[Git][security-tracker-team/security-tracker][master] 2 commits: Remove no-dsa tagged entries for CVEs which got an update for expat
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Thu Jul 30 10:27:01 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
910c3faa by Salvatore Bonaccorso at 2026-07-30T11:24:44+02:00
Remove no-dsa tagged entries for CVEs which got an update for expat
- - - - -
a28cba02 by Salvatore Bonaccorso at 2026-07-30T11:25:09+02:00
Add missing list of CVEs for DSA-6404-1/expat
- - - - -
2 changed files:
- data/CVE/list
- data/DSA/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -78263,7 +78263,6 @@ CVE-2026-41082 (In OCaml opam before 2.5.1, a .install field containing a destin
NOTE: https://github.com/ocaml/security-advisories/blob/main/advisories/2026/OSEC-2026-03.md
CVE-2026-41080 (libexpat before 2.8.0 uses insufficient entropy, and thus hash floodin ...)
- expat 2.8.0-1 (bug #1134732)
- [trixie] - expat <no-dsa> (Minor issue)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/issues/47
@@ -96748,7 +96747,6 @@ CVE-2026-4171 (A security vulnerability has been detected in CodeGenieApp server
NOT-FOR-US: CodeGenieApp serverless-express
CVE-2026-32778 (libexpat before 2.7.5 allows a NULL pointer dereference in the functio ...)
- expat 2.7.5-1 (bug #1131119)
- [trixie] - expat <no-dsa> (Minor issue)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1163
@@ -96756,7 +96754,6 @@ CVE-2026-32778 (libexpat before 2.7.5 allows a NULL pointer dereference in the f
NOTE: Test: https://github.com/libexpat/libexpat/commit/d5fa769b7a7290a7e2c4a0b2287106dec9b3c030
CVE-2026-32777 (libexpat before 2.7.5 allows an infinite loop while parsing DTD conten ...)
- expat 2.7.5-1 (bug #1131118)
- [trixie] - expat <no-dsa> (Minor issue)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/issues/1161
@@ -96765,7 +96762,6 @@ CVE-2026-32777 (libexpat before 2.7.5 allows an infinite loop while parsing DTD
NOTE: Test: https://github.com/libexpat/libexpat/commit/a7805c1a8a48d2ce83ef289cf55bdc8b45de76a8
CVE-2026-32776 (libexpat before 2.7.5 allows a NULL pointer dereference with empty ext ...)
- expat 2.7.5-1 (bug #1131117)
- [trixie] - expat <no-dsa> (Minor issue)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
NOTE: https://github.com/libexpat/libexpat/pull/1158
@@ -115989,7 +115985,6 @@ CVE-2025-12899 (A flaw in Zephyr\u2019s network stack allows an IPv4 packet cont
NOT-FOR-US: Zephyr, different from src:zephyr
CVE-2026-25210 (In libexpat before 2.7.4, the doContent function does not properly det ...)
- expat 2.7.4-1 (bug #1126697)
- [trixie] - expat <no-dsa> (Minor issue)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue)
NOTE: Fixed by: https://github.com/libexpat/libexpat/commit/7ddea353ad3795f7222441274d4d9a155b523cba (R_2_7_4)
@@ -118387,7 +118382,6 @@ CVE-2025-71145 (In the Linux kernel, the following vulnerability has been resolv
- linux <not-affected> (Vulnerable code not present)
CVE-2026-24515 (In libexpat before 2.7.4, XML_ExternalEntityParserCreate does not copy ...)
- expat 2.7.3-2 (bug #1126277)
- [trixie] - expat <no-dsa> (Minor issue)
[bookworm] - expat <no-dsa> (Minor issue)
[bullseye] - expat <postponed> (Minor issue, DoS)
NOTE: https://github.com/libexpat/libexpat/pull/1131
@@ -170057,7 +170051,6 @@ CVE-2025-59375 (libexpat in Expat before 2.7.2 allows attackers to trigger large
- firefox-esr 140.9.0esr-1
- thunderbird 1:140.9.0esr-1
- expat 2.7.2-1 (bug #1115298)
- [trixie] - expat <no-dsa> (Minor issue)
[bookworm] - expat <ignored> (Minor issue)
[bullseye] - expat <ignored> (Minor issue, too intrusive to backport)
NOTE: https://github.com/libexpat/libexpat/issues/1018
=====================================
data/DSA/list
=====================================
@@ -1,4 +1,5 @@
[30 Jul 2026] DSA-6404-1 expat - security update
+ {CVE-2025-59375 CVE-2026-24515 CVE-2026-25210 CVE-2026-32776 CVE-2026-32777 CVE-2026-32778 CVE-2026-41080 CVE-2026-45186 CVE-2026-50219 CVE-2026-56131 CVE-2026-56132 CVE-2026-56403 CVE-2026-56404 CVE-2026-56405 CVE-2026-56406 CVE-2026-56407 CVE-2026-56408 CVE-2026-56409 CVE-2026-56410 CVE-2026-56411 CVE-2026-56412}
[trixie] - expat 2.8.2-1~deb13u1
[29 Jul 2026] DSA-6403-1 nss - security update
{CVE-2026-16389}
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b47e2cf5b3c5bf97653114be940ccc483ef4c9ad...a28cba020201af80f41cee60aacb6ea02c87d159
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/b47e2cf5b3c5bf97653114be940ccc483ef4c9ad...a28cba020201af80f41cee60aacb6ea02c87d159
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260730/d56330a9/attachment.htm>
More information about the debian-security-tracker-commits
mailing list