[Git][security-tracker-team/security-tracker][master] Add CVE-2026-9672/libgd2

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Jul 31 06:08:19 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
36857b05 by Salvatore Bonaccorso at 2026-07-31T07:07:53+02:00
Add CVE-2026-9672/libgd2

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -320,6 +320,12 @@ CVE-2026-62268
 	NOTE: Fixed by: https://github.com/borgbackup/borg/commit/4f37fdfed10b50559a0dd333b0d5581c642af329 (2.0.0b22)
 	NOTE: Fixed by: https://github.com/borgbackup/borg/commit/3e9ed6d1ad6d3531b39c07b8ef3ecf41fce4437f (1.4.5)
 	NOTE: Fixed by: https://github.com/borgbackup/borg/commit/141888f2fabcd57a300547c2aa63212cb213924d (1.4.5)
+CVE-2026-9672
+	- libgd2 <unfixed> (bug #1143152)
+	- php8.4 <unfixed> (unimportant)
+	- php8.2 <removed> (unimportant)
+	- php7.4 <removed> (unimportant)
+	NOTE: Fixed by: https://github.com/php/php-src/commit/b590f0380fda26ed180874a0255f0be078434315 (php-8.4.24)
 CVE-2026-17544 (Attacker-provided inputs to bccomp() could lead to an out-of-bounds wr ...)
 	- php8.4 <unfixed>
 	- php8.2 <removed>



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/36857b05f858364d1dcb80813f0a5e70ef0eeda6

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/36857b05f858364d1dcb80813f0a5e70ef0eeda6
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/416d2bee/attachment.htm>


More information about the debian-security-tracker-commits mailing list