[Git][security-tracker-team/security-tracker][master] Add new busybox issues

Salvatore Bonaccorso (@carnil) carnil at debian.org
Fri Sep 25 08:00:26 BST 2026



Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker


Commits:
fae42231 by Salvatore Bonaccorso at 2026-09-25T08:59:39+02:00
Add new busybox issues

Kept TODO as entries not specific linked to upstream reports yet.

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -1807,18 +1807,32 @@ CVE-2026-88845 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.
 CVE-2026-88843 (The MasterStudy LMS WordPress Plugin  WordPress plugin before 3.7.50 d ...)
 	NOT-FOR-US: WordPress plugin
 CVE-2026-88840 (BusyBox TLS get_client_hello() reads past the end of the input buffer  ...)
+	- busybox <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531354
 	TODO: check
 CVE-2026-88839 (BusyBox passwd/group tokenize() references a stale endpoint pointer af ...)
+	- busybox <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531353
 	TODO: check
 CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as plaintext durin ...)
+	- busybox <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
 	TODO: check
 CVE-2026-88835 (BusyBox dpkg read_package_field() steps past a NUL terminator on malfo ...)
+	- busybox <unfixed>
+	NOTE: ttps://bugzilla.redhat.com/show_bug.cgi?id=2531349
 	TODO: check
 CVE-2026-88832 (BusyBox romfs volume ID parsing uses unbounded strlen on attacker-cont ...)
+	- busybox <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531345
 	TODO: check
 CVE-2026-88831 (BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open ...)
+	- busybox <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531346
 	TODO: check
 CVE-2026-88830 (A unit confusion in BusyBox TLS Montgomery reduction buffer allocation ...)
+	- busybox <unfixed>
+	NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531344
 	TODO: check
 CVE-2026-87978 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
 	NOT-FOR-US: WordPress plugin



View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fae42231dc769bdccb864ce5665dd7c4feb8dc85

-- 
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fae42231dc769bdccb864ce5665dd7c4feb8dc85
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help


-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/8969c23a/attachment-0001.htm>


More information about the debian-security-tracker-commits mailing list