Skip to content

Commit 9173802

Browse files
Sync Collecting Fix Commits: Fri Jul 24 01:32:22 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 947656e commit 9173802

6 files changed

Lines changed: 133 additions & 35 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 39 additions & 13 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,45 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-P7MV-53F2-4CWJ": {
5+
"c6c3034d8af08317bb5cc8fac30d768b261c3d1a": "Improve GHSA-p7mv-53f2-4cwj",
6+
"dcb78c85968a14824bea7f324512aecaf17e282f": "Publish Advisories\n\nGHSA-p93v-m2r2-4387\nGHSA-p7mv-53f2-4cwj",
7+
"a8c044968e17b0dc5861e351073e7b8975d360b3": "Merge pull request #7730 from cookesan/ghsa-p7mv-53f2-4cwj-fix-commit",
8+
"c50935a5ac752614a695552ebd037847cb468082": "Add fix commit to GHSA-p7mv-53f2-4cwj",
9+
"0ec07a5b71b92c38a1a38702a10ce9b826cad428": "Publish GHSA-p7mv-53f2-4cwj",
10+
"ec9f6d19043f91bad6c9a71ed10ed7401c4d5b99": "Publish GHSA-p7mv-53f2-4cwj"
11+
},
12+
"GHSA-W6W4-RJH9-9R58": {
13+
"e34d23bc289ec08cf13b2c7e74563dcd9a8c17e9": "Publish Advisories\n\nGHSA-w6w4-rjh9-9r58\nGHSA-x2f5-4prf-w687"
14+
},
15+
"GHSA-X2F5-4PRF-W687": {
16+
"e34d23bc289ec08cf13b2c7e74563dcd9a8c17e9": "Publish Advisories\n\nGHSA-w6w4-rjh9-9r58\nGHSA-x2f5-4prf-w687"
17+
},
18+
"GHSA-WRJC-X8RR-H8H6": {
19+
"aa1baf23cc8965a716b41ac529e82841bae18db1": "Publish GHSA-wrjc-x8rr-h8h6"
20+
},
21+
"GHSA-H8FP-F39C-Q6MH": {
22+
"33a37fd652a997c38abd026516d447966a1f193b": "Publish Advisories\n\nGHSA-h8fp-f39c-q6mh\nGHSA-jjmj-jmhj-qwj2"
23+
},
24+
"GHSA-JJMJ-JMHJ-QWJ2": {
25+
"33a37fd652a997c38abd026516d447966a1f193b": "Publish Advisories\n\nGHSA-h8fp-f39c-q6mh\nGHSA-jjmj-jmhj-qwj2"
26+
},
27+
"GHSA-337J-9HXR-RHXG": {
28+
"a5af9b61922c1a8aad1260822968cf60991a9dbd": "Publish Advisories\n\nGHSA-337j-9hxr-rhxg\nGHSA-8g53-9m3c-69xg\nGHSA-c96f-x56v-gq3h"
29+
},
30+
"GHSA-8G53-9M3C-69XG": {
31+
"a5af9b61922c1a8aad1260822968cf60991a9dbd": "Publish Advisories\n\nGHSA-337j-9hxr-rhxg\nGHSA-8g53-9m3c-69xg\nGHSA-c96f-x56v-gq3h"
32+
},
33+
"GHSA-C96F-X56V-GQ3H": {
34+
"a5af9b61922c1a8aad1260822968cf60991a9dbd": "Publish Advisories\n\nGHSA-337j-9hxr-rhxg\nGHSA-8g53-9m3c-69xg\nGHSA-c96f-x56v-gq3h"
35+
},
36+
"GHSA-PVX3-GM3C-GMPR": {
37+
"8d4ff1d4cc3bc142a539ae566807823a9feb54d8": "Improve GHSA-pvx3-gm3c-gmpr",
38+
"a30bc7f17fac8c5112b0de21dfd38e760b438f89": "Publish GHSA-pvx3-gm3c-gmpr",
39+
"e185ae123fb385f19a6336b1e633e1a96886c96c": "Publish GHSA-pvx3-gm3c-gmpr",
40+
"a99445897a468c00d7da849c0fce962175623024": "Publish GHSA-pvx3-gm3c-gmpr",
41+
"ce4a7e7c0ee9ee479c24ac693b06d7b289061dac": "Publish GHSA-pvx3-gm3c-gmpr"
42+
},
443
"GHSA-GF47-QGG5-9G9Q": {
544
"069754fd5b85da44823fa5b587f61e5006ad8e94": "Improve GHSA-gf47-qgg5-9g9q",
645
"9bd8bb3206f470d79d7e1879c1aca72b06491432": "Improve GHSA-gf47-qgg5-9g9q"
@@ -16827,13 +16866,6 @@
1682716866
"3365a7bdac3f0c5bebf882014762b04546ad6161": "Add fix commit to GHSA-p93v-m2r2-4387",
1682816867
"13e3bc12750eed9504dddfdded7d9edf110de513": "Publish GHSA-p93v-m2r2-4387"
1682916868
},
16830-
"GHSA-P7MV-53F2-4CWJ": {
16831-
"dcb78c85968a14824bea7f324512aecaf17e282f": "Publish Advisories\n\nGHSA-p93v-m2r2-4387\nGHSA-p7mv-53f2-4cwj",
16832-
"a8c044968e17b0dc5861e351073e7b8975d360b3": "Merge pull request #7730 from cookesan/ghsa-p7mv-53f2-4cwj-fix-commit",
16833-
"c50935a5ac752614a695552ebd037847cb468082": "Add fix commit to GHSA-p7mv-53f2-4cwj",
16834-
"0ec07a5b71b92c38a1a38702a10ce9b826cad428": "Publish GHSA-p7mv-53f2-4cwj",
16835-
"ec9f6d19043f91bad6c9a71ed10ed7401c4d5b99": "Publish GHSA-p7mv-53f2-4cwj"
16836-
},
1683716869
"GHSA-F8CH-W75V-C847": {
1683816870
"47a07a2a253020587832ea1a5fbcba28296201eb": "Publish Advisories\n\nGHSA-f8ch-w75v-c847\nGHSA-c2c3-pqw5-5p7c",
1683916871
"1b2656dd49309bf6871c697a95109d0a9b9c4d06": "Merge pull request #7734 from cookesan/ghsa-f8ch-w75v-c847-fix-commit",
@@ -214317,12 +214349,6 @@
214317214349
"6d62edc9eb7d1974c6862246117439d3796bdd9b": "Publish GHSA-cg88-rpvp-cjv5",
214318214350
"233234ef48e8d6cf68c39bad5553352ed211425b": "Publish Advisories\n\nGHSA-368v-7v32-52fx\nGHSA-cg88-rpvp-cjv5\nGHSA-g9fm-r5mm-rf9f\nGHSA-xvwp-h6jv-7472"
214319214351
},
214320-
"GHSA-PVX3-GM3C-GMPR": {
214321-
"a30bc7f17fac8c5112b0de21dfd38e760b438f89": "Publish GHSA-pvx3-gm3c-gmpr",
214322-
"e185ae123fb385f19a6336b1e633e1a96886c96c": "Publish GHSA-pvx3-gm3c-gmpr",
214323-
"a99445897a468c00d7da849c0fce962175623024": "Publish GHSA-pvx3-gm3c-gmpr",
214324-
"ce4a7e7c0ee9ee479c24ac693b06d7b289061dac": "Publish GHSA-pvx3-gm3c-gmpr"
214325-
},
214326214352
"GHSA-5M8F-CHRV-7RW5": {
214327214353
"c35d1b55041cc7e22b6a13cbeab642fe6b2ced57": "Publish GHSA-5m8f-chrv-7rw5"
214328214354
},

