Skip to content

Commit 2f6f63d

Browse files
Sync Collecting Fix Commits: Sun Aug 16 12:09:16 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent c6483c6 commit 2f6f63d

3 files changed

Lines changed: 71 additions & 8 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 39 additions & 5 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,45 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-2RQ5-699J-X7P6": {
5+
"c2bd7395a37eb03edd393cb75d1f86dd80f8f74a": "Improve GHSA-2rq5-699j-x7p6",
6+
"d88fcb9e32e8ee97968ae3e09fcd0c3683ae054c": "Publish Advisories\n\nGHSA-c5hg-mr8r-f6jp\nGHSA-2rq5-699j-x7p6",
7+
"e53513921b1ba6c9771bc70e07333ac61abcd290": "Publish Advisories\n\nGHSA-2rq5-699j-x7p6\nGHSA-8h9c-r582-mggc\nGHSA-gq6w-q6wh-jggc\nGHSA-r5x6-w42p-jhpp",
8+
"8f82dde8134cf444d00b4e48d368390d59956d0c": "Publish Advisories\n\nGHSA-2rq5-699j-x7p6\nGHSA-4grc-q4fj-45p8\nGHSA-p4g9-c9qr-wmg5\nGHSA-2rq5-699j-x7p6\nGHSA-p4g9-c9qr-wmg5"
9+
},
10+
"GHSA-4VM7-68XQ-QF98": {
11+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
12+
},
13+
"GHSA-82J5-9JQ4-R793": {
14+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
15+
},
16+
"GHSA-CJ84-VF64-52HG": {
17+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
18+
},
19+
"GHSA-CPVM-7QMF-33MV": {
20+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
21+
},
22+
"GHSA-FH4P-V6R7-6956": {
23+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
24+
},
25+
"GHSA-FP78-CPF3-8FQX": {
26+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
27+
},
28+
"GHSA-FWC7-4RGJ-4VMQ": {
29+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
30+
},
31+
"GHSA-MP8R-X8V9-XF3Q": {
32+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
33+
},
34+
"GHSA-P6X4-H8M9-9MR2": {
35+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
36+
},
37+
"GHSA-P9QR-8PG6-7HVC": {
38+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
39+
},
40+
"GHSA-Q2CH-2Q4J-VQ6H": {
41+
"747a5f7cdf4bbcf64df46ade502b7d1b4bfa7298": "Publish Advisories\n\nGHSA-4vm7-68xq-qf98\nGHSA-82j5-9jq4-r793\nGHSA-cj84-vf64-52hg\nGHSA-cpvm-7qmf-33mv\nGHSA-fh4p-v6r7-6956\nGHSA-fp78-cpf3-8fqx\nGHSA-fwc7-4rgj-4vmq\nGHSA-mp8r-x8v9-xf3q\nGHSA-p6x4-h8m9-9mr2\nGHSA-p9qr-8pg6-7hvc\nGHSA-q2ch-2q4j-vq6h"
42+
},
443
"GHSA-22XP-GMQF-MRV3": {
544
"3e5f8f96a14669d5a423f877c8d8ef853db0cf05": "Publish Advisories\n\nGHSA-22xp-gmqf-mrv3\nGHSA-39c6-m2p4-vg3h\nGHSA-5xrw-wm8f-vm47\nGHSA-c7w5-449g-58mm\nGHSA-gmqq-p6mp-w5p6\nGHSA-p2pw-xc8c-mvmj\nGHSA-vv7q-2wgr-7w2p\nGHSA-x9xw-hf2x-647j"
645
},
@@ -244834,11 +244873,6 @@
244834244873
"b19a7a68382a9cab4311977c397d1c94f4ddaec3": "Publish Advisories\n\nGHSA-c5hg-mr8r-f6jp\nGHSA-cgp8-4m63-fhh5",
244835244874
"450a3ebe05708a8c4ac242f6fe3b9be1b95779cf": "Publish GHSA-c5hg-mr8r-f6jp"
244836244875
},
244837-
"GHSA-2RQ5-699J-X7P6": {
244838-
"d88fcb9e32e8ee97968ae3e09fcd0c3683ae054c": "Publish Advisories\n\nGHSA-c5hg-mr8r-f6jp\nGHSA-2rq5-699j-x7p6",
244839-
"e53513921b1ba6c9771bc70e07333ac61abcd290": "Publish Advisories\n\nGHSA-2rq5-699j-x7p6\nGHSA-8h9c-r582-mggc\nGHSA-gq6w-q6wh-jggc\nGHSA-r5x6-w42p-jhpp",
244840-
"8f82dde8134cf444d00b4e48d368390d59956d0c": "Publish Advisories\n\nGHSA-2rq5-699j-x7p6\nGHSA-4grc-q4fj-45p8\nGHSA-p4g9-c9qr-wmg5\nGHSA-2rq5-699j-x7p6\nGHSA-p4g9-c9qr-wmg5"
244841-
},
244842244876
"GHSA-F7F4-5W9J-23P2": {
244843244877
"07042e071fdadeecd8a5fec6c2ef900c87e38968": "Publish Advisories\n\nGHSA-229r-pqp6-8w6g\nGHSA-4c4w-3q45-hp9j\nGHSA-f7f4-5w9j-23p2\nGHSA-6fcq-3cm2-j3j5\nGHSA-4g4c-8gqh-m4vm\nGHSA-rwpr-83g3-96g7\nGHSA-hhwc-8g49-j8jx\nGHSA-3892-2r52-p65m\nGHSA-p6fg-723f-hgpw",
244844244878
"9fa313006e9346d5212be92c0a98a77cd6650a0c": "Publish Advisories\n\nGHSA-229r-pqp6-8w6g\nGHSA-4c4w-3q45-hp9j\nGHSA-f7f4-5w9j-23p2\nGHSA-6fcq-3cm2-j3j5\nGHSA-4g4c-8gqh-m4vm\nGHSA-rwpr-83g3-96g7\nGHSA-hhwc-8g49-j8jx\nGHSA-3892-2r52-p65m\nGHSA-p6fg-723f-hgpw\nGHSA-rfhw-fm4m-52j6",

