Salvatore Bonaccorso pushed to branch master at Debian Security Tracker /
security-tracker
Commits:
b7947be3 by Salvatore Bonaccorso at 2026-09-09T22:23:34+02:00
Add new zstd-jni-java issues
- - - - -
1 changed file:
- data/CVE/list
Changes:
=====================================
data/CVE/list
=====================================
@@ -9,7 +9,10 @@ CVE-2026-87928 (MaxSite CMS versions 0.94 through 109.6
contain a cross-site scr
CVE-2026-87927 (MaxSite CMS through 109.6 contains a local file inclusion
vulnerabilit ...)
NOT-FOR-US: MaxSite CMS
CVE-2026-87877 (zstd-jni versions before 1.5.7-14 fail to validate closed
state in set ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-2jw3-mg7f-vw4q
+ NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/f38f9a1563113d96d0fc38baee543f7457dd8a8e
(v1.5.7-14)
+ NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555
(v1.5.7-14)
CVE-2026-87876 (Two case-insensitive comparisons on request-derived usernames
outside ...)
TODO: check
CVE-2026-87875 (The cupsUTF32ToUTF8() function in CUPS's cups/transcode.c
lacks a sour ...)
@@ -23,11 +26,18 @@ CVE-2026-87853 (A flaw was found in SSSD's IdP
authentication provider. The eval
CVE-2026-87827 (Certain KGUARD DVR devices running vulnerable firmware expose
a system ...)
TODO: check
CVE-2026-87825 (zstd-jni before 1.5.7-14 contains a use-after-free
vulnerability where ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-947w-pxjj-c7m9
+ NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/393d7311766abbc285b149302c0fe1f94b16d555
(v1.5.7-14)
+ NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/a560131d7834598afd9cea6b7c107bc88e915936
(v1.5.7-14)
CVE-2026-87824 (zstd-jni before 1.5.7-14 fails to validate the samples buffer
capacity ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-257p-3h6w-pg7h
+ NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/bba6cfca2c0897f1fa004f4193247479f10da853
(v1.5.7-14)
CVE-2026-87823 (zstd-jni before 1.5.7-14 performs 32-bit signed bounds checks
on three ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-jfr6-9xqw-2g2q
+ NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/d7a1c99322d5e1fc71932e722c0b5bb2fc525d3f
(v1.5.7-14)
CVE-2026-87822 (t-digest versions 3.1 through 3.3 fail to validate centroid
means duri ...)
TODO: check
CVE-2026-87821 (Lara Dashboard through 1.3.1 contains a server-side request
forgery vu ...)
@@ -63,7 +73,9 @@ CVE-2026-87807 (siyuan versions before v3.8.2 contain an
authenticated SQL injec
CVE-2026-87806 (Parse Server versions <= 8.6.87 and >= 9.0.0 < 9.10.1-alpha.7
contain ...)
NOT-FOR-US: Parse Server
CVE-2026-87795 (zstd-jni versions before 1.5.7-14 fail to validate offset and
length p ...)
- TODO: check
+ - zstd-jni-java <unfixed>
+ NOTE:
https://github.com/luben/zstd-jni/security/advisories/GHSA-ff36-7w3w-g8rm
+ NOTE: Fixed by:
https://github.com/luben/zstd-jni/commit/0d64de4dee6606ff506be36c7f2e714ad0c80fdb
(v1.5.7-14)
CVE-2026-87794 (bestzip versions 2.2.6 and 3.0.2 contain an argument injection
vulnera ...)
TODO: check
CVE-2026-86777 (AlchemyCMS versions before 7.4.16 and 8.x before 8.3.6 fail to
authori ...)
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7947be34c90944af5f710953c9de313b0154ab3
--
View it on GitLab:
https://salsa.debian.org/security-tracker-team/security-tracker/-/commit/b7947be34c90944af5f710953c9de313b0154ab3
You're receiving this email because of your account on salsa.debian.org. Manage
all notifications: https://salsa.debian.org/-/profile/notifications | Help:
https://salsa.debian.org/help
_______________________________________________
debian-security-tracker-commits mailing list
[email protected]
https://alioth-lists.debian.net/cgi-bin/mailman/listinfo/debian-security-tracker-commits