[Git][security-tracker-team/security-tracker][master] Add two new lwip issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Wed Sep 23 13:02:16 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
182a4e2e by Salvatore Bonaccorso at 2026-09-23T14:01:39+02:00
Add two new lwip issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -346,7 +346,8 @@ CVE-2026-91025 (The Booking Manager WordPress plugin before 2.1.21 does not ver
CVE-2026-91024 (The Booking Manager WordPress plugin before 2.1.21 does not sanitize ...)
NOT-FOR-US: WordPress plugin
CVE-2026-91018 (lwIP (Lightweight IP)has a double free vulnerability, which could cras ...)
- TODO: check
+ - lwip <unfixed>
+ NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f873b6295933e4149a2132adf3e9a2d2a676a5ec
CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 do ...)
NOT-FOR-US: WordPress plugin
CVE-2026-90951 (The Paid Membership Subscriptions WordPress plugin before 3.1.0 does ...)
@@ -392,7 +393,8 @@ CVE-2026-87981 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does n
CVE-2026-87979 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
NOT-FOR-US: WordPress plugin
CVE-2026-87121 (lwIPTCP/IP Stack MQTTis vulnerable to an out-of-bounds write, which ma ...)
- TODO: check
+ - lwip <unfixed>
+ NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f89407ea711879c04d91c92b35d67be78bbaf0f1
CVE-2026-87074 (The Forminator Forms WordPress plugin before 1.57.2.1 does not bind i ...)
NOT-FOR-US: WordPress plugin
CVE-2026-87069 (The Forminator Forms WordPress plugin before 1.57.2.1 does not perfor ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/182a4e2e4de69a07ed871f68a56a35c274146cdb
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/182a4e2e4de69a07ed871f68a56a35c274146cdb
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260923/cd4217c9/attachment.htm>
More information about the debian-security-tracker-commits
mailing list