[Git][security-tracker-team/security-tracker][master] Correct status for CVE-2026-32316 in trixie

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 07:11:46 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2cfab1d3 by Salvatore Bonaccorso at 2026-08-05T08:09:03+02:00
Correct status for CVE-2026-32316 in trixie

The patch was not applied in the 1.7.1-6+deb13u2

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -83624,9 +83624,8 @@ CVE-2026-33555 (An issue was discovered in HAProxy before 3.3.6. The HTTP/3 pars
 CVE-2026-32316 (jq is a command-line JSON processor. An integer overflow vulnerability ...)
 	{DLA-4662-1 DLA-4599-1}
 	- jq 1.8.1-5 (bug #1133921)
-	[trixie] - jq 1.7.1-6+deb13u2
 	NOTE: https://github.com/jqlang/jq/security/advisories/GHSA-q3h9-m34w-h76f
-	NOTE: Fixed by: https://github.com/jqlang/jq/commit/e47e56d226519635768e6aab2f38f0ab037c09e5
+	NOTE: Fixed by: https://github.com/jqlang/jq/commit/e47e56d226519635768e6aab2f38f0ab037c09e5 (jq-1.8.2rc1)
 CVE-2026-31283 (In Totara LMS v19.1.5 and before, the forgot password API does not imp ...)
 	NOT-FOR-US: Totara LMS
 CVE-2026-31282 (Totara LMS v19.1.5 and before is vulnerable to Incorrect Access Contro ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2cfab1d33e1050e2c4d5eb186b7726acb67a2268

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2cfab1d33e1050e2c4d5eb186b7726acb67a2268
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/434b1493/attachment.htm>


More information about the debian-security-tracker-commits mailing list