Skip to content

Commit e754689

Browse files
Sync Collecting Fix Commits: Fri Sep 11 08:04:50 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent b4a482c commit e754689

7 files changed

Lines changed: 210 additions & 57 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 145 additions & 27 deletions
Large diffs are not rendered by default.

data/fix-commits/bun-1f8d61fe.json

Lines changed: 1 addition & 1 deletion
Large diffs are not rendered by default.

data/fix-commits/gentoo.git-f7ec53e2.json

Lines changed: 12 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,18 @@
11
{
22
"vcs_url": "https://gitweb.gentoo.org/repo/gentoo.git",
33
"vulnerabilities": {
4+
"CVE-2026-8450": {
5+
"053756a224e8b06931f3d0659b30236f62483dee": "dev-perl/HTTP-Daemon: fix CVE-2026-8450\n\n- backport fix for CVE-2026-8450\n- Remove unversioned perl virtuals (MissingVersionedVirtualPerlDependency)\n- Remove blocker for dev-perl/libwww-perl-6 (NonexistentBlocker)\n\nBug: https://bugs.gentoo.org/976110\nSigned-off-by: Brett A C Sheffield <bacs@librecast.net>\nPart-of: https://codeberg.org/gentoo/gentoo/pulls/1033\nMerges: https://codeberg.org/gentoo/gentoo/pulls/1033\nSigned-off-by: Sam James <sam@gentoo.org>"
6+
},
7+
"CVE-2025-15646": {
8+
"c6fb9f0a32e71db44c54db73417cfcd9eecd35cf": "dev-perl/HTML-Gumbo: add 0.190.0\n\n- fixes CVE-2025-15646\n- fix MissingVersionedVirtualPerlDependency\n\nBug: https://bugs.gentoo.org/979603\nSigned-off-by: Brett A C Sheffield <bacs@librecast.net>\nPart-of: https://codeberg.org/gentoo/gentoo/pulls/1479\nMerges: https://codeberg.org/gentoo/gentoo/pulls/1479\nSigned-off-by: Sam James <sam@gentoo.org>"
9+
},
10+
"CVE-2026-60074": {
11+
"45b6d1403bf1aa885c5d3708e4d30694ead09590": "dev-perl/Date-Manip: revbump, security fixes\n\nApply patches for CVE-2026-60074, CVE-2026-60075.\n\nBug: https://bugs.gentoo.org/980109\nSigned-off-by: Brett A C Sheffield <bacs@librecast.net>\nPart-of: https://codeberg.org/gentoo/gentoo/pulls/1595\nMerges: https://codeberg.org/gentoo/gentoo/pulls/1595\nSigned-off-by: Sam James <sam@gentoo.org>"
12+
},
13+
"CVE-2026-60075": {
14+
"45b6d1403bf1aa885c5d3708e4d30694ead09590": "dev-perl/Date-Manip: revbump, security fixes\n\nApply patches for CVE-2026-60074, CVE-2026-60075.\n\nBug: https://bugs.gentoo.org/980109\nSigned-off-by: Brett A C Sheffield <bacs@librecast.net>\nPart-of: https://codeberg.org/gentoo/gentoo/pulls/1595\nMerges: https://codeberg.org/gentoo/gentoo/pulls/1595\nSigned-off-by: Sam James <sam@gentoo.org>"
15+
},
416
"CVE-2026-10805": {
517
"ec0ea2587aafab8b3c5c32730aea428f094db01c": "net-misc/networkmanager: fixup 1.58.1\n\n* Add recently postponed changes after CVE-2026-10805 has been addressed\n in eafe7bdca6\n* enable python3.15\n* add clat use flag and deps\n* add wext deprecation ewarn\n\nSee: https://codeberg.org/gentoo/gentoo/pulls/1717\nCloses: https://bugs.gentoo.org/981154\nSigned-off-by: Lukas Schmelting <lschmelting@posteo.com>\nPart-of: https://codeberg.org/gentoo/gentoo/pulls/1718\nSigned-off-by: Sam James <sam@gentoo.org>",
618
"eafe7bdca65bcb3eedb33770110077576719647b": "net-misc/networkmanager: add 1.58.1\n\n* upstream changes contain fix for CVE-2026-10805. Necessary ebuild changes\n only, other changes postponed to a follow-up PR:\n * add slang dep for nmtui\n * Remove obsolete dhclient use flag,\n * Remove obsolete 'modify_system' meson option which \"is no longer allowed due\n to security reasons\"\n\nSee: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/0b75d905e59999539ab1e92a92646b634c221215\nSee: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/1756ec54e384cc7e66878e9eecf7dd713df9de29\nSee: https://gitlab.freedesktop.org/NetworkManager/NetworkManager/-/commit/fbcaa53b42a8483e00ab3c17919eb7e6504beb1a\nBug: https://bugs.gentoo.org/981154\nBug: https://bugs.gentoo.org/981249\nSigned-off-by: Lukas Schmelting <lschmelting@posteo.com>\nPart-of: https://codeberg.org/gentoo/gentoo/pulls/1717\nMerges: https://codeberg.org/gentoo/gentoo/pulls/1717\nSigned-off-by: Sam James <sam@gentoo.org>"

