[Git][security-tracker-team/security-tracker][master] Add initial tracking for new libxi issues (not yet merged upstream)

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 07:48:16 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
5272807e by Salvatore Bonaccorso at 2026-09-25T08:47:48+02:00
Add initial tracking for new libxi issues (not yet merged upstream)

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -150,18 +150,27 @@ CVE-2026-94604
 	REJECTED
 CVE-2026-94416 (An authorization bypass was found in the Ansible Automation Platform ( ...)
 	NOT-FOR-US: Red Hat Ansible Automation Platform
+CVE-2026-94282
+	- libxi <unfixed>
+	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-94281 (An out-of-bounds read in libXi's XListInputDevices() class parsing in  ...)
-	TODO: check
+	- libxi <unfixed>
+	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93545 (An out-of-bounds read in libXi's XListInputDevices() in libXi before 1 ...)
-	TODO: check
+	- libxi <unfixed>
+	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93544 (An out-of-bounds read in libXi's XI2 XIQueryDevice reply parsing in li ...)
-	TODO: check
+	- libxi <unfixed>
+	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93543 (An out-of-bounds read in libXi's XI2 class parser in libXi before 1.8. ...)
-	TODO: check
+	- libxi <unfixed>
+	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93542 (An out-of-bounds read in libXi's XI2 class parsing via size_classes()  ...)
-	TODO: check
+	- libxi <unfixed>
+	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93541 (An out-of-bounds read in libXi's XQueryDeviceState() in libXi before 1 ...)
-	TODO: check
+	- libxi <unfixed>
+	NOTE: https://gitlab.freedesktop.org/xorg/lib/libxi/-/merge_requests/23
 CVE-2026-93425 (Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior t ...)
 	TODO: check
 CVE-2026-93405 (Mailspring is a fast, cross-platform, open-source email client. Prior  ...)



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5272807e67f6e5b66281113f80b7d4d6bd81dd5b

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5272807e67f6e5b66281113f80b7d4d6bd81dd5b
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/8ef07c74/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list