[Git][security-tracker-team/security-tracker][master] Add more ocaml-mirage-crypto issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 9 09:46:10 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
bc34a14d by Salvatore Bonaccorso at 2026-09-09T10:45:44+02:00
Add more ocaml-mirage-crypto issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,15 +7,23 @@ CVE-2026-87737 (An issue was discovered in the mirage-crypto-ec package before 2
 	NOTE: https://osv.dev/vulnerability/OSEC-2026-17
 	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/1a61aeee7f593ec067612df1739ec905eab0450f (v2.4.0)
 CVE-2026-87736 (An issue was discovered in the mirage-crypto-ec package before 2.3.0 f ...)
-	TODO: check
+	- ocaml-mirage-crypto 2.3.0-1
+	NOTE: https://osv.dev/vulnerability/OSEC-2026-15
+	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/1f0bf67044e67cf6e46911fcd77a0ff706b6c3e7 (v2.3.0)
 CVE-2026-87735 (An issue was discovered in the mirage-crypto-pk package before 2.3.0 f ...)
-	TODO: check
+	- ocaml-mirage-crypto 2.3.0-1
+	NOTE: https://osv.dev/vulnerability/OSEC-2026-14
+	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/a0f59a0c90eb067505b55a03d3bb104eacd6dd33 (v2.3.0)
 CVE-2026-87734 (An issue was discovered in the utcp package before 0.0.6 for OCaml. Ou ...)
 	TODO: check
 CVE-2026-87733 (An issue was discovered in the mirage-crypto-ec function before 2.2.0  ...)
-	TODO: check
+	- ocaml-mirage-crypto 2.2.0-1
+	NOTE: https://osv.dev/vulnerability/OSEC-2026-13
+	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/ca84f5ee8ede80bd1dd2aa4cd7cc90197752184e (v2.2.0)
 CVE-2026-87732 (An issue was discovered in the mirage-crypto package before 2.2.0 for  ...)
-	TODO: check
+	- ocaml-mirage-crypto 2.2.0-1
+	NOTE: https://osv.dev/vulnerability/OSEC-2026-12
+	NOTE: Fixed by: https://github.com/mirage/mirage-crypto/commit/25e7570aec91e092b347561c23f84b6ec39e7163 (v2.2.0)
 CVE-2026-87724 (Tor before 0.4.9.12 interprets the CC_RESPONSE extension even when CC_ ...)
 	- tor <unfixed>
 	NOTE: Fixed by: https://gitlab.com/torproject/tor/-/commit/10d4b8ffefa7c00aab2b631ed7e7f15e42cd012d (tor-0.4.9.12)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc34a14dc0f0f23ae4a566d1c55e07021605f30b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/bc34a14dc0f0f23ae4a566d1c55e07021605f30b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/e304cff0/attachment.htm>


More information about the debian-security-tracker-commits mailing list