[Git][security-tracker-team/security-tracker][master] Track fixed version for lz4-java issues fixed via unstable

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 31 05:54:12 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
eac5bf82 by Salvatore Bonaccorso at 2026-08-31T06:51:51+02:00
Track fixed version for lz4-java issues fixed via unstable

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -14277,7 +14277,7 @@ CVE-2026-61407 (Dell Watchdog Timer Driver versions prior to 2.0.0.1 contain an
 CVE-2026-5224 (Cleartext storage of sensitive information vulnerability in Kriptok Cr ...)
 	NOT-FOR-US: Cryptosim
 CVE-2026-59949 (yawkat LZ4 Java provides LZ4 compression for Java. Prior to 1.11.1, JN ...)
-	- lz4-java <unfixed> (bug #1145019)
+	- lz4-java 1.11.2+ds1-1 (bug #1145019)
 	NOTE: https://github.com/yawkat/lz4-java/security/advisories/GHSA-xx22-p4ch-683r
 	NOTE: Fixed by: https://github.com/yawkat/lz4-java/commit/dbd86d04b8dd716e1c2bc626be54189997d910da (v1.11.1)
 CVE-2026-59940 (Seroval facilitates JS value stringification, including complex struct ...)
@@ -178141,7 +178141,7 @@ CVE-2025-66570 (cpp-httplib is a C++11 single-file header-only cross platform HT
 	NOTE: https://github.com/yhirose/cpp-httplib/security/advisories/GHSA-xm2j-vfr9-mg9m
 	NOTE: Fixed by: https://github.com/yhirose/cpp-httplib/commit/ac9ebb0ee333ce8bf13523f487bdfad9518a2aff (v0.27.0)
 CVE-2025-66566 (yawkat LZ4 Java provides LZ4 compression for Java. Insufficient cleari ...)
-	- lz4-java <unfixed> (bug #1122026)
+	- lz4-java 1.11.2+ds1-1 (bug #1122026)
 	[trixie] - lz4-java <no-dsa> (Minor issue)
 	[bookworm] - lz4-java <no-dsa> (Minor issue)
 	[bullseye] - lz4-java <no-dsa> (Minor issue)
@@ -180213,7 +180213,7 @@ CVE-2025-12638 (Keras version 3.11.3 is affected by a path traversal vulnerabili
 	NOTE: https://huntr.com/bounties/f94f5beb-54d8-4e6a-8bac-86d9aee103f4
 	NOTE: Fixed by: https://github.com/keras-team/keras/commit/47fcb397ee4caffd5a75efd1fa3067559594e951 (v3.12.0)
 CVE-2025-12183 (Out-of-bounds memory operations in org.lz4:lz4-java 1.8.0 and earlier  ...)
-	- lz4-java <unfixed> (bug #1122026)
+	- lz4-java 1.11.2+ds1-1 (bug #1122026)
 	[trixie] - lz4-java <no-dsa> (Minor issue)
 	[bookworm] - lz4-java <no-dsa> (Minor issue)
 	[bullseye] - lz4-java <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eac5bf82ed4b5803e812a698d2a8c0922e656179

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/eac5bf82ed4b5803e812a698d2a8c0922e656179
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/b7566083/attachment.htm>


More information about the debian-security-tracker-commits mailing list