[Git][security-tracker-team/security-tracker][master] Add CVE-2026-76878/{aodh,watcher}

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 09:24:34 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d9ab282b by Salvatore Bonaccorso at 2026-08-20T09:46:18+02:00
Add CVE-2026-76878/{aodh,watcher}

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -57,7 +57,11 @@ CVE-2026-76880 (RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.
 CVE-2026-76879 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18  ...)
 	TODO: check
 CVE-2026-76878 (In OpenStack Aodh before 22.0.1, the alarm list API bypasses project s ...)
-	TODO: check
+	- aodh <unfixed> (bug #1144879)
+	- watcher 16.0.0-5 (bug #1144880)
+	NOTE: https://launchpad.net/bugs/2161276
+	NOTE: https://launchpad.net/bugs/2161771
+	NOTE: https://security.openstack.org/ossa/OSSA-2026-036.html
 CVE-2026-76850 (LMDeploy deserializes disaggregated-serving peer messages with pickle. ...)
 	TODO: check
 CVE-2026-76832 (Agno's PythonTools in libs/agno/agno/tools/python.py contains a path t ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9ab282b73d05a8b2d9b399f04be56068760b6da

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d9ab282b73d05a8b2d9b399f04be56068760b6da
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/c51c57a7/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list