[Git][security-tracker-team/security-tracker][master] Add new batch of hdf5 issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 6 10:03:41 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
3d141b58 by Salvatore Bonaccorso at 2026-08-06T11:02:25+02:00
Add new batch of hdf5 issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -205,17 +205,35 @@ CVE-2026-34966 (Gitea prior to 1.27.0 contains a server-side request forgery vul
 CVE-2026-21766 (The default login portlet in HCL Digital Experience and Digital Experi ...)
 	NOT-FOR-US: HCL
 CVE-2026-19028 (H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 comput ...)
-	TODO: check
+	- hdf5 <unfixed> (unimportant)
+	NOTE: https://github.com/HDFGroup/hdf5/pull/6497
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6488
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6490
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-19027 (The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype,  ...)
-	TODO: check
+	- hdf5 <unfixed> (unimportant)
+	NOTE: https://github.com/HDFGroup/hdf5/pull/6497
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6489
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6492
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-19026 (H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_va ...)
-	TODO: check
+	- hdf5 <unfixed> (unimportant)
+	NOTE: https://github.com/HDFGroup/hdf5/pull/6497
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6489
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6492
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-19025 (H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not valid ...)
-	TODO: check
+	- hdf5 <unfixed> (unimportant)
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6491
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-19024 (NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 all ...)
-	TODO: check
+	- hdf5 <unfixed> (unimportant)
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6487
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-19023 (Untrusted pointer dereference in the render_bin_output function in the ...)
-	TODO: check
+	- hdf5 <unfixed> (unimportant)
+	NOTE: https://github.com/HDFGroup/hdf5/issues/6486
+	NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
 CVE-2026-19007 (A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. Thi ...)
 	TODO: check
 CVE-2026-19006 (A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affect ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d141b589100a1359a2169e59d47e81451bb5124

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d141b589100a1359a2169e59d47e81451bb5124
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/1e604052/attachment.htm>


More information about the debian-security-tracker-commits mailing list