[Git][security-tracker-team/security-tracker][master] Add CVE-2026-93658/rust-coreutils
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 18 21:38:50 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
78cacd3a by Salvatore Bonaccorso at 2026-09-18T22:38:18+02:00
Add CVE-2026-93658/rust-coreutils
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -61,7 +61,10 @@ CVE-2026-93660 (SQLBot through 1.10.1 fails to verify dashboard ownership in upd
CVE-2026-93659 (Concrete CMS Community Store before 2.7.8 renders customer-supplied or ...)
NOT-FOR-US: Concrete CMS Community Store
CVE-2026-93658 (uutils coreutils versions before 0.10.0 apply setuid or setgid mode to ...)
- TODO: check
+ - rust-coreutils 0.10.0-1
+ NOTE: https://github.com/uutils/coreutils/security/advisories/GHSA-cgg3-923w-v53m
+ NOTE: https://github.com/uutils/coreutils/pull/13629
+ NOTE: Fixed by: https://github.com/uutils/coreutils/commit/7c87ab04fee8e52d989fb2625568a3eeda1b1f55 (0.10.0)
CVE-2026-93657 (hickory-resolver versions before 0.26.2 fail to propagate bogus DNSSEC ...)
TODO: check
CVE-2026-93653 (A denial of service flaw was found in Poppler's Splash backend. A craf ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/78cacd3acd4bf918c19ae1fe187237e579fe493c
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/78cacd3acd4bf918c19ae1fe187237e579fe493c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/7a2d49fb/attachment.htm>
More information about the debian-security-tracker-commits
mailing list