Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
a5b9ef9a by Salvatore Bonaccorso at 2026-06-25T22:34:26+02:00
Add some new wolfssl issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -27,11 +27,14 @@ CVE-2026-9083 (A flaw was found in Keycloak. A realm
administrator with the "man
CVE-2026-6432 (Improper bounds validation in EmberZNet SDK versions 9.0.2 and
earlier ...)
NOT-FOR-US: Silicon Labs
CVE-2026-6291 (Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When
decrypti ...)
- TODO: check
+ - wolfssl <unfixed>
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10203 (v5.9.2-stable)
CVE-2026-6094 (Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when
parsing craf ...)
- TODO: check
+ - wolfssl <unfixed>
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10128 (v5.9.2-stable)
CVE-2026-6091 (Partial-chain certificate verification may accept chains that
terminat ...)
- TODO: check
+ - wolfssl <unfixed>
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10170 (v5.9.2-stable)
CVE-2026-57700 (Unrestricted Upload of File with Dangerous Type vulnerability
in Daan. ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-57619 (Contributor Sensitive Data Exposure in Elementor Website
Builder <= 4. ...)
@@ -174,9 +177,11 @@ CVE-2026-56006 (Unauthenticated Cross Site Scripting (XSS)
in H5P <= 1.17.6 vers
CVE-2026-56005 (Subscriber Cross Site Scripting (XSS) in WP Activity Log <=
5.6.3.1 ve ...)
NOT-FOR-US: WordPress plugin or theme
CVE-2026-55967 (AES-GCM encryption/decryption with extremely large cumulative
single m ...)
- TODO: check
+ - wolfssl <unfixed>
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10709 (v5.9.2-stable)
CVE-2026-55961 (wolfSSL_PKCS7_verify() returning success for a degenerate
(certs-only) ...)
- TODO: check
+ - wolfssl <unfixed>
+ NOTE: https://github.com/wolfSSL/wolfssl/pull/10702 (v5.9.2-stable)
CVE-2026-55895 (Vim is an open source, command line text editor. Prior to
9.2.0663, a ...)
- vim <unfixed>
NOTE: https://github.com/vim/vim/security/advisories/GHSA-vhh8-v6wx-hjjh
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5b9ef9add1cc319df8d7dddf42fb97cb286b31b
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/a5b9ef9add1cc319df8d7dddf42fb97cb286b31b
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits