[Git][security-tracker-team/security-tracker][master] Add new crun issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 11 04:45:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7eef3341 by Salvatore Bonaccorso at 2026-09-11T05:45:12+02:00
Add new crun issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -183,9 +183,11 @@ CVE-2026-88269 (GeoVision GV-LPC2211 V1.13 allows a Guest user to retrieve persi
 CVE-2026-88268 (GeoVision GV-LPC2211 V1.13 contains an authenticated stack buffer over ...)
 	NOT-FOR-US: GeoVision
 CVE-2026-88265 (A flaw was found in crun. After pivot_root, reopening /dev/null for st ...)
-	TODO: check
+	- crun <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531224
 CVE-2026-88264 (A flaw was found in crun. When the container configuration does not gi ...)
-	TODO: check
+	- crun <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531223
 CVE-2026-88060 (Angular is a development platform for building mobile and desktop web  ...)
 	- angular.js <unfixed>
 	NOTE: https://github.com/angular/angular/security/advisories/GHSA-v3p8-whq6-r5jg
@@ -343,7 +345,8 @@ CVE-2026-84819 (Unauthenticated Cross Site Scripting (XSS) in WPAdverts <= 2.3.3
 CVE-2026-84816 (Unauthenticated Cross Site Scripting (XSS) in WPCS <= 1.3.2 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-84042 (A flaw was found in crun. When crun is built with libkrun and a contai ...)
-	TODO: check
+	- crun <not-affected> (Vulnerable code introduced in 1.29)
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531222
 CVE-2026-81805 (Unauthenticated Privilege Escalation in SiteSkite <= 2.1.5 versions.)
 	NOT-FOR-US: WordPress plugin or theme
 CVE-2026-81804 (Unauthenticated Sensitive Data Exposure in ZHBackup \u2013 Backup, Res ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7eef33411422603a78fbe9e4aaba1c66df99b589

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7eef33411422603a78fbe9e4aaba1c66df99b589
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/d05b72f7/attachment.htm>


More information about the debian-security-tracker-commits mailing list