Salvatore Bonaccorso pushed to branch master at Debian Security Tracker / 
security-tracker


Commits:
5957f380 by Salvatore Bonaccorso at 2026-08-20T18:03:22+02:00
Add Debian bug references for various issues

- - - - -


1 changed file:

- data/CVE/list


Changes:

=====================================
data/CVE/list
=====================================
@@ -7,109 +7,109 @@ CVE-2026-75803 [Check the tag on EVP_Cipher() finalize: 
Poly1305 and OCB AEADs]
 CVE-2026-8619 (An unauthenticated denial-of-service vulnerability was 
identified in T ...)
        NOT-FOR-US: TPLink
 CVE-2026-76957 (libexpat before 2.8.4 lacks handler call depth tracking with 
custom en ...)
-       - expat <unfixed>
+       - expat <unfixed> (bug #1144927)
        NOTE: https://github.com/libexpat/libexpat/pull/1322
 CVE-2026-76956 (In libexpat 2.8.2 and 2.8.3 before 2.8.4, misinterpretation of 
getentr ...)
-       - expat <unfixed>
+       - expat <unfixed> (bug #1144926)
        NOTE: https://github.com/libexpat/libexpat/pull/1326
 CVE-2026-76929 (Pcapng file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 
allows  ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-84.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21460
 CVE-2026-76928 (X.509IF protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 
to 4.4.18 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-87.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21469
 CVE-2026-76927 (H.245 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18 a ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-77.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21447
 CVE-2026-76926 (BUSMASTER file parser abnormal exit in 4.6.0 to 4.6.7 and 
4.4.0 to 4.4 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-70.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21435
 CVE-2026-76924 (Kerberos protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 
to 4.4.1 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-78.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21449
 CVE-2026-76923 (Bluetooth HFP Profile protocol dissector crash in 4.6.0 to 
4.6.7 and 4 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-79.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21451
 CVE-2026-76922 (Bluetooth BR/EDR FHS protocol dissector crash in 4.6.0 to 
4.6.7 and 4. ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-80.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21452
 CVE-2026-76921 (CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18 all ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-83.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21458
        NOTE: https://gitlab.com/wireshark/wireshark/-/issues/21457 (private)
 CVE-2026-76920 (3gpp phone log file parser crash in 4.6.0 to 4.6.7 and 4.4.0 
to 4.4.18 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-81.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21454
 CVE-2026-76919 (ESS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18 all ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-86.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21467
 CVE-2026-76918 (SSH protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18 all ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-85.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21465
 CVE-2026-76917 (Bluetooth AVRCP Profile protocol dissector crash in 4.6.0 to 
4.6.7 and ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-91.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21488
 CVE-2026-76891 (Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows 
denial of ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-64
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21395
 CVE-2026-76890 (Crash in sharkd in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 allows 
denial of ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-65
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21399
 CVE-2026-76889 (UMTS FP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 
to 4.4.18 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-66
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21413
 CVE-2026-76888 (RDP protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18 all ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-67
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21396
 CVE-2026-76887 (Crash in the Wireshark dissection engine in 4.6.0 to 4.6.7 and 
4.4.0 t ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-69.html
 CVE-2026-76886 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18  ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-75.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21439
 CVE-2026-76885 (Tektronix K12xx file parser crash in 4.6.0 to 4.6.7 and 4.4.0 
to 4.4.1 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-71.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21414
 CVE-2026-76884 (ERF file parser crash in 4.6.0 to 4.6.7 and 4.4.0 to 4.4.18 
allows den ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-72.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21415
 CVE-2026-76883 (Catapult DCT2000 file parser crash in 4.6.0 to 4.6.7 and 4.4.0 
to 4.4. ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-74.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21427
 CVE-2026-76882 (Bluetooth Attribute Protocol dissector crash in 4.6.0 to 4.6.7 
and 4.4 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-73.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21424
 CVE-2026-76881 (CMS protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18 all ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-76.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21446
 CVE-2026-76880 (RRC protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18 all ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-88.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21478
 CVE-2026-76879 (C12.22 protocol dissector crash in 4.6.0 to 4.6.7 and 4.4.0 to 
4.4.18  ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-89.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/issues/21480 (private)
 CVE-2026-76878 (In OpenStack Aodh before 22.0.1, the alarm list API bypasses 
project s ...)
@@ -795,22 +795,22 @@ CVE-2026-76224 (ArcadeDB before 26.8.1 (arcadedb-gremlin, 
affected <= 26.7.3) co
 CVE-2026-76223 (ArcadeDB (com.arcadedb) versions 26.7.3 and earlier fail to 
enforce th ...)
        NOT-FOR-US: ArcadeDB
 CVE-2026-76222 (GitPython before 3.1.58 fails to validate submodule names from 
.gitmod ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144929)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hmq2-w58f-27jc
