Skip to content

Commit 05b35d9

Browse files
Sync Collecting Fix Commits: Sun Sep 6 15:56:48 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 07a1775 commit 05b35d9

6 files changed

Lines changed: 281 additions & 49 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 58 additions & 15 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,64 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-PQWR-MV7C-MQ9Q": {
5+
"1be4607fe56dfdcb3147dd3e1c7771e37b209603": "Publish Advisories\n\nGHSA-pqwr-mv7c-mq9q\nGHSA-w6q9-cjvw-4mhm",
6+
"040d287c5bbb43c736318ee4e5f2f465dcc2045b": "Publish Advisories\n\nGHSA-pqwr-mv7c-mq9q\nGHSA-w6q9-cjvw-4mhm"
7+
},
8+
"GHSA-W6Q9-CJVW-4MHM": {
9+
"1be4607fe56dfdcb3147dd3e1c7771e37b209603": "Publish Advisories\n\nGHSA-pqwr-mv7c-mq9q\nGHSA-w6q9-cjvw-4mhm",
10+
"040d287c5bbb43c736318ee4e5f2f465dcc2045b": "Publish Advisories\n\nGHSA-pqwr-mv7c-mq9q\nGHSA-w6q9-cjvw-4mhm"
11+
},
12+
"GHSA-5JGF-P345-68V8": {
13+
"3f96b865468b408d9b2b0f0324770ad81b1d017f": "Improve GHSA-5jgf-p345-68v8",
14+
"f85ffe2ae5b98b4c506f1e5f0f49f445a0dbbfa5": "Publish Advisories\n\nGHSA-8vh5-mgjj-w6hg\nGHSA-qg9p-xrhj-435m\nGHSA-3gqm-fcw5-w839\nGHSA-5jgf-p345-68v8\nGHSA-f65p-4m7j-42xc\nGHSA-fph4-wmhf-6fwf\nGHSA-jqff-g426-hqxp\nGHSA-p3m8-78j2-g5p3\nGHSA-8vh5-mgjj-w6hg\nGHSA-qg9p-xrhj-435m"
15+
},
16+
"GHSA-4JGG-5R84-R28R": {
17+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
18+
},
19+
"GHSA-5JH7-HRJ4-QC2F": {
20+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
21+
},
22+
"GHSA-837F-QV58-PP2C": {
23+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
24+
},
25+
"GHSA-9PCW-998M-HC65": {
26+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
27+
},
28+
"GHSA-HWRX-F5X3-47MW": {
29+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
30+
},
31+
"GHSA-J4XR-52MG-MP9G": {
32+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
33+
},
34+
"GHSA-P8HF-XHQ2-R8H2": {
35+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
36+
},
37+
"GHSA-PCC8-7Q79-F457": {
38+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
39+
},
40+
"GHSA-PGC8-X3XQ-85CM": {
41+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
42+
},
43+
"GHSA-PX86-MRRQ-WXM3": {
44+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
45+
},
46+
"GHSA-V8GG-42JM-2F6P": {
47+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
48+
},
49+
"GHSA-XR7F-QPJ4-XP37": {
50+
"89466dab73fb39444100389f6800b4ba4bf1cc49": "Publish Advisories\n\nGHSA-4jgg-5r84-r28r\nGHSA-5jh7-hrj4-qc2f\nGHSA-837f-qv58-pp2c\nGHSA-9pcw-998m-hc65\nGHSA-hwrx-f5x3-47mw\nGHSA-j4xr-52mg-mp9g\nGHSA-p8hf-xhq2-r8h2\nGHSA-pcc8-7q79-f457\nGHSA-pgc8-x3xq-85cm\nGHSA-px86-mrrq-wxm3\nGHSA-v8gg-42jm-2f6p\nGHSA-xr7f-qpj4-xp37"
51+
},
52+
"GHSA-RG39-PRFR-F2W6": {
53+
"8cb1e385645e32cccbebb4051c1be80fa2292601": "Publish GHSA-rg39-prfr-f2w6"
54+
},
55+
"GHSA-663R-X48J-FG8P": {
56+
