[Git][security-tracker-team/security-tracker][master] Update status for weechat issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Aug 18 16:58:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
4d3656cf by Salvatore Bonaccorso at 2026-08-18T17:56:12+02:00
Update status for weechat issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -22529,17 +22529,20 @@ CVE-2026-11391 (Tanium addressed a SQL injection vulnerability in Patch.)
 	NOT-FOR-US: Tanium
 CVE-2026-11351 (The ShinyStat Analytics WordPress plugin before 1.0.17 does not perfor ...)
 	NOT-FOR-US: WordPress plugin
-CVE-2026-XXXX [relay: use-after-free and double free when a remote relay sends an event with an array as body]
+CVE-2026-XXXX [GHSA-hx59-4hq9-6vmw: relay: use-after-free and double free when a remote relay sends an event with an array as body]
 	- weechat 4.9.5-1 (bug #1142894)
 	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-hx59-4hq9-6vmw
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/3be2b43ffbc05e1be2c5135ba1ac895eee69afeb (v4.9.5)
 	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-14/
-CVE-2026-XXXX [Use-after-free in the irc plugin when a batched message disconnects the server]
+CVE-2026-XXXX [GHSA-rfmh-3r7f-jpx5: Use-after-free in the irc plugin when a batched message disconnects the server]
 	- weechat 4.9.5-1 (bug #1142894)
 	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-rfmh-3r7f-jpx5
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/42db6cf48485ce1fddd997f528d66b4552878059 (v4.9.5)
 	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-13/
-CVE-2026-XXXX [Stack buffer overflow in irc_message_split_join when building a JOIN with keys]
+CVE-2026-XXXX [GHSA-q2xg-9ggx-77mr: Stack buffer overflow in irc_message_split_join when building a JOIN with keys]
 	- weechat 4.9.5-1 (bug #1142894)
 	NOTE: https://github.com/weechat/weechat/security/advisories/GHSA-q2xg-9ggx-77mr
+	NOTE: Fixed by: https://github.com/weechat/weechat/commit/55126dbf4a0d6edcb39d646360a3ca597009ceff (v4.9.5)
 	NOTE: https://weechat.org/doc/weechat/security/WSA-2026-12/
 CVE-2026-XXXX [WSA-2026-11: Logger: Write of logger file outside of configured path]
 	- weechat 4.9.4-1



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d3656cf5e1c1e60cdc347e891835e03f5d07c86

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/4d3656cf5e1c1e60cdc347e891835e03f5d07c86
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260818/62221050/attachment.htm>


More information about the debian-security-tracker-commits mailing list