[Git][security-tracker-team/security-tracker][master] Update status for three libkcapi issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 19 19:41:40 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
36090151 by Salvatore Bonaccorso at 2026-09-19T20:39:47+02:00
Update status for three libkcapi issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -59831,20 +59831,23 @@ CVE-2026-71232 (MacCMS10's admin template editor (application/admin/controller/T
CVE-2026-71231 (IOTSmartHome's gui/login.php checkCookie function builds an authentica ...)
NOT-FOR-US: IOTSmartHome
CVE-2026-71227 (A flaw was found in libkcapi. A local attacker can influence an applic ...)
- - libkcapi <unfixed> (bug #1143974)
+ - libkcapi 1.5.1-1 (bug #1143974)
[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462867
+ NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/9a29cc2ce0fa87ec212d58118402eafe07db3f60 (v1.5.1)
CVE-2026-71226 (Memory Corruption via Uncanceled AIO Requests on Error: libkcapi's one ...)
- - libkcapi <unfixed> (bug #1143974)
+ - libkcapi 1.5.1-1 (bug #1143974)
[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462114
+ NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/cd966ffa08cf605ae5853d2f9a42fdd2b6df8bb4 (v1.5.1)
CVE-2026-71225 (A flaw was found in libkcapi. When performing one-shot symmetric ciphe ...)
- - libkcapi <unfixed> (bug #1143974)
+ - libkcapi 1.5.1-1 (bug #1143974)
[trixie] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
[bookworm] - libkcapi <postponed> (Minor issue, revisit when fixed upstream)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2462011
+ NOTE: Fixed by: https://github.com/smuellerDD/libkcapi/commit/017adba8f54f36f92e1919687fb67a89c4d299c6 (v1.5.1)
CVE-2026-71215 (art-template's sub-template resolution logic (src/compile/adapter/reso ...)
NOT-FOR-US: art-template
CVE-2026-71214 (The Aerie/PlanDev sequencing-server's authorization middleware (sequen ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/360901511ade7de3d26e5da52a73f5c4d7393b99
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/360901511ade7de3d26e5da52a73f5c4d7393b99
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260919/59be218c/attachment.htm>
More information about the debian-security-tracker-commits
mailing list