Skip to content

Commit fb227a9

Browse files
Sync Collecting Fix Commits: Sun Aug 30 17:43:37 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent ad37799 commit fb227a9

4 files changed

Lines changed: 79 additions & 14 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 55 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,61 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-42P8-VFG5-26VR": {
5+
"631e472e68a0063b378c35500bf1bd64132a652a": "Publish Advisories\n\nGHSA-42p8-vfg5-26vr\nGHSA-54f9-jfc2-qh3v\nGHSA-9h33-6q7m-9r9j\nGHSA-9rhj-r9gw-f4p2\nGHSA-q78f-c32r-53f2\nGHSA-v975-p34v-4fvr"
6+
},
7+
"GHSA-54F9-JFC2-QH3V": {
8+
"631e472e68a0063b378c35500bf1bd64132a652a": "Publish Advisories\n\nGHSA-42p8-vfg5-26vr\nGHSA-54f9-jfc2-qh3v\nGHSA-9h33-6q7m-9r9j\nGHSA-9rhj-r9gw-f4p2\nGHSA-q78f-c32r-53f2\nGHSA-v975-p34v-4fvr"
9+
},
10+
"GHSA-9H33-6Q7M-9R9J": {
11+
"631e472e68a0063b378c35500bf1bd64132a652a": "Publish Advisories\n\nGHSA-42p8-vfg5-26vr\nGHSA-54f9-jfc2-qh3v\nGHSA-9h33-6q7m-9r9j\nGHSA-9rhj-r9gw-f4p2\nGHSA-q78f-c32r-53f2\nGHSA-v975-p34v-4fvr"
12+
},
13+
"GHSA-9RHJ-R9GW-F4P2": {
14+
"631e472e68a0063b378c35500bf1bd64132a652a": "Publish Advisories\n\nGHSA-42p8-vfg5-26vr\nGHSA-54f9-jfc2-qh3v\nGHSA-9h33-6q7m-9r9j\nGHSA-9rhj-r9gw-f4p2\nGHSA-q78f-c32r-53f2\nGHSA-v975-p34v-4fvr"
15+
},
16+
"GHSA-Q78F-C32R-53F2": {
17+
"631e472e68a0063b378c35500bf1bd64132a652a": "Publish Advisories\n\nGHSA-42p8-vfg5-26vr\nGHSA-54f9-jfc2-qh3v\nGHSA-9h33-6q7m-9r9j\nGHSA-9rhj-r9gw-f4p2\nGHSA-q78f-c32r-53f2\nGHSA-v975-p34v-4fvr"
18+
},
19+
"GHSA-V975-P34V-4FVR": {
20+
"631e472e68a0063b378c35500bf1bd64132a652a": "Publish Advisories\n\nGHSA-42p8-vfg5-26vr\nGHSA-54f9-jfc2-qh3v\nGHSA-9h33-6q7m-9r9j\nGHSA-9rhj-r9gw-f4p2\nGHSA-q78f-c32r-53f2\nGHSA-v975-p34v-4fvr"
21+
},
22+
"GHSA-73MF-M39P-WPM9": {
23+
"920c24b33a009d8f48d579eb0665b1d6d8fb0eef": "Improve GHSA-73mf-m39p-wpm9",
24+
"15d19eb26fc43e30afe0bbf649dd5b3491db9ffd": "Publish Advisories\n\nGHSA-73mf-m39p-wpm9\nGHSA-9jg3-g3wh-w9pj"
