[Git][security-tracker-team/security-tracker][master] Update status for two libpcap issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Tue Sep 15 07:48:17 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
22987bf1 by Salvatore Bonaccorso at 2026-09-15T08:34:07+02:00
Update status for two libpcap issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -10009,15 +10009,15 @@ CVE-2026-31911 (libpcap BPF interpreter calls abort() if it encounters a BPF ins
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/a715bcdde830299cba4171514385cb17ec19b6e9 (libpcap-1.10.7)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/09/2
CVE-2026-18313 (rpcapd can allocate up to 65536 bytes per each RPCAP_MSG_UPDATEFILTER_ ...)
- - libpcap 1.10.7-1 (bug #1146825)
- [trixie] - libpcap <no-dsa> (Minor issue)
+ - libpcap 1.10.7-1 (bug #1146825; unimportant)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/f9775af1a0ec76db60c7213241e6b48f1be10ac7 (libpcap-1.10.7)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/09/2
+ NOTE: Debian binary packages not built with experimental --enable-remote
CVE-2026-18238 (The rpcap client code that processes a RPCAP_MSG_PACKET message receiv ...)
- - libpcap 1.10.7-1 (bug #1146825)
- [trixie] - libpcap <no-dsa> (Minor issue)
+ - libpcap 1.10.7-1 (bug #1146825; unimportant)
NOTE: Fixed by: https://github.com/the-tcpdump-group/libpcap/commit/b9590d482986d64673712460aae1d48d11fa0473 (libpcap-1.10.7)
NOTE: https://www.openwall.com/lists/oss-security/2026/09/09/2
+ NOTE: Debian binary packages not built with experimental --enable-remote
CVE-2026-15550 (The Ninja Forms - Save Progress plugin for WordPress is vulnerable to ...)
NOT-FOR-US: WordPress plugin
CVE-2026-12843 (The LearnDash LMS plugin for WordPress is vulnerable to authorization ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22987bf134f3157ebd9527085517d0dfddd86d5d
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/22987bf134f3157ebd9527085517d0dfddd86d5d
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260915/238a86f0/attachment.htm>
More information about the debian-security-tracker-commits
mailing list