Skip to content

Commit df194d6

Browse files
Sync Collecting Fix Commits: Sat Jul 25 14:08:35 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 8b77632 commit df194d6

5 files changed

Lines changed: 72 additions & 0 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 9 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,15 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-6QX8-MXXJ-98FC": {
5+
"458762a518138a26e597ac195eb82ce6c30238eb": "Publish Advisories\n\nGHSA-6qx8-mxxj-98fc\nGHSA-g685-9q2w-88f4\nGHSA-xghp-9m6j-2mx2"
6+
},
7+
"GHSA-G685-9Q2W-88F4": {
8+
"458762a518138a26e597ac195eb82ce6c30238eb": "Publish Advisories\n\nGHSA-6qx8-mxxj-98fc\nGHSA-g685-9q2w-88f4\nGHSA-xghp-9m6j-2mx2"
9+
},
10+
"GHSA-XGHP-9M6J-2MX2": {
11+
"458762a518138a26e597ac195eb82ce6c30238eb": "Publish Advisories\n\nGHSA-6qx8-mxxj-98fc\nGHSA-g685-9q2w-88f4\nGHSA-xghp-9m6j-2mx2"
12+
},
413
"GHSA-C964-568J-VXX7": {
514
"30b2e88d407156e5425e05ff25f0ec9537280e2f": "Publish Advisories\n\nGHSA-c964-568j-vxx7\nGHSA-pw7g-jh5j-6w4m"
615
},

data/fix-commits/buildroot-0b809119.json

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,39 @@
11
{
22
"vcs_url": "https://github.com/buildroot/buildroot",
33
"vulnerabilities": {
4+
"CVE-2026-62289": {
5+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
6+
},
7+
"CVE-2026-62291": {
8+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
9+
},
10+
"CVE-2026-62292": {
11+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
12+
},
13+
"CVE-2026-62377": {
14+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
15+
},
16+
"GHSA-JC8F-P23P-5HJG": {
17+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
18+
},
19+
"GHSA-XPW3-9RHW-482X": {
20+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
21+
},
22+
"GHSA-73P7-M7GG-W2JV": {
23+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
24+
},
25+
"GHSA-9WW4-9V47-M7PJ": {
26+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
27+
},
28+
"GHSA-46RP-PCQ2-RPMR": {
29+
"bcb48623faecb73e7b14469b31f4cec73c979cb9": "package/libheif: security bump version to 1.23.1\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.1\n\nFixes the following CVEs:\n\nCVE-2026-62289 (GHSA-jc8f-p23p-5hjg)\nInteger underflow in Fraction constructor via double clap transform\napplication\n\nCVE-2026-62291 (GHSA-xpw3-9rhw-482x)\nHeap out of bounds write in libheif uncompressed encoder when writing\nimages with mismatched auxiliary alpha dimensions\n\nCVE-2026-62292 (GHSA-73p7-m7gg-w2jv)\nOut-of-bounds read in uncompressed unci tile range slicing\n\nCVE-2026-62377 (GHSA-9ww4-9v47-m7pj)\nReachable assertion in HeifContext::get_track() aborts on a valid-but-\nempty HEIF sequence file\n\n(GHSA-46rp-pcq2-rpmr)\nHeap out-of-bounds write in the uncompressed encoder for RRGGBB images\nwith interleaved bit-depth \u2264 8\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
30+
},
31+
"CVE-2026-61626": {
32+
"f6ca8d4f5f27232f439bb3e68ace6f7baf20d5cd": "package/libass: security bump version to 0.17.5\n\nhttps://github.com/libass/libass/releases/tag/0.17.5\n\nFixes CVE-2026-61626 & CVE-2026-61627.\n\nSwitched to sha256 tarball hash provided by upstream.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
33+
},
34+
"CVE-2026-61627": {
35+
"f6ca8d4f5f27232f439bb3e68ace6f7baf20d5cd": "package/libass: security bump version to 0.17.5\n\nhttps://github.com/libass/libass/releases/tag/0.17.5\n\nFixes CVE-2026-61626 & CVE-2026-61627.\n\nSwitched to sha256 tarball hash provided by upstream.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
36+
},
437
"CVE-2026-42616": {
538
"9b4559d6f10d1a1b3ba78506da33c64c190e9d91": "package/ntfs-3g: security bump version to 2026.7.7\n\nhttps://github.com/tuxera/ntfs-3g/wiki/NTFS-3G-Release-History\nhttps://seclists.org/oss-sec/2026/q3/152\n\n Multiple vulnerabilities have been discovered in ntfs-3g.\n A new version 2026.7.7 is now available at https://github.com/tuxera/ntfs-3g\n\n (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616)\n Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)\n Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618)\n Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569)\n Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571)\n Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570)\n Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572)\n Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135)\n Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136)\n\nSwitched to sha256 tarball hash provided by upstream.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>\n(cherry picked from commit 26811cb110217797fb44862aa401d68e73f9b1ae)\nSigned-off-by: Thomas Perale <thomas.perale@mind.be>",
639
"a0d575df1f807a830d8e450c4329ae6a8acfe183": "package/ntfs-3g: security bump version to 2026.7.7\n\nhttps://github.com/tuxera/ntfs-3g/wiki/NTFS-3G-Release-History\nhttps://seclists.org/oss-sec/2026/q3/152\n\n Multiple vulnerabilities have been discovered in ntfs-3g.\n A new version 2026.7.7 is now available at https://github.com/tuxera/ntfs-3g\n\n (ntfscat) Fix heap memory corruption when processing a corrupt or maliciously crafted filesystem. (CVE-2026-42616)\n Fix heap memory corruption when copying index data from root to an index block in a corrupt or maliciously crafted filesystem. (CVE-2026-42617)\n Fix single-byte heap buffer overflow when decompressing maliciously crafted compressed file data. (CVE-2026-42618)\n Fix heap buffer overflow when copying the tail data of an index block to a freshly allocated block. (CVE-2026-46569)\n Fix out-of-bounds read when processing symlink reparse data in a corrupt or maliciously crafted filesystem. (CVE-2026-46571)\n Fix heap memory corruption for maliciously crafted or corrupt index data descending to an out-of-bounds tree depth. (CVE-2026-46570)\n Fix heap buffer overflow for maliciously crafted or corrupt index data during a node split. (CVE-2026-46572)\n Fix heap buffer overflow when building inherited ACL data. (CVE-2026-56135)\n Fix out of bounds access when clearing an index root in maliciously crafted or corrupt index data. (CVE-2026-56136)\n\nSwitched to sha256 tarball hash provided by upstream.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>\n(cherry picked from commit 26811cb110217797fb44862aa401d68e73f9b1ae)\nSigned-off-by: Thomas Perale <thomas.perale@mind.be>",