data/fix-commits/moby-fc18b20f.json

Lines changed: 44 additions & 26 deletions
Large diffs are not rendered by default.

data/fix-commits/qemu-0a8b25ef.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11
{
22
"vcs_url": "https://gitlab.com/qemu-project/qemu",
33
"vulnerabilities": {
4+
"CVE-2026-66020": {
5+
"5bf61eef114add377890fef01a5ed55de554241d": "Merge tag 'virtio-gpu-pr-v2' of https://gitlab.com/marcandre.lureau/qemu into staging\n\nVarious virtio-gpu/dmabuf related fixes\n\nWhile working on CVE-2026-66020 (which had a few revision on list), I\nkept finding several places where virtio-gpu scanout and dmabuf\nownership was unclear.\n\nThe CVE comes from using a blob after RESOURCE_DETACH_BACKING has\nunmapped its memory. Following that path also found stale dmabuf\nreferences, duplicated scanout bookkeeping, and inconsistent cleanup\nbetween display backends.\n\nThose changes touch a lot of area and I have done basic testing with the\nvarious backends. I would not recommend backporting them all to stable.\nThe first 2 patches address CVE-2026-66020 in the general case and\nshould be safe to backport.\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmqi0+8ACgkQ2ujhCXWW\n# nOVihA/+P9OvMzadaVVLXzML6uK+tHJfKiX6kFICIzXMYmVPyFO3ociPKS0n8645\n# CpaYNZc+xqXbtFtxXkzXW7Lg7dYkfYRKFS7IhgN7mSPo/f3+d3p/rMOsrraXZd8y\n# UnpDaEnheA9KWBmNHizVUv83PCsrCo19NkBnB13tcoc7Yiy+xE8/P20ohoxc+KDX\n# cchpy31x2ccqAv3P3gaclvlclsj4UaiNPT71oTbm1fZnfsGVWKdxnAxTY6mmtEC5\n# kP0MmK41wOUcxM9u/1qw95YVRYc7Fhdlxbf9ZaOli9mVFzGYC1LCCDu9xTxaIE6+\n# w0AXe1NVIdt9FpuraoOovsdFiF2NU8U6+kTVMOkSO8qP2UtIyvfbk65pCQOjClNr\n# S9fhS4+Gkx1dIjJASLfyd3Ej222safwmBHBrY9KgCZ8o439gQMjIgD9pUoS21Nak\n# j5H6eQ3YHCZcoSClQCPH+wl3elundraZO38wuME+3a4EcrFN3bFxOThws3Ns2Bf3\n# MlA73vZLHOC22x/RR3M4rxzoPKEKArBIQaHQXO8wqfsTABImPzGRYyjfXGRqGDEK\n# atBYTR++tS7lG8EM9a+IW482D4/tVCkvwMjA5G6+dyx7bUdJ3bhj854yce7wSI8u\n# PeUoP5QzqAxy4xRvWLWhRJIJiFzhK7Ag/BrzN7cTnefIa5L6mNQ=\n# =3aXk\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Thu 10 Sep 2026 05:59:43 AM HST\n# gpg: using RSA key 87A9BD933F87C606D276F62DDAE8E10975969CE5\n# gpg: Good signature from \"Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\" [unknown]\n# gpg: aka \"Marc-Andr\u00e9 Lureau <marcandre.lureau@gmail.com>\" [unknown]\n# gpg: WARNING: This key is not certified with a trusted signature!\n# gpg: There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: 87A9 BD93 3F87 C606 D276 F62D DAE8 E109 7596 9CE5\n\n* tag 'virtio-gpu-pr-v2' of https://gitlab.com/marcandre.lureau/qemu: (24 commits)\n contrib/vhost-user-gpu: disable scanouts on resource unref\n virtio-gpu: extract virtio_gpu_disable_scanout_for_resource helper\n virtio-gpu/virgl: disable scanouts on resource unref\n virtio-gpu: minor refactoring\n virtio-gpu: consolidate disabling scanout\n virtio-gpu/virgl: release dmabuf when a texture replaces a scanout\n virtio-gpu: release dmabuf when switching to a surface\n virtio-gpu: drop scanout_bitmask bookkeeping\n virtio-gpu-rutabaga: fix scanout handling\n contrib/vhost-user-gpu: drop scanout_bitmask bookkeeping\n virtio-gpu: release the dmabuf when a scanout is disabled\n ui: make GL context current in display backend callbacks\n ui/dmabuf: own and close fds on free\n ui/sdl2: clear guest_fb.dmabuf on release\n ui/console: disable GL scanout when dmabuf is the active one\n virtio-gpu: store the scanout DMABUF in virtio_gpu_scanout\n ui/dbus: disable scanout iff dmabuf is current\n ui/gtk: move draw_submitted from QemuDmaBuf to VirtualGfxConsole\n ui/gtk: move GL fence tracking from QemuDmaBuf to VirtualGfxConsole\n hw/display/virtio-gpu: set share_handle for udmabuf blob resources\n ...\n\nSigned-off-by: Richard Henderson <richard.henderson@linaro.org>",
