[Git][security-tracker-team/security-tracker][master] Reserve DLA-4683-1 for wolfssl
Utkarsh Gupta (@utkarsh)
utkarsh at debian.org
Wed Jul 15 01:51:01 BST 2026
Utkarsh Gupta pushed to branch master at Debian Security Tracker / security-tracker
Commits:
3d1d55e0 by Utkarsh Gupta at 2026-07-15T06:20:52+05:30
Reserve DLA-4683-1 for wolfssl
- - - - -
3 changed files:
- data/CVE/list
- data/DLA/list
- data/dla-needed.txt
Changes:
=====================================
data/CVE/list
=====================================
@@ -11328,19 +11328,16 @@ CVE-2026-7531 (Use-after-free in PQC hybrid key-share handling. This is an incom
CVE-2026-7511 (PKCS7_verify signer confusion allows forged signatures, where the sign ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6731 (X.509 name constraint bypass via the Subject Common Name when treated ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10223 (v5.9.2-stable)
CVE-2026-6681 (The PKCS#7 decode path ignores the caller-supplied output buffer size ...)
- wolfssl 5.9.2-1
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10116 (v5.9.1-stable)
CVE-2026-6679 (A heap buffer overflow could occur in the DTLS 1.3 ACK serialization p ...)
@@ -11352,13 +11349,11 @@ CVE-2026-6679 (A heap buffer overflow could occur in the DTLS 1.3 ACK serializat
CVE-2026-6678 (Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other R ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6450 (A CRL critical extension bypass exists in ParseCRL_Extensions where cr ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10239 (v5.9.2-stable)
CVE-2026-6412 (Certificate policy and RFC 8446 compliance concerns regarding the cont ...)
@@ -11370,7 +11365,6 @@ CVE-2026-6412 (Certificate policy and RFC 8446 compliance concerns regarding the
CVE-2026-6331 (HMAC zero-length tag forgery in EVP_DigestVerifyFinal, where a zero-le ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext comparison only compares half of the ...)
@@ -11382,19 +11376,16 @@ CVE-2026-6330 (The ML-KEM ARM64 NEON ciphertext comparison only compares half of
CVE-2026-6329 (PKCS#12 MAC verification uses an attacker-controlled comparison length ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10192 (v5.9.2-stable)
CVE-2026-6325 (Out-of-bounds write in SetSuitesHashSigAlgo when processing an oversiz ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10204 (v5.9.2-stable)
CVE-2026-6092 (When HAVE_ENCRYPT_THEN_MAC is configured, the implementation could fal ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10167 (v5.9.2-stable)
CVE-2026-57522 (Bitwarden Server before 2026.5.0 contains a JSON injection vulnerabili ...)
@@ -11414,7 +11405,6 @@ CVE-2026-55964 (Chain intermediate CA:TRUE without keyCertSign accepted as a sig
CVE-2026-55962 (TLS 1.3 post-handshake authentication (PHA) issue where a server could ...)
- wolfssl 5.9.2-1 (bug #1140815)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55960 (Un-negotiated Raw Public Key (RFC 7250) accepted in place of an X.509 ...)
@@ -11691,7 +11681,6 @@ CVE-2026-6291 (Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When dec
CVE-2026-6094 (Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing craf ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Can be fixed in point release)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10128 (v5.9.2-stable)
CVE-2026-6091 (Partial-chain certificate verification may accept chains that terminat ...)
@@ -11887,13 +11876,11 @@ CVE-2026-56005 (Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.
CVE-2026-55967 (AES-GCM encryption/decryption with extremely large cumulative single m ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10709 (v5.9.2-stable)
CVE-2026-55961 (wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) ...)
- wolfssl 5.9.2-1 (bug #1140765)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <end-of-life> (EOL in bookworm LTS)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55895 (Vim is an open source, command line text editor. Prior to 9.2.0663, a ...)
@@ -62699,7 +62686,6 @@ CVE-2026-5263 (URI nameConstraints from constrained intermediate CAs are parsed
CVE-2026-5194 (Missing hash/digest size and OID checks allow digests smaller than all ...)
- wolfssl 5.9.1-0.1 (bug #1133835)
[trixie] - wolfssl <no-dsa> (Minor issue)
- [bookworm] - wolfssl <no-dsa> (Minor issue)
[bullseye] - wolfssl <postponed> (Minor issue)
NOTE: https://github.com/wolfSSL/wolfssl/pull/10131
NOTE: Fixed by (merge): https://github.com/wolfSSL/wolfssl/commit/53a3d23ce67086861344711225667f14d794812f (v5.9.1-stable)
=====================================
data/DLA/list
=====================================
@@ -1,3 +1,6 @@
+[15 Jul 2026] DLA-4683-1 wolfssl - security update
+ {CVE-2026-5194 CVE-2026-6092 CVE-2026-6094 CVE-2026-6325 CVE-2026-6329 CVE-2026-6331 CVE-2026-6450 CVE-2026-6678 CVE-2026-6681 CVE-2026-6731 CVE-2026-7511 CVE-2026-55961 CVE-2026-55962 CVE-2026-55967}
+ [bookworm] - wolfssl 5.5.4-2+deb12u3
[13 Jul 2026] DLA-4682-1 redis - security update
{CVE-2026-23631 CVE-2026-25243}
[bookworm] - redis 5:7.0.15-1~deb12u8
=====================================
data/dla-needed.txt
=====================================
@@ -787,11 +787,6 @@ watcher/bullseye
wireshark/bullseye
NOTE: 20260430: Added by Front-Desk (lamby)
--
-wolfssl/bookworm
- NOTE: 20260714: Added by Front-Desk (Beuc)
- NOTE: 20260714: Upstream interested in helping with bookworm (Beuc/front-desk)
- NOTE: 20260714: https://lists.debian.org/debian-lts/2026/07/msg00020.html
---
xen/bookworm
NOTE: 20260714: Added by Front-Desk (Beuc)
NOTE: 20260714: Upcoming DSA + 2 postponed CVEs fixed in trixie (Beuc/front-desk)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d1d55e0c3084c9b283233b68da750fbc1450423
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/3d1d55e0c3084c9b283233b68da750fbc1450423
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260715/0d2b6b35/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list