[Git][security-tracker-team/security-tracker][master] 6 commits: lts: golang-1.15 not-affected in bullseye (CVE-2026-39822, CVE-2026-42505)

Utkarsh Gupta (@utkarsh) utkarsh at debian.org
Fri Jul 10 23:49:40 BST 2026



Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8abb10fd by Utkarsh Gupta at 2026-07-11T04:09:12+05:30
lts: golang-1.15 not-affected in bullseye (CVE-2026-39822, CVE-2026-42505)

- - - - -
083d7a8c by Utkarsh Gupta at 2026-07-11T04:09:33+05:30
lts: buildah not-affected (CVE-2026-44517)

- - - - -
d47ec90b by Utkarsh Gupta at 2026-07-11T04:18:47+05:30
lts: echo.v2 not-affected / echo.v3 postponed in bullseye (CVE-2026-55677)

- - - - -
4f0f33c1 by Utkarsh Gupta at 2026-07-11T04:18:57+05:30
lts: gobgp postponed (CVE-2026-49838 and bookworm triage for 7 more)

- - - - -
5fc6045f by Utkarsh Gupta at 2026-07-11T04:18:59+05:30
lts: golang-golang-x-image postponed (CVE-2026-46604, CVE-2026-46602, CVE-2026-46601)

- - - - -
8ce4ef53 by Utkarsh Gupta at 2026-07-11T04:19:00+05:30
lts: dhcpcd5 postponed in bullseye (CVE-2026-56114, CVE-2025-70102)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2294,7 +2294,8 @@ CVE-2026-39822 (On Unix systems, opening a file in an os.Root improperly follows
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
-	- golang-1.15 <removed>
+	- golang-1.15 <not-affected> (Vulnerable code introduced later)
+	NOTE: golang-1.15: os.Root API introduced in Go 1.24 (go.dev/doc/go1.24); absent in 1.15
 	NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
 	NOTE: https://github.com/golang/go/issues/79005
 	NOTE: Fixed by: https://github.com/golang/go/commit/f9ef7f55988f03afeb3b8354367d0fa8d053683d (go1.26.5)
@@ -2306,7 +2307,8 @@ CVE-2026-42505 (Handshakes which used Encrypted Client Hello could be de-anonymi
 	- golang-1.24 <removed>
 	[trixie] - golang-1.24 <no-dsa> (Minor issue)
 	- golang-1.19 <removed>
-	- golang-1.15 <removed>
+	- golang-1.15 <not-affected> (Vulnerable code introduced later)
+	NOTE: golang-1.15: crypto/tls client Encrypted Client Hello introduced in Go 1.23 (issue #63369); absent in 1.15
 	NOTE: https://groups.google.com/g/golang-announce/c/OrmQE_Yp5Sc
 	NOTE: https://github.com/golang/go/issues/79282
 	NOTE: Fixed by: https://github.com/golang/go/commit/ca8ca590ccfda1e1c3186faf975afdb02cb6d2f0 (go1.26.5)
@@ -4083,6 +4085,8 @@ CVE-2026-12996
 CVE-2026-49838
 	- gobgp 4.7.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)
+	[bookworm] - gobgp <postponed> (Minor issue, DoS via empty AS_PATH in confed eBGP validation)
+	[bullseye] - gobgp <postponed> (Limited support, follow bookworm security updates)
 	NOTE: https://github.com/osrg/gobgp/security/advisories/GHSA-frrj-87jh-2772
 	NOTE: https://github.com/osrg/gobgp/commit/4a319a6c25630fb3cdbda3e9ccfe56e702bdaaa0 (v4.7.0)
 CVE-2026-9834 (The WP Database Backup \u2013 Unlimited Database & Files Backup by Bac ...)
@@ -8833,6 +8837,8 @@ CVE-2026-46710 (Notepad++ is a free and open-source source code editor. From 8.9
 CVE-2026-46604 (The TIFF decoder can panic when decoding an invalid image with an out- ...)
 	- golang-golang-x-image <unfixed> (bug #1140919)
 	[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+	[bookworm] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS on 32-bit)
+	[bullseye] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS on 32-bit)
 	NOTE: https://github.com/golang/go/issues/80122
 	NOTE: Fixed by: https://github.com/golang/image/commit/7c04344368b6bcc71df693702522f4f03af45250 (v0.43.0)
 CVE-2026-46386 (OpenProject is open-source, web-based project management software. Pri ...)
@@ -9457,7 +9463,9 @@ CVE-2026-55677 (Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's ro
 	- golang-github-labstack-echo <unfixed> (bug #1141444)
 	[trixie] - golang-github-labstack-echo <no-dsa> (Minor issue)
 	- golang-github-labstack-echo.v3 <removed>
+	[bullseye] - golang-github-labstack-echo.v3 <postponed> (Minor issue; limited/case-by-case golang support, no upstream v3 fix)
 	- golang-github-labstack-echo.v2 <removed>
