[Git][security-tracker-team/security-tracker][master] Add Debian bug references as reported for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Aug 9 08:03:24 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ac71b32a by Salvatore Bonaccorso at 2026-08-09T09:02:56+02:00
Add Debian bug references as reported for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1796,11 +1796,11 @@ CVE-2026-67872 (An issue in Systerel S2OPC 1.7.3 allows a remote attacker to cau
 CVE-2026-67871 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote  ...)
 	NOT-FOR-US: Systerel S2OPC
 CVE-2026-67870 (In open62541 v1.5.5, the server-side AddReferences implementation cont ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8172
 CVE-2026-67869 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote atta ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8171
 CVE-2026-67867 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a remote  ...)
@@ -1810,11 +1810,11 @@ CVE-2026-67866 (Buffer Overflow vulnerability in Systerel S2OPC 1.7.3 allows a r
 CVE-2026-67865 (S2OPC 1.7.3 contains an out-of-bounds read in RepublishResponse handli ...)
 	NOT-FOR-US: Systerel S2OPC
 CVE-2026-67864 (An issue in open62541 v.1.5.5 and before allows a remote attacker to c ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8133
 CVE-2026-67863 (In open62541 1.5.5, a server-side use-after-free exists in the local M ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8131
 CVE-2026-67531 (FrontMCP is a TypeScript-first framework for the Model Context Protoco ...)
@@ -2769,35 +2769,35 @@ CVE-2026-68060 (A pre-authentication attacker could leverage type size/count han
 CVE-2026-67979 (Incorrect access control in the Executive Services dynamic application ...)
 	NOT-FOR-US: NASA cFS
 CVE-2026-67862 (open62541 1.5.5 contains a buffer-overflow in the high-level attribute ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8139
 CVE-2026-67861 (An issue in open62541 v.1.5.5 and before allows a remote attacker to c ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8140
 CVE-2026-67860 (open62541 1.5.5 contains a heap-based buffer overflow in the default H ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8091
 CVE-2026-67859 (Buffer Overflow vulnerability in open62541 v1.5.5 allows a remote atta ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8095
 CVE-2026-67858 (Buffer Overflow vulnerability exists in open62541 1.5.5 when the Local ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8094
 CVE-2026-67857 (open62541 1.5.5 contains an out-of-bounds read in the client-side func ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8104
 CVE-2026-67856 (An issue in open62541 v.1.5.5 and before allows a remote attacker to c ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8092
 CVE-2026-67855 (open62541 contains a heap use-after-free in the GDS PushManagement cer ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8093
 CVE-2026-67592 (It was not possible to govern the maximum number of transfer frames pe ...)
@@ -3231,11 +3231,11 @@ CVE-2026-18788 (A security flaw has been discovered in Trippo ResponsiveFilemana
 CVE-2026-18787 (A vulnerability was identified in GL.iNet AX1800 up to 4.8.3. The affe ...)
 	NOT-FOR-US: GL.iNet
 CVE-2026-18785 (A vulnerability was determined in o6 open62541 ca356b088ada7dee824d1b4 ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8131
 CVE-2026-18784 (A vulnerability was found in o6 open62541 up to 1.5.5. This issue affe ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: https://github.com/open62541/open62541/issues/8139
 CVE-2026-18775 (A vulnerability has been found in NousResearch hermes-agent up to 0.16 ...)
@@ -5230,7 +5230,7 @@ CVE-2026-65835 (Capsule is a multi-tenancy and policy-based framework for Kubern
 CVE-2026-65834 (Capsule is a multi-tenancy and policy-based framework for Kubernetes.  ...)
 	NOT-FOR-US: Capsule
 CVE-2026-65423 (An integer overflow in the UA_Variant arrayDimensions product  computa ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/open62541/open62541/commit/8098907673099afe6b726de05675146066b24d9c (v1.3.19, v1.4.18, v1.5.6)
 	NOTE: Fixed by: https://github.com/open62541/open62541/commit/a1257feec0c539f191cb2d40f72f116a901d3322 (v1.3.19, v1.4.18, v1.5.6)
@@ -5241,7 +5241,7 @@ CVE-2026-65421 (The MMS BER decoder contains a flaw in decoding fixed-width BER
 CVE-2026-64816 (RapidRAW before 1.6.0 does not validate the lutPath field in preset fi ...)
 	NOT-FOR-US: RapidRAW
 CVE-2026-63559 (An integer overflow in the UA_Variant arrayDimensions product  computa ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/open62541/open62541/commit/8098907673099afe6b726de05675146066b24d9c (v1.3.19, v1.4.18, v1.5.6)
 	NOTE: Fixed by: https://github.com/open62541/open62541/commit/a1257feec0c539f191cb2d40f72f116a901d3322 (v1.3.19, v1.4.18, v1.5.6)
@@ -5250,7 +5250,7 @@ CVE-2026-63559 (An integer overflow in the UA_Variant arrayDimensions product  c
 CVE-2026-63550 (The MMS BER decoder contains a boundary-handling flaw in the processin ...)
 	NOT-FOR-US: MZ Automation
 CVE-2026-63362 (An unsigned integer underflow in the PubSub signature verification pat ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/open62541/open62541/commit/8098907673099afe6b726de05675146066b24d9c (v1.3.19, v1.4.18, v1.5.6)
 	NOTE: Fixed by: https://github.com/open62541/open62541/commit/a1257feec0c539f191cb2d40f72f116a901d3322 (v1.3.19, v1.4.18, v1.5.6)
@@ -5265,7 +5265,7 @@ CVE-2026-63221 (CodeIgniter is a PHP full-stack web framework. From 4.3.0 throug
 CVE-2026-63220 (CodeIgniter is a PHP full-stack web framework. In versions prior to 4. ...)
 	- codeigniter <itp> (bug #471583)
 CVE-2026-63035 (A heap use-after-free vulnerability in the TransferSubscriptions servi ...)
-	- open62541 <unfixed>
+	- open62541 <unfixed> (bug #1143975)
 	[trixie] - open62541 <no-dsa> (Minor issue)
 	NOTE: Fixed by: https://github.com/open62541/open62541/commit/8098907673099afe6b726de05675146066b24d9c (v1.3.19, v1.4.18, v1.5.6)
 	NOTE: Fixed by: https://github.com/open62541/open62541/commit/a1257feec0c539f191cb2d40f72f116a901d3322 (v1.3.19, v1.4.18, v1.5.6)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac71b32a547e4a4cdec232985f7d495682847242

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac71b32a547e4a4cdec232985f7d495682847242
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260809/5f7c1d14/attachment.htm>


More information about the debian-security-tracker-commits mailing list