[Git][security-tracker-team/security-tracker][master] Add CVE-2026-100419/rust-gix-fs
Salvatore Bonaccorso (@carnil)
carnil at debian.org
Sat Sep 26 21:37:11 BST 2026
Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / security-tracker
Commits:
88d2b911 by Salvatore Bonaccorso at 2026-09-26T22:36:32+02:00
Add CVE-2026-100419/rust-gix-fs
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -605,7 +605,9 @@ CVE-2026-100502 (Flame through 2.4.0 contains an insufficient session expiration
CVE-2026-100501 (Flame through 2.4.0 contains an improper restriction of excessive auth ...)
NOT-FOR-US: Flame
CVE-2026-100419 (gitoxide gix-fs before 0.23.0 contains a path validation bypass vulner ...)
- TODO: check
+ - rust-gix-fs <unfixed>
+ NOTE: https://github.com/GitoxideLabs/gitoxide/security/advisories/GHSA-6p9q-f2xg-6pr5
+ NOTE: Fixed by: https://github.com/GitoxideLabs/gitoxide/commit/b62498378b8bc2c95863a044b700f2063b0b5875 (gix-fs-v0.23.0)
CVE-2026-100418 (Flame through 2.4.0 contains an information exposure vulnerability in ...)
NOT-FOR-US: Flame
CVE-2026-100417 (RustDesk before 1.5.0 on Windows fails to enforce the one-way file tra ...)
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d2b91170e62dfb9e20efb224f3138350f9700f
--
View it on GitLab: https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/88d2b91170e62dfb9e20efb224f3138350f9700f
You're receiving this email because of your account on salsa.debian.org. Manage all notifications: https://salsa.debian.org/-/profile/notifications | Help: https://salsa.debian.org/help
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://alioth-lists.debian.net/pipermail/debian-security-tracker-commits/attachments/20260926/3789b18f/attachment-0001.htm>
More information about the debian-security-tracker-commits
mailing list