[Git][security-tracker-team/security-tracker][master] Mark CVE-2026-35512 CVE-2026-42218 as not-affected for both

Abhijith PA (@abhijith) abhijith at debian.org
Fri Jul 31 20:01:18 BST 2026



Abhijith PA pushed to branch master at Debian Security Tracker / security-tracker


Commits:
cc4076c3 by Abhijith PA at 2026-08-01T00:19:59+05:30
Mark CVE-2026-35512 CVE-2026-42218 as not-affected for both
bullseye and bookworm. Mark CVE-2026-55626 as not bullseye.

CVE-2026-35512, EGFX (graphics dynamic virtual channel) function
implemented in version v0.10.0-ard-macos.

CVE-2026-42218 CVE-2026-55626 sesman/sesexec functions mentioned
in the patches not present in version 0.9.21.1.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -22528,6 +22528,8 @@ CVE-2026-44178 (xrdp is an open source RDP server. Versions 0.10.6 and prior con
 CVE-2026-42218 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
 	[experimental] - xrdp 0.10.6.1-1
 	- xrdp 0.10.6.1-2
+	[bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
+	[bullseye] - xrdp <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-3wr5-fwmh-qh34
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/13bbb975d49c7e2e328322c3ea052c9d01d53092 (v0.10.6.1)
 CVE-2026-44978 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
@@ -22550,6 +22552,7 @@ CVE-2026-55626 (xrdp is an open source RDP server. In versions 0.10.6 and prior,
 	- xrdp 0.10.6.1-2
 	[trixie] - xrdp <not-affected> (Vulnerable code introduced later)
 	[bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
+	[bullseye] - xrdp <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-m3xx-cpc4-982r
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/517b8a180d8cbad1b7950ff4f6b31491318f5bb5 (v0.10.6.1)
 CVE-2026-55639 (xrdp is an open source RDP server. Versions 0.10.6 and prior contain a ...)
@@ -78548,6 +78551,8 @@ CVE-2026-35546 (AnvizCX2 Lite and CX7are vulnerable to unauthenticated firmware
 	NOT-FOR-US: Anviz
 CVE-2026-35512 (xrdp is an open source RDP server. Versions through 0.10.5 have a heap ...)
 	- xrdp 0.10.6-1 (bug #1134339)
+	[bookworm] - xrdp <not-affected> (Vulnerable code introduced later)
+	[bullseye] - xrdp <not-affected> (Vulnerable code introduced later)
 	NOTE: https://github.com/neutrinolabs/xrdp/security/advisories/GHSA-jg6p-7fg8-9hh6
 	NOTE: https://github.com/neutrinolabs/xrdp/commit/8c407ce3ed690100fd9fd259c506f526ab74ee5f (v0.10.6)
 CVE-2026-35465 (SecureDrop Client is a desktop app for journalists to securely communi ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cc4076c38b70d0711dfc729bb196e858879893b8

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/cc4076c38b70d0711dfc729bb196e858879893b8
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260731/747ba31c/attachment.htm>


More information about the debian-security-tracker-commits mailing list