25+
},
26+
"GHSA-2MV6-FVG7-6F57": {
27+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
28+
},
29+
"GHSA-4X5W-68JG-4H4R": {
30+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
31+
},
32+
"GHSA-5FQ3-W569-GQX5": {
33+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
34+
},
35+
"GHSA-88RF-74WH-96Q8": {
36+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
37+
},
38+
"GHSA-C4G6-W433-V47V": {
39+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
40+
},
41+
"GHSA-C5MG-RWRQ-R34J": {
42+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
43+
},
44+
"GHSA-J9G4-34J9-XVCM": {
45+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
46+
},
47+
"GHSA-MGQ4-QPJF-4PFW": {
48+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
49+
},
50+
"GHSA-RMH2-MRXF-CJQV": {
51+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
52+
},
53+
"GHSA-W464-C99H-248P": {
54+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
55+
},
56+
"GHSA-XG5H-JCFM-24G6": {
57+
"c26615798c9356556d53b406eb511473e7c15d0f": "Publish Advisories\n\nGHSA-2mv6-fvg7-6f57\nGHSA-4x5w-68jg-4h4r\nGHSA-5fq3-w569-gqx5\nGHSA-88rf-74wh-96q8\nGHSA-c4g6-w433-v47v\nGHSA-c5mg-rwrq-r34j\nGHSA-j9g4-34j9-xvcm\nGHSA-mgq4-qpjf-4pfw\nGHSA-rmh2-mrxf-cjqv\nGHSA-w464-c99h-248p\nGHSA-xg5h-jcfm-24g6"
58+
},
459
"GHSA-6CV3-J4MC-JF2R": {
560
"86a891354e54e56948849b7f16a55d166fb8d24c": "Publish Advisories\n\nGHSA-6cv3-j4mc-jf2r\nGHSA-6hcx-8gm4-gx5h\nGHSA-fq2p-334f-fcrf\nGHSA-h35r-6hg6-mcg3"
661
},
@@ -528,9 +583,6 @@
528583
"GHSA-C64Q-HJ4J-375F": {
529584
"dbea0ac4554c95be2698b74a00b5833cb4630344": "Publish GHSA-c64q-hj4j-375f"
530585
},
531-
"GHSA-73MF-M39P-WPM9": {
532-
"15d19eb26fc43e30afe0bbf649dd5b3491db9ffd": "Publish Advisories\n\nGHSA-73mf-m39p-wpm9\nGHSA-9jg3-g3wh-w9pj"
533-
},
534586
"GHSA-9JG3-G3WH-W9PJ": {
535587
"15d19eb26fc43e30afe0bbf649dd5b3491db9ffd": "Publish Advisories\n\nGHSA-73mf-m39p-wpm9\nGHSA-9jg3-g3wh-w9pj"
536588
},

