[Git][security-tracker-team/security-tracker][master] Add ndpi issue

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 09:10:12 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
f1e14a7d by Salvatore Bonaccorso at 2026-09-05T10:09:54+02:00
Add ndpi issue

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -41,7 +41,8 @@ CVE-2026-86137 (In libxml2 before 2.15.4, xmlFAParsePosCharGroup has an out-of-b
 CVE-2026-86100 (Camaleon CMS versions 2.7.5 through 2.9.1 fail to validate redirect ta ...)
 	NOT-FOR-US: Camaleon CMS
 CVE-2026-86098 (ntop nDPI versions before 6.0 contain a heap buffer overflow vulnerabi ...)
-	TODO: check
+	- ndpi <unfixed>
+	NOTE: Fixed by: https://github.com/ntop/nDPI/commit/94e82c1de12323d992895830231865736a8abf2c (6.0)
 CVE-2026-86097 (PX4 Autopilot through 1.17.0 contains a null pointer dereference vulne ...)
 	NOT-FOR-US: PX4 Autopilot
 CVE-2026-86096 (PX4 Autopilot through 1.17.0 contains a use-after-free vulnerability i ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1e14a7d0772fecd544f7503d4cf29d5c8c38130

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/f1e14a7d0772fecd544f7503d4cf29d5c8c38130
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/0220812d/attachment.htm>


More information about the debian-security-tracker-commits mailing list