[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Aug 20 18:10:05 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
5957f380 by Salvatore Bonaccorso at 2026-08-20T18:03:22+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -7,109 +7,109 @@ CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: Poly1305 and OCB AEADs]
CVE-2026-8619 (An unauthenticated denial-of-service vulnerability was identified in T ...)
NOT-FOR-US: TPLink
CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with custom en ...)
- - expat <unfixed>
+ - expat <unfixed> (bug #1144927)
NOTE: https://github.com/libexpat/libexpat/pull/1322
CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentr ...)
- - expat <unfixed>
+ - expat <unfixed> (bug #1144926)
NOTE: https://github.com/libexpat/libexpat/pull/1326
CVE-2026-76929 (Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-84.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21460
CVE-2026-76928 (X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-87.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21469
CVE-2026-76927 (H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 a ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-77.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21447
CVE-2026-76926 (BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 4.4.0 to 4.4 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-70.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21435
CVE-2026-76924 (Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.1 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-78.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21449
CVE-2026-76923 (Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 4.6.7 and 4 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-79.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21451
CVE-2026-76922 (Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 4.6.7 and 4. ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-80.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21452
CVE-2026-76921 (CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-83.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21458
NOTE: https://gitlab.com/wireshark/wireshark/-/issues/21457 (private)
CVE-2026-76920 (3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-81.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21454
CVE-2026-76919 (ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-86.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21467
CVE-2026-76918 (SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-85.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21465
CVE-2026-76917 (Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 4.6.7 and ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-91.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21488
CVE-2026-76891 (Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-64
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21395
CVE-2026-76890 (Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows denial of ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-65
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21399
CVE-2026-76889 (UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-66
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21413
CVE-2026-76888 (RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-67
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21396
CVE-2026-76887 (Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 4.4.0 t ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-69.html
CVE-2026-76886 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-75.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21439
CVE-2026-76885 (Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.1 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-71.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21414
CVE-2026-76884 (ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows den ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-72.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21415
CVE-2026-76883 (Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4. ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-74.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21427
CVE-2026-76882 (Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 and 4.4 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-73.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21424
CVE-2026-76881 (CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-76.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21446
CVE-2026-76880 (RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 all ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-88.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21478
CVE-2026-76879 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-89.html
NOTE: https://gitlab.com/wireshark/wireshark/-/issues/21480 (private)
CVE-2026-76878 (In OpenStack Aodh before 22.0.1, the alarm list API bypasses project s ...)
@@ -795,22 +795,22 @@ CVE-2026-76224 (ArcadeDB before 26.8.1 (arcadedb-gremlin, affected <= 26.7.3) co
CVE-2026-76223 (ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to enforce th ...)
NOT-FOR-US: ArcadeDB
CVE-2026-76222 (GitPython before 3.1.58 fails to validate submodule names from .gitmod ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc
CVE-2026-76221 (GitPython before 3.1.58 contains a config-name injection vulnerability ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-jm78-9fvv-mhgr
CVE-2026-76220 (GitPython before 3.1.58 contains a command execution vulnerability in ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j
CVE-2026-76219 (GitPython versions before 3.1.58 contain an arbitrary file overwrite v ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p
CVE-2026-76218 (GitPython before 3.1.58 contains a remote code execution vulnerability ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r
CVE-2026-76217 (GitPython versions before 3.1.58 fail to validate options passed to gi ...)
- - python-git <unfixed>
+ - python-git <unfixed> (bug #1144929)
NOTE: https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc
CVE-2026-76216 (Vikunja through 2.4.0 contains a principal-type confusion vulnerabilit ...)
NOT-FOR-US: Vikunja
@@ -1661,7 +1661,7 @@ CVE-2026-71153 (Vulnerability in the Helidon product of Oracle Fusion Middleware
CVE-2026-71152 (Vulnerability in the Helidon product of Oracle Fusion Middleware (comp ...)
NOT-FOR-US: Oracle
CVE-2026-71151 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71150 (Vulnerability in the Oracle Hyperion Financial Management product of O ...)
NOT-FOR-US: Oracle
CVE-2026-71149 (Vulnerability in the Oracle Hyperion Financial Management product of O ...)
@@ -1681,37 +1681,37 @@ CVE-2026-71143 (Vulnerability in the Oracle Communications Unified Inventory Man
CVE-2026-71142 (Vulnerability in the Oracle Communications Unified Inventory Managemen ...)
NOT-FOR-US: Oracle
CVE-2026-71141 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71140 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71139 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71138 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71137 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71136 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71135 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71134 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71132 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71131 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71130 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71129 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71128 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71127 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71126 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71125 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71124 (Vulnerability in the Oracle Access Manager product of Oracle Fusion Mi ...)
NOT-FOR-US: Oracle
CVE-2026-71123 (Vulnerability in the Oracle Hyperion Financial Management product of O ...)
@@ -1729,13 +1729,13 @@ CVE-2026-71118 (Vulnerability in the Oracle Hyperion Financial Management produc
CVE-2026-71117 (Vulnerability in the Oracle Hyperion Financial Management product of O ...)
NOT-FOR-US: Oracle
CVE-2026-71116 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71115 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71114 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71113 (Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualiza ...)
- - virtualbox <unfixed>
+ - virtualbox <unfixed> (bug #1144928)
CVE-2026-71112 (Vulnerability in the PeopleSoft Enterprise FIN Common Objects product ...)
NOT-FOR-US: Oracle
CVE-2026-71111 (Vulnerability in the Oracle Identity Manager product of Oracle Fusion ...)
@@ -4350,7 +4350,7 @@ CVE-2026-66621 (Unauthenticated Cross Site Scripting (XSS) in Ultimate Dashboard
CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability caused ...)
- - expat <unfixed>
+ - expat <unfixed> (bug #1144925)
NOTE: https://github.com/libexpat/libexpat/pull/1321
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
@@ -12057,21 +12057,21 @@ CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) in the user management comp
CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student Information ...)
NOT-FOR-US: SourceCodester
CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes in 4.6.0 ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
[trixie] - wireshark <not-affected> (Only affects 4.6)
[bookworm] - wireshark <not-affected> (Only affects 4.6)
[bullseye] - wireshark <not-affected> (Only affects 4.6)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-82.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21455
CVE-2026-19695 (Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows denial of ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
[trixie] - wireshark <not-affected> (Only affects 4.6)
[bookworm] - wireshark <not-affected> (Only affects 4.6)
[bullseye] - wireshark <not-affected> (Only affects 4.6)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-90.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21475
CVE-2026-19694 (TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial of servic ...)
- - wireshark <unfixed>
+ - wireshark <unfixed> (bug #1144924)
NOTE: https://www.wireshark.org/security/wnpa-sec-2026-68.html
NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21389
CVE-2026-19487 (Perl versions from 5.9.4 before 5.41.9 produce incorrect regular expre ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5957f380a8e24a96af289e995d21212bc010848b
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5957f380a8e24a96af289e995d21212bc010848b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/2720ab47/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list