[Git][security-tracker-team/security-tracker][master] Update status for some expat issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 31 19:27:01 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a87da6cc by Salvatore Bonaccorso at 2026-08-31T20:25:48+02:00
Update status for some expat issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -10147,6 +10147,8 @@ CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with cus
 	- expat <unfixed> (bug #1144927)
 	[trixie] - expat <no-dsa> (Minor issue)
 	NOTE: https://github.com/libexpat/libexpat/pull/1322
+	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/127b7d4beb8fe7e5ce5cb021c2e56379c95863d0 (R_2_8_4)
+	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/acbd2e1179c04fe9a8c3f3837701904d05de71fc (R_2_8_4)
 CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentr ...)
 	- expat <unfixed> (bug #1144926)
 	[trixie] - expat <no-dsa> (Minor issue)
@@ -10154,6 +10156,7 @@ CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of g
 	[bullseye] - expat <not-affected> (Vulnerable code not present)
 	NOTE: https://github.com/libexpat/libexpat/pull/1326
 	NOTE: Introduced with: https://github.com/libexpat/libexpat/commit/c90f80c10c08c095221d78c2964697d842ea087b (R_2_8_2)
+	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/40daa9996d616e66a75dea41ed2b18f2c3901b9f (R_2_8_4)
 CVE-2026-76929 (Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows  ...)
 	{DSA-6471-1}
 	- wireshark <unfixed> (bug #1144924)
@@ -14626,10 +14629,10 @@ CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability c
 	- expat <unfixed> (bug #1144925)
 	[trixie] - expat <no-dsa> (Minor issue)
 	NOTE: https://github.com/libexpat/libexpat/pull/1321
-	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
-	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
+	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656 (R_2_8_4)
+	NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738 (R_2_8_4)
 	NOTE: Requires followup to not open CVE-2026-76641:
-	NOTE: https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf
+	NOTE: https://github.com/libexpat/libexpat/commit/98599f6dcc2b460410881fe420f5f55d6bec63bf (R_2_8_4)
 CVE-2026-65959 (Vitess is a database clustering system for horizontal scaling of MySQL ...)
 	NOT-FOR-US: Vitess
 CVE-2026-63643 (MagicMirror\xb2 is an open source modular smart mirror platform. Prior ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a87da6cccbbb72e4cf75bf1cb98fd41dc4dce53e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a87da6cccbbb72e4cf75bf1cb98fd41dc4dce53e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/4c746fc1/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list