[Git][security-tracker-team/security-tracker][master] Add CVE-2026-15997/bouncycastle

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 08:50:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
22bad807 by Salvatore Bonaccorso at 2026-07-20T09:49:58+02:00
Add CVE-2026-15997/bouncycastle

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3661,7 +3661,9 @@ CVE-2026-22752 (Authentication bypass by primary weakness vulnerability in Sprin
 CVE-2026-21770 (HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a DLL hija ...)
 	NOT-FOR-US: HCL
 CVE-2026-15997 (Out-of-bounds write vulnerability in Legion of the Bouncy Castle Inc.  ...)
-	TODO: check
+	- bouncycastle <not-affected> (Vulnerable code not present)
+	NOTE: https://github.com/bcgit/bc-lts-java/wiki/CVE%E2%80%902026%E2%80%9015997
+	NOTE: https://github.com/bcgit/bc-lts-java/commit/f5df0d2ac1fce2454a8efb55ffd5b08011858c89 (r2rv73dot12dot1)
 CVE-2026-15982 (The Aimogen Pro - All-in-One AI Content Writer, Editor, ChatBot & Auto ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-15945 (A flaw was found in the group search functionality of the Keycloak ser ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22bad807d2de66ac961386d4fca1c1982d372a13

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22bad807d2de66ac961386d4fca1c1982d372a13
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/446207a8/attachment.htm>


More information about the debian-security-tracker-commits mailing list