[Git][security-tracker-team/security-tracker][master] Track fixed version for expat issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Aug 31 19:31:07 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
c5b69185 by Salvatore Bonaccorso at 2026-08-31T20:30:38+02:00
Track fixed version for expat issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10144,13 +10144,13 @@ CVE-2026-75803 (Issue summary: ChaCha20-Poly1305 and AES-OCB decryption with an
CVE-2026-8619 (An unauthenticated denial-of-service vulnerability was identified in T ...)
NOT-FOR-US: TPLink
CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with custom en ...)
- - expat <unfixed> (bug #1144927)
+ - expat 2.8.4-1 (bug #1144927)
[trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1322
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/127b7d4beb8fe7e5ce5cb021c2e56379c95863d0 (R_2_8_4)
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/acbd2e1179c04fe9a8c3f3837701904d05de71fc (R_2_8_4)
CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of getentr ...)
- - expat <unfixed> (bug #1144926)
+ - expat 2.8.4-1 (bug #1144926)
[trixie] - expat <no-dsa> (Minor issue)
[bookworm] - expat <not-affected> (Vulnerable code not present)
[bullseye] - expat <not-affected> (Vulnerable code not present)
@@ -14626,7 +14626,7 @@ CVE-2026-66621 (Improper Neutralization of Input During Web Page Generation ('Cr
CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability caused ...)
- - expat <unfixed> (bug #1144925)
+ - expat 2.8.4-1 (bug #1144925)
[trixie] - expat <no-dsa> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1321
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656 (R_2_8_4)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5b691857212e10958f3ef839bf7d9999d2de6da
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c5b691857212e10958f3ef839bf7d9999d2de6da
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/7b0b5163/attachment.htm>
More information about the debian-security-tracker-commits
mailing list