[Git][security-tracker-team/security-tracker][master] Add new buildkit issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 22 07:54:08 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f41988aa by Salvatore Bonaccorso at 2026-08-22T08:53:52+02:00
Add new buildkit issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1834,7 +1834,9 @@ CVE-2026-75595 (Netty is an asynchronous, event-driven network application frame
NOTE: https://github.com/netty/netty/pull/17217
NOTE: Fixed by: https://github.com/netty/netty/commit/9e0519239108a69b7e9bbc5e9182ee139a0d7961 (netty-4.1.137.Final)
CVE-2026-75593 (BuildKit is a toolkit for converting source code to build artifacts in ...)
- TODO: check
+ - golang-github-moby-buildkit <itp> (bug #1094971)
+ NOTE: https://github.com/moby/buildkit/security/advisories/GHSA-g2h8-426c-7976
+ TODO: check security impact on docker.io
CVE-2026-75569 (A flaw was found in mce-operator-bundle. The build process fetches and ...)
NOT-FOR-US: mce-operator-bundle
CVE-2026-75476 (Tanium addressed a compression bomb vulnerability in Threat Response.)
@@ -1903,9 +1905,17 @@ CVE-2026-62727 (Concurrent execution using shared resource with improper synchro
CVE-2026-62317 (Logto is the modern, open-source auth infrastructure for SaaS and AI a ...)
NOT-FOR-US: Logto
CVE-2026-61712 (BuildKit is a toolkit for converting source code to build artifacts in ...)
- TODO: check
+ - golang-github-moby-buildkit <itp> (bug #1094971)
+ NOTE: https://github.com/moby/buildkit/security/advisories/GHSA-72x6-4j93-7w86
+ NOTE: Fixed by: https://github.com/moby/buildkit/commit/69a3924648e485acb3faad3081e03a8554431255 (v0.31.1)
+ NOTE: Fixed by: https://github.com/moby/buildkit/commit/408266e4ba254cecabedaacdad6905de4d2a75a1 (v0.32.0-rc1)
+ TODO: check potential security impact on docker.io
CVE-2026-61711 (BuildKit is a toolkit for converting source code to build artifacts in ...)
- TODO: check
+ - golang-github-moby-buildkit <itp> (bug #1094971)
+ NOTE: https://github.com/moby/buildkit/security/advisories/GHSA-7236-3392-c5c6
+ NOTE: Fixed by: https://github.com/moby/buildkit/commit/3ea6dd0ce7d269cdb8aa23348718e2c1bf64f109 (v0.31.1)
+ NOTE: Fixed by: https://github.com/moby/buildkit/commit/64bbec89ca43dd95b2853edeca240c33c6729910 (v0.32.0-rc1)
+ TODO: check security impact on docker.io
CVE-2026-61556 (LiquidJS is a Shopify / GitHub Pages compatible template engine in pur ...)
NOT-FOR-US: LiquidJS
CVE-2026-59992 (Tina is a headless content management system. Prior to next-tinacms-s3 ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f41988aa876b3d530227804ef2858b4b00f29209
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f41988aa876b3d530227804ef2858b4b00f29209
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/0c71f4aa/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list