[Git][security-tracker-team/security-tracker][master] Add new u-boot issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Jul 14 06:19:09 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
884bbee0 by Salvatore Bonaccorso at 2026-07-14T07:18:50+02:00
Add new u-boot issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -2982,11 +2982,17 @@ CVE-2026-3688 (The WCFM Membership \u2013 WooCommerce Memberships for Multivendo
CVE-2026-3144 (IBM API Connect 12.1.0.0 through 12.1.0.3 uses default credentials whi ...)
NOT-FOR-US: IBM
CVE-2026-29009 (U-Boot through 2026.04-rc3 contains a buffer overflow vulnerability in ...)
- TODO: check
+ - u-boot <unfixed>
+ NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
+ NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
CVE-2026-29008 (U-Boot through 2026.04-rc3 contains an integer underflow vulnerability ...)
- TODO: check
+ - u-boot <unfixed>
+ NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
+ NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
CVE-2026-29007 (U-Boot through 2026.04-rc3 contains an out-of-bounds read vulnerabilit ...)
- TODO: check
+ - u-boot <unfixed>
+ NOTE: https://y637f9qq2x.com/posts/u-boot-tcp-nfs-vulns/
+ NOTE: https://lists.denx.de/pipermail/u-boot/2026-May/617853.html
CVE-2026-24700 (An OS command injection vulnerability exists in the start_lltd() funct ...)
NOT-FOR-US: Cisco RV130/RV130W
CVE-2026-24699 (An OS command injection vulnerability exists in the sub_34984() functi ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/884bbee0d6bfbebbbb69821257e4e813f6491c3f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/884bbee0d6bfbebbbb69821257e4e813f6491c3f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260714/e5460314/attachment.htm>
More information about the debian-security-tracker-commits
mailing list