[Git][security-tracker-team/security-tracker][master] libslirp fixed in sid

Moritz Muehlenhoff (@jmm) jmm at debian.org
Thu Sep 24 12:27:38 BST 2026



Moritz Muehlenhoff pushed to branch master at Debian Security Tracker / security-tracker


Commits:
a134b5ab by Moritz Muehlenhoff at 2026-09-24T13:27:09+02:00
libslirp fixed in sid

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -2070,13 +2070,14 @@ CVE-2026-95619 (A flaw was found in libstdc++. An integer overflow can occur whe
 CVE-2026-95511
 	REJECTED
 CVE-2026-95508 (A heap-based buffer overflow was found in the DHCPv6 and TFTP response ...)
-	- libslirp <unfixed> (bug #1148836)
+	- libslirp 4.9.5-1 (bug #1148836)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537748
 	NOTE: Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/97f2dd0afea0db8b31135f768ecafe0775722a25 (v4.9.5)
 	NOTE: Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/5815f119c334c26e6e7a14ac87eca12b69918627 (v4.9.5)
-	TODO: check if fixes complete, the TFTP part is missing yet in v4.9.5?
+	NOTE: CVE description is wrong, per https://gitlab.freedesktop.org/slirp/libslirp/-/commit/62b298621dfc413a42d2181933f5335815afa1a4
+	NOTE: is only for the DHCPv6 part
 CVE-2026-95507
-	- libslirp <unfixed> (bug #1148835)
+	- libslirp 4.9.5-1 (bug #1148835)
 	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2537747
 	NOTE: Fixed by: https://gitlab.freedesktop.org/slirp/libslirp/-/commit/b4b2b07812fcadd2754281e5ae8d9fe2bfb3c96a (v4.9.5)
 CVE-2026-95503 (A flaw was found in the Kerberos federation provider of Keycloak, an o ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a134b5ab9ae494676e680c69ab30d448bc655024

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a134b5ab9ae494676e680c69ab30d448bc655024
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260924/a2cb0e44/attachment.htm>


More information about the debian-security-tracker-commits mailing list