[Git][security-tracker-team/security-tracker][master] 2 commits: lts: c-ares not-affected in bullseye/bookworm (CVE-2026-33630 + GHSA-jv8r/GHSA-pjmc)
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Sat Jul 11 01:44:27 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b47064d3 by Utkarsh Gupta at 2026-07-11T06:12:37+05:30
lts: c-ares not-affected in bullseye/bookworm (CVE-2026-33630 + GHSA-jv8r/GHSA-pjmc)
- - - - -
a23c750c by Utkarsh Gupta at 2026-07-11T06:12:38+05:30
lts: cifs-utils postponed in bullseye/bookworm (CVE-2026-12505)
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2765,6 +2765,8 @@ CVE-2026-59089 (A flaw was found in GIMP. The PlayStation TIM loader, responsibl
CVE-2026-XXXX [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via unvalidated DNS header record counts]
- c-ares 1.34.7-1
[trixie] - c-ares <no-dsa> (Minor issue)
+ [bookworm] - c-ares <not-affected> (New DNS-record parser prealloc (ares_dns_record_rr_prealloc/ares_array_set_size) not present; introduced in the 1.20+ rewrite)
+ [bullseye] - c-ares <not-affected> (New DNS-record parser prealloc not present; introduced in the 1.20+ rewrite)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/06/8
NOTE: https://github.com/c-ares/c-ares/security/advisories/GHSA-jv8r-gqr9-68wj
NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/eaded4cb200b2a5f8d73f11021ff7c8d6968aaab (main)
@@ -2772,6 +2774,8 @@ CVE-2026-XXXX [GHSA-jv8r-gqr9-68wj: Memory-amplification denial of service via u
CVE-2026-XXXX [GHSA-pjmc-gx33-gc76: CPU-exhaustion denial of service via unbounded DNS name compression pointer chains]
- c-ares 1.34.7-1
[trixie] - c-ares <no-dsa> (Minor issue)
+ [bookworm] - c-ares <not-affected> (Vulnerable 1.34 DNS-name decompression parser (src/lib/record/ares_dns_name.c, ares_buf) not present)
+ [bullseye] - c-ares <not-affected> (Vulnerable 1.34 DNS-name decompression parser not present)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/06/8
NOTE: https://github.com/c-ares/c-ares/security/advisories/GHSA-pjmc-gx33-gc76
NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/f1288bbc70e9a1e0a77134c2382157e52d326aea (main)
@@ -2779,6 +2783,8 @@ CVE-2026-XXXX [GHSA-pjmc-gx33-gc76: CPU-exhaustion denial of service via unbound
CVE-2026-33630
- c-ares 1.34.7-1
[trixie] - c-ares <no-dsa> (Minor issue)
+ [bookworm] - c-ares <not-affected> (Vulnerable event-loop code not present; read_answers()/requeue/host_query re-entrancy introduced in the 1.20+ rewrite, cf. CVE-2025-31498)
+ [bullseye] - c-ares <not-affected> (Vulnerable event-loop code not present; cf. CVE-2025-31498)
NOTE: https://www.openwall.com/lists/oss-security/2026/07/06/8
NOTE: https://github.com/c-ares/c-ares/security/advisories/GHSA-6wfj-rwm7-3542
NOTE: Fixed by: https://github.com/c-ares/c-ares/commit/1fa3b86a0b8d18fe7b60f3228a01d770feb026bc (main)
@@ -15894,6 +15900,8 @@ CVE-2026-12529 (A security vulnerability has been detected in SourceCodester CET
CVE-2026-12505 (A flaw was found in the cifs-utils package where the cifs.upcall helpe ...)
- cifs-utils <unfixed> (bug #1140422)
[trixie] - cifs-utils <no-dsa> (Minor issue)
+ [bookworm] - cifs-utils <postponed> (Minor issue; local privesc via cifs.upcall getpwuid in caller ns)
+ [bullseye] - cifs-utils <postponed> (Minor issue; local privesc via cifs.upcall getpwuid in caller ns)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2489805
NOTE: https://git.samba.org/?p=cifs-utils.git;a=commit;h=972c5b5ff95e3e812bc8daa72d0383654ab0dba7
CVE-2026-12407 (The E2Pdf \u2013 Export Pdf Tool for WordPress plugin for WordPress is ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8ce4ef53199677c3bfaecab3aaaff840bf20e577...a23c750c2ef4ec8ce8eef0615d73bf99233a50ab
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/8ce4ef53199677c3bfaecab3aaaff840bf20e577...a23c750c2ef4ec8ce8eef0615d73bf99233a50ab
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260711/97c68f8b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list