[Git][security-tracker-team/security-tracker][master] Add new qpid-proton issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Aug 5 10:11:13 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
b9eee8c6 by Salvatore Bonaccorso at 2026-08-05T11:01:58+02:00
Add new qpid-proton issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -118,15 +118,20 @@ CVE-2026-67855 (open62541 contains a heap use-after-free in the GDS PushManageme
 	- open62541 <unfixed>
 	NOTE: https://github.com/open62541/open62541/issues/8093
 CVE-2026-67592 (It was not possible to govern the maximum number of transfer frames pe ...)
-	TODO: check
+	- qpid-proton <unfixed>
+	NOTE: https://lists.apache.org/thread/b4pv9hfdk7ox78pss77sb4nzwjrvqhhz
 CVE-2026-67591 (An authenticated attacker could exceed the session flow control incomi ...)
-	TODO: check
+	- qpid-proton <unfixed>
+	NOTE: https://lists.apache.org/thread/rwmggh2bkm6qotxpdfcplht3jgw5n036
 CVE-2026-67590 (A pre-authentication attacker could leverage type nesting to cause a S ...)
-	TODO: check
+	- qpid-proton <unfixed>
+	NOTE: https://lists.apache.org/thread/kmov6k7f3moqy01m1s370fl61vgos3ly
 CVE-2026-67589 (A pre-authentication attacker could leverage type size/count handling  ...)
-	TODO: check
+	- qpid-proton <unfixed>
+	NOTE: https://lists.apache.org/thread/bs24x4778dh72xtfs299cy8krvdlo47q
 CVE-2026-67588 (A pre-authentication attacker could leverage unbounded symbol value ca ...)
-	TODO: check
+	- qpid-proton <unfixed>
+	NOTE: https://lists.apache.org/thread/vk4j02dzggfdrdkwvzmqo4jro2tgj0jt
 CVE-2026-67555 (It was not possible to govern the maximum number of transfer frames pe ...)
 	TODO: check
 CVE-2026-67554 (An authenticated attacker can craft a disposition frame with large or  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9eee8c6dab1acaf20941c206064025d621155c7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b9eee8c6dab1acaf20941c206064025d621155c7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260805/5f4d2b6f/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list