[Git][security-tracker-team/security-tracker][master] Track fixed version for golang-oras-oras-go issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Jul 28 18:42:03 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5ea131bc by Salvatore Bonaccorso at 2026-07-28T19:41:05+02:00
Track fixed version for golang-oras-oras-go issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -11378,18 +11378,18 @@ CVE-2026-50271 (Datadog dd-trace-py is the Datadog Python APM client. Prior to 4
 CVE-2026-50197 (Skipper is an HTTP router and reverse proxy for service composition. P ...)
 	NOT-FOR-US: Zalando Skipper
 CVE-2026-50163 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.2, en ...)
-	- golang-oras-oras-go <unfixed> (bug #1142456)
+	- golang-oras-oras-go 2.6.2-1 (bug #1142456)
 	[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, content/utils.go os.Link()s the unresolved Linkname)
 	NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-fxhp-mv3v-67qp
 	NOTE: https://github.com/oras-project/oras-go/pull/1232
 	NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/c463c654ab3ef34422c1764cd619806cebf20451 (v2.6.2)
 CVE-2026-50162 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...)
-	- golang-oras-oras-go <unfixed> (bug #1142456)
+	- golang-oras-oras-go 2.6.2-1 (bug #1142456)
 	[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, content/file.go resolveWritePath() lacks symlink resolution)
 	NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-8xwf-rjm4-xvhv
 	NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/cc323e564d90c6b5b4bdd71d3c8d2ee2713b37e5 (v2.6.1)
 CVE-2026-50151 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, re ...)
-	- golang-oras-oras-go <unfixed> (bug #1142456)
+	- golang-oras-oras-go 2.6.2-1 (bug #1142456)
 	[bookworm] - golang-oras-oras-go <not-affected> (Blob upload path not present in v1.1.1; no blobStore and the Location header is never read)
 	NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-jxpm-75mh-9fp7
 	NOTE: https://github.com/oras-project/oras-go/pull/1152
@@ -11417,7 +11417,7 @@ CVE-2026-49284 (SimpleSAMLphp versions before 1.18.6 contain an information disc
 	[bullseye] - simplesamlphp <postponed> (Reachability-gated: multi-IdP mixed-trust deployments only; SP warns-and-continues on issuer mismatch and accepts unsigned Response InResponseTo; fix along with the next DLA)
 	NOTE: https://github.com/simplesamlphp/simplesamlphp/security/advisories/GHSA-q8r6-xj3f-wrrm
 CVE-2026-48978 (oras-go is a Go library for managing OCI artifacts. Prior to 2.6.1, au ...)
-	- golang-oras-oras-go <unfixed> (bug #1142456)
+	- golang-oras-oras-go 2.6.2-1 (bug #1142456)
 	[bookworm] - golang-oras-oras-go <postponed> (Limited support, minor issue; v1.1.1 affected too, auth/client.go follows an unvalidated WWW-Authenticate realm)
 	NOTE: https://github.com/oras-project/oras-go/security/advisories/GHSA-xf85-363p-868w
 	NOTE: Fixed by: https://github.com/oras-project/oras-go/commit/7a9f4b0b9558821b0422152ebe21ae56930fe764 (v2.6.1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ea131bceac8e39b6784d5a8abf986c3d747718f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5ea131bceac8e39b6784d5a8abf986c3d747718f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260728/36c720ac/attachment.htm>


More information about the debian-security-tracker-commits mailing list