <no-dsa> (Minor issue; can be fixed in point release)
[bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10674 (v5.9.2-stable)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0e5b6c77ecafcdc7fe774256bb97b35ef52b9465
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0e5b6c77ecafcdc7fe774256bb97b35ef52b9465
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260802/3bbac1c5/attachment.htm>
More information about the debian-security-tracker-commits
mailing list