data/fix-commits/bun-1f8d61fe.json

Lines changed: 1 addition & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -2,6 +2,7 @@
22
"vcs_url": "https://github.com/oven-sh/bun",
33
"vulnerabilities": {
44
"CVE-2024-36139": {
5+
"955457f9d1182c7090b9b96084a7e76914e800fd": "node:path: port Node's drive and reserved device name guards to win32 normalize and join\n\npath.win32.normalize now prefixes a relative result with .\\ when it would\notherwise look like a drive (c:) or end a segment with a colon (CON:), and\nrecognizes reserved DOS device names (CON, PRN, AUX, NUL, COM1-9, LPT1-9 and\nsuperscript variants) as device roots. path.win32.join skips normalization\nwhen a joined part is a reserved device name, leaving .. segments\nuncollapsed. This matches Node's behavior since the CVE-2024-36139 fix.\n\nFixes #35610",
56
"4da3f3bb53a042be1331b360aee87554f8d94f86": "path: port Node v26 win32 device-root and reserved-name handling\n\npath.win32 was still on the Node v21.6.1 algorithm and was missing three\nupstream changes.\n\nDevice roots. \\\\.\\X and \\\\?\\X are device roots, not UNC shares, so\nresolve() and normalize() must not append a trailing separator:\npath.win32.resolve('\\\\\\\\?\\\\foo') returned '\\\\\\\\?\\\\foo\\\\'\nwhere Node returns '\\\\\\\\?\\\\foo'. toNamespacedPath inherited the same\nextra separator through resolve.\n\nCVE-2024-36139. path.win32.normalize('test/../C:/Windows') returned\n'C:\\\\Windows' - a relative path normalizing into a different drive root.\nNode returns '.\\\\C:\\\\Windows'. normalize now applies the same guard: when\nthe input is relative, has no device, and contains a colon, the result is\nprefixed with '.\\\\'.\n\nReserved device names. CON, PRN, AUX, NUL, COM1-9 and LPT1-9 (including the\nsuperscript COM\\u00b9 spellings) are recognised in normalize's root match and\nin join, which skips normalization entirely when any joined segment is a\nreserved name so that '..' after 'CON:' is not resolved away.\n\nRestores four upstream tests to verbatim v26.3.0: test-path-normalize,\ntest-path-makelong, test-path-join, test-url-urltooptions.\n\nurlToHttpOptions now rejects non-objects with ERR_INVALID_ARG_TYPE, matching\nNode's validateObject(url, 'url', kValidateObjectAllowObjects).\n\nThe Bun-owned to-namespaced-path test asserted the old trailing separator;\nits two expectations now match real Node output.",
67
"ed1812b7f017f4860ebd1a6434f24e48cc83ad83": "path: normalize reserved Windows device names; domain: node's thrown-error ordering\n\npath.win32.normalize() did not know about reserved DOS device names, so\n`CON:` came back as `CON:` instead of `.\\CON:.`, and a relative path with a\ncolon such as `foo:/bar` was not made explicitly relative (CVE-2024-36139).\nPort the v26.3.0 algorithm: reserved names form their own root, `\\\\.\\` and\n`\\\\?\\` device roots are recognized (including `\\\\?\\COM1:`), and both the\nreserved and colon cases prefix the result with `.\\`. The reserved-name list\ncovers the superscript COM\u00b9/\u00b2/\u00b3 and LPT\u00b9/\u00b2/\u00b3 spellings in both the UTF-8 and\nUTF-16 representations.\n\nnode:domain routed a thrown error straight to the 'error' handler while the\ndomain was still active. Node exits the domain first and clears the stack\nafterwards, so `process.domain` is undefined inside the handler and null once\nthe tick ends.\n\nutil.debuglog() ignored its documented second argument and exposed no\n`enabled` property; both now follow lib/internal/util/debuglog.js.\n\nVendored from Node v26.3.0, each verified with a canary (appending a throw to\na copy must make the run fail):\n test-pipe-unref.js\n test-stdout-close-catch.js\n test-timers-reset-process-domain-on-throw.js\n test-path-win32-normalize-device-names.js (runs on the Windows lane; the\n table it asserts is covered on every platform by normalize.test.js)"
78
},

0 commit comments

Comments
 (0)