[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Thu Sep 24 06:58:43 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
559165c3 by Salvatore Bonaccorso at 2026-09-24T07:57:49+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -524,7 +524,7 @@ CVE-2026-91025 (The Booking Manager  WordPress plugin before 2.1.21 does not ver
 CVE-2026-91024 (The Booking Manager  WordPress plugin before 2.1.21 does not sanitize  ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-91018 (lwIP (Lightweight IP)has a double free vulnerability, which could cras ...)
-	- lwip <unfixed>
+	- lwip <unfixed> (bug #1148822)
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f873b6295933e4149a2132adf3e9a2d2a676a5ec
 CVE-2026-90985 (The WPC Smart Compare for WooCommerce WordPress plugin before 6.6.1 do ...)
 	NOT-FOR-US: WordPress plugin
@@ -580,7 +580,7 @@ CVE-2026-87981 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does n
 CVE-2026-87979 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-87121 (lwIPTCP/IP Stack MQTTis vulnerable to an out-of-bounds write, which ma ...)
-	- lwip <unfixed>
+	- lwip <unfixed> (bug #1148822)
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=68b2c1191886578d40342846db6ab9a0099c2f40
 	NOTE: Fixed by: https://cgit.git.savannah.gnu.org/cgit/lwip.git/commit/?id=f89407ea711879c04d91c92b35d67be78bbaf0f1
 CVE-2026-87074 (The Forminator Forms  WordPress plugin before 1.57.2.1 does not bind i ...)
@@ -1318,50 +1318,50 @@ CVE-2026-81998 (Substance3D - Modeler is affected by an out-of-bounds write vuln
 CVE-2026-81995 (Adobe Experience Manager Forms JEE is affected by an Improper Input Va ...)
 	NOT-FOR-US: Adobe
 CVE-2026-81886 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-3xrx-wh64-8xr8
 	NOTE: https://github.com/radareorg/radare2/issues/26224
 	NOTE: https://github.com/radareorg/radare2/pull/26180
 	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/a7519fdb4da6835c2cecd8fe248e7dd1133cf17a (6.2.0)
 CVE-2026-81885 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-43wr-4j49-rcxj
 	NOTE: https://github.com/radareorg/radare2/issues/26225
 	NOTE: https://github.com/radareorg/radare2/pull/26192
 	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/93d794caa7c2f08413106255d49546e544c1f9f0 (6.2.0)
 CVE-2026-81884 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-c2g2-2mc7-3x5w
 	NOTE: https://github.com/radareorg/radare2/issues/26226
 	NOTE: https://github.com/radareorg/radare2/pull/26193
 	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/a73de09fea7516f65c14917d66113316ec7e7d6e (6.2.0)
 CVE-2026-81883 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-96m5-hvwp-674c
 	NOTE: https://github.com/radareorg/radare2/issues/26228
 	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/26c2eac360033458e9d266e5e30667d1f8d642e3 (6.2.0)
 CVE-2026-81882 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-r5cr-f9p6-5pvj
 	NOTE: https://github.com/radareorg/radare2/issues/26227
 	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/38d82a949626dba3783f40508bb66179e631fa45 (6.2.0)
 CVE-2026-81881 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-q4w7-225g-64j9
 	NOTE: https://github.com/radareorg/radare2/issues/26229
 	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/1da6e782df220edf56138ef5fe4f33745b04db74 (6.2.0)
 CVE-2026-81880 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-fg6f-rj8g-25pq
 	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/87c780e29ee6251cebaab51585d14482cb7740ac (6.2.0)
 CVE-2026-81879 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-jqfq-hvcp-xh4p
 	NOTE: https://github.com/radareorg/radare2/issues/26223
 	NOTE: https://github.com/radareorg/radare2/pull/26178
 	NOTE: Fixed by: https://github.com/radareorg/radare2/commit/9449b07579c19b6b187c1a0918fbec2cef1a036e (6.2.0)
 CVE-2026-81878 (radare2 is a UNIX-like reverse engineering framework and command-line  ...)
-	- radare2 <unfixed>
+	- radare2 <unfixed> (bug #1148820)
 	NOTE: https://github.com/radareorg/radare2/security/advisories/GHSA-9phv-v2w8-56j3
 	NOTE: https://github.com/radareorg/radare2/issues/26222
 	NOTE: https://github.com/radareorg/radare2/pull/26177
@@ -1434,7 +1434,7 @@ CVE-2026-77555 (A malicious actor with access to the network could exploit an Ou
 CVE-2026-77544 (A malicious actor with access to the network could exploit an Out-of-b ...)
 	NOT-FOR-US: Ubiquity
 CVE-2026-77399 (icalendar is an RFC 5545 compatible parser and generator of iCalendar  ...)
-	- python-icalendar <unfixed>
+	- python-icalendar <unfixed> (bug #1148817)
 	[trixie] - python-icalendar <not-affected> (Vulnerable code not present, introduced in 6.1.0)
 	[bookworm] - python-icalendar <not-affected> (Vulnerable code not present, introduced in 6.1.0)
 	NOTE: https://github.com/collective/icalendar/security/advisories/GHSA-qjcq-q7h7-r74v
@@ -3671,10 +3671,10 @@ CVE-2026-75892 (In osmo-ggsn 1.14.0 an out of bounds write issue was found in th
 	NOTE: Introduced in: https://cgit.osmocom.org/osmo-ggsn/commit/?id=d46d0cc3684522a053670946e1719d2520f3ac2a (1.14.0)
 	NOTE: Fixed in: https://cgit.osmocom.org/osmo-ggsn/commit/?id=6c322f4dd339401a437da3c89c95f2bf64bca995 (1.15.0)
 CVE-2026-85495
-	- ppp <unfixed>
+	- ppp <unfixed> (bug #1148821)
 	NOTE: https://github.com/ppp-project/ppp/security/advisories/GHSA-frhv-j822-2pvx
 CVE-2026-75883 (The code in pppd that formats a response to a PEAP Request packet in p ...)
-	- ppp <unfixed>
+	- ppp <unfixed> (bug #1148816)
 	NOTE: https://github.com/ppp-project/ppp/security/advisories/GHSA-rwr9-4vx8-vc35
 CVE-2026-75157 (Apache Airflow's asset queued-events DELETE endpoints checked the call ...)
 	- airflow <itp> (bug #819700)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/559165c3446002462bfbffef5d5e2c59f7a6bd4f

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/559165c3446002462bfbffef5d5e2c59f7a6bd4f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/24350468/attachment.htm>


More information about the debian-security-tracker-commits mailing list