"8e1eab33dc967b85f50cee1fa0c3dd31ddb088c3": "Improve GHSA-663r-x48j-fg8p",
57+
"3de023087fe24229186551ba8f1c1bd007f29a7b": "Improve GHSA-663r-x48j-fg8p",
58+
"23cadf20e75092dac0614eb894084d46f574d10c": "Improve GHSA-663r-x48j-fg8p",
59+
"49749c362e00f2a57ca8acf0ef804acbf18c0772": "Improve GHSA-663r-x48j-fg8p",
60+
"29380f98d951ef41070b775a7ee297c940161f97": "Publish Advisories\n\nGHSA-59w5-j22f-h3rv\nGHSA-cm99-m826-vgg7\nGHSA-wmqx-rmqw-vxp8\nGHSA-64mj-fhhf-6gmf\nGHSA-663r-x48j-fg8p\nGHSA-785f-3qgq-ghq3\nGHSA-8237-h92m-mj9j\nGHSA-8v2r-35gr-p77q\nGHSA-gpg8-377c-3rgp\nGHSA-j9g6-3rjm-j8f4\nGHSA-m3f2-gxh3-v237\nGHSA-mj5p-9vqp-6mww\nGHSA-vg9f-q4xh-62r4\nGHSA-wrcg-234w-hfhq"
61+
},
462
"GHSA-PQXV-X4WF-XVVC": {
563
"79c0979acff67a783c8a48e3ce38c167eae98925": "Publish Advisories\n\nGHSA-pqxv-x4wf-xvvc\nGHSA-vpg3-44vc-j965\nGHSA-w592-pr34-frcq"
664
},
@@ -194,12 +252,6 @@
194252
"GHSA-F7C4-3R82-969W": {
195253
"1ed8ca2b4ac6a80503bf60f6548e67a35b72fd65": "Publish GHSA-f7c4-3r82-969w"
196254
},
197-
"GHSA-PQWR-MV7C-MQ9Q": {
198-
"040d287c5bbb43c736318ee4e5f2f465dcc2045b": "Publish Advisories\n\nGHSA-pqwr-mv7c-mq9q\nGHSA-w6q9-cjvw-4mhm"
199-
},
200-
"GHSA-W6Q9-CJVW-4MHM": {
201-
"040d287c5bbb43c736318ee4e5f2f465dcc2045b": "Publish Advisories\n\nGHSA-pqwr-mv7c-mq9q\nGHSA-w6q9-cjvw-4mhm"
202-
},
203255
"GHSA-35HH-C4H4-VP3Q": {
204256
"403e6b6833532470d16f43884f5270c97babb9ef": "Publish Advisories\n\nGHSA-35hh-c4h4-vp3q\nGHSA-3cj7-86g6-85rv\nGHSA-3j54-vf3c-f8mg\nGHSA-3x7x-qm6m-gh57\nGHSA-499q-6rmh-w6p7\nGHSA-4rx5-c9jj-cfrj\nGHSA-63mm-gwfc-cmcq\nGHSA-6vjm-3j93-7v9p\nGHSA-6wfp-pwm3-667v\nGHSA-6wmc-mmch-49h7\nGHSA-7g6w-jj32-qj92\nGHSA-7vxj-qhff-f4pc\nGHSA-cq7w-3xjv-g47g\nGHSA-h6w8-m27h-f268\nGHSA-hmq6-c24m-v98g\nGHSA-r2q6-6v35-773j\nGHSA-v4gg-2cxp-fc23"
205257
},
@@ -1123,9 +1175,6 @@
11231175
"GHSA-3GQM-FCW5-W839": {
11241176
"f85ffe2ae5b98b4c506f1e5f0f49f445a0dbbfa5": "Publish Advisories\n\nGHSA-8vh5-mgjj-w6hg\nGHSA-qg9p-xrhj-435m\nGHSA-3gqm-fcw5-w839\nGHSA-5jgf-p345-68v8\nGHSA-f65p-4m7j-42xc\nGHSA-fph4-wmhf-6fwf\nGHSA-jqff-g426-hqxp\nGHSA-p3m8-78j2-g5p3\nGHSA-8vh5-mgjj-w6hg\nGHSA-qg9p-xrhj-435m"
11251177
},
1126-
"GHSA-5JGF-P345-68V8": {
1127-
"f85ffe2ae5b98b4c506f1e5f0f49f445a0dbbfa5": "Publish Advisories\n\nGHSA-8vh5-mgjj-w6hg\nGHSA-qg9p-xrhj-435m\nGHSA-3gqm-fcw5-w839\nGHSA-5jgf-p345-68v8\nGHSA-f65p-4m7j-42xc\nGHSA-fph4-wmhf-6fwf\nGHSA-jqff-g426-hqxp\nGHSA-p3m8-78j2-g5p3\nGHSA-8vh5-mgjj-w6hg\nGHSA-qg9p-xrhj-435m"
1128-
},
11291178
"GHSA-F65P-4M7J-42XC": {
11301179
"f85ffe2ae5b98b4c506f1e5f0f49f445a0dbbfa5": "Publish Advisories\n\nGHSA-8vh5-mgjj-w6hg\nGHSA-qg9p-xrhj-435m\nGHSA-3gqm-fcw5-w839\nGHSA-5jgf-p345-68v8\nGHSA-f65p-4m7j-42xc\nGHSA-fph4-wmhf-6fwf\nGHSA-jqff-g426-hqxp\nGHSA-p3m8-78j2-g5p3\nGHSA-8vh5-mgjj-w6hg\nGHSA-qg9p-xrhj-435m"
11311180
},
@@ -13491,12 +13540,6 @@
1349113540
"7c22ea2ea0935e1ba50a88d833501bc1347cbe87": "Publish GHSA-8wx3-8m4x-g5h4",
1349213541