6+
"3ece85b53c124142c7d5cbb1165d4da125b7c369": "virtio-gpu: disable blob scanouts on mapping cleanup\n\nWhen a blob resource backing is cleaned up (for ex via detach_backing),\nany scanouts referencing it must be disabled first to prevent the\ndmabuf from outliving its backing memory.\n\nFixes: CVE-2026-66020\nFixes: 32db3c63ae11 (\"virtio-gpu: Add virtio_gpu_set_scanout_blob\")\nReported-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>\nReviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>\nSigned-off-by: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>"
7+
},
48
"CVE-2026-84788": {
59
"7a72a4652a7955db579d2b9244a09edbf7b0529b": "io/channel-websock: do not lose QIO_CHANNEL_ERR_BLOCK while reading\n\nqio_channel_websock_handshake_read() folds every negative return from\nqio_channel_read() into -1. QIO_CHANNEL_ERR_BLOCK leaves errp unset, so\nqio_channel_websock_handshake_io() then hands a NULL Error to\nerror_get_pretty() and QEMU dies.\n\nThe master channel is non-blocking and, for a wss:// client, is a TLS\nchannel. A G_IO_IN wakeup carrying only part of a TLS record makes\ngnutls report EAGAIN, which is all it takes to reach this before the\nclient has authenticated.\n\nERR_BLOCK here means the headers are not complete yet, which is what a\n0 return already tells the caller. Report it that way and keep waiting.\nThe watch is level triggered, so an incomplete record sitting in the\nsocket spins the main loop until the rest of it arrives. That is\nbounded by the round trip and is what every reader layered over TLS\nalready does.\n\nFixes: 2d1d0e70cf3e (\"io: add QIOChannelWebsock class\")\nFixes: CVE-2026-84788\nCc: qemu-stable@nongnu.org\nCc: Daniel P. Berrang\u00e9 <berrange@redhat.com>\nCc: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\nReviewed-by: Daniel P. Berrang\u00e9 <berrange@redhat.com>\nReviewed-by: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\nSigned-off-by: Denis V. Lunev <den@openvz.org>\nSigned-off-by: Daniel P. Berrang\u00e9 <berrange@redhat.com>",
610
"e867e2047c6cf8c1e59e8e1155291cc0a0b9dd29": "tests/unit: add websock handshake test\n\nCheck that malformed HTTP greetings are answered with an HTTP 400\nrather than an empty response. The no-space case is the one which used\nto leave the response buffer empty.\n\nFixes: CVE-2026-84788\nCc: Daniel P. Berrang\u00e9 <berrange@redhat.com>\nCc: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\nReviewed-by: Daniel P. Berrang\u00e9 <berrange@redhat.com>\nReviewed-by: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\nSigned-off-by: Denis V. Lunev <den@openvz.org>\n[DB: exclude test from Windows since it depends on AF_UNIX\n which is not universally available]\nSigned-off-by: Daniel P. Berrang\u00e9 <berrange@redhat.com>",

