|
1 | 1 | { |
2 | 2 | "vcs_url": "https://github.com/nixos/nixpkgs", |
3 | 3 | "vulnerabilities": { |
| 4 | + "CVE-2026-84964": { |
| 5 | + "c05d66308e17058e87bcb4ac67196a5d3b2747ac": "mongoc: 1.30.3 -> 1.30.9\n\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9\n\nthis also automaticaly fixes the cmake error currently occuring with\ncmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671)\nas\nhttps://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d\nis included in this release.\n\nFixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963\n(cherry picked from commit 9a63787cc28e8c3563386113217d3fa9f9cdd593)", |
| 6 | + "9a63787cc28e8c3563386113217d3fa9f9cdd593": "mongoc: 1.30.3 -> 1.30.9\n\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9\n\nthis also automaticaly fixes the cmake error currently occuring with\ncmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671)\nas\nhttps://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d\nis included in this release.\n\nFixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963" |
| 7 | + }, |
| 8 | + "CVE-2026-84965": { |
| 9 | + "c05d66308e17058e87bcb4ac67196a5d3b2747ac": "mongoc: 1.30.3 -> 1.30.9\n\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9\n\nthis also automaticaly fixes the cmake error currently occuring with\ncmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671)\nas\nhttps://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d\nis included in this release.\n\nFixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963\n(cherry picked from commit 9a63787cc28e8c3563386113217d3fa9f9cdd593)", |
| 10 | + "9a63787cc28e8c3563386113217d3fa9f9cdd593": "mongoc: 1.30.3 -> 1.30.9\n\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9\n\nthis also automaticaly fixes the cmake error currently occuring with\ncmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671)\nas\nhttps://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d\nis included in this release.\n\nFixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963" |
| 11 | + }, |
| 12 | + "CVE-2026-84969": { |
| 13 | + "c05d66308e17058e87bcb4ac67196a5d3b2747ac": "mongoc: 1.30.3 -> 1.30.9\n\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9\n\nthis also automaticaly fixes the cmake error currently occuring with\ncmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671)\nas\nhttps://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d\nis included in this release.\n\nFixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963\n(cherry picked from commit 9a63787cc28e8c3563386113217d3fa9f9cdd593)", |
| 14 | + "9a63787cc28e8c3563386113217d3fa9f9cdd593": "mongoc: 1.30.3 -> 1.30.9\n\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9\n\nthis also automaticaly fixes the cmake error currently occuring with\ncmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671)\nas\nhttps://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d\nis included in this release.\n\nFixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963" |
| 15 | + }, |
| 16 | + "CVE-2026-84963": { |
| 17 | + "c05d66308e17058e87bcb4ac67196a5d3b2747ac": "mongoc: 1.30.3 -> 1.30.9\n\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9\n\nthis also automaticaly fixes the cmake error currently occuring with\ncmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671)\nas\nhttps://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d\nis included in this release.\n\nFixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963\n(cherry picked from commit 9a63787cc28e8c3563386113217d3fa9f9cdd593)", |
| 18 | + "9a63787cc28e8c3563386113217d3fa9f9cdd593": "mongoc: 1.30.3 -> 1.30.9\n\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.4\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.5\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.6\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.7\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.8\nhttps://github.com/mongodb/mongo-c-driver/releases/tag/1.30.9\n\nthis also automaticaly fixes the cmake error currently occuring with\ncmake 4.4.0+ on staging-next (https://hydra.nixos.org/build/344554671)\nas\nhttps://github.com/mongodb/mongo-c-driver/commit/3f9366cb27623f1a6f3b038146235059a378ad6d\nis included in this release.\n\nFixes: CVE-2026-84964, CVE-2026-84965, CVE-2026-84969, CVE-2026-84963" |
