[Git][security-tracker-team/security-tracker][master] Track fixed version for openssl via unstable
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Aug 25 22:04:22 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
599efa77 by Salvatore Bonaccorso at 2026-08-25T23:03:57+02:00
Track fixed version for openssl via unstable
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -563,7 +563,7 @@ CVE-2026-XXXX [GHSA-75g3-96fr-7p2r: SABnzbd PAR2 path traversal enabling cross-j
NOTE: Fixed by: https://github.com/sabnzbd/sabnzbd/commit/c57af32131216de3e1df3097a0cce06c8c99ceb8 (5.1.2)
CVE-2026-18798 (Issue summary: QUIC server may double free QRX (QUIC record layer RX) ...)
{DSA-6465-1}
- - openssl <unfixed>
+ - openssl 3.6.4-1
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
NOTE: https://github.com/openssl/openssl/commit/a14a1deac403522fbeafabcb198503cf6caa7dc4 (openssl-4.0.2)
@@ -572,7 +572,7 @@ CVE-2026-18798 (Issue summary: QUIC server may double free QRX (QUIC record laye
NOTE: https://openssl-library.org/news/secadv/20260825.txt
CVE-2026-63072 (Issue summary: OpenSSL CMS decryption sizes the key-unwrap output buff ...)
{DSA-6465-1}
- - openssl <unfixed>
+ - openssl 3.6.4-1
NOTE: https://github.com/openssl/openssl/commit/9530a5fd1aacaeccdced4478ea2340a480613335 (openssl-4.0.2)
NOTE: https://github.com/openssl/openssl/commit/2a3dac874c8057c1f0186849bf1ede1ae7b6b756 (openssl-3.6.4)
NOTE: https://github.com/openssl/openssl/commit/87784ad619af36b8807c2044b3940006fccc1e42 (openssl-3.5.8)
@@ -580,7 +580,7 @@ CVE-2026-63072 (Issue summary: OpenSSL CMS decryption sizes the key-unwrap outpu
NOTE: https://openssl-library.org/news/secadv/20260825.txt
CVE-2026-63076 (Issue summary: OpenSSL CMP password based protection verification only ...)
{DSA-6465-1}
- - openssl <unfixed>
+ - openssl 3.6.4-1
NOTE: https://github.com/openssl/openssl/commit/a17cc8d612ecff6d94a9b7ca8b5283ddf5ff570e (openssl-4.0.2)
NOTE: https://github.com/openssl/openssl/commit/a7af46a92d0ce19a90e669ef56d2576a07924226 (openssl-3.6.4)
NOTE: https://github.com/openssl/openssl/commit/cdacfff557389abfa9e4615abded2ec984517d6c (openssl-3.5.8)
@@ -588,7 +588,7 @@ CVE-2026-63076 (Issue summary: OpenSSL CMP password based protection verificatio
NOTE: https://openssl-library.org/news/secadv/20260825.txt
CVE-2026-14457 (Issue summary: In a server or client configuration with RFC7250 Raw Pu ...)
{DSA-6465-1}
- - openssl <unfixed>
+ - openssl 3.6.4-1
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
NOTE: https://github.com/openssl/openssl/commit/dad836b071da6579510c968615848ba03cac593b (openssl-4.0.2)
@@ -597,7 +597,7 @@ CVE-2026-14457 (Issue summary: In a server or client configuration with RFC7250
NOTE: https://openssl-library.org/news/secadv/20260825.txt
CVE-2026-54874 (Issue summary: Receiving a DTLS record for a future epoch while a hand ...)
{DSA-6465-1}
- - openssl <unfixed>
+ - openssl 3.6.4-1
NOTE: https://github.com/openssl/openssl/commit/cc0c6710917cd5eec001b297355d2ba723505107 (openssl-4.0.2)
NOTE: https://github.com/openssl/openssl/commit/f52ffc11b90737ac89083909618dc2e1f42c561c (openssl-3.6.4)
NOTE: https://github.com/openssl/openssl/commit/4808b5d64176451f3d93d87d0ac9c81a9b13fb23 (openssl-3.5.8)
@@ -605,7 +605,7 @@ CVE-2026-54874 (Issue summary: Receiving a DTLS record for a future epoch while
NOTE: https://openssl-library.org/news/secadv/20260825.txt
CVE-2026-63073 (Issue summary: OpenSSL CMP response validation passed an unexpected re ...)
