[Git][security-tracker-team/security-tracker][master] CVE-2026-79619/zfs-linux assigned
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Aug 26 21:18:13 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
11e5a92a by Salvatore Bonaccorso at 2026-08-26T22:17:44+02:00
CVE-2026-79619/zfs-linux assigned
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -407,8 +407,6 @@ CVE-2026-79902 (A flaw was found in the Seattle FilmWorks plugin in GIMP. When p
[bullseye] - gimp <not-affected> (Vulnerable code not present)
NOTE: https://gitlab.gnome.org/GNOME/gimp/-/work_items/16582
NOTE: Fixed by: https://gitlab.gnome.org/GNOME/gimp/-/commit/fa9503bcc41e41ac0a5ae162a97486c79a7790ce
-CVE-2026-79619 (On Linux, several OpenZFS ioctl authorization checks accept a capabili ...)
- TODO: check
CVE-2026-78237 (Insufficient input validation in ABR allows a low-privileged user to i ...)
TODO: check
CVE-2026-78236 (An insecure PIN derivation mechanism in ABR allows a low-privileged us ...)
@@ -4701,9 +4699,9 @@ CVE-2026-74584 (In the Linux kernel, the following vulnerability has been resolv
[bookworm] - linux 6.1.177-1
[bullseye] - linux 5.10.262-1
NOTE: https://git.kernel.org/linus/f6b079629becfa977f9c51fe53ad2e6dcc55ef44 (7.1-rc5)
-CVE-2026-XXXX [OpenZFS Linux open zpool manipulation and escapes via unprivileged userns]
+CVE-2026-79619 [OpenZFS Linux open zpool manipulation and escapes via unprivileged userns]
- zfs-linux 2.4.4-1
- [trixie] - zfs-linux 2.3.9-0+deb13u1
+ NOTE: https://github.com/advisories/GHSA-mhf5-q8gw-qg9v
NOTE: https://www.openwall.com/lists/oss-security/2026/08/16/5
NOTE: https://github.com/openzfs/zfs/issues/18936
NOTE: https://github.com/openzfs/zfs/pull/18959
=====================================
data/DSA/list
=====================================
@@ -17,6 +17,7 @@
{CVE-2026-43804 CVE-2026-64713 CVE-2026-64719 CVE-2026-64728 CVE-2026-64730 CVE-2026-64757 CVE-2026-64783}
[trixie] - webkit2gtk 2.52.6-1~deb13u1
[24 Aug 2026] DSA-6462-1 zfs-linux - security update
+ {CVE-2026-79619}
[trixie] - zfs-linux 2.3.9-0+deb13u1
[23 Aug 2026] DSA-6461-1 thunderbird - security update
{CVE-2026-74934 CVE-2026-74935 CVE-2026-74936 CVE-2026-74939 CVE-2026-74940 CVE-2026-74941 CVE-2026-74942 CVE-2026-74943 CVE-2026-74944 CVE-2026-74945 CVE-2026-74946 CVE-2026-74948 CVE-2026-74949 CVE-2026-74953 CVE-2026-74957 CVE-2026-74959 CVE-2026-74960 CVE-2026-74962 CVE-2026-74963 CVE-2026-74964 CVE-2026-74965 CVE-2026-74967 CVE-2026-74969 CVE-2026-74971 CVE-2026-74972 CVE-2026-74973 CVE-2026-74974 CVE-2026-74976 CVE-2026-74983 CVE-2026-74987 CVE-2026-74990}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11e5a92a657b90e9d9ad0b642fccd5f976fed110
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/11e5a92a657b90e9d9ad0b642fccd5f976fed110
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260826/42388859/attachment.htm>
More information about the debian-security-tracker-commits
mailing list