[Git][security-tracker-team/security-tracker][master] Add GHSA references for svxlink issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 11 12:24:14 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
30b93050 by Salvatore Bonaccorso at 2026-08-11T13:23:36+02:00
Add GHSA references for svxlink issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,31 +1,45 @@
CVE-2026-73141 [GHSA-xmcv-mjpv-x46q: Audio decoders: stack VLA exhaustion]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-xmcv-mjpv-x46q
CVE-2026-73142 [GHSA-5xr9-fmm8-7p8x: remotetrx NetUplink: connection object leak DoS]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-5xr9-fmm8-7p8x
CVE-2026-73143 [GHSA-38fq-mrrg-8rmr: RtlTcp: malformed greeting causes daemon exit]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-38fq-mrrg-8rmr
CVE-2026-73144 [GHSA-qccg-7pw6-787v: FRN module: unbounded memory growth]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-qccg-7pw6-787v
CVE-2026-73145 [GHSA-58ph-q79f-7x9x: HTTP server: unbounded request accumulation]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-58ph-q79f-7x9x
CVE-2026-73146 [GHSA-r2gm-p682-3mpm: svxreflector: use-after-free via reentrant client deletion]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-r2gm-p682-3mpm
CVE-2026-73147 [GHSA-pc2g-2p95-4cr5: TCL command injection in reflector client]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-pc2g-2p95-4cr5
CVE-2026-73148 [GHSA-6wgq-wg3w-jgvx: svxreflector: use-after-free write via dangling JSON reference]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-6wgq-wg3w-jgvx
CVE-2026-73149 [GHSA-mh75-5pr3-qv2p: NetRx: out-of-bounds read via unvalidated MsgAudio length]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-mh75-5pr3-qv2p
CVE-2026-73150 [GHSA-4f8x-49pf-3x5v: Buffer overflow in APRS message construction]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-4f8x-49pf-3x5v
CVE-2026-73151 [GHSA-x5r8-rq62-q9cj: remotetrx: unvalidated audio length + exposed transceiver control]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-x5r8-rq62-q9cj
CVE-2026-73152 [GHSA-4g8q-rgxf-fmgf: EchoLink proxy: integer truncation in message length]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-4g8q-rgxf-fmgf
CVE-2026-73153 [GHSA-624p-cp8x-6hp6: EchoLink RTCP/SDES: out-of-bounds read]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-624p-cp8x-6hp6
CVE-2026-73154 [GHSA-5g48-xjmf-7p4q: StationData::setData stack overflow]
- svxlink 26.05.1-1
+ NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-5g48-xjmf-7p4q
CVE-2026-XXXX [GHSA-xppc-j946-vcj7: buffer overflow on 32-bit systems]
- ostree 2026.3-1 (bug #1144106)
NOTE: https://github.com/ostreedev/ostree/security/advisories/GHSA-xppc-j946-vcj7
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30b93050be70337ce78efc7b65c5e6741c5e22e7
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/30b93050be70337ce78efc7b65c5e6741c5e22e7
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260811/9c9b06a6/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list