[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-57234

Salvatore Bonaccorso (@carnil) carnil at debian.org
Mon Jul 20 10:19:09 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
c83343ef by Salvatore Bonaccorso at 2026-07-20T11:18:28+02:00
Update status for CVE-2026-57234

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18629,11 +18629,10 @@ CVE-2026-57235 (Nokogiri is an open source XML and HTML library for the Ruby pro
 	[bullseye] - ruby-nokogiri <postponed> (Minor issue)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-5prr-v3j2-97mh
 CVE-2026-57234 (Nokogiri is an open source XML and HTML library for the Ruby programmi ...)
-	- ruby-nokogiri 1.19.4+dfsg-1 (bug #1140769)
-	[trixie] - ruby-nokogiri <no-dsa> (Minor issue)
-	[bookworm] - ruby-nokogiri <not-affected> (JRuby-only; Debian builds/uses the CRuby implementation)
-	[bullseye] - ruby-nokogiri <not-affected> (JRuby-only; Debian builds/uses the CRuby implementation)
+	- ruby-nokogiri 1.19.4+dfsg-1 (bug #114076; unimportant)
 	NOTE: https://github.com/sparklemotion/nokogiri/security/advisories/GHSA-8678-w3jw-xfc2
+	NOTE: Fixed by: https://github.com/sparklemotion/nokogiri/commit/f658a54ab2df58a3525967c339edce9649c197d4 (v1.19.4)
+	NOTE: Debian builds excludes ext/java/* for Ruby Gem installation and not using JRuby implementation
 CVE-2026-56790 (CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one  ...)
 	- canboat <itp> (bug #921311)
 CVE-2026-56789 (RTKLIB through 2.4.3 contains a heap buffer overflow vulnerability in  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c83343efc7464e2381796a354283d68409ab8b4e

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/c83343efc7464e2381796a354283d68409ab8b4e
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260720/c55181b2/attachment.htm>


More information about the debian-security-tracker-commits mailing list