data/fix-commits/buildroot-0b809119.json

Lines changed: 27 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,33 @@
11
{
22
"vcs_url": "https://github.com/buildroot/buildroot",
33
"vulnerabilities": {
4+
"CVE-2026-10723": {
5+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
6+
},
7+
"CVE-2026-10822": {
8+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
9+
},
10+
"CVE-2026-11331": {
11+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
12+
},
13+
"CVE-2026-11605": {
14+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
15+
},
16+
"CVE-2026-11622": {
17+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
18+
},
19+
"CVE-2026-11721": {
20+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
21+
},
22+
"CVE-2026-12617": {
23+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
24+
},
25+
"CVE-2026-13204": {
26+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
27+
},
28+
"CVE-2026-13321": {
29+
"8c96a8981f40689c352910372404216ab0d9482e": "package/bind: security bump version to 9.20.26\n\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/notes.html#notes-for-bind-9-20-26\nhttps://downloads.isc.org/isc/bind9/9.20.26/doc/arm/html/changelog.html\nhttps://seclists.org/oss-sec/2026/q3/208\n\nFixes\n\nCVE-2026-10723: Incorrect acceptance of NSEC3 records\nCVE-2026-10822: Key Record using PRIVATEDNS algorithm may lead to unexpected exit\nCVE-2026-11331: Potential wildcard CNAME RPZ policy bypass\nCVE-2026-11605: Unnecessary validation of DNSSEC signed records\nCVE-2026-11622: Potential memory usage beyond configured limits\nCVE-2026-11721: Cache poisoning possible with label count discrepancy, RRSIG, and wildcards\nCVE-2026-12617: Record ordering based unexpected exit with CNAME or DNAME\nCVE-2026-13204: Unexpected exit in certain situations with NSEC and NSEC3 both present\nCVE-2026-13321: DNSSEC Validation Bypass via Out-of-Zone NSEC Next Field\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\n[Julien: update pgp key id in hash file comment]\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
30+
},
431
"CVE-2026-15370": {
532
"93e7a673e83ee9b66f10f70cd3c7c0a53dcee6b0": "package/libssh: security bump version to 0.12.1\n\nhttps://gitlab.com/libssh/libssh-mirror/-/tags/libssh-0.12.1\nhttps://www.libssh.org/2026/07/21/libssh-0-12-1-and-0-11-5-security-releases/\n\nFixes the following security problems:\n\nCVE-2026-15370: Stack buffer overflow in SFTP server longname construction\nCVE-2026-59842: Information disclosure via short GSSAPI Curve25519 public key\nCVE-2026-59843: Denial of service via zero advertised channel packet size\nCVE-2026-59844: Denial of service via oversized SFTP read length\nCVE-2026-59845: Denial of service via unchecked ProxyCommand fork() failure\nCVE-2026-59846: Information disclosure via ProxyCommand %r username expansion\nCVE-2026-59847: Integrity downgrade via OpenSSL AES-GCM tag verification\nCVE-2026-59848: Denial of service via SFTP responses with unknown request IDs\nCVE-2026-59849: Denial of service via automatic certificate authentication loop\nCVE-2026-59850: Use-after-free via data callbacks on closed channels\nCVE-2026-59851: Authentication bypass via missing GSSAPI principal check\nZero-initialize every ssh_string\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
633
},

0 commit comments

Comments
 (0)