[Git][security-tracker-team/security-tracker][master] Add new zstd-jni-java issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 9 21:24:09 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
b7947be3 by Salvatore Bonaccorso at 2026-09-09T22:23:34+02:00
Add new zstd-jni-java issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,7 +9,10 @@ CVE-2026-87928 (MaxSite CMS versions 0.94 through 109.6 contain a cross-site scr
CVE-2026-87927 (MaxSite CMS through 109.6 contains a local file inclusion vulnerabilit ...)
NOT-FOR-US: MaxSite CMS
CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail to validate closed state in set ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-2jw3-mg7f-vw4q
+ NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e (v1.5.7-14)
+ NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555 (v1.5.7-14)
CVE-2026-87876 (Two case-insensitive comparisons on request-derived usernames outside ...)
TODO: check
CVE-2026-87875 (The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c lacks a sour ...)
@@ -23,11 +26,18 @@ CVE-2026-87853 (A flaw was found in SSSD's IdP authentication provider. The eval
CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose a system ...)
TODO: check
CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free vulnerability where ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-947w-pxjj-c7m9
+ NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555 (v1.5.7-14)
+ NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936 (v1.5.7-14)
CVE-2026-87824 (zstd-jni before 1.5.7-14 fails to validate the samples buffer capacity ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-257p-3h6w-pg7h
+ NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/bba6cfca2c0897f1fa004f4193247479f10da853 (v1.5.7-14)
CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks on three ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-jfr6-9xqw-2g2q
+ NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/d7a1c99322d5e1fc71932e722c0b5bb2fc525d3f (v1.5.7-14)
CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid means duri ...)
TODO: check
CVE-2026-87821 (Lara Dashboard through 1.3.1 contains a server-side request forgery vu ...)
@@ -63,7 +73,9 @@ CVE-2026-87807 (siyuan versions before v3.8.2 contain an authenticated SQL injec
CVE-2026-87806 (Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7 contain ...)
NOT-FOR-US: Parse Server
CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to validate offset and length p ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE: https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
+ NOTE: Fixed by: https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb (v1.5.7-14)
CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection vulnera ...)
TODO: check
CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to authori ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7947be34c90944af5f710953c9de313b0154ab3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7947be34c90944af5f710953c9de313b0154ab3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260909/c1d29c74/attachment.htm>
More information about the debian-security-tracker-commits
mailing list