{DSA-6465-1}
- - openssl <unfixed>
+ - openssl 3.6.4-1
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
NOTE: https://github.com/openssl/openssl/commit/7eb2e3ec9d1d4f35c8022fccd4b03398b3f33e21 (openssl-4.0.2)
@@ -614,7 +614,7 @@ CVE-2026-63073 (Issue summary: OpenSSL CMP response validation passed an unexpec
NOTE: https://openssl-library.org/news/secadv/20260825.txt
CVE-2026-63074 (Issue summary: The OpenSSL Certificate Management Protocol (CMP) cache ...)
{DSA-6465-1}
- - openssl <unfixed>
+ - openssl 3.6.4-1
NOTE: https://github.com/openssl/openssl/commit/74ae7f6df47a5767c1010b88c47507dfc5b32c46 (openssl-4.0.2)
NOTE: https://github.com/openssl/openssl/commit/01e567978a55fba18142a230380c31296049fae7 (openssl-3.6.4)
NOTE: https://github.com/openssl/openssl/commit/75360af9650d4e0c82ba0050c5c9912cd79e54af (openssl-3.5.8)
@@ -622,7 +622,7 @@ CVE-2026-63074 (Issue summary: The OpenSSL Certificate Management Protocol (CMP)
NOTE: https://openssl-library.org/news/secadv/20260825.txt
CVE-2026-63075 (Issue summary: When OpenSSL processes QUIC traffic from a peer that re ...)
{DSA-6465-1}
- - openssl <unfixed>
+ - openssl 3.6.4-1
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
NOTE: https://github.com/openssl/openssl/commit/7308946576b12e64b8be53bcf0a120354b2b42bc (openssl-4.0.2)
@@ -4096,7 +4096,7 @@ CVE-2026-XXXX [OSSN-0103]
NOTE: https://bugs.launchpad.net/manila/+bug/2161287
CVE-2026-75803 (Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an empty ...)
{DSA-6465-1}
- - openssl <unfixed> (bug #1145172)
+ - openssl 3.6.4-1 (bug #1145172)
NOTE: https://github.com/openssl/openssl/commit/6c7aa6f8f6449b7fe0137ee8be65fcd239bd7d6a (openssl-4.0.2)
NOTE: https://github.com/openssl/openssl/commit/3621257986e27e540bf96a11570929a6e5a9e05b (openssl-3.6.4)
NOTE: https://github.com/openssl/openssl/commit/bdeb0cd994d915342787f117ee75044f0dc36f34 (openssl-3.5.8)
@@ -16350,7 +16350,7 @@ CVE-2026-15413 (The Link Factory WordPress plugin is a backdoor. Distributed as
NOT-FOR-US: WordPress plugin
CVE-2026-14456 (Issue summary: When an OpenSSL QUIC server (Listener SSL object) proce ...)
{DSA-6465-1}
- - openssl <unfixed> (bug #1144615)
+ - openssl 3.6.4-1 (bug #1144615)
NOTE: https://openssl-library.org/news/secadv/20260813.txt
NOTE: https://github.com/openssl/openssl/commit/f2f1465f2d2e5c61dfeac4d20fd093797d821139 (openssl-4.0.2)
NOTE: https://github.com/openssl/openssl/commit/4084152e040329ca0194c4c1750b9b46d00a5b6b (openssl-3.6.4)
@@ -25993,7 +25993,7 @@ CVE-2026-0516 (A improper neutralization of HTTP Headers for Scripting Syntax vu
CVE-2025-70962 (Zosi C519M V4.2.8.823C01450BA is vulnerable to Incorrect Access Contro ...)
NOT-FOR-US: Zosi C519M
CVE-2026-54876 (Issue summary: A malicious TLS server can cause a memory leak in a TLS ...)
- - openssl <unfixed> (bug #1143841)
+ - openssl 3.6.4-1 (bug #1143841)
[trixie] - openssl <not-affected> (Vulnerable code not present)
[bookworm] - openssl <not-affected> (Vulnerable code not present)
[bullseye] - openssl <not-affected> (Vulnerable code not present)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/599efa77094a026bf7d5460c5fb188f0031dae4e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/599efa77094a026bf7d5460c5fb188f0031dae4e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260825/d815a1f0/attachment.htm>
More information about the debian-security-tracker-commits
mailing list