"e8145bd113979423239c925ff6cf3a05cdba503e": "Publish Advisories\n\nGHSA-6mjq-9x4w-m3w9\nGHSA-8wx3-8m4x-g5h4\nGHSA-pjx8-984p-7p3x"
1349313542
},
13494-
"GHSA-663R-X48J-FG8P": {
13495-
"3de023087fe24229186551ba8f1c1bd007f29a7b": "Improve GHSA-663r-x48j-fg8p",
13496-
"23cadf20e75092dac0614eb894084d46f574d10c": "Improve GHSA-663r-x48j-fg8p",
13497-
"49749c362e00f2a57ca8acf0ef804acbf18c0772": "Improve GHSA-663r-x48j-fg8p",
13498-
"29380f98d951ef41070b775a7ee297c940161f97": "Publish Advisories\n\nGHSA-59w5-j22f-h3rv\nGHSA-cm99-m826-vgg7\nGHSA-wmqx-rmqw-vxp8\nGHSA-64mj-fhhf-6gmf\nGHSA-663r-x48j-fg8p\nGHSA-785f-3qgq-ghq3\nGHSA-8237-h92m-mj9j\nGHSA-8v2r-35gr-p77q\nGHSA-gpg8-377c-3rgp\nGHSA-j9g6-3rjm-j8f4\nGHSA-m3f2-gxh3-v237\nGHSA-mj5p-9vqp-6mww\nGHSA-vg9f-q4xh-62r4\nGHSA-wrcg-234w-hfhq"
13499-
},
1350013543
"GHSA-23QV-C3W3-QC96": {
1350113544
"b7a93df7f7051799495805bc211adea8d202dae7": "Publish Advisories\n\nGHSA-23qv-c3w3-qc96\nGHSA-3hjj-97jw-2f47\nGHSA-5cpx-56hx-wvjh\nGHSA-65p5-8cm9-qcxx\nGHSA-88gq-qj38-4cpw\nGHSA-95xv-f86p-3j6g\nGHSA-fx4r-pqvc-gggc\nGHSA-hh4v-5fxf-qpv6\nGHSA-p847-q8vx-c3fg\nGHSA-pp39-pq9r-8cpp\nGHSA-prj2-8qrm-q9fc\nGHSA-r67c-r6r6-mj6m\nGHSA-v6f8-q5jg-rg7r\nGHSA-w939-c8qp-6hm2\nGHSA-xw2w-9955-6f5w"
1350213545
},

data/fix-commits/buildkit-34c30119.json

Lines changed: 15 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,21 @@
11
{
22
"vcs_url": "https://github.com/moby/buildkit",
33
"vulnerabilities": {
4+
"CVE-2026-53495": {
5+
"de650e3cb550004aaa2f1a841f1dafdacf35d124": "vendor: github.com/containerd/containerd/v2 v2.3.5\n\nfull diff: https://github.com/containerd/containerd/compare/v2.3.4...v2.3.5\n\nSecurity Updates\n\n- [**CVE-2026-53495**](https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv)\n- [**GHSA-rp3h-jf77-q9p4**](https://github.com/containerd/containerd/security/advisories/GHSA-rp3h-jf77-q9p4)\n\nImage Distribution\n\n- Apply hardening to strip sensitive authentication headers when fetching descriptor URLs\n\nRuntime\n\n- Avoid hangs and data races when streaming container standard I/O in CRI\n- Fix missing error messages in OpenTelemetry trace attributes\n- Fix user and group lookup failures in container rootfs containing symlinked /etc/passwd or /etc/group\n- Fix configuration loading error when drop-in configuration files have a higher version than the root configuration\n- Avoid containerd startup hangs when loading shims\n- Add context to error when shim delete times out\n- Fix Windows Server 2022 container compatibility on host builds newer than the latest LTSC\n\nSnapshotters\n\n- Fix unpack failure for EROFS images containing the erofs OS feature\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>"
6+
},
7+
"GHSA-7JXH-36Q5-GCQV": {
8+