data/fix-commits/qemu-11410379.json

Lines changed: 4 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,10 @@
11
{
22
"vcs_url": "https://github.com/qemu/qemu",
33
"vulnerabilities": {
4+
"CVE-2026-66020": {
5+
"5bf61eef114add377890fef01a5ed55de554241d": "Merge tag 'virtio-gpu-pr-v2' of https://gitlab.com/marcandre.lureau/qemu into staging\n\nVarious virtio-gpu/dmabuf related fixes\n\nWhile working on CVE-2026-66020 (which had a few revision on list), I\nkept finding several places where virtio-gpu scanout and dmabuf\nownership was unclear.\n\nThe CVE comes from using a blob after RESOURCE_DETACH_BACKING has\nunmapped its memory. Following that path also found stale dmabuf\nreferences, duplicated scanout bookkeeping, and inconsistent cleanup\nbetween display backends.\n\nThose changes touch a lot of area and I have done basic testing with the\nvarious backends. I would not recommend backporting them all to stable.\nThe first 2 patches address CVE-2026-66020 in the general case and\nshould be safe to backport.\n\n# -----BEGIN PGP SIGNATURE-----\n#\n# iQIzBAABCgAdFiEEh6m9kz+HxgbSdvYt2ujhCXWWnOUFAmqi0+8ACgkQ2ujhCXWW\n# nOVihA/+P9OvMzadaVVLXzML6uK+tHJfKiX6kFICIzXMYmVPyFO3ociPKS0n8645\n# CpaYNZc+xqXbtFtxXkzXW7Lg7dYkfYRKFS7IhgN7mSPo/f3+d3p/rMOsrraXZd8y\n# UnpDaEnheA9KWBmNHizVUv83PCsrCo19NkBnB13tcoc7Yiy+xE8/P20ohoxc+KDX\n# cchpy31x2ccqAv3P3gaclvlclsj4UaiNPT71oTbm1fZnfsGVWKdxnAxTY6mmtEC5\n# kP0MmK41wOUcxM9u/1qw95YVRYc7Fhdlxbf9ZaOli9mVFzGYC1LCCDu9xTxaIE6+\n# w0AXe1NVIdt9FpuraoOovsdFiF2NU8U6+kTVMOkSO8qP2UtIyvfbk65pCQOjClNr\n# S9fhS4+Gkx1dIjJASLfyd3Ej222safwmBHBrY9KgCZ8o439gQMjIgD9pUoS21Nak\n# j5H6eQ3YHCZcoSClQCPH+wl3elundraZO38wuME+3a4EcrFN3bFxOThws3Ns2Bf3\n# MlA73vZLHOC22x/RR3M4rxzoPKEKArBIQaHQXO8wqfsTABImPzGRYyjfXGRqGDEK\n# atBYTR++tS7lG8EM9a+IW482D4/tVCkvwMjA5G6+dyx7bUdJ3bhj854yce7wSI8u\n# PeUoP5QzqAxy4xRvWLWhRJIJiFzhK7Ag/BrzN7cTnefIa5L6mNQ=\n# =3aXk\n# -----END PGP SIGNATURE-----\n# gpg: Signature made Thu 10 Sep 2026 05:59:43 AM HST\n# gpg: using RSA key 87A9BD933F87C606D276F62DDAE8E10975969CE5\n# gpg: Good signature from \"Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\" [unknown]\n# gpg: aka \"Marc-Andr\u00e9 Lureau <marcandre.lureau@gmail.com>\" [unknown]\n# gpg: WARNING: This key is not certified with a trusted signature!\n# gpg: There is no indication that the signature belongs to the owner.\n# Primary key fingerprint: 87A9 BD93 3F87 C606 D276 F62D DAE8 E109 7596 9CE5\n\n* tag 'virtio-gpu-pr-v2' of https://gitlab.com/marcandre.lureau/qemu: (24 commits)\n contrib/vhost-user-gpu: disable scanouts on resource unref\n virtio-gpu: extract virtio_gpu_disable_scanout_for_resource helper\n virtio-gpu/virgl: disable scanouts on resource unref\n virtio-gpu: minor refactoring\n virtio-gpu: consolidate disabling scanout\n virtio-gpu/virgl: release dmabuf when a texture replaces a scanout\n virtio-gpu: release dmabuf when switching to a surface\n virtio-gpu: drop scanout_bitmask bookkeeping\n virtio-gpu-rutabaga: fix scanout handling\n contrib/vhost-user-gpu: drop scanout_bitmask bookkeeping\n virtio-gpu: release the dmabuf when a scanout is disabled\n ui: make GL context current in display backend callbacks\n ui/dmabuf: own and close fds on free\n ui/sdl2: clear guest_fb.dmabuf on release\n ui/console: disable GL scanout when dmabuf is the active one\n virtio-gpu: store the scanout DMABUF in virtio_gpu_scanout\n ui/dbus: disable scanout iff dmabuf is current\n ui/gtk: move draw_submitted from QemuDmaBuf to VirtualGfxConsole\n ui/gtk: move GL fence tracking from QemuDmaBuf to VirtualGfxConsole\n hw/display/virtio-gpu: set share_handle for udmabuf blob resources\n ...\n\nSigned-off-by: Richard Henderson <richard.henderson@linaro.org>",
