[Git][security-tracker-team/security-tracker][master] Triage CVE-2026-46603 in golang-golang-x-image for bookworm and bullseye LTS.
Chris Lamb (@lamby)
lamby at debian.org
Sat Aug 22 18:52:20 BST 2026
Chris Lamb pushed to branch master at Debian Security Tracker / security-tracker
Commits:
f49fa811 by Chris Lamb at 2026-08-22T10:52:03-07:00
Triage CVE-2026-46603 in golang-golang-x-image for bookworm and bullseye LTS.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -13064,6 +13064,8 @@ CVE-2026-48528 (Metacat is data repository software that helps researchers prese
CVE-2026-46603 (VP8L decoding in golang.org/x/image/vp8l can allocate an excessive amo ...)
- golang-golang-x-image 0.45.0-1 (bug #1144496)
[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+ [bookworm] - golang-golang-x-image <postponed> (Minor issue; can be fixed in next update)
+ [bullseye] - golang-golang-x-image <postponed> (Minor issue; can be fixed in next update)
NOTE: https://github.com/golang/go/issues/80069
NOTE: Fixed by: https://github.com/golang/image/commit/981eaa05a5065f5dd09c3139029c0d7dbda956d8 (v0.45.0)
CVE-2026-46439 (compliance-trestle is a tooling platform for managing compliance as co ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f49fa811a1fc81d772cdce885792cf09e2a05633
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f49fa811a1fc81d772cdce885792cf09e2a05633
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260822/bae3d4a7/attachment.htm>
More information about the debian-security-tracker-commits
mailing list