[Git][security-tracker-team/security-tracker][master] bubblewrap DSA
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Thu Aug 27 10:20:11 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
050ec37f by Moritz Mühlenhoff at 2026-08-27T11:19:46+02:00
bubblewrap DSA
- - - - -
3 changed files:
- data/CVE/list
- data/DSA/list
- data/dsa-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -1069,6 +1069,7 @@ CVE-2023-42179 (Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incor
TODO: check
CVE-2026-XXXX [GHSA-pxhw-h44j-8pfx: sandbox escape via symlink traversal during setup]
- bubblewrap 0.12.0-1 (bug #1145655)
+ [trixie] - bubblewrap 0.12.0-1~deb13u1
NOTE: https://github.com/containers/bubblewrap/security/advisories/GHSA-pxhw-h44j-8pfx
CVE-2026-9805 (SMM IHISI command handler, FMTSWriteUseIntelLib, for FMTS command 0x32 ...)
NOT-FOR-US: Insyde
=====================================
data/DSA/list
=====================================
@@ -1,3 +1,5 @@
+[27 Aug 2026] DSA-6472-1 bubblewrap - security update
+ [trixie] - bubblewrap 0.12.0-1~deb13u1
[27 Aug 2026] DSA-6471-1 wireshark - security update
{CVE-2026-15163 CVE-2026-15164 CVE-2026-15166 CVE-2026-15167 CVE-2026-15168 CVE-2026-15169 CVE-2026-15170 CVE-2026-15171 CVE-2026-15172 CVE-2026-15174 CVE-2026-76879 CVE-2026-76880 CVE-2026-76881 CVE-2026-76882 CVE-2026-76883 CVE-2026-76884 CVE-2026-76885 CVE-2026-76886 CVE-2026-76887 CVE-2026-76888 CVE-2026-76889 CVE-2026-76890 CVE-2026-76891 CVE-2026-76917 CVE-2026-76918 CVE-2026-76919 CVE-2026-76920 CVE-2026-76921 CVE-2026-76922 CVE-2026-76923 CVE-2026-76924 CVE-2026-76926 CVE-2026-76927 CVE-2026-76928 CVE-2026-76929}
[trixie] - wireshark 4.4.18-0+deb13u1
=====================================
data/dsa-needed.txt
=====================================
@@ -23,8 +23,6 @@ amd64-microcode (carnil)
bouncycastle
possibly move to 1.85 for trixie
--
-bubblewrap (jmm)
---
cacti
probably best to move to 1.2.31
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/050ec37fe4708992c25a23e456920906eac58957
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/050ec37fe4708992c25a23e456920906eac58957
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260827/0eeb8ec3/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list