[Git][security-tracker-team/security-tracker][master] Add new batch of hdf5 issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 6 10:03:41 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3d141b58 by Salvatore Bonaccorso at 2026-08-06T11:02:25+02:00
Add new batch of hdf5 issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -205,17 +205,35 @@ CVE-2026-34966 (Gitea prior to 1.27.0 contains a server-side request forgery vul
CVE-2026-21766 (The default login portlet in HCL Digital Experience and Digital Experi ...)
NOT-FOR-US: HCL
CVE-2026-19028 (H5Z__filter_fletcher32 in H5Zfletcher32.c in HDF5 through 2.3.0 comput ...)
- TODO: check
+ - hdf5 <unfixed> (unimportant)
+ NOTE: https://github.com/HDFGroup/hdf5/pull/6497
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6488
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6490
+ NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
CVE-2026-19027 (The H5Z__nbit_decompress_one_byte, H5Z__nbit_decompress_one_nooptype, ...)
- TODO: check
+ - hdf5 <unfixed> (unimportant)
+ NOTE: https://github.com/HDFGroup/hdf5/pull/6497
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6489
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6492
+ NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
CVE-2026-19026 (H5Z__filter_nbit in H5Znbit.c in HDF5 through 2.3.0 dereferences cd_va ...)
- TODO: check
+ - hdf5 <unfixed> (unimportant)
+ NOTE: https://github.com/HDFGroup/hdf5/pull/6497
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6489
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6492
+ NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
CVE-2026-19025 (H5O__layout_decode in H5Olayout.c in HDF5 through 2.3.0 does not valid ...)
- TODO: check
+ - hdf5 <unfixed> (unimportant)
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6491
+ NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
CVE-2026-19024 (NULL pointer dereference in H5Pget_fill_value in HDF5 before 2.1.1 all ...)
- TODO: check
+ - hdf5 <unfixed> (unimportant)
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6487
+ NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
CVE-2026-19023 (Untrusted pointer dereference in the render_bin_output function in the ...)
- TODO: check
+ - hdf5 <unfixed> (unimportant)
+ NOTE: https://github.com/HDFGroup/hdf5/issues/6486
+ NOTE: HDF not covered by security support, see https://bugs.debian.org/1117722
CVE-2026-19007 (A vulnerability was determined in mf-yang openclaw-cn up to 0.2.1. Thi ...)
TODO: check
CVE-2026-19006 (A vulnerability was found in mf-yang openclaw-cn 2026.2.5. This affect ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d141b589100a1359a2169e59d47e81451bb5124
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d141b589100a1359a2169e59d47e81451bb5124
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260806/1e604052/attachment.htm>
More information about the debian-security-tracker-commits
mailing list