[Git][security-tracker-team/security-tracker][master] Add CVE-2026-78422/rust-zbus-polkit

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Aug 31 21:27:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
0ed346b7 by Salvatore Bonaccorso at 2026-08-31T22:26:28+02:00
Add CVE-2026-78422/rust-zbus-polkit

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -211,7 +211,9 @@ CVE-2026-79744 (MCPHub is a unified hub for centrally managing and dynamically o
 CVE-2026-79743 (MCPHub is a unified hub for centrally managing and dynamically orchest ...)
 	NOT-FOR-US: MCPHub
 CVE-2026-78422 (Subject::new_for_owner() in the zbus_polkit crate encodes the uid entr ...)
-	TODO: check
+	- rust-zbus-polkit <unfixed>
+	NOTE: https://github.com/z-galaxy/zbus_polkit/pull/101
+	NOTE: Fixed by: https://github.com/z-galaxy/zbus_polkit/commit/6e155eabdf996d947d28cc71c761fe32ba3d0296 (zbus_polkit-5.1.0)
 CVE-2026-78079 (Joomla Extension - joomshaper.com - Open Redirect via Base64 Return Pa ...)
 	NOT-FOR-US: Joomla
 CVE-2026-78078 (Joomla Extension - joomshaper.com - Privileged File Upload Bypass via  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ed346b7f413726747b0b0550f1f77d8f0aa730d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/0ed346b7f413726747b0b0550f1f77d8f0aa730d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260831/6ed571fa/attachment.htm>


More information about the debian-security-tracker-commits mailing list