[Git][security-tracker-team/security-tracker][master] Update status for coreutils issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sun Jul 26 21:57:32 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d00a7350 by Salvatore Bonaccorso at 2026-07-26T22:57:03+02:00
Update status for coreutils issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1809,11 +1809,15 @@ CVE-2026-58586 (Image::WebP versions through 0.2 for Perl bundle a vulnerable ve
 CVE-2026-57106 (Server-side request forgery (ssrf) in Data Quality allows an unauthori ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-56392 (GNU coreutils unexpand is vulnerable to a heap-based buffer overflow d ...)
-	- coreutils <unfixed>
+	- coreutils <unfixed> (unimportant)
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=b60a159fdc5bfcf9988d3a4cb6f53abe8ad5d35d
+	NOTE: https://www.openwall.com/lists/oss-security/2026/07/25/2
+	NOTE: Negligible security impact
 CVE-2026-56391 (GNU coreutils uniq is vulnerable to an out\u2011of\u2011bounds read du ...)
-	- coreutils <unfixed>
+	- coreutils <unfixed> (unimportant)
 	NOTE: Fixed by: https://git.savannah.gnu.org/cgit/coreutils.git/commit/?id=d64e35a8a4c0e4608321433e0d84d917e4e36371
+	NOTE: https://www.openwall.com/lists/oss-security/2026/07/25/2
+	NOTE: Negligible security impact
 CVE-2026-56163 (Missing authentication for critical function in Microsoft Azure Kubern ...)
 	NOT-FOR-US: Microsoft
 CVE-2026-55732 (Out-of-bounds Read (CWE-125)in BACnet packet parsing (`bacdt_datetime_ ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d00a7350e6aeacc43ef83970d3fba1f64b6d4d4d

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d00a7350e6aeacc43ef83970d3fba1f64b6d4d4d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260726/161de68c/attachment.htm>


More information about the debian-security-tracker-commits mailing list