[Git][security-tracker-team/security-tracker][master] Add bug clones for CVE-2026-12087 and CVE-2026-7010

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Aug 29 15:50:22 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7b652229 by Niko Tyni at 2026-08-29T16:34:54+02:00
Add bug clones for CVE-2026-12087 and CVE-2026-7010

These packages have separate copies of the affected modules.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -75194,7 +75194,7 @@ CVE-2026-53705 (A flaw was found in GStreamer's WavPack audio decoder in gst-plu
 	NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/9326c636a22a678952a6cae6518465d35d441a87 (1.28.4)
 	NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f7cb3e0288627cce919e656584b852ac8605c922 (1.28.4)
 CVE-2026-12087 (Socket versions before 2.041 for Perl have an out-of-bounds heap read. ...)
-	- libsocket-perl 2.041-1
+	- libsocket-perl 2.041-1 (bug #1146063)
 	[trixie] - libsocket-perl <no-dsa> (Minor issue)
 	[bookworm] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
 	[bullseye] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
@@ -99081,7 +99081,7 @@ CVE-2026-0541 (ACAP applications can gain elevated privileges due to improper in
 CVE-2026-0502 (Due to insufficient CSRF protection in SAP BusinessObjects Business In ...)
 	NOT-FOR-US: SAP
 CVE-2026-7010 (HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP ...)
-	- libhttp-tiny-perl 0.092-2
+	- libhttp-tiny-perl 0.092-2 (bug #1146064)
 	[trixie] - libhttp-tiny-perl <no-dsa> (Minor issue)
 	[bookworm] - libhttp-tiny-perl <no-dsa> (Minor issue)
 	- perl 5.40.1-8 (bug #1138858)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b652229586e66412ebabceb95643718701e8cc0

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b652229586e66412ebabceb95643718701e8cc0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260829/04b0a009/attachment.htm>


More information about the debian-security-tracker-commits mailing list