+	[bullseye] - golang-github-labstack-echo.v2 <not-affected> (static handler does no url.PathUnescape; encoded-separator path absent)
 	NOTE: https://github.com/labstack/echo/security/advisories/GHSA-vfp3-v2gw-7wfq
 CVE-2026-55448 (mise manages dev tools like node, python, cmake, and terraform. From 2 ...)
 	NOT-FOR-US: mise
@@ -9766,11 +9774,15 @@ CVE-2026-50176 (The WebSocket Application Programming Interface lacks restrictio
 CVE-2026-46602 (The TIFF decoder does not set a limit on the size of tiles in tiled im ...)
 	- golang-golang-x-image <unfixed> (bug #1140919)
 	[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+	[bookworm] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS)
+	[bullseye] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS)
 	NOTE: https://github.com/golang/go/issues/79905
 	NOTE: Fixed by: https://github.com/golang/image/commit/304d4cc4ee82f96f864f1a4c9a3ae30a4016c9ce (v0.43.0)
 CVE-2026-46601 (The webp decoder can panic when processing a VP8 chunk with dimensions ...)
 	- golang-golang-x-image <unfixed> (bug #1140919)
 	[trixie] - golang-golang-x-image <no-dsa> (Minor issue)
+	[bookworm] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS)
+	[bullseye] - golang-golang-x-image <postponed> (Limited support, minor issue, DoS)
 	NOTE: https://github.com/golang/go/issues/79869
 	NOTE: Fixed by: https://github.com/golang/image/commit/c5511df3ee92e86ce3fa383fdd247080019257c7 (v0.43.0)
 CVE-2026-44622 (Charging station authentication identifiers are publicly accessible vi ...)
@@ -13648,6 +13660,7 @@ CVE-2026-56114 (dhcpcd through 10.3.2, fixed in commit 2f00c7b, contains a one-b
 	[trixie] - dhcpcd <no-dsa> (Minor issue)
 	- dhcpcd5 <removed>
 	[bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point release)
+	[bullseye] - dhcpcd5 <postponed> (Minor issue; needs non-default IA_PD config + adjacent DHCPv6 server; 1-byte OOB, availability-only)
 	NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/2f00c7bfc408b6582d331932dfa47829c4819029
 CVE-2026-56113 (dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-af ...)
 	- dhcpcd 1:10.3.2-4 (bug #1140767)
@@ -13957,6 +13970,9 @@ CVE-2023-54365 (Traefik before 2.10.5 and 3.0.0-beta4 is affected by a denial-of
 CVE-2026-44517
 	- golang-github-containers-buildah 1.43.2+ds1-1 (bug #1140619)
 	[trixie] - golang-github-containers-buildah <no-dsa> (Minor issue)
+	[bookworm] - golang-github-containers-buildah <not-affected> (Vulnerable build-context URL refactor introduced in 1.38.1; 1.28.2 predates it)
+	[bullseye] - golang-github-containers-buildah <not-affected> (Vulnerable build-context URL refactor introduced in 1.38.1; 1.19.6 predates it)
+	NOTE: GHSA-49p4-px3h-rq49 affects >= 1.38.1, < 1.43.2 (TempDirForURL download-subdir path traversal); absent in bookworm 1.28.2 and bullseye 1.19.6. Fixed by 54459cf8.
 	NOTE: https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49
 	NOTE: Fixed by: https://github.com/podman-container-tools/buildah/security/advisories/GHSA-49p4-px3h-rq49 (v1.43.2)
 CVE-2026-11940 (tarfile.extractall() with the 'data' or 'tar'  filter could be bypasse ...)
@@ -18652,6 +18668,7 @@ CVE-2025-70102 (A NULL pointer dereference occurs in Roy Marples NetworkConfigur
 	[trixie] - dhcpcd <no-dsa> (Minor issue)
 	- dhcpcd5 <removed>
 	[bookworm] - dhcpcd5 <no-dsa> (Minor issue; will be fixed in point release)
+	[bullseye] - dhcpcd5 <postponed> (Minor issue; NULL deref only via malformed local dhcpcd.conf; not network-reachable)
 	NOTE: https://github.com/NetworkConfiguration/dhcpcd/issues/567
 	NOTE: Fixed by: https://github.com/NetworkConfiguration/dhcpcd/commit/117742d755b591764036dd4218f314f748a3d2b7 (v10.3.1)
 CVE-2025-69332 (Subscriber Broken Access Control in Bookify <= 1.1.1 versions.)
@@ -25826,7 +25843,9 @@ CVE-2026-50593 (Graphite before 1.3.15 has an integer underflow and resultant ou
 CVE-2026-49837
 	- gobgp 4.6.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)
+	[bookworm] - gobgp <postponed> (Minor issue, OPEN capability length under-enforcement)