| 19 | + }, |
4 | 20 | "CVE-2026-79604": { |
5 | 21 | "d8a628df371e38d77b7849ed6b83be2614a1b409": "ocamlPackages.oxenstored: patch with XSA-512\n\n Xen Security Advisory CVE-2026-79604 / XSA-512\n version 3\n\n oxenstored: Unbounded accumulation of watches\n\nOxenstored maintains two datastructures about watches; one global trie,\nand one hashtable tracked per domain. When a xenbus reconnect is\nrequested, watches are not cleared out of the global trie.\n\nA guest can cause unbounded memory usage in oxenstored. This can lead\nto a system-wide DoS.\n\nThis is the XAPI oxenstored patch.\n\nhttps://xenbits.xenproject.org/xsa/advisory-512.html\n\nSigned-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>", |
6 | 22 | "a36b0d5d62e07851b4a9bd65d5f1617d11604593": "xen: patch with XSA-512\n\n Xen Security Advisory CVE-2026-79604 / XSA-512\n version 3\n\n oxenstored: Unbounded accumulation of watches\n\nOxenstored maintains two datastructures about watches; one global trie,\nand one hashtable tracked per domain. When a xenbus reconnect is\nrequested, watches are not cleared out of the global trie.\n\nA guest can cause unbounded memory usage in oxenstored. This can lead\nto a system-wide DoS.\n\nThis is the Xen oxenstored patch.\n\nhttps://xenbits.xenproject.org/xsa/advisory-512.html\n\nSigned-off-by: Fernando Rodrigues <alpha@sigmasquadron.net>" |
|
381 | 397 | "dcd7ad7d9ed5573a2e7844bf96d0deedd992f3a1": "[26.05] dolibarr: fix CVE-2026-81728 and CVE-2026-82633 (#558698)", |
382 | 398 | "5d53f7125d453c62b38d6f38493506c5f4a91662": "dolibarr: fix CVE-2026-81728 and CVE-2026-82633\n\nAssisted-by: pi coding agent / Mika (OpenAI gpt-5.6-sol)\nNot-cherry-picked-because: master is already fixed by Dolibarr 24.0.0" |
383 | 399 | }, |
| 400 | + "CVE-2023-29552": { |
| 401 | + "808056bc4afd7d0da8a678b4f50a190e5bd0b8b0": "openslp: drop\n\nAffected by CVE-2023-29552: https://ubuntu.com/security/CVE-2023-29552", |
| 402 | + "aa8c9e7d23dbd3844d26c36e914557b9477bee71": "openslp: Mark vulnerable to CVE-2023-29552" |
| 403 | + }, |
384 | 404 | "CVE-2026-84353": { |
385 | 405 | "cb032254520de4ab99e737f6d754561b975cc37d": "ungoogled-chromium: 152.0.7977.64-1 -> 152.0.7977.75-1\n\nhttps://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html\n\nThis update includes 26 security fixes.\n\nCVEs:\nCVE-2026-84353 CVE-2026-84352 CVE-2026-84354 CVE-2026-84359\nCVE-2026-84357 CVE-2026-84324 CVE-2026-84349 CVE-2026-84326\nCVE-2026-84333 CVE-2026-84351 CVE-2026-84325 CVE-2026-84328\nCVE-2026-84347 CVE-2026-84323 CVE-2026-84355 CVE-2026-84358\nCVE-2026-84332 CVE-2026-84330 CVE-2026-84334 CVE-2026-84348\nCVE-2026-84335 CVE-2026-84327 CVE-2026-84329 CVE-2026-84356\nCVE-2026-84350 CVE-2026-84331\n\n(cherry picked from commit d1173f76d8fb2f202e9e1cfdb89dc5998bf597d9)", |
386 | 406 | "d1173f76d8fb2f202e9e1cfdb89dc5998bf597d9": "ungoogled-chromium: 152.0.7977.64-1 -> 152.0.7977.75-1\n\nhttps://chromereleases.googleblog.com/2026/09/stable-channel-update-for-desktop.html\n\nThis update includes 26 security fixes.\n\nCVEs:\nCVE-2026-84353 CVE-2026-84352 CVE-2026-84354 CVE-2026-84359\nCVE-2026-84357 CVE-2026-84324 CVE-2026-84349 CVE-2026-84326\nCVE-2026-84333 CVE-2026-84351 CVE-2026-84325 CVE-2026-84328\nCVE-2026-84347 CVE-2026-84323 CVE-2026-84355 CVE-2026-84358\nCVE-2026-84332 CVE-2026-84330 CVE-2026-84334 CVE-2026-84348\nCVE-2026-84335 CVE-2026-84327 CVE-2026-84329 CVE-2026-84356\nCVE-2026-84350 CVE-2026-84331", |
|
30991 | 31011 | "b65d5650628bdba206410b1427009b6fa86caccd": "Merge pull request #219350 from yl3dy/strongswan-cve-2023-26463\n\nstrongswan: fix CVE-2023-26463", |
30992 | 31012 | "56227123fc7ad32103af6726d1f65cf0da3c80d9": "strongswan: fix CVE-2023-26463\n\nhttps://www.strongswan.org/blog/2023/03/02/strongswan-vulnerability-(cve-2023-26463).html" |
30993 | 31013 | }, |
30994 | | - "CVE-2023-29552": { |
30995 | | - "aa8c9e7d23dbd3844d26c36e914557b9477bee71": "openslp: Mark vulnerable to CVE-2023-29552" |
30996 | | - }, |
30997 | 31014 | "CVE-2023-22845": { |
30998 | 31015 | "46559d5fca477f1d5ce692253be958b64abd6834": "openimageio_1: add CVE-2023-22845, CVE-2023-24472 & CVE-2023-24473 to knownVulnerabilities" |
30999 | 31016 | }, |
|
0 commit comments