[Git][security-tracker-team/security-tracker][master] Update status for two expat issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Aug 20 22:24:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a8dcf972 by Salvatore Bonaccorso at 2026-08-20T22:21:09+02:00
Update status for two expat issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -92,7 +92,11 @@ CVE-2026-76987 (A security flaw has been discovered in liftoff-sr CIPster 180252
 CVE-2026-76833 (@cgauge/yaml npm package contains an arbitrary code execution vulnerab ...)
 	TODO: check
 CVE-2026-76641 (Expat through 2.8.3 contains an out-of-bounds read vulnerability that  ...)
-	TODO: check
+	- expat <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/libexpat/libexpat/pull/1331
+	NOTE: Introduced with: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
+	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf
+	NOTE: Vulnerability covered by this CVE is introduced by the fix for CVE-2026-66046.
 CVE-2026-76635 (baserCMS before 5.3.0 contains a SQL injection vulnerability in BcData ...)
 	TODO: check
 CVE-2026-76634 (WeGIA before 3.9.2 contains an insecure direct object reference vulner ...)
@@ -4942,6 +4946,8 @@ CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability c
 	NOTE: https://github.com/libexpat/libexpat/pull/1321
 	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
 	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
+	NOTE: Requires followup to not open CVE-2026-76641:
+	NOTE: https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf
 CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
 	NOT-FOR-US: Vitess
 CVE-2026-63643 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8dcf972cf4f6b70ddc39be81dafab92994f0eb0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a8dcf972cf4f6b70ddc39be81dafab92994f0eb0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260820/b85f7fe0/attachment.htm>


More information about the debian-security-tracker-commits mailing list