[Git][security-tracker-team/security-tracker][master] Update status for two rclone issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Tue Sep 15 06:43:48 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
94f4d8ee by Salvatore Bonaccorso at 2026-09-15T07:41:16+02:00
Update status for two rclone issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -3911,9 +3911,7 @@ CVE-2026-88045 (rclone is a command-line program to sync files and directories t
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/7c1dfd99f3e6a22fcefd8686cc478226a15e63a1 (v1.75.1)
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/ab1f458013aaf6356e4bdeca61f7cb9139f8eb86 (v1.75.1)
 CVE-2026-88044 (rclone is a command-line program to sync files and directories to and  ...)
-	- rclone <unfixed> (bug #1147404)
-	[trixie] - rclone <not-affected> (Vulnerable code not present, affects 1.70 and later)
-	[bookworm] - rclone <not-affected> (Vulnerable code not present, affects 1.70 and later)
+	- rclone <not-affected> (Vulnerable code not present, affects 1.70 and later)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p569-5gjg-9cmj
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/739403963abf6f58003c2becd5f7c4ad0d644153 (v1.75.1)
 CVE-2026-88038 (cookies is a Node.js library for reading and writing HTTP cookies, use ...)
@@ -3998,9 +3996,7 @@ CVE-2026-88015 (rclone is a command-line program to sync files and directories t
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-p6m2-r3w9-mpxw
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/28bf49d66f94acc3f4f7f318504a706686281af9 (v1.75.1)
 CVE-2026-88014 (rclone is a command-line program to sync files and directories to and  ...)
-	- rclone <unfixed> (bug #1147404)
-	[trixie] - rclone <not-affected> (Vulnerable code not present, only affects 1.72 and later)
-	[bookworm] - rclone <not-affected> (Vulnerable code not present, only affects 1.72 and later)
+	- rclone <not-affected> (Vulnerable code not present, only affects 1.72 and later)
 	NOTE: https://github.com/rclone/rclone/security/advisories/GHSA-66hp-wgxq-6f5q
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/5dae3adbf571a6cd9ba501eb47397a7e871e1ae0 (v1.75.1)
 	NOTE: Fixed by: https://github.com/rclone/rclone/commit/6507e13d5a83789f500af96d7188c302c9d74d98 (v1.75.1)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/94f4d8ee14a9bcfd36ab1d9ca44996e1cecc4a10

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/94f4d8ee14a9bcfd36ab1d9ca44996e1cecc4a10
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/6aa48f20/attachment.htm>


More information about the debian-security-tracker-commits mailing list