[Git][security-tracker-team/security-tracker][master] Add new busybox issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 25 08:00:26 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fae42231 by Salvatore Bonaccorso at 2026-09-25T08:59:39+02:00
Add new busybox issues
Kept TODO as entries not specific linked to upstream reports yet.
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -1807,18 +1807,32 @@ CVE-2026-88845 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.
CVE-2026-88843 (The MasterStudy LMS WordPress Plugin WordPress plugin before 3.7.50 d ...)
NOT-FOR-US: WordPress plugin
CVE-2026-88840 (BusyBox TLS get_client_hello() reads past the end of the input buffer ...)
+ - busybox <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531354
TODO: check
CVE-2026-88839 (BusyBox passwd/group tokenize() references a stale endpoint pointer af ...)
+ - busybox <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531353
TODO: check
CVE-2026-88837 (BusyBox httpd treats yescrypt ($y$) password hashes as plaintext durin ...)
+ - busybox <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531351
TODO: check
CVE-2026-88835 (BusyBox dpkg read_package_field() steps past a NUL terminator on malfo ...)
+ - busybox <unfixed>
+ NOTE: ttps://bugzilla.redhat.com/show_bug.cgi?id=2531349
TODO: check
CVE-2026-88832 (BusyBox romfs volume ID parsing uses unbounded strlen on attacker-cont ...)
+ - busybox <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531345
TODO: check
CVE-2026-88831 (BusyBox httpd IP deny rules with invalid CIDR prefix lengths fail open ...)
+ - busybox <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531346
TODO: check
CVE-2026-88830 (A unit confusion in BusyBox TLS Montgomery reduction buffer allocation ...)
+ - busybox <unfixed>
+ NOTE: https://bugzilla.redhat.com/show_bug.cgi?id=2531344
TODO: check
CVE-2026-87978 (The Paymob for WooCommerce WordPress plugin before 4.1.14 does not ver ...)
NOT-FOR-US: WordPress plugin
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fae42231dc769bdccb864ce5665dd7c4feb8dc85
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fae42231dc769bdccb864ce5665dd7c4feb8dc85
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/8969c23a/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list