[Git][security-tracker-team/security-tracker][master] 2 commits: One network-manager-l2tp issue go published CVE-2026-93337 instead of CVE-2026-75883

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 17 20:59:11 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
301124ff by Salvatore Bonaccorso at 2026-09-17T21:56:48+02:00
One network-manager-l2tp issue go published CVE-2026-93337 instead of CVE-2026-75883

- - - - -
19fca044 by Salvatore Bonaccorso at 2026-09-17T21:58:28+02:00
Add references for  network-manager-l2tp issues

- - - - -


2 changed files:

- data/CVE/list
- data/DSA/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -18,8 +18,6 @@ CVE-2026-XXXX [GHSA-rhgw-q5g8-xjh2: WebCodecs decoder plugin reads the coded rec
 	NOTE: https://github.com/strukturag/libheif/security/advisories/GHSA-rhgw-q5g8-xjh2
 CVE-2026-9314
 	REJECTED
-CVE-2026-93337 (NetworkManager-l2tp contains an improper input validation vulnerabilit ...)
-	TODO: check
 CVE-2026-93296 (MISP contains a stored cross-site scripting (XSS) vulnerability in the ...)
 	TODO: check
 CVE-2026-93295 (MISP contains a vulnerability in its background job dispatch mechanism ...)
@@ -9609,14 +9607,17 @@ CVE-2024-58383 (Froxlor before 2.2.0 (affected up to and including 2.2.0-rc3) ge
 CVE-2026-19624 (A flaw was found in NetworkManager-l2tp. The plugin writes attacker-co ...)
 	{DSA-6498-1}
 	- network-manager-l2tp 1.52.6-1
+	NOTE: https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-fcq2-qh3w-4xq5
 	NOTE: Fixed by: https://github.com/nm-l2tp/NetworkManager-l2tp/commit/3704d8c9d5e5f9ed1626a8ce7627a04247cea673 (1.52.6, 1.20.26)
 CVE-2026-75131
 	{DSA-6498-1}
 	- network-manager-l2tp 1.52.6-1
+	NOTE: https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-v2wj-xr2m-xc4j
 	NOTE: Fixed by: https://github.com/nm-l2tp/NetworkManager-l2tp/commit/64879ce0ad866f7c9a45babe4d95731a916ea00f (1.52.6, 1.20.26)
-CVE-2026-75883
+CVE-2026-93337
 	{DSA-6498-1}
 	- network-manager-l2tp 1.52.6-1
+	NOTE: https://github.com/nm-l2tp/NetworkManager-l2tp/security/advisories/GHSA-rp84-8h2r-5xc3
 	NOTE: Fixed by: https://github.com/nm-l2tp/NetworkManager-l2tp/commit/64879ce0ad866f7c9a45babe4d95731a916ea00f (1.52.6, 1.20.26)
 CVE-2026-XXXX [GHSA-484h-v688-jq5j: Source URL scheme bypasses sandboxed mode protections across multiple source subtypes]
 	- flatpak-builder 1.4.11-1 (bug #1147701)


=====================================
data/DSA/list
=====================================
@@ -22,7 +22,7 @@
 	{CVE-2026-53938 CVE-2026-53939}
 	[trixie] - cjose 0.6.2.3-1+deb13u1
 [14 Sep 2026] DSA-6498-1 network-manager-l2tp - security update
-	{CVE-2026-19624 CVE-2026-75131 CVE-2026-75883}
+	{CVE-2026-19624 CVE-2026-75131 CVE-2026-93337}
 	[trixie] - network-manager-l2tp 1.20.20-2+deb13u1
 [12 Sep 2026] DSA-6497-1 xorg-server - security update
 	{CVE-2026-55999 CVE-2026-56000}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/73ffafa7c9d17f4bfbbac64d62297d613ad6d485...19fca044176c655bb1fbdc075462f14139ab1cc2

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/compare/73ffafa7c9d17f4bfbbac64d62297d613ad6d485...19fca044176c655bb1fbdc075462f14139ab1cc2
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260917/23d107eb/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list