[Git][security-tracker-team/security-tracker][master] Add new curl issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 2 08:39:21 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
49919883 by Salvatore Bonaccorso at 2026-09-02T09:39:12+02:00
Add new curl issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -452,31 +452,54 @@ CVE-2024-35585 (Oxford Nanopore MinKNOW before 24.06 relies on a client's source
TODO: check
CVE-2023-54391 (Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentic ...)
TODO: check
+CVE-2026-82209
+ - curl 8.22.0-1
+ NOTE: https://curl.se/docs/CVE-2026-82209.html
+ NOTE: Introduced with: https://github.com/curl/curl/commit/e77b5b7453c1e8ccd7ec0816890d98e2f392e465 (curl-7_46_0)
+ NOTE: Fixed by: https://github.com/curl/curl/commit/95c1e8915dce64606bd753fd47fc0bd236e31cd6 (curl-8_22_0)
+CVE-2026-82208
+ - curl 8.22.0-1 (unimportant)
+ [bookworm] - curl <not-affected> (Vulnerable code introduced later)
+ NOTE: https://curl.se/docs/CVE-2026-82208.html
+ NOTE: Introduced with: https://github.com/curl/curl/commit/0f2876b2c33f6784a27b6f7345bd8cd95b46352a (curl-8_9_1)
+ NOTE: Fixed by: https://github.com/curl/curl/commit/ed0338befd1d865a8ea1fbaa90013a096dedd07a (curl-8_22_0)
+ NOTE: curl in Debian not built with wolfSSL support
+CVE-2026-80255
+ - curl 8.22.0-1
+ [bookworm] - curl <not-affected> (Vulnerable code introduced later)
+ NOTE: https://curl.se/docs/CVE-2026-80255.html
+ NOTE: Introduced with: https://github.com/curl/curl/commit/1aea05a6c2699e80c75936d58569851555acd603 (curl-8_13_0)
+ NOTE: Fixed by: https://github.com/curl/curl/commit/4f6aa41a0145e930e766775dbe860883d350aa0a (curl-8_22_0)
+CVE-2026-80231
+ - curl <not-affected> (Only affects Curl on Windows and macOS)
+ NOTE: https://curl.se/docs/CVE-2026-80231.html
+ NOTE: Introduced with: https://github.com/curl/curl/commit/148534db57dda611cf8516e92e4d6e35fc1e5074 (curl-7_71_0)
+ NOTE: Fixed by: https://github.com/curl/curl/commit/7be1e70cb6bcd83e130ecfe8cb91b6a7dcdeff42 (rc-8_22_0-3)
CVE-2026-80230
- curl 8.22.0~rc3-1
NOTE: https://curl.se/docs/CVE-2026-80230.html
- NOTE: Introduced with: https://github.com/curl/curl/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
+ NOTE: Introduced with: https://github.com/curl/curl/commit/8363656cb4e0c60a11d8531ead0ec43120b50591 (curl-7_45_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/5267ed859d545534d0c21675a2b70af5a3b6e3ef (rc-8_22_0-3)
CVE-2026-80229
- curl 8.22.0~rc3-1
[bookworm] - curl <not-affected> (Vulnerable code introduced later)
NOTE: https://curl.se/docs/CVE-2026-80229.html
- NOTE: Introduced with: https://github.com/curl/curl/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 (rc-8_14_0-1)
+ NOTE: Introduced with: https://github.com/curl/curl/commit/f2ce6c46b9dcc46ced0ce43fa95176ea7599a854 (rc-8_14_0-1)
NOTE: Fixed by: https://github.com/curl/curl/commit/7ea37abc6ac0120ba5f6d94be8d196f7cf1506bb (rc-8_22_0-3)
CVE-2026-19931
- curl 8.22.0~rc2-1
NOTE: https://curl.se/docs/CVE-2026-19931.html
- NOTE: Introduced with: https://github.com/curl/curl/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
+ NOTE: Introduced with: https://github.com/curl/curl/commit/6c6035532383e300c712e4c1cd9fdd749ed5cf59 (curl-7_64_1)
NOTE: Fixed by: https://github.com/curl/curl/commit/7103a93b05bc69ea98ed9d05d02fa9eeba533f2f (rc-8_22_0-2)
CVE-2026-18924
- curl 8.22.0~rc2-1
NOTE: https://curl.se/docs/CVE-2026-18924.html
- NOTE: Introduced with: https://github.com/curl/curl/ea7134ac874a66107e54ff93657ac565cf2ec4aa (curl-7_44_0)
+ NOTE: Introduced with: https://github.com/curl/curl/commit/ea7134ac874a66107e54ff93657ac565cf2ec4aa (curl-7_44_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/90325ff0444cbdff368bda5d26d6405a0bb6ee43 (rc-8_22_0-1)
CVE-2026-13608
- curl 8.22.0~rc2-1
NOTE: https://curl.se/docs/CVE-2026-13608.html
- NOTE: Introduced with: https://github.com/curl/curl/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 (curl-7_82_0)
+ NOTE: Introduced with: https://github.com/curl/curl/commit/eeca818b1e8d1e61c2d4d833aed56ce4c510a9d4 (curl-7_82_0)
NOTE: Fixed by: https://github.com/curl/curl/commit/ea71c3b6b60e563651ea8596a975aef0c8199519 (rc-8_22_0-1)
CVE-2026-84470 (A flaw was found in Ansible Automation Platform's automation-controlle ...)
NOT-FOR-US: automation-controller/AWX
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49919883455dba32e3ad1dd564167ebab20040e4
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/49919883455dba32e3ad1dd564167ebab20040e4
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260902/b3050b7b/attachment.htm>
More information about the debian-security-tracker-commits
mailing list