[Git][security-tracker-team/security-tracker][master] two libxls issues affected r-cran-readxl
Moritz Muehlenhoff (@jmm)
jmm at debian.org
Fri Sep 11 17:55:16 BST 2026
Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker
Commits:
2aaad754 by Moritz Muehlenhoff at 2026-09-11T18:54:32+02:00
two libxls issues affected r-cran-readxl
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -155,9 +155,15 @@ CVE-2026-79724 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote attac
CVE-2026-79723 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticat ...)
NOT-FOR-US: IBM
CVE-2026-79592 (An out-of-bounds read vulnerability exists in the xls_dumpSummary() fu ...)
- TODO: check
+ - r-cran-readxl <unfixed>
+ [trixie] - r-cran-readxl <no-dsa> (Minor issue)
+ NOTE: https://github.com/libxls/libxls/issues/162
+ NOTE: https://github.com/libxls/libxls/pull/165/changes/6eed8bc1d51d6649faebab0184b21ab8768d8fa6
CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists in the ...)
- TODO: check
+ - r-cran-readxl <unfixed>
+ [trixie] - r-cran-readxl <no-dsa> (Minor issue)
+ NOTE: https://github.com/libxls/libxls/issues/161
+ NOTE: https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c
CVE-2026-79590 (A NULL pointer dereference vulnerability exists in the Prism parser co ...)
TODO: check
CVE-2026-78575 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticat ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2aaad7544a4b6045ffc2d1dfd2d4e4243aab71e3
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/2aaad7544a4b6045ffc2d1dfd2d4e4243aab71e3
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/5e7693e6/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list