[Git][security-tracker-team/security-tracker][master] Two CVEs assigned for c-ares issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 10 18:03:50 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4bfba777 by Salvatore Bonaccorso at 2026-08-10T16:29:20+02:00
Two CVEs assigned for c-ares issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -31162,7 +31162,7 @@ CVE-2026-59089 (A flaw was found in GIMP. The PlayStation TIM loader, responsibl
 	[bullseye] - gimp <not-affected> (PlayStation TIM loader plug-ins/common/file-tim.c added in GIMP 3.x; 2.10 has no such loader)
 	NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16493
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/53cdb27fa2b1676d11e9677c9975b5ad7b61b2ee
-CVE-2026-XXXX [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via unvalidated DNS header record counts]
+CVE-2026-69186 [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via unvalidated DNS header record counts]
 	- c-ares 1.34.7-1
 	[trixie] - c-ares <no-dsa> (Minor issue)
 	[bookworm] - c-ares <not-affected> (New DNS-record parser prealloc (ares_dns_record_rr_prealloc/ares_array_set_size) not present; introduced in the 1.20+ rewrite)
@@ -31171,7 +31171,7 @@ CVE-2026-XXXX [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via u
 	NOTE: https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj
 	NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/eaded4cb200b2a5f8d73f11021ff7c8d6968aaab (main)
 	NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/e47c203f91cd8b749c8736bc18d75a31ffdec8f4 (v1.34.7)
-CVE-2026-XXXX [GHSA-pjmc-gx33-gc76: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains]
+CVE-2026-69184 [GHSA-pjmc-gx33-gc76: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains]
 	- c-ares 1.34.7-1
 	[trixie] - c-ares <no-dsa> (Minor issue)
 	[bookworm] - c-ares <not-affected> (Vulnerable 1.34 DNS-name decompression parser (src/lib/record/ares_dns_name.c, ares_buf) not present)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4bfba777df1cd2dd7adcb82666bccf8da34335f7

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4bfba777df1cd2dd7adcb82666bccf8da34335f7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260810/81698d43/attachment.htm>


More information about the debian-security-tracker-commits mailing list