[Git][security-tracker-team/security-tracker][master] Add two new bluez issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 26 08:20:28 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
55fca7c1 by Salvatore Bonaccorso at 2026-08-26T09:18:42+02:00
Add two new bluez issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -36,10 +36,14 @@ CVE-2026-80191 (GROWI applies its page-viewer permission check to attachment req
TODO: check
CVE-2026-80189 (LeafWiki extracts an uploaded ZIP archive without limiting how much da ...)
TODO: check
-CVE-2026-80186 (A stack-based buffer overflow vulnerability exists in BlueZ, the Linux ...)
- TODO: check
-CVE-2026-80185 (BlueZ sdp-xml.c type confusion via RegisterProfile(ServiceRecord) can ...)
- TODO: check
+CVE-2026-80186 [Stack Overflow in name2utf8 causes DoS and potential code execution]
+ - bluez <unfixed>
+ NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-68h6-5qgp-3975
+ NOTE: Fixed by: https://github.com/bluez/bluez/commit/381b5d0d208972586282116d333865ba93b8dec2
+CVE-2026-80185 [unprivileged-local and adjacent-LE-peer leads to arbitrary code execution as root]
+ - bluez <unfixed>
+ NOTE: https://github.com/bluez/bluez/security/advisories/GHSA-7mmr-gwqx-vc34
+ NOTE: Fixed by: https://github.com/bluez/bluez/commit/985e643d78b09afc81d606bc0a08581fc05b1b15
CVE-2026-80138 (ClipBucket V5's web installer fails to properly validate or escape the ...)
TODO: check
CVE-2026-80104 (DB-GPT builds the destination path for an uploaded skill from the mult ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/55fca7c14b52d650b65d49d7664ceb501c7d4c97
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/55fca7c14b52d650b65d49d7664ceb501c7d4c97
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/54b1d54d/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list