[Git][security-tracker-team/security-tracker][master] Add some new bouncycastle issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 3 18:47:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c11fe44f by Salvatore Bonaccorso at 2026-08-03T19:46:37+02:00
Add some new bouncycastle issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -13,7 +13,9 @@ CVE-2026-18568
 CVE-2026-9593 (A vulnerability in the iDTM FDI allows an attacker with elevated privi ...)
 	NOT-FOR-US: iDTM FDI
 CVE-2026-8763 (In Bouncy Castle for Java before 1.85, Name Constraints bypass via tra ...)
-	TODO: check
+	- bouncycastle <unfixed>
+	NOTE: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%908763
+	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/2c28b253a44681fbbc562561eab6ad383d2ae558 (r1rv85)
 CVE-2026-6695 (A flaw was found in GIMP. A remote attacker could exploit this by tric ...)
 	- gimp 3.2.4-1
 	[trixie] - gimp <not-affected> (Vulnerable code not present)
@@ -28,15 +30,25 @@ CVE-2026-6694 (A flaw was found in GIMP's file-png plugin. A remote attacker can
 CVE-2026-65875 (BaserCMS provided by baserCMS Users Community contains a CSV file inje ...)
 	NOT-FOR-US: BaserCMS
 CVE-2026-59652 (In Bouncy Castle for Java before 1.85, LDAP filter injection in legacy ...)
-	TODO: check
+	- bouncycastle <unfixed>
+	NOTE: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059652
+	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/27c468af54ee6c6af87eab5a3a8468dce17e24a0 (r1rv85)
 CVE-2026-59651 (In Bouncy Castle for Java before 1.85, BKS keystore accepts legacy ver ...)
-	TODO: check
+	- bouncycastle <unfixed>
+	NOTE: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059651
+	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/faf5daa6e9b8460f862afc0af1cc0da365f7d4d2 (r1rv85)
 CVE-2026-59650 (In Bouncy Castle for Java before 1.85, MTI/A0 DH agreement exponentiat ...)
-	TODO: check
+	- bouncycastle <unfixed>
+	NOTE: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059650
+	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/daeaae9d7075d04f40812e68671ebf4c777b5148 (r1rv85)
 CVE-2026-59649 (In Bouncy Castle for Java before 1.85, OpenPGP user-attribute subpacke ...)
-	TODO: check
+	- bouncycastle <unfixed>
+	NOTE: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059649
+	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/a43c40dc12c3e1c6cbd03c83fe30aaec4029b824 (r1rv85)
 CVE-2026-59648 (In Bouncy Castle for Java before 1.85, OpenPGP Argon2 S2K honours atta ...)
-	TODO: check
+	- bouncycastle <unfixed>
+	NOTE: https://github.com/bcgit/bc-java/wiki/CVE%E2%80%902026%E2%80%9059648
+	NOTE: Fixed by: https://github.com/bcgit/bc-java/commit/c915cc3f7a8d58f5ea2f88f01dfef2d402dd0799 (r1rv85)
 CVE-2026-59647 (In Bouncy Castle for Java before 1.85, CRMF/CMP password-MAC honours u ...)
 	TODO: check
 CVE-2026-59646 (In Bouncy Castle for Java before 1.85, DTLS handshake reassembler allo ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c11fe44ff63b9dbac38d30007e4db73de3591939

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c11fe44ff63b9dbac38d30007e4db73de3591939
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260803/d6cf83a5/attachment.htm>


More information about the debian-security-tracker-commits mailing list