data/fix-commits/buildroot-0b809119.json

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,33 @@
11
{
22
"vcs_url": "https://github.com/buildroot/buildroot",
33
"vulnerabilities": {
4+
"CVE-2026-72522": {
5+
"e3d5341e01eb83fb4f76a5c721a3363cff8a7f73": "package/expat: security bump version to 2.8.3\n\nhttps://github.com/libexpat/libexpat/blob/R_2_8_3/expat/Changes\nhttps://blog.hartwork.org/posts/expat-2-8-3-released/\n\nFixes CVE-2026-72522.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
6+
},
7+
"CVE-2025-31936": {
8+
"2c92087605c30bd5c1384a62198855f7836b5215": "package/intel-microcode: security bump version to 20260812\n\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811\n\nFixes the following CVEs:\n\nCVE-2025-31936\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html\n\nCVE-2025-31938\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html\n\nCVE-2026-20917\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html\n\nCVE-2025-35973\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html\n\nCVE-2026-20716\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html\n\nCVE-2026-20760\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html\n\nCVE-2026-20713\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html\n\nCVE-2026-20707\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
9+
},
10+
"CVE-2025-31938": {
11+
"2c92087605c30bd5c1384a62198855f7836b5215": "package/intel-microcode: security bump version to 20260812\n\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811\n\nFixes the following CVEs:\n\nCVE-2025-31936\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html\n\nCVE-2025-31938\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html\n\nCVE-2026-20917\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html\n\nCVE-2025-35973\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html\n\nCVE-2026-20716\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html\n\nCVE-2026-20760\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html\n\nCVE-2026-20713\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html\n\nCVE-2026-20707\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
12+
},
13+
"CVE-2026-20917": {
14+
"2c92087605c30bd5c1384a62198855f7836b5215": "package/intel-microcode: security bump version to 20260812\n\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811\n\nFixes the following CVEs:\n\nCVE-2025-31936\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html\n\nCVE-2025-31938\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html\n\nCVE-2026-20917\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html\n\nCVE-2025-35973\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html\n\nCVE-2026-20716\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html\n\nCVE-2026-20760\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html\n\nCVE-2026-20713\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html\n\nCVE-2026-20707\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
15+
},
16+
"CVE-2025-35973": {
17+
"2c92087605c30bd5c1384a62198855f7836b5215": "package/intel-microcode: security bump version to 20260812\n\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811\n\nFixes the following CVEs:\n\nCVE-2025-31936\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html\n\nCVE-2025-31938\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html\n\nCVE-2026-20917\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html\n\nCVE-2025-35973\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html\n\nCVE-2026-20716\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html\n\nCVE-2026-20760\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html\n\nCVE-2026-20713\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html\n\nCVE-2026-20707\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
18+
},
19+
"CVE-2026-20716": {
20+
"2c92087605c30bd5c1384a62198855f7836b5215": "package/intel-microcode: security bump version to 20260812\n\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811\n\nFixes the following CVEs:\n\nCVE-2025-31936\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html\n\nCVE-2025-31938\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html\n\nCVE-2026-20917\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html\n\nCVE-2025-35973\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html\n\nCVE-2026-20716\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html\n\nCVE-2026-20760\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html\n\nCVE-2026-20713\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html\n\nCVE-2026-20707\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
21+
},
22+
"CVE-2026-20760": {
23+
"2c92087605c30bd5c1384a62198855f7836b5215": "package/intel-microcode: security bump version to 20260812\n\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811\n\nFixes the following CVEs:\n\nCVE-2025-31936\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html\n\nCVE-2025-31938\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html\n\nCVE-2026-20917\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html\n\nCVE-2025-35973\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html\n\nCVE-2026-20716\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html\n\nCVE-2026-20760\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html\n\nCVE-2026-20713\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html\n\nCVE-2026-20707\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
