[Git][security-tracker-team/security-tracker][master] Add new batch of 389-ds-base issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 8 05:56:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
e1759c31 by Salvatore Bonaccorso at 2026-09-08T06:55:35+02:00
Add new batch of 389-ds-base issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -320,7 +320,8 @@ CVE-2026-76578 (A flaw was found in FreeIPA. The self-managed OTP token ACI does
 	NOTE: FreeIPA in Debian only builds the client packages, not the server
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519522
 CVE-2026-76560 (A flaw was found in 389 Directory Server. The SELFDN ACI bind-rule eva ...)
-	TODO: check
+	- 389-ds-base <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2519521
 CVE-2026-6431 (The User Profile Builder \u2013 Beautiful User Registration Forms, Use ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-6377 (Improper Limitation of a Pathname to a Restricted Directory ('Path Tra ...)
@@ -336,17 +337,21 @@ CVE-2026-4945 (The Otter Blocks \u2013 Gutenberg Blocks, Page Builder for Gutenb
 CVE-2026-2390 (The Powerkit plugin for WordPress is vulnerable to Stored Cross-Site S ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-19843 (A flaw was found in 389-ds-base. The Cockpit 389 Console's LDAP editor ...)
-	TODO: check
+	- 389-ds-base <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2515965
 CVE-2026-19204 (A client may send a WebSocket frame with an unknown opcode and a very  ...)
 	TODO: check
 CVE-2026-18922 (A flaw was found in 389 Directory Server. During SASL PLAIN authentica ...)
-	TODO: check
+	- 389-ds-base <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2511388
 CVE-2026-18796 (Any application that      uses external QSPI flash for encrypted XIP o ...)
 	NOT-FOR-US: Nordic Semiconductor ASA
 CVE-2026-18453 (A flaw was found in 389 Directory Server. A missing NULL pointer check ...)
-	TODO: check
+	- 389-ds-base <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509696
 CVE-2026-18355 (A heap buffer overflow flaw was found in the SASL I/O layer of 389 Dir ...)
-	TODO: check
+	- 389-ds-base <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2509186
 CVE-2026-16028 (Protocol::HTTP2 versions before 1.14 for Perl allow memory exhaustion  ...)
 	- libprotocol-http2-perl <unfixed>
 	NOTE: https://lists.security.metacpan.org/cve-announce/msg/43351225/



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1759c317dfd1d10501bfe2e3c673f9f5118cbda

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e1759c317dfd1d10501bfe2e3c673f9f5118cbda
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260908/418e58b2/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list