[Git][security-tracker-team/security-tracker][master] Add Debian bug references for various issues
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Fri Sep 25 13:40:40 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
72790588 by Salvatore Bonaccorso at 2026-09-25T14:37:00+02:00
Add Debian bug references for various issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -3459,10 +3459,10 @@ CVE-2026-6721 (IBM Concert 1.0.0 through 3.0.0 allows an unauthenticated remote
CVE-2026-6718 (IBM Concert 1.0.0 through 3.0.0 is vulnerable to improper access contr ...)
NOT-FOR-US: IBM
CVE-2026-6669 (Missing upper bound on the key derivation iteration count accepted dur ...)
- - pgbouncer <unfixed>
+ - pgbouncer <unfixed> (bug #1148946)
NOTE: Fixed by: https://github.com/pgbouncer/pgbouncer/commit/0a1d2f8656b508c815f416902bcec38e433a1061 (pgbouncer_1_26_0)
CVE-2026-6668 (Integer overflow in the packet buffer growth logic in PgBouncer throug ...)
- - pgbouncer <unfixed>
+ - pgbouncer <unfixed> (bug #1148946)
NOTE: Fixed by: https://github.com/pgbouncer/pgbouncer/commit/f2ff5538b0abc262e84dab4e946999dfbd3b0e18 (pgbouncer_1_26_0)
CVE-2026-6327 (IBM Concert 1.0.0 through 3.0.0 could allow an unauthorized user to in ...)
NOT-FOR-US: IBM
@@ -3583,7 +3583,7 @@ CVE-2026-5695 (Arbitrary file upload vulnerability due to a lack of proper valid
CVE-2026-59990 (Jawn is an open source JSON parser. Prior to 1.7.0, Jawn parse methods ...)
TODO: check
CVE-2026-59980 (hpack is an HTTP/2 Header Encoding for Python. Prior to version 4.2.0, ...)
- - python-hpack <unfixed>
+ - python-hpack <unfixed> (bug #1148944)
NOTE: https://github.com/python-hyper/hpack/security/advisories/GHSA-8v8h-hg4w-mvq2
NOTE: https://github.com/python-hyper/hpack/commit/8cfb02c547740e16dbfe7aba77bad84b297cec2c (v4.2.0)
CVE-2026-59167 (SunEditor is a lightweight and powerful WYSIWYG editor in vanilla Java ...)
@@ -3621,7 +3621,7 @@ CVE-2026-3626 (IBM Concert 1.0.0 through 3.0.0 could allow a remote attacker to
CVE-2026-31377 (An Improper Authentication vulnerability in the Apache Doris Frontend ...)
NOT-FOR-US: Apache software not packaged in Debian
CVE-2026-19888 (Missing validation of a mandatory attribute in the SCRAM client-final- ...)
- - pgbouncer <unfixed>
+ - pgbouncer <unfixed> (bug #1148946)
NOTE: Fixed by: https://github.com/pgbouncer/pgbouncer/commit/35749bc1c4e3c50dd5141071498066d85a011b85 (pgbouncer_1_26_0)
CVE-2026-19599 (ZohoCorp ManageEngine OpManager MSP versions 12.8.709 and below were v ...)
NOT-FOR-US: Zoho
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7279058846dda5b899250b61de9318c33a949ffc
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/7279058846dda5b899250b61de9318c33a949ffc
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260925/abfc2d4c/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list