[Git][security-tracker-team/security-tracker][master] Add CVE-2026-79590/mruby

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 11 22:11:51 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d5d78e6a by Salvatore Bonaccorso at 2026-09-11T23:11:30+02:00
Add CVE-2026-79590/mruby

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -487,7 +487,9 @@ CVE-2026-79591 (A heap-buffer-overflow and use-after-free vulnerability exists i
 	NOTE: https://github.com/libxls/libxls/issues/161
 	NOTE: https://github.com/libxls/libxls/pull/164/changes/902c8f9b13710c3a13b6232fb86626c5c729402c
 CVE-2026-79590 (A NULL pointer dereference vulnerability exists in the Prism parser co ...)
-	TODO: check
+	- mruby <unfixed>
+	NOTE: https://github.com/mruby/mruby/issues/7032
+	NOTE: Fixed by: https://github.com/mruby/mruby/commit/c6866eed4ad5640b552ba79d16063e7ec70a0ac9 (4.1.0-rc)
 CVE-2026-78575 (IBM Langflow OSS 1.0.0 through 1.11.5 could allow a remote authenticat ...)
 	NOT-FOR-US: IBM
 CVE-2026-78573 (IBM ContextForge MCP Gateway 1.0.0 through 1.0.7 could allow a remote  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5d78e6a33e69aae7eff46d6d0feb18064cc6135

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5d78e6a33e69aae7eff46d6d0feb18064cc6135
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260911/c716c04c/attachment.htm>


More information about the debian-security-tracker-commits mailing list