[Git][security-tracker-team/security-tracker][master] Track fixed version for glib-networking issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Sat Sep 19 12:55:47 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
7cf2076b by Salvatore Bonaccorso at 2026-09-19T13:44:17+02:00
Track fixed version for glib-networking issues

Two CVEs had a typo in the year in the debian/changelog file as
uploaded, they are CVE-2025-60018 and CVE-2025-60019 and fixed as well
with the 2.90.0-1 upload.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -115473,7 +115473,7 @@ CVE-2026-2128 (The Breeze plugin for WordPress is vulnerable to Exposure of Sens
 CVE-2026-10044 (Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary fil ...)
 	NOT-FOR-US: Usagi-org ai-goofish-monitor
 CVE-2026-10028 (A flaw was found in glib-networking. A remote attacker can exploit thi ...)
-	- glib-networking <unfixed> (bug #1138235)
+	- glib-networking 2.90.0-1 (bug #1138235)
 	[trixie] - glib-networking <postponed> (Minor issue, revisit when fixed upstream)
 	[bookworm] - glib-networking <postponed> (Minor issue, revisit when fixed upstream)
 	[bullseye] - glib-networking <postponed> (Minor issue)
@@ -174444,7 +174444,7 @@ CVE-2026-2604 (A flaw was found in evolution-data-server. Inconsistent compariso
 CVE-2026-2575 (A flaw was found in Keycloak. An unauthenticated remote attacker can t ...)
 	- keycloak <itp> (bug #1088287)
 CVE-2026-2574
-	- glib-networking <unfixed> (unimportant)
+	- glib-networking 2.90.0-1 (unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/issues/228
 	NOTE: OpenSSL backend disabled by default upstream and in Debian
 CVE-2026-2474 (Crypt::URandom versions from 0.41 before 0.55 for Perl is vulnerable t ...)
@@ -229438,13 +229438,13 @@ CVE-2025-10036 (The Featured Image from URL (FIFU) plugin for WordPress is vulne
 CVE-2025-60249 (vulnerability-lookup 2.16.0 allows XSS in bundle.py, comment.py, and u ...)
 	NOT-FOR-US: vulnerability-lookup
 CVE-2025-60019 (glib-networking's OpenSSL backend fails to properly check the return v ...)
-	- glib-networking <unfixed> (bug #1116429; unimportant)
+	- glib-networking 2.90.0-1 (bug #1116429; unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/issues/227
 	NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/merge_requests/263
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/glib-networking/-/commit/70df675dd4f5e4a593b2f95406c1aac031aa8bc7
 	NOTE: OpenSSL backend disabled by default upstream and in Debian
 CVE-2025-60018 (glib-networking's OpenSSL backend fails to properly check the return v ...)
-	- glib-networking <unfixed> (bug #1116430; unimportant)
+	- glib-networking 2.90.0-1 (bug #1116430; unimportant)
 	NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/issues/226
 	NOTE: https://gitlab.gnome.org/GNOME/glib-networking/-/merge_requests/262
 	NOTE: Fixed by: https://gitlab.gnome.org/GNOME/glib-networking/-/commit/4dd540505d40babe488404f3174ec39f49a84485



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cf2076b91dadabd6d3395bf5cbfc7d617947e3a

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7cf2076b91dadabd6d3395bf5cbfc7d617947e3a
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/8ffc27b8/attachment.htm>


More information about the debian-security-tracker-commits mailing list