[Git][security-tracker-team/security-tracker][master] Add CVE-2026-88358/simdjson
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 25 11:02:17 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
fc795ffc by Salvatore Bonaccorso at 2026-09-25T12:01:52+02:00
Add CVE-2026-88358/simdjson
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -298,7 +298,10 @@ CVE-2026-88359 (libfyaml 0.9.6 contains a stack exhaustion vulnerability in fy_a
NOTE: https://github.com/pantoniou/libfyaml/issues/315
NOTE: Fixed by: https://github.com/pantoniou/libfyaml/commit/12d903a5c9163d15edf2ef9d7311bd0d1505d902 (v1.0.0-beta1)
CVE-2026-88358 (simdjson 4.6.1 contains a one-byte out-of-bounds read vulnerability in ...)
- TODO: check
+ - simdjson <unfixed>
+ NOTE: https://github.com/simdjson/simdjson/issues/2815
+ NOTE: https://github.com/simdjson/simdjson/pull/2817
+ NOTE: Fixed by: https://github.com/simdjson/simdjson/commit/20b28712ffce8320237b75a587d35a2e89140577
CVE-2026-88357 (nDPI 5.1.0 contains a memory access issue in the DNS dissector and ser ...)
TODO: check
CVE-2026-88355 (An incorrect buffer size calculation vulnerability exists in tinyexpr ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fc795ffc8d7a22a76250110dee4de18b3d618b8f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/fc795ffc8d7a22a76250110dee4de18b3d618b8f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/92a3394f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list