[Git][security-tracker-team/security-tracker][master] Add CVE-2026-672{6,7} for libtpms
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 12 06:04:27 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3871661a by Salvatore Bonaccorso at 2026-08-12T07:03:52+02:00
Add CVE-2026-672{6,7} for libtpms
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -449,9 +449,19 @@ CVE-2026-70304 (Heap-based buffer overflow in Windows DNS allows an authorized a
CVE-2026-70130 (Heap-based buffer overflow in Microsoft Office allows an unauthorized ...)
NOT-FOR-US: Microsoft
CVE-2026-6727 (A timing side-channel vulnerability exists in the RSA OAEP decryption ...)
- TODO: check
+ - libtpms <unfixed> (unimportant)
+ NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/fd5b4174622032e131b70389b40ec6add4da3237 (stable-0.10 branch)
+ NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/b26c0755e3ae37c41da9822027098878bdb5a196 (stable-0.9 branch)
+ NOTE: Debian binary packages not build with --disable-use-openssl-functions or -DUSE_OPENSSL_FUNCTIONS_RSA=0
+ NOTE: https://groups.google.com/g/libtpms-announce/c/xB2PqSQRA_8
CVE-2026-6726 (An information leakage vulnerability was reported in the TCG TPM 2.0 r ...)
- TODO: check
+ - libtpms 0.9.1-1
+ NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/17255da54cf8354d02369f1323dc50cfb87e2bf4 (v0.9.0)
+ NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/33a03986e0a09dde439985e0312d1c8fb3743aab (v0.8.5)
+ NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/1196ab8a3d55eaadb1c8093cd102c4057eb7d9a6 (stable-0.10 branch)
+ NOTE: Fixed by: https://github.com/stefanberger/libtpms/commit/854f547769251a8c5673e7ec5018e0ef363f4dd3 (stable-0.9 branch)
+ NOTE: Consider already fixed with the changes applied in v0.8.5 and v0.9.0
+ NOTE: https://groups.google.com/g/libtpms-announce/c/xB2PqSQRA_8
CVE-2026-69320 (Improper neutralization of special elements used in an os command ('os ...)
NOT-FOR-US: Microsoft
CVE-2026-69306 (Not failing securely ('failing open') in Visual Studio Code allows an ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3871661a27c6a15e1f4dae3a5aee909e18ffa9aa
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3871661a27c6a15e1f4dae3a5aee909e18ffa9aa
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/dd0d16aa/attachment.htm>
More information about the debian-security-tracker-commits
mailing list