 	[bullseye] - gobgp <postponed> (Limited support)
+	NOTE: GHSA scopes affected to v4 <= 4.5.0, but the CapLen-ignoring read is present in 3.10.0 (bookworm) and 2.25.0 (bullseye): CapFourOctetASNumber.DecodeFromBytes reads data[0:4] past the 2-byte header. Minor (OPEN-time capability misparse).
 	NOTE: https://github.com/osrg/gobgp/security/advisories/GHSA-gjrg-jjr3-56cm
 CVE-2026-8916 (Out-of-bounds write vulnerability in Samsung Open Source rlottie allow ...)
 	{DLA-4675-1}
@@ -26423,6 +26442,7 @@ CVE-2026-39107 (A Cross Site Scripting vulnerability exists in the Kimi AI v1.0
 CVE-2026-37462 (An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/b ...)
 	- gobgp 4.4.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)
+	[bookworm] - gobgp <postponed> (Minor issue, uint16 underflow in BGPUpdate.DecodeFromBytes)
 	[bullseye] - gobgp <postponed> (Limited support)
 	NOTE: https://github.com/osrg/gobgp/commit/9ce8936672ebc07df524da77fa4c6ae26d92be6d (v4.4.0)
 CVE-2026-37460 (Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) ...)
@@ -48224,6 +48244,7 @@ CVE-2026-38669 (wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when crea
 CVE-2026-37461 (An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) o ...)
 	- gobgp 4.4.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)
+	[bookworm] - gobgp <postponed> (Minor issue, not exploitable in practice; caller guarantees >=20 bytes)
 	[bullseye] - gobgp <postponed> (Limited support, follow bookworm security updates)
 	NOTE: https://github.com/osrg/gobgp/commit/362cce3e325f56e7a4f792ccb9689b3bdda9e682 (v4.4.0)
 	NOTE: https://github.com/osrg/gobgp/commit/9ce8936672ebc07df524da77fa4c6ae26d92be6d (v4.4.0)
@@ -48424,21 +48445,25 @@ CVE-2026-7738 (A security flaw has been discovered in puchunjie doc-tools-mcp 1.
 CVE-2026-7737 (A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by  ...)
 	- gobgp 4.4.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)
+	[bookworm] - gobgp <postponed> (Minor issue, missing length check in BMP ParseBody)
 	[bullseye] - gobgp <postponed> (Limited support, follow bookworm security updates)
 	NOTE: Fixed by: https://github.com/osrg/gobgp/commit/bc77597d42335c78464bc8e15a471d887bbdf260 (v4.4.0)
 CVE-2026-7736 (A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by  ...)
 	- gobgp 4.4.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)
+	[bookworm] - gobgp <postponed> (Minor issue, uint16 underflow in MRT RibEntry decode)
 	[bullseye] - gobgp <postponed> (Limited support, follow bookworm security updates)
 	NOTE: Fixed by: https://github.com/osrg/gobgp/commit/76d911046344a3923cbe573364197aa081944592 (v4.4.0)
 CVE-2026-7735 (A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the f ...)
 	- gobgp 4.4.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)
+	[bookworm] - gobgp <postponed> (Minor issue, AIGP attr parser error handling)
 	[bullseye] - gobgp <postponed> (Limited support, follow bookworm security updates)
 	NOTE: Fixed by: https://github.com/osrg/gobgp/commit/51ad1ada06cb41ce47b7066799981816f50b7ced (v4.4.0)
 CVE-2026-7734 (A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts ...)
 	- gobgp 4.4.0-1
 	[trixie] - gobgp <no-dsa> (Minor issue)
+	[bookworm] - gobgp <postponed> (Minor issue, SRv6 prefix-SID unknown sub-TLV loop)
 	[bullseye] - gobgp <postponed> (Limited support, follow bookworm security updates)
 	NOTE: Fixed by: https://github.com/osrg/gobgp/commit/f9f7b55ec258e514be0264871fa645a2c3edad11 (v4.4.0)
 CVE-2026-7733 (A flaw has been found in funadmin up to 7.1.0-rc6. This affects the fu ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1c3b68c99265d9a2ed9fe0cef1aa1070c4bd972f...8ce4ef53199677c3bfaecab3aaaff840bf20e577

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/1c3b68c99265d9a2ed9fe0cef1aa1070c4bd972f...8ce4ef53199677c3bfaecab3aaaff840bf20e577
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260710/a1994a34/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list