[Git][security-tracker-team/security-tracker][master] Add CVE-2026-9672/libgd2
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Jul 31 06:08:19 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
36857b05 by Salvatore Bonaccorso at 2026-07-31T07:07:53+02:00
Add CVE-2026-9672/libgd2
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -320,6 +320,12 @@ CVE-2026-62268
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/4f37fdfed10b50559a0dd333b0d5581c642af329 (2.0.0b22)
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/3e9ed6d1ad6d3531b39c07b8ef3ecf41fce4437f (1.4.5)
NOTE: Fixed by: https://github.com/borgbackup/borg/commit/141888f2fabcd57a300547c2aa63212cb213924d (1.4.5)
+CVE-2026-9672
+ - libgd2 <unfixed> (bug #1143152)
+ - php8.4 <unfixed> (unimportant)
+ - php8.2 <removed> (unimportant)
+ - php7.4 <removed> (unimportant)
+ NOTE: Fixed by: https://github.com/php/php-src/commit/b590f0380fda26ed180874a0255f0be078434315 (php-8.4.24)
CVE-2026-17544 (Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...)
- php8.4 <unfixed>
- php8.2 <removed>
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/36857b05f858364d1dcb80813f0a5e70ef0eeda6
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/36857b05f858364d1dcb80813f0a5e70ef0eeda6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/416d2bee/attachment.htm>
More information about the debian-security-tracker-commits
mailing list