[Git][security-tracker-team/security-tracker][master] Add new libpcap issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 5 20:34:33 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
ac309e36 by Salvatore Bonaccorso at 2026-09-05T21:34:05+02:00
Add new libpcap issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -83,17 +83,23 @@ CVE-2026-75586 (The Unlimited Elements For Elementor plugin for WordPress is vul
 CVE-2026-75018 (The Custom Contact Forms plugin for WordPress is vulnerable to authori ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-6554 (libpcap BPF interpreter treats the offset in the 'ja L' BPF instructio ...)
-	TODO: check
+	- libpcap <unfixed>
+	NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/ff3c83475ac303c6b681c52ad0b6e14795a8e0ce (libpcap-1.10.7)
 CVE-2026-6244 (libpcap BPF interpreter for the 'div #k' and 'mod #k' ALU instructions ...)
-	TODO: check
+	- libpcap <unfixed>
+	NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/98bb921b141aa642faedbf2ac510541c76499a19 (libpcap-1.10.7)
 CVE-2026-31912 (libpcap BPF interpreter detects neither reaching the end of the filter ...)
-	TODO: check
+	- libpcap <unfixed>
+	NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/d3f358d3cffbe1ecb94d5284b3e81f052a0adcb9 (libpcap-1.10.7)
 CVE-2026-31911 (libpcap BPF interpreter calls abort() if it encounters a BPF instructi ...)
-	TODO: check
+	- libpcap <unfixed>
+	NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 (libpcap-1.10.7)
 CVE-2026-18313 (rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_ ...)
-	TODO: check
+	- libpcap <unfixed>
+	NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7 (libpcap-1.10.7)
 CVE-2026-18238 (The rpcap client code that processes a RPCAP_MSG_PACKET message receiv ...)
-	TODO: check
+	- libpcap <unfixed>
+	NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473 (libpcap-1.10.7)
 CVE-2026-15550 (The Ninja Forms - Save Progress plugin for WordPress is vulnerable to  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-12843 (The LearnDash LMS plugin for WordPress is vulnerable to authorization  ...)
@@ -101,7 +107,8 @@ CVE-2026-12843 (The LearnDash LMS plugin for WordPress is vulnerable to authoriz
 CVE-2026-10196 (The Mail Mint \u2013 Email Marketing, Newsletter, Email Automation & W ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-0799 (In BPF instructions that load/store a value from/to a scratch memory r ...)
-	TODO: check
+	- libpcap <unfixed>
+	NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/48e8960a7108e9e828f9d7bdc7e97bdab841aec7 (libpcap-1.10.7)
 CVE-2025-9049 (The Nokri \u2013 Job Board WordPress Theme theme for WordPress is vuln ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2025-15647 (CDT before 1.4.5 contains an out-of-bounds read vulnerability in the o ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac309e361166bd387c26aab9d8661806fff22ff2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/ac309e361166bd387c26aab9d8661806fff22ff2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260905/e316e6d6/attachment.htm>


More information about the debian-security-tracker-commits mailing list