[Git][security-tracker-team/security-tracker][master] Add two new lwip issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Wed Sep 23 13:02:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
182a4e2e by Salvatore Bonaccorso at 2026-09-23T14:01:39+02:00
Add two new lwip issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -346,7 +346,8 @@ CVE-2026-91025 (The Booking Manager  WordPress plugin before 2.1.21 does not ver
 CVE-2026-91024 (The Booking Manager  WordPress plugin before 2.1.21 does not sanitize  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-91018 (lwIP (Lightweight IP)has a double free vulnerability, which could cras ...)
-	TODO: check
+	- lwip <unfixed>
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f873b6295933e4149a2132adf3e9a2d2a676a5ec
 CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 do ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-90951 (The Paid Membership Subscriptions  WordPress plugin before 3.1.0 does  ...)
@@ -392,7 +393,8 @@ CVE-2026-87981 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does n
 CVE-2026-87979 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87121 (lwIPTCP/IP Stack MQTTis vulnerable to an out-of-bounds write, which ma ...)
-	TODO: check
+	- lwip <unfixed>
+	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f89407ea711879c04d91c92b35d67be78bbaf0f1
 CVE-2026-87074 (The Forminator Forms  WordPress plugin before 1.57.2.1 does not bind i ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87069 (The Forminator Forms  WordPress plugin before 1.57.2.1 does not perfor ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/182a4e2e4de69a07ed871f68a56a35c274146cdb

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/182a4e2e4de69a07ed871f68a56a35c274146cdb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/cd4217c9/attachment.htm>


More information about the debian-security-tracker-commits mailing list