[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-93393 after feedback from maintainer

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 19 08:15:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
d5035a06 by Salvatore Bonaccorso at 2026-09-19T09:15:16+02:00
Update status for CVE-2026-93393 after feedback from maintainer

We actually could as well mark it not-affected exceptionally as it only
affects the Windows platform.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1064,10 +1064,11 @@ CVE-2026-93394 (A flaw in libmongoc's SCRAM authentication implementation caused
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/6b27da3e0384170ac0efc75321556bd37a2ae03f (2.4.0)
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/0b9bbbff0b949dcddb97e518e7fdb5950e187be3 (1.30.11)
 CVE-2026-93393 (A heap-based buffer overflow exists in the TLS transport layer of the  ...)
-	- mongo-c-driver <unfixed> (bug #1148331)
+	- mongo-c-driver <unfixed> (bug #1148331; unimportant)
 	NOTE: https://jira.mongodb.org/browse/CDRIVER-6417
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/5536089200aeb837f27f39465d89506eeff689e1 (2.5.4)
 	NOTE: Fixed by: https://github.com/mongodb/mongo-c-driver/commit/01b1cf32fbe78044676c2fb163ba4f561a8d3ee3 (1.30.11)
+	NOTE: Only an issue when built with the Windows platform TLS backend.
 CVE-2026-93387 (Improper state validation in Skia in Google Chrome prior to 153.0.8010 ...)
 	- chromium 153.0.8010.52-1
 CVE-2026-93386 (UI misrepresentation in WebAppInstalls in Google Chrome prior to 153.0 ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5035a06cf9fc2bd55408134a34e01bb001c225c

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/d5035a06cf9fc2bd55408134a34e01bb001c225c
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/c71a71bf/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list