6+
"3ece85b53c124142c7d5cbb1165d4da125b7c369": "virtio-gpu: disable blob scanouts on mapping cleanup\n\nWhen a blob resource backing is cleaned up (for ex via detach_backing),\nany scanouts referencing it must be disabled first to prevent the\ndmabuf from outliving its backing memory.\n\nFixes: CVE-2026-66020\nFixes: 32db3c63ae11 (\"virtio-gpu: Add virtio_gpu_set_scanout_blob\")\nReported-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>\nReviewed-by: Akihiko Odaki <odaki@rsg.ci.i.u-tokyo.ac.jp>\nSigned-off-by: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>"
7+
},
48
"CVE-2026-84788": {
59
"7a72a4652a7955db579d2b9244a09edbf7b0529b": "io/channel-websock: do not lose QIO_CHANNEL_ERR_BLOCK while reading\n\nqio_channel_websock_handshake_read() folds every negative return from\nqio_channel_read() into -1. QIO_CHANNEL_ERR_BLOCK leaves errp unset, so\nqio_channel_websock_handshake_io() then hands a NULL Error to\nerror_get_pretty() and QEMU dies.\n\nThe master channel is non-blocking and, for a wss:// client, is a TLS\nchannel. A G_IO_IN wakeup carrying only part of a TLS record makes\ngnutls report EAGAIN, which is all it takes to reach this before the\nclient has authenticated.\n\nERR_BLOCK here means the headers are not complete yet, which is what a\n0 return already tells the caller. Report it that way and keep waiting.\nThe watch is level triggered, so an incomplete record sitting in the\nsocket spins the main loop until the rest of it arrives. That is\nbounded by the round trip and is what every reader layered over TLS\nalready does.\n\nFixes: 2d1d0e70cf3e (\"io: add QIOChannelWebsock class\")\nFixes: CVE-2026-84788\nCc: qemu-stable@nongnu.org\nCc: Daniel P. Berrang\u00e9 <berrange@redhat.com>\nCc: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\nReviewed-by: Daniel P. Berrang\u00e9 <berrange@redhat.com>\nReviewed-by: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\nSigned-off-by: Denis V. Lunev <den@openvz.org>\nSigned-off-by: Daniel P. Berrang\u00e9 <berrange@redhat.com>",
610
"e867e2047c6cf8c1e59e8e1155291cc0a0b9dd29": "tests/unit: add websock handshake test\n\nCheck that malformed HTTP greetings are answered with an HTTP 400\nrather than an empty response. The no-space case is the one which used\nto leave the response buffer empty.\n\nFixes: CVE-2026-84788\nCc: Daniel P. Berrang\u00e9 <berrange@redhat.com>\nCc: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\nReviewed-by: Daniel P. Berrang\u00e9 <berrange@redhat.com>\nReviewed-by: Marc-Andr\u00e9 Lureau <marcandre.lureau@redhat.com>\nSigned-off-by: Denis V. Lunev <den@openvz.org>\n[DB: exclude test from Windows since it depends on AF_UNIX\n which is not universally available]\nSigned-off-by: Daniel P. Berrang\u00e9 <berrange@redhat.com>",

0 commit comments

Comments
 (0)