[Git][security-tracker-team/security-tracker][master] Track fixed version for golang-golang-x-image issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 22 05:55:32 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fdd8ebf8 by Salvatore Bonaccorso at 2026-08-22T06:53:19+02:00
Track fixed version for golang-golang-x-image issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -12170,7 +12170,7 @@ CVE-2026-49263 (Capstone is a disassembly framework. Prior to version 6.0.0-Alph
 CVE-2026-48528 (Metacat is data repository software that helps researchers preserve, s ...)
 	NOT-FOR-US: Metacat
 CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amo ...)
-	- golang-golang-x-image <unfixed> (bug #1144496)
+	- golang-golang-x-image 0.45.0-1 (bug #1144496)
 	[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
 	NOTE: https://github.com/golang/go/issues/80069
 	NOTE: Fixed by: https://github.com/golang/image/commit/981eaa05a5065f5dd09c3139029c0d7dbda956d8 (v0.45.0)
@@ -56486,7 +56486,7 @@ CVE-2026-47193 (OpenProject is open-source, web-based project management softwar
 CVE-2026-46710 (Notepad++ is a free and open-source source code editor. From 8.9.4 unt ...)
 	NOT-FOR-US: Notepad++
 CVE-2026-46604 (The TIFF decoder can panic when decoding an invalid image with an out- ...)
-	- golang-golang-x-image <unfixed> (bug #1140919)
+	- golang-golang-x-image 0.45.0-1 (bug #1140919)
 	[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
 	[bookworm] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS on 32-bit)
 	[bullseye] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS on 32-bit)
@@ -57472,14 +57472,14 @@ CVE-2026-50739 (A bypass for CVE\u20112026\u201134913 exists with proper ownersh
 CVE-2026-50176 (The WebSocket Application Programming Interface lacks restrictions on  ...)
 	NOT-FOR-US: Evoke
 CVE-2026-46602 (The TIFF decoder does not set a limit on the size of tiles in tiled im ...)
-	- golang-golang-x-image <unfixed> (bug #1140919)
+	- golang-golang-x-image 0.45.0-1 (bug #1140919)
 	[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
 	[bookworm] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS)
 	[bullseye] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS)
 	NOTE: https://github.com/golang/go/issues/79905
 	NOTE: Fixed by: https://github.com/golang/image/commit/304d4cc4ee82f96f864f1a4c9a3ae30a4016c9ce (v0.43.0)
 CVE-2026-46601 (The webp decoder can panic when processing a VP8 chunk with dimensions ...)
-	- golang-golang-x-image <unfixed> (bug #1140919)
+	- golang-golang-x-image 0.45.0-1 (bug #1140919)
 	[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
 	[bookworm] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS)
 	[bullseye] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fdd8ebf81a292b4564d2ec647a633553184f8d4c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fdd8ebf81a292b4564d2ec647a633553184f8d4c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/c2eacea9/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list