[Git][security-tracker-team/security-tracker][master] Add bug clones for CVE-2026-12087 and CVE-2026-7010
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Aug 29 15:50:22 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
7b652229 by Niko Tyni at 2026-08-29T16:34:54+02:00
Add bug clones for CVE-2026-12087 and CVE-2026-7010
These packages have separate copies of the affected modules.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -75194,7 +75194,7 @@ CVE-2026-53705 (A flaw was found in GStreamer's WavPack audio decoder in gst-plu
NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/9326c636a22a678952a6cae6518465d35d441a87 (1.28.4)
NOTE: Fixed by: https://gitlab.freedesktop.org/gstreamer/gstreamer/-/commit/f7cb3e0288627cce919e656584b852ac8605c922 (1.28.4)
CVE-2026-12087 (Socket versions before 2.041 for Perl have an out-of-bounds heap read. ...)
- - libsocket-perl 2.041-1
+ - libsocket-perl 2.041-1 (bug #1146063)
[trixie] - libsocket-perl <no-dsa> (Minor issue)
[bookworm] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
[bullseye] - libsocket-perl <postponed> (Minor issue; up-to-3-byte heap over-read, only reachable when a script passes attacker-controlled source to pack_ip_mreq_source())
@@ -99081,7 +99081,7 @@ CVE-2026-0541 (ACAP applications can gain elevated privileges due to improper in
CVE-2026-0502 (Due to insufficient CSRF protection in SAP BusinessObjects Business In ...)
NOT-FOR-US: SAP
CVE-2026-7010 (HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP ...)
- - libhttp-tiny-perl 0.092-2
+ - libhttp-tiny-perl 0.092-2 (bug #1146064)
[trixie] - libhttp-tiny-perl <no-dsa> (Minor issue)
[bookworm] - libhttp-tiny-perl <no-dsa> (Minor issue)
- perl 5.40.1-8 (bug #1138858)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b652229586e66412ebabceb95643718701e8cc0
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7b652229586e66412ebabceb95643718701e8cc0
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260829/04b0a009/attachment.htm>
More information about the debian-security-tracker-commits
mailing list