Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
a5b9ef9a by Salvatore Bonaccorso at 2026-06-25T22:34:26+02:00
Add some new wolfssl issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -27,11 +27,14 @@ CVE-2026-9083 (A flaw was found in Keycloak. A realm 
administrator with the "man
 CVE-2026-6432 (Improper bounds validation in EmberZNet SDK versions 9.0.2 and 
earlier ...)
        NOT-FOR-US: Silicon Labs
 CVE-2026-6291 (Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When 
decrypti ...)
-       TODO: check
+       - wolfssl <unfixed>
+       NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
 CVE-2026-6094 (Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when 
parsing craf ...)
-       TODO: check
+       - wolfssl <unfixed>
+       NOTE: https://github.com/wolfSSL/wolfssl/pull/10128 (v5.9.2-stable)
 CVE-2026-6091 (Partial-chain certificate verification may accept chains that 
terminat ...)
-       TODO: check
+       - wolfssl <unfixed>
+       NOTE: https://github.com/wolfSSL/wolfssl/pull/10170 (v5.9.2-stable)
 CVE-2026-57700 (Unrestricted Upload of File with Dangerous Type vulnerability 
in Daan. ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-57619 (Contributor Sensitive Data Exposure in Elementor Website 
Builder <= 4. ...)
@@ -174,9 +177,11 @@ CVE-2026-56006 (Unauthenticated Cross Site Scripting (XSS) 
in H5P <= 1.17.6 vers
 CVE-2026-56005 (Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 
5.6.3.1 ve ...)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-55967 (AES-GCM encryption/decryption with extremely large cumulative 
single m ...)
-       TODO: check
+       - wolfssl <unfixed>
+       NOTE: https://github.com/wolfSSL/wolfssl/pull/10709 (v5.9.2-stable)
 CVE-2026-55961 (wolfSSL_PKCS7_verify() returning success for a degenerate 
(certs-only) ...)
-       TODO: check
+       - wolfssl <unfixed>
+       NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
 CVE-2026-55895 (Vim is an open source, command line text editor. Prior to 
9.2.0663, a  ...)
        - vim <unfixed>
        NOTE: https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5b9ef9add1cc319df8d7dddf42fb97cb286b31b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5b9ef9add1cc319df8d7dddf42fb97cb286b31b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to