[Git][security-tracker-team/security-tracker][master] Add new wolfssl issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 20:16:54 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
2ad147d8 by Salvatore Bonaccorso at 2026-07-26T21:16:21+02:00
Add new wolfssl issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -26014,11 +26014,14 @@ CVE-2026-12975 (A flaw was found in Apicurio Registry. The ContentTypeUtil.isPar
 CVE-2026-12473 (Two data sources (DICOMWebProxy and DICOMJSON) shipped in the default  ...)
 	NOT-FOR-US: Open Health Imaging Foundation (OHIF)
 CVE-2026-12340 (Out-of-bounds heap read during SM2/SM3 certificate signature verificat ...)
-	TODO: check
+	- wolfssl 5.9.2-1 (unimportant)
+	NOTE: https://github.com/wolfSSL/wolfssl/pull/10641 (v5.9.2-stable)
+	NOTE: Debian binary packages not built with --enable-sm2
 CVE-2026-11800 (A flaw was found in Keycloak. This JWT algorithm confusion vulnerabili ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2026-11703 (Missing SNI/ALPN binding on stateful (session-ID) resumption, which pr ...)
-	TODO: check
+	- wolfssl 5.9.2-1
+	NOTE: https://github.com/wolfSSL/wolfssl/pull/10489 (v5.9.2-stable)
 CVE-2026-11310 (X.509 trust-chain bypass in the OpenSSL compatibility certificate veri ...)
 	TODO: check
 CVE-2026-10835 (The SALESmanago & Leadoo WordPress plugin before 3.11.3 does not prope ...)
@@ -26625,7 +26628,8 @@ CVE-2026-12897 (Horner Automation Cscape versions prior to 10.2 SP3 are vulnerab
 CVE-2026-12755 (Improper input validation in the PAM AD discovery endpoints in  Devolu ...)
 	NOT-FOR-US: Devolutions
 CVE-2026-11999 (X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compat ...)
-	TODO: check
+	- wolfssl 5.9.2-1
+	NOTE: https://github.com/wolfSSL/wolfssl/pull/10674 (v5.9.2-stable)
 CVE-2026-12844 (List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer o ...)
 	- liblist-someutils-xs-perl 0.59-1
 	[trixie] - liblist-someutils-xs-perl <no-dsa> (Minor issue)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ad147d8e7d73a5937c8fe05a1b6b0f314fcaec4

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2ad147d8e7d73a5937c8fe05a1b6b0f314fcaec4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/6732a571/attachment.htm>


More information about the debian-security-tracker-commits mailing list