[Git][security-tracker-team/security-tracker][master] GHSA-r7hp-698j-2h6c/xdg-dbus-proxy: mark bullseye,bookworm not-affected
Carlos Henrique Lima Melara (@charles)
gitlab at salsa.debian.org
Wed Aug 12 02:03:13 BST 2026
Carlos Henrique Lima Melara pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2b305824 by Carlos Henrique Lima Melara at 2026-08-11T21:52:19-03:00
GHSA-r7hp-698j-2h6c/xdg-dbus-proxy: mark bullseye,bookworm not-affected
Also add NOTE with commit introducing and fixing the vulnerability.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1779,7 +1779,11 @@ CVE-2026-XXXX [GHSA-q4gr-vc25-57m5]
NOTE: https://github.com/flatpak/flatpak/security/advisories/GHSA-q4gr-vc25-57m5
CVE-2026-XXXX [GHSA-r7hp-698j-2h6c: filtering for broadcast messages bypasses path/interface/member checks]
- xdg-dbus-proxy 0.1.8-1 (bug #1144129)
+ [bookworm] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
+ [bullseye] - xdg-dbus-proxy <not-affected> (Vulnerable code not present)
NOTE: https://github.com/flatpak/xdg-dbus-proxy/security/advisories/GHSA-r7hp-698j-2h6c
+ NOTE: Introduced with: https://github.com/flatpak/xdg-dbus-proxy/commit/029784535ed9cbec6c431b12ba1a9eca6c147055 (0.1.6)
+ NOTE: Fixed by: https://github.com/flatpak/xdg-dbus-proxy/commit/7cf6be73b7ad84f3c54d6fdae069c955948f78e4 (0.1.8)
CVE-2026-73141 [GHSA-xmcv-mjpv-x46q: Audio decoders: stack VLA exhaustion]
- svxlink 26.05.1-1
NOTE: https://github.com/sm0svx/svxlink/security/advisories/GHSA-xmcv-mjpv-x46q
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b305824fac7e73053a2877d248c66d3dfd84377
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2b305824fac7e73053a2877d248c66d3dfd84377
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/e8c36fb4/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list