[Git][security-tracker-team/security-tracker][master] Update status for some expat issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 31 19:27:01 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
a87da6cc by Salvatore Bonaccorso at 2026-08-31T20:25:48+02:00
Update status for some expat issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10147,6 +10147,8 @@ CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with cus
- expat <unfixed> (bug #1144927)
[trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1322
+ NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/127b7d4beb8fe7e5ce5cb021c2e56379c95863d0 (R_2_8_4)
+ NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/acbd2e1179c04fe9a8c3f3837701904d05de71fc (R_2_8_4)
CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentr ...)
- expat <unfixed> (bug #1144926)
[trixie] - expat <no-dsa> (Minor issue)
@@ -10154,6 +10156,7 @@ CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of g
[bullseye] - expat <not-affected> (Vulnerable code not present)
NOTE: https://github.com/libexpat/libexpat/pull/1326
NOTE: Introduced with: https://github.com/libexpat/libexpat/commit/c90f80c10c08c095221d78c2964697d842ea087b (R_2_8_2)
+ NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/40daa9996d616e66a75dea41ed2b18f2c3901b9f (R_2_8_4)
CVE-2026-76929 (Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows ...)
{DSA-6471-1}
- wireshark <unfixed> (bug #1144924)
@@ -14626,10 +14629,10 @@ CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability c
- expat <unfixed> (bug #1144925)
[trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1321
- NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
- NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
+ NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656 (R_2_8_4)
+ NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738 (R_2_8_4)
NOTE: Requires followup to not open CVE-2026-76641:
- NOTE: https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf
+ NOTE: https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf (R_2_8_4)
CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
NOT-FOR-US: Vitess
CVE-2026-63643 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a87da6cccbbb72e4cf75bf1cb98fd41dc4dce53e
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a87da6cccbbb72e4cf75bf1cb98fd41dc4dce53e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/4c746fc1/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list