"de650e3cb550004aaa2f1a841f1dafdacf35d124": "vendor: github.com/containerd/containerd/v2 v2.3.5\n\nfull diff: https://github.com/containerd/containerd/compare/v2.3.4...v2.3.5\n\nSecurity Updates\n\n- [**CVE-2026-53495**](https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv)\n- [**GHSA-rp3h-jf77-q9p4**](https://github.com/containerd/containerd/security/advisories/GHSA-rp3h-jf77-q9p4)\n\nImage Distribution\n\n- Apply hardening to strip sensitive authentication headers when fetching descriptor URLs\n\nRuntime\n\n- Avoid hangs and data races when streaming container standard I/O in CRI\n- Fix missing error messages in OpenTelemetry trace attributes\n- Fix user and group lookup failures in container rootfs containing symlinked /etc/passwd or /etc/group\n- Fix configuration loading error when drop-in configuration files have a higher version than the root configuration\n- Avoid containerd startup hangs when loading shims\n- Add context to error when shim delete times out\n- Fix Windows Server 2022 container compatibility on host builds newer than the latest LTSC\n\nSnapshotters\n\n- Fix unpack failure for EROFS images containing the erofs OS feature\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>"
9+
},
10+
"GHSA-RP3H-JF77-Q9P4": {
11+
"de650e3cb550004aaa2f1a841f1dafdacf35d124": "vendor: github.com/containerd/containerd/v2 v2.3.5\n\nfull diff: https://github.com/containerd/containerd/compare/v2.3.4...v2.3.5\n\nSecurity Updates\n\n- [**CVE-2026-53495**](https://github.com/containerd/containerd/security/advisories/GHSA-7jxh-36q5-gcqv)\n- [**GHSA-rp3h-jf77-q9p4**](https://github.com/containerd/containerd/security/advisories/GHSA-rp3h-jf77-q9p4)\n\nImage Distribution\n\n- Apply hardening to strip sensitive authentication headers when fetching descriptor URLs\n\nRuntime\n\n- Avoid hangs and data races when streaming container standard I/O in CRI\n- Fix missing error messages in OpenTelemetry trace attributes\n- Fix user and group lookup failures in container rootfs containing symlinked /etc/passwd or /etc/group\n- Fix configuration loading error when drop-in configuration files have a higher version than the root configuration\n- Avoid containerd startup hangs when loading shims\n- Add context to error when shim delete times out\n- Fix Windows Server 2022 container compatibility on host builds newer than the latest LTSC\n\nSnapshotters\n\n- Fix unpack failure for EROFS images containing the erofs OS feature\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>"
12+
},
13+
"CVE-2026-56855": {
14+
"51e3b4f5ce1b417c1df86434e347ea446275e61c": "vendor: golang.org/x/crypto v0.56.0\n\nfull diff: https://github.com/golang/crypto/compare/v0.55.0...v0.56.0\n\nWe have tagged version v0.56.0 of golang.org/x/crypto in\norder to address the following security issues:\n- ssh: prevent DoS on deadlocked established channel\n Previously, after a channel has been established, a\n malicious peer could send crafted messages that would\n deadlock the entire connection.