24+
},
25+
"CVE-2026-20713": {
26+
"2c92087605c30bd5c1384a62198855f7836b5215": "package/intel-microcode: security bump version to 20260812\n\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811\n\nFixes the following CVEs:\n\nCVE-2025-31936\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html\n\nCVE-2025-31938\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html\n\nCVE-2026-20917\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html\n\nCVE-2025-35973\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html\n\nCVE-2026-20716\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html\n\nCVE-2026-20760\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html\n\nCVE-2026-20713\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html\n\nCVE-2026-20707\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
27+
},
28+
"CVE-2026-20707": {
29+
"2c92087605c30bd5c1384a62198855f7836b5215": "package/intel-microcode: security bump version to 20260812\n\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260812\nhttps://github.com/intel/Intel-Linux-Processor-Microcode-Data-Files/releases/tag/microcode-20260811\n\nFixes the following CVEs:\n\nCVE-2025-31936\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01379.html\n\nCVE-2025-31938\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01404.html\n\nCVE-2026-20917\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01423.html\n\nCVE-2025-35973\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01428.html\n\nCVE-2026-20716\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01435.html\n\nCVE-2026-20760\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01441.html\n\nCVE-2026-20713\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01442.html\n\nCVE-2026-20707\nhttps://www.intel.com/content/www/us/en/security-center/advisory/intel-sa-01443.html\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
30+
},
431
"CVE-2026-6464": {
532
"2456e44d6779f9664b45c8d2b85f3ea8a250ecc0": "package/postgresql: security bump version to 18.6\n\nhttps://www.postgresql.org/about/news/postgresql-186-1711-1615-1519-1424-and-19-beta-3-released-3365/\n\"This release skips PostgreSQL 18 versions from PostgreSQL 18.4 to 18.6.\n 18.5 was not shipped due to a regression.\"\n\nFixes the following CVEs:\n\nCVE-2026-6464: psql COPY FROM STDIN early failure processes data lines as psql commands (CVSS v3.1: 8.1)\nCVE-2026-6469: ALTER TABLE ALTER TYPE resets extended statistics ownership (CVSS v3.1: 3.8)\nCVE-2026-6470: Fails to check type USAGE privilege (CVSS v3.1: 4.3)\nCVE-2026-6471: Logical decoding can dlopen arbitrary file (CVSS v3.1: 7.2)\nCVE-2026-14662: tsvector and tsquery undersize allocations, via integer wraparound (CVSS v3.1: 8.8)\nCVE-2026-14663: pgcrypto, for OpenSSL-disabled ciphers, silently encrypts to and decrypts from cleartext (CVSS v3.1: 6.5)\nCVE-2026-14664: Regexp heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8)\nCVE-2026-14666: Row security caching disregards role modifications (CVSS v3.1: 4.2)\nCVE-2026-14668: ctid type confusion in selectivity estimator discloses derivative of arbitrary read (CVSS v3.1: 8.1)\nCVE-2026-14669: to_char heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8)\nCVE-2026-14670: plperl tied object heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8)\nCVE-2026-14671: refint plan cache type confusion executes arbitrary code (CVSS v3.1: 8.8)\nCVE-2026-14672: Observable response discrepancy with non-default scram_iterations provides user existence oracle (CVSS v3.1: 5.3)\nCVE-2026-14673: amcheck does not clear untrusted search path (CVSS v3.1: 3.8)\nCVE-2026-14676: pg_stat_statements heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8)\nCVE-2026-14677: 32-bit pltcl and plperl undersize allocations, via integer wraparound (CVSS v3.1: 8.8)\nCVE-2026-14678: pg_trgm picksplit reads past end of buffer (CVSS v3.1: 4.3)\nCVE-2026-14679: Stack buffer overflow in argument match writes 0x0 and 0x1 to server memory (CVSS v3.1: 8.2)\nCVE-2026-14680: Type confusion via \"internal\" arguments (CVSS v3.1: 8.8)\nCVE-2026-14681: Improper enforcement of GSSAPI encryption when coupled with SSL (CVSS v3.1: 4.2)\nCVE-2026-15741: Expression deparse allows SQL injection via EXTRACT argument (CVSS v3.1: 8.8)\nCVE-2026-15742: fuzzystrmatch writes effectively-arbitrary addresses, via integer wraparound (CVSS v3.1: 8.8)\nCVE-2026-16238: Type confusion in pg_restore_attribute_stats() executes arbitrary code (CVSS v3.1: 8.8)\nCVE-2026-16239: Type confusion in cursor CLOSE + DECLARE executes arbitrary code (CVSS v3.1: 8.8)\nCVE-2026-16241: ECPG integer underflow can crash the client (CVSS v3.1: 3.8)\nCVE-2026-18024: ascii() function reads past end of buffer (CVSS v3.1: 4.3)\nCVE-2026-18408: psql \\unrestrict lets superuser of pg_dump origin server execute arbitrary code in psql client (CVSS v3.1: 8.8)\nCVE-2026-19385: pg_dump heap buffer overflow executes arbitrary code (CVSS v3.1: 8.8)\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
633
},

0 commit comments

Comments
 (0)