[Git][security-tracker-team/security-tracker][master] new mongoose issues
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Wed Aug 12 11:54:50 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
dce10923 by Moritz Muehlenhoff at 2026-08-12T12:54:30+02:00
new mongoose issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1,3 +1,61 @@
+CVE-2026-52073 [ppp_handle_ipcp attacker-controlled IPCP length -- OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52054 [find_opt zero-length PPP option -- infinite loop]
+ - mongoose 7.22+ds-1
+CVE-2026-52068 [rx_ndp_na NDP NA missing option length check -- OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52070 [rx_ndp_ns ICMPv6 NS minimum length insufficient -- OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52053 [rx_ip6 IPv6 extension header OOB read; 16-bit len wrap]
+ - mongoose 7.22+ds-1
+CVE-2026-52062 [NDP RA allows any value for MTU]
+ - mongoose 7.22+ds-1
+CVE-2026-52047 [w5100_rx wraparound RX path copies n instead of r bytes]
+ - mongoose 7.22+ds-1
+CVE-2026-52076 [cyw_spi_tx SPI alignment padding indexes uint32_t* buffer with byte offset]
+ - mongoose 7.22+ds-1
+CVE-2026-52067 [rx_ip truncated DHCP options size_t underflow OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52069 [rx_dhcp_client 32-bit overflow in DHCP lease millisecond conversion]
+ - mongoose 7.22+ds-1
+CVE-2026-52078 [opendir() stack overflow via wcscat on MAX_PATH path]
+ - mongoose 7.22+ds-1
+CVE-2026-52079 [ENET_IRQHandler RX descriptor not re-owned on error -- RX ring stall]
+ - mongoose 7.22+ds-1
+CVE-2026-52064 [DNS transaction ID is sequential -- enables response injection]
+ - mongoose 7.22+ds-1
+CVE-2026-52048 [MQTT v5 properties bounds check uses relative offset against absolute position]
+ - mongoose 7.22+ds-1
+CVE-2026-52056 [skip_chunk off-by-one OOB read in chunked HTTP CRLF check]
+ - mongoose 7.22+ds-1
+CVE-2026-52050 [precompute_slide_window NULL deref on OOM / more_comps NULL deref after failed calloc / bi_initialize / alloc NULL deref on OOM]
+ - mongoose 7.22+ds-1
+CVE-2026-52072 [mg_tls_client_recv_hello size_t underflow in ext_len bounds check / mg_tls_client_recv_hello ext_len fixed-offset OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52051 [mg_tls_server_recv_hello session_id_len OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52065 [mg_tls_client_recv_hello key_share extension OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52071 [mg_tls_verify_cert_signature OOB read for short ECDSA integers]
+ - mongoose 7.22+ds-1
+CVE-2026-52052 [mg_tls_parse_cert_der pubkey BIT STRING length underflow -- OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52058 [mg_der_to_tlv long-form DER length OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52055 [mg_der_to_tlv long-form DER length OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52057 [mg_der_find_oid unbounded recursion on constructed DER tags]
+ - mongoose 7.22+ds-1
+CVE-2026-52061 [mg_tls_recv_cert certificate chain length unchecked -- OOB read]
+ - mongoose 7.22+ds-1
+CVE-2026-52075 [mg_random rand() fallback used for TLS secrets]
+ - mongoose 7.22+ds-1
+CVE-2026-52066 [TLS certificate notAfter validated against hardcoded 2025-01-01 string]
+ - mongoose 7.22+ds-1
+CVE-2026-52060 [TLS certificate notAfter validated against hardcoded 2025-01-01 string]
+ - mongoose 7.22+ds-1
+CVE-2026-52059 [RSA-PSS CertificateVerify checks only 0xbc trailer]
+ - mongoose 7.22+ds-1
CVE-2026-19566
- libnet-cidr-set-perl 0.23-1
NOTE: https://lists.security.metacpan.org/cve-announce/msg/42620063/
@@ -32357,7 +32415,7 @@ CVE-2026-12170 (The AcyMailing \u2013 An Ultimate Newsletter Plugin and Marketin
CVE-2026-12116 (A vulnerability in the Xerte Online Tools allows for RCE through the a ...)
NOT-FOR-US: Xerte Online Tools
CVE-2026-11404 (Cesanta Mongoose before 7.22 contains an out-of-bounds read in the bui ...)
- TODO: check
+ - mongoose 7.22+ds-1
CVE-2026-11359 (The Memberships and User Profiles for WooCommerce \u2013 ProfileGrid W ...)
NOT-FOR-US: WordPress plugin
CVE-2026-0287 (Multiple denial of service vulnerabilities in Palo Alto Networks PAN-O ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dce1092332152b16ca7363aa2038ad3c2572f178
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/dce1092332152b16ca7363aa2038ad3c2572f178
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260812/f25284c2/attachment.htm>
More information about the debian-security-tracker-commits
mailing list