\n Now, we handle all RFC 4254 channel messages; global\n requests are handled explicitly. Then, treat all other\n messages as a protocol error and tear the connection\n down instead of buffering and blocking.\n Thanks to Will Mortensen for reporting this issue.\n This is CVE-2026-56855 and Go issue https://go.dev/issue/81317.\n- ssh: prevent DoS on deadlocked undecided channel\n Previously, a channel registered in the mux's chanList is\n not usable until it is established. A malicious peer was\n able flood the channel's incomingRequests, deadlocking the\n entire connection.\n Now, we add an atomic established state, set when a channel\n becomes usable. Until such a time, handlePacket drops every\n packet other than the open confirmation/failure, without\n blocking and without tearing down the connection.\n Thanks to Will Mortensen for reporting this issue.\n This is CVE-2026-78662 and Go issue https://go.dev/issue/81316.\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>"
15+
},
16+
"CVE-2026-78662": {
17+
"51e3b4f5ce1b417c1df86434e347ea446275e61c": "vendor: golang.org/x/crypto v0.56.0\n\nfull diff: https://github.com/golang/crypto/compare/v0.55.0...v0.56.0\n\nWe have tagged version v0.56.0 of golang.org/x/crypto in\norder to address the following security issues:\n- ssh: prevent DoS on deadlocked established channel\n Previously, after a channel has been established, a\n malicious peer could send crafted messages that would\n deadlock the entire connection.\n Now, we handle all RFC 4254 channel messages; global\n requests are handled explicitly. Then, treat all other\n messages as a protocol error and tear the connection\n down instead of buffering and blocking.\n Thanks to Will Mortensen for reporting this issue.\n This is CVE-2026-56855 and Go issue https://go.dev/issue/81317.\n- ssh: prevent DoS on deadlocked undecided channel\n Previously, a channel registered in the mux's chanList is\n not usable until it is established. A malicious peer was\n able flood the channel's incomingRequests, deadlocking the\n entire connection.\n Now, we add an atomic established state, set when a channel\n becomes usable. Until such a time, handlePacket drops every\n packet other than the open confirmation/failure, without\n blocking and without tearing down the connection.\n Thanks to Will Mortensen for reporting this issue.\n This is CVE-2026-78662 and Go issue https://go.dev/issue/81316.\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>"
18+
},
419
"GHSA-2V4P-QF9Q-27WJ": {
520
"964cf3d104ed8178991e0adf4964b6ed367d3279": "vendor: google.golang.org/grpc v1.83.2\n\ncontains a fix for [GHSA-2v4p-qf9q-27wj]\n\nfull diff: https://github.com/grpc/grpc-go/compare/v1.83.1...v1.83.2\n\n[GHSA-2v4p-qf9q-27wj]: https://github.com/grpc/grpc-go/security/advisories/GHSA-2v4p-qf9q-27wj\n\nSigned-off-by: Sebastiaan van Stijn <github@gone.nl>"
621
},

0 commit comments

Comments
 (0)