[Git][security-tracker-team/security-tracker][master] Two rust-ls-webpki issues CVEified

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 18 21:52:39 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
79a0dad8 by Salvatore Bonaccorso at 2026-09-18T22:52:27+02:00
Two rust-ls-webpki issues CVEified

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -84,14 +84,10 @@ CVE-2026-93604 (vm2 through 3.12.0 exposes Node.js's crypto.setFips() function t
 	NOT-FOR-US: Node.js vm2
 CVE-2026-93603 (vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nulli ...)
 	NOT-FOR-US: Node.js vm2
-CVE-2026-93602 (rustls-webpki versions before 0.103.10 and 0.104.0-alpha.5 contain fau ...)
-	TODO: check
 CVE-2026-93601 (rustls-webpki (the Rust webpki fork used by rustls) versions >= 0.101. ...)
 	TODO: check
 CVE-2026-93600 (rustls-webpki (rustls/webpki) versions 0.101.0 through 0.103.11 and 0. ...)
 	TODO: check
-CVE-2026-93599 (rustls-webpki through 0.103.12 (and 0.104.0-alpha releases before 0.10 ...)
-	TODO: check
 CVE-2026-93598 (ArcadeDB (Maven artifact com.arcadedb:arcadedb-engine) through 26.8.1  ...)
 	TODO: check
 CVE-2026-93597 (ArcadeDB versions before 26.9.1 fail to validate IPv6 transition addre ...)
@@ -137742,11 +137738,11 @@ CVE-2026-41248 (Clerk JavaScript is the official JavaScript repository for Clerk
 	NOT-FOR-US: Clerk
 CVE-2026-41244 (Mojic is a CLI tool to transform readable C code into an unrecognizabl ...)
 	NOT-FOR-US: Mojic
-CVE-2026-XXXX [RUSTSEC-2026-0104]
+CVE-2026-93599 [RUSTSEC-2026-0104]
 	- rust-rustls-webpki 0.103.13+ds-1
 	[trixie] - rust-rustls-webpki <no-dsa> (Minor issue)
+	NOTE: https://github.com/rustls/webpki/security/advisories/GHSA-82j2-j2ch-gfr8
 	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0104.html
-	NOTE: https://github.com/advisories/GHSA-82j2-j2ch-gfr8
 CVE-2026-42254 (Hickory DNS hickory-recursor 0.1 through 0.25.2 allows cross-zone pois ...)
 	- rust-hickory-recursor <unfixed> (bug #1134954)
 	[trixie] - rust-hickory-recursor <no-dsa> (Minor issue)
@@ -146767,9 +146763,10 @@ CVE-2024-1490 (An authenticated remote attacker with high privileges can exploit
 	NOT-FOR-US: WAGO
 CVE-2026-1403
 	- gitlab <removed>
-CVE-2026-XXXX [RUSTSEC-2026-0049]
+CVE-2026-93602 [RUSTSEC-2026-0049]
 	- rust-rustls-webpki 0.103.10+ds-1 (bug #1133085)
 	[trixie] - rust-rustls-webpki <no-dsa> (Minor issue)
+	NOTE: https://github.com/rustls/webpki/security/advisories/GHSA-pwjx-qhcg-rvj4
 	NOTE: https://rustsec.org/advisories/RUSTSEC-2026-0049.html
 CVE-2026-5919 (Insufficient validation of untrusted input in WebSockets in Google Chr ...)
 	{DSA-6205-1}



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/79a0dad8006c86c75b2ec6743bb39167c9109030

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/79a0dad8006c86c75b2ec6743bb39167c9109030
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260918/45c76604/attachment.htm>


More information about the debian-security-tracker-commits mailing list