[Git][security-tracker-team/security-tracker][master] Add CVE-2026-36189/uncrustify

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 14:53:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
49da3580 by Salvatore Bonaccorso at 2026-07-26T15:53:21+02:00
Add CVE-2026-36189/uncrustify

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -52407,7 +52407,13 @@ CVE-2026-39531 (Improper Neutralization of Special Elements used in an SQL Comma
 CVE-2026-39461 (libcasper(3) communicates with helper processes via UNIX domain socket ...)
 	NOT-FOR-US: FreeBSD
 CVE-2026-36189 (Buffer Overflow vulnerability in Uncrustify Project Affected v.Uncrust ...)
-	TODO: check
+	- uncrustify <unfixed>
+	NOTE: https://github.com/uncrustify/uncrustify/issues/4636
+	NOTE: https://github.com/uncrustify/uncrustify/pull/4641
+	NOTE: https://github.com/uncrustify/uncrustify/pull/4650
+	NOTE: tokenizer related code moved to subfolder in:
+	NOTE: https://github.com/uncrustify/uncrustify/commit/35f4eb550fd0cb419d0d48575c51b1d19def18fa (uncrustify-0.79.0)
+	NOTE: Fixed by: https://github.com/uncrustify/uncrustify/commit/04e7614fd25d283508d6d68d85006d9b420c0f1a (uncrustify-0.83.0)
 CVE-2026-34930 (An origin validation vulnerability in the Apex One/SEP agent could all ...)
 	NOT-FOR-US: Trend Micro
 CVE-2026-34929 (An origin validation vulnerability in the Apex One/SEP agent could all ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49da3580b34b4a34d846a6184acadfb8c85a0e13

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49da3580b34b4a34d846a6184acadfb8c85a0e13
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/6989c335/attachment.htm>


More information about the debian-security-tracker-commits mailing list