[Git][security-tracker-team/security-tracker][master] Add CVE-2026-9265/libcrypt-openssl-pkcs12-perl

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Jun 20 08:43:21 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
8711af91 by Salvatore Bonaccorso at 2026-06-20T09:42:49+02:00
Add CVE-2026-9265/libcrypt-openssl-pkcs12-perl

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -6,7 +6,9 @@ CVE-2026-9375 (urllib3 version 2.6.3 is vulnerable to a decompression bomb bypas
 	NOTE: Fixed by: https://github.com/urllib3/urllib3/commit/2bdcc44d1e163fb5cc48a8662425e35e15adfe6a (2.7.0)
 	NOTE: Relates to the fix for CVE-2025-66471.
 CVE-2026-9265 (Crypt::OpenSSL::PKCS12 versions before 1.96 for Perl permits a heap OO ...)
-	TODO: check
+	- libcrypt-openssl-pkcs12-perl <unfixed>
+	NOTE: https://github.com/dsully/perl-crypt-openssl-pkcs12/issues/55
+	NOTE: Fixed by: https://github.com/dsully/perl-crypt-openssl-pkcs12/commit/a7bd2f319fa8aab8177b3d767ea06dd85ceb3173 (v1.96)
 CVE-2026-56216 (Capgo before 12.128.2 contains a scope escalation vulnerability in the ...)
 	TODO: check
 CVE-2026-56215 (Capgo before 12.128.12 allows authenticated users to modify their muta ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8711af91d7d6a158126e9b34d6c4e13f81f23487

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/8711af91d7d6a158126e9b34d6c4e13f81f23487
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260620/141c389e/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list