 CVE-2026-76221 (GitPython before 3.1.58 contains a config-name injection 
vulnerability ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144929)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-jm78-9fvv-mhgr
 CVE-2026-76220 (GitPython before 3.1.58 contains a command execution 
vulnerability in  ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144929)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-wvpp-8hx9-p66j
 CVE-2026-76219 (GitPython versions before 3.1.58 contain an arbitrary file 
overwrite v ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144929)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-4gmw-gg2m-w46p
 CVE-2026-76218 (GitPython before 3.1.58 contains a remote code execution 
vulnerability ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144929)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-9rj7-rf2p-w77r
 CVE-2026-76217 (GitPython versions before 3.1.58 fail to validate options 
passed to gi ...)
-       - python-git <unfixed>
+       - python-git <unfixed> (bug #1144929)
        NOTE: 
https://github.com/gitpython-developers/GitPython/security/advisories/GHSA-hh9p-6wh2-4mfc
 CVE-2026-76216 (Vikunja through 2.4.0 contains a principal-type confusion 
vulnerabilit ...)
        NOT-FOR-US: Vikunja
@@ -1661,7 +1661,7 @@ CVE-2026-71153 (Vulnerability in the Helidon product of 
Oracle Fusion Middleware
 CVE-2026-71152 (Vulnerability in the Helidon product of Oracle Fusion 
Middleware (comp ...)
        NOT-FOR-US: Oracle
 CVE-2026-71151 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71150 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
        NOT-FOR-US: Oracle
 CVE-2026-71149 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
@@ -1681,37 +1681,37 @@ CVE-2026-71143 (Vulnerability in the Oracle 
Communications Unified Inventory Man
 CVE-2026-71142 (Vulnerability in the Oracle Communications Unified Inventory 
Managemen ...)
        NOT-FOR-US: Oracle
 CVE-2026-71141 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71140 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71139 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71138 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71137 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71136 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71135 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71134 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71132 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71131 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71130 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71129 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71128 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71127 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71126 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71125 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71124 (Vulnerability in the Oracle Access Manager product of Oracle 
Fusion Mi ...)
        NOT-FOR-US: Oracle
 CVE-2026-71123 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
@@ -1729,13 +1729,13 @@ CVE-2026-71118 (Vulnerability in the Oracle Hyperion 
Financial Management produc
 CVE-2026-71117 (Vulnerability in the Oracle Hyperion Financial Management 
product of O ...)
        NOT-FOR-US: Oracle
 CVE-2026-71116 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71115 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71114 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71113 (Vulnerability in the Oracle VM VirtualBox product of Oracle 
Virtualiza ...)
-       - virtualbox <unfixed>
+       - virtualbox <unfixed> (bug #1144928)
 CVE-2026-71112 (Vulnerability in the PeopleSoft Enterprise FIN Common Objects 
product  ...)
        NOT-FOR-US: Oracle
 CVE-2026-71111 (Vulnerability in the Oracle Identity Manager product of Oracle 
Fusion  ...)
@@ -4350,7 +4350,7 @@ CVE-2026-66621 (Unauthenticated Cross Site Scripting 
(XSS) in Ultimate Dashboard
 CVE-2026-66620 (Editor PHP Object Injection in OptionTree <= 2.7.3 versions.)
        NOT-FOR-US: WordPress plugin or theme
 CVE-2026-66046 (Expat through 2.8.3 contains a denial of service vulnerability 
caused  ...)
-       - expat <unfixed>
+       - expat <unfixed> (bug #1144925)
        NOTE: https://github.com/libexpat/libexpat/pull/1321
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/98f5acc146af76859cd7c345c0906e9e9e8ea656
        NOTE: Fixed by: 
https://github.com/libexpat/libexpat/commit/f8f7c4ffd883e3c2c58f0ebb49416a6c1d248738
@@ -12057,21 +12057,21 @@ CVE-2026-19716 (Stored Cross-site Scripting (CWE-79) 
in the user management comp
 CVE-2026-19710 (A vulnerability was found in SourceCodester Simple Student 
Information ...)
        NOT-FOR-US: SourceCodester
 CVE-2026-19696 (Ixia IxVeriWave and Vector Informatik BLF file parser crashes 
in 4.6.0 ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        [trixie] - wireshark <not-affected> (Only affects 4.6)
        [bookworm] - wireshark <not-affected> (Only affects 4.6)
        [bullseye] - wireshark <not-affected> (Only affects 4.6)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-82.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21455
 CVE-2026-19695 (Gammu DCT3 trace file parser crash in 4.6.0 to 4.6.7 allows 
denial of  ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        [trixie] - wireshark <not-affected> (Only affects 4.6)
        [bookworm] - wireshark <not-affected> (Only affects 4.6)
        [bullseye] - wireshark <not-affected> (Only affects 4.6)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-90.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21475
 CVE-2026-19694 (TTX Logger file parser crash in 4.6.0 to 4.6.7 allows denial 
of servic ...)
-       - wireshark <unfixed>
+       - wireshark <unfixed> (bug #1144924)
        NOTE: https://www.wireshark.org/security/wnpa-sec-2026-68.html
        NOTE: https://gitlab.com/wireshark/wireshark/-/work_items/21389
 CVE-2026-19487 (Perl versions from 5.9.4 before 5.41.9 produce incorrect 
regular expre ...)



View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5957f380a8e24a96af289e995d21212bc010848b

-- 
View it on GitLab: 
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/5957f380a8e24a96af289e995d21212bc010848b
You're receiving this email because of your account on salsa.debian.org. Manage 
all notifications: https://salsa.debian.org/-/profile/notifications | Help: 
https://salsa.debian.org/help


_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits

Reply via email to