[Git][security-tracker-team/security-tracker][master] Update status for CVE-2026-14330
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Mon Sep 21 12:56:40 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
e2be05c5 by Salvatore Bonaccorso at 2026-09-21T13:56:07+02:00
Update status for CVE-2026-14330
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -90628,6 +90628,7 @@ CVE-2026-14330 (Multiple unbounded alloca() calls in the PulseAudio protocol ser
[bookworm] - pipewire <postponed> (Minor issue)
[bullseye] - pipewire <postponed> (Minor issue)
NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2495907
+ NOTE: Fixed by: https://gitlab.freedesktop.org/pipewire/pipewire/-/commit/ed2c0ad4eee1695381e06f7accb902cbcf547420
CVE-2026-14324 (RAOP module accepts unbounded Content-Length values and does not check ...)
- pipewire 1.6.8-1 (bug #1141308)
[trixie] - pipewire <no-dsa> (Minor issue)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2be05c58a5dd0ac0e629b0aa12d4f2710132bce
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/e2be05c58a5dd0ac0e629b0aa12d4f2710132bce
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260921/6a048698/attachment.htm>
More information about the debian-security-tracker-commits
mailing list