data/fix-commits/buildroot-0b809119.json

Lines changed: 13 additions & 3 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,19 @@
11
{
22
"vcs_url": "https://github.com/buildroot/buildroot",
33
"vulnerabilities": {
4+
"CVE-2026-19499": {
5+
"be382f6061216ca82a735d0992894c4e6fe5173a": "package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc\n\nFixes the following CVEs:\n\nCVE-2026-19499:\nhttps://gitlab.com/gnutools/glibc/-/commit/63b53df549451a5d69fcba6d7612ea99f517e8e3\n\nCVE-2026-77117:\nhttps://gitlab.com/gnutools/glibc/-/commit/6f9b2bfa500bf5d1cff5d990adfff4b71298dadd\n\nCVE-2026-80489:\nhttps://gitlab.com/gnutools/glibc/-/commit/cb61572ea3f773e1e1978f6c412cc36a30acdb0c\n\nAdded GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in\nbuildroot commit 58f31377389dd2f5090e4dd69deb4d5f994f88c0.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
6+
},
7+
"CVE-2026-77117": {
8+
"be382f6061216ca82a735d0992894c4e6fe5173a": "package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc\n\nFixes the following CVEs:\n\nCVE-2026-19499:\nhttps://gitlab.com/gnutools/glibc/-/commit/63b53df549451a5d69fcba6d7612ea99f517e8e3\n\nCVE-2026-77117:\nhttps://gitlab.com/gnutools/glibc/-/commit/6f9b2bfa500bf5d1cff5d990adfff4b71298dadd\n\nCVE-2026-80489:\nhttps://gitlab.com/gnutools/glibc/-/commit/cb61572ea3f773e1e1978f6c412cc36a30acdb0c\n\nAdded GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in\nbuildroot commit 58f31377389dd2f5090e4dd69deb4d5f994f88c0.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
9+
},
10+
"CVE-2026-80489": {
11+
"be382f6061216ca82a735d0992894c4e6fe5173a": "package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc\n\nFixes the following CVEs:\n\nCVE-2026-19499:\nhttps://gitlab.com/gnutools/glibc/-/commit/63b53df549451a5d69fcba6d7612ea99f517e8e3\n\nCVE-2026-77117:\nhttps://gitlab.com/gnutools/glibc/-/commit/6f9b2bfa500bf5d1cff5d990adfff4b71298dadd\n\nCVE-2026-80489:\nhttps://gitlab.com/gnutools/glibc/-/commit/cb61572ea3f773e1e1978f6c412cc36a30acdb0c\n\nAdded GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in\nbuildroot commit 58f31377389dd2f5090e4dd69deb4d5f994f88c0.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
12+
},
13+
"CVE-2026-19542": {
14+
"be382f6061216ca82a735d0992894c4e6fe5173a": "package/{glibc, localedef}: security bump version to 2.44-36-g2d5421ffc\n\nFixes the following CVEs:\n\nCVE-2026-19499:\nhttps://gitlab.com/gnutools/glibc/-/commit/63b53df549451a5d69fcba6d7612ea99f517e8e3\n\nCVE-2026-77117:\nhttps://gitlab.com/gnutools/glibc/-/commit/6f9b2bfa500bf5d1cff5d990adfff4b71298dadd\n\nCVE-2026-80489:\nhttps://gitlab.com/gnutools/glibc/-/commit/cb61572ea3f773e1e1978f6c412cc36a30acdb0c\n\nAdded GLIBC_IGNORE_CVES for CVE-2026-19542 which was forgotten in\nbuildroot commit 58f31377389dd2f5090e4dd69deb4d5f994f88c0.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>",
15+
"58f31377389dd2f5090e4dd69deb4d5f994f88c0": "package/{glibc, localedef}: security bump version to 2.44-27-gae9225d55\n\nFixes CVE-2026-19542:\nhttps://gitlab.com/gnutools/glibc/-/commit/d6ff274313d79feb864cc10eb775b91c817a67e9\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=34506\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Peter Korsgaard <peter@korsgaard.com>"
16+
},
417
"GHSA-G89C-P67H-R497": {
518
"0fe2d74ffd1290422d0fb721481f4acd60d12cc0": "package/libheif: security bump version to 1.23.2\n\nhttps://github.com/strukturag/libheif/releases/tag/v1.23.2\n\nFixes the following CVEs:\n\n(CVE numbers will be added upstream when assigned.)\n\nCVE-2026-XXXXX (GHSA-g89c-p67h-r497)\n Heap buffer overflow in scale_nearest_neighbor() via duplicate alpha\n planes from nested iden/auxl items. (critical)\n\n(GHSA-2jg2-4ch7-h545)\n Out-of-bounds read and write in derived-item and pixel-plane handling.\n Through iden and auxl item chains, a crafted file could attach pixel\n planes whose size differs from the image geometry; crop, scale, and\n plane-extraction code then indexed those planes with the wrong size.\n A working code-execution exploit was confirmed. Plane sizes are now\n validated wherever they are consumed. (critical)\n\nCVE-2026-XXXXX (GHSA-24wx-9w62-c96w)\n brotli/zlib decompression of mime metadata and unci image data had no\n effective output-size limit, so a decompression bomb could exhaust\n memory. Decompressed output is now bounded by the security limits.\n (high)\n\nCVE-2026-XXXXX (GHSA-x8xm-cm2c-cfc8)\n Chains of derived-image references (grid, iovl, iden) bypassed decode\n caching and memory limits, causing CPU and memory amplification. (high)\n\nCVE-2026-XXXXX (GHSA-xw34-mjcp-jqh8)\n Sequence sample-timing initialization could produce non-terminating\n decode loops and unbounded memory, bypassing max_sequence_frames.\n (high)\n\nCVE-2026-XXXXX (GHSA-j264-xvrp-5v7q)\n Out-of-bounds write in the unci encoder when\n heif_context_add_image_tile() is given a tile whose planes do not match\n its declared size. (high)\n\nCVE-2026-XXXXX (GHSA-p58j-h3vm-3fp5)\n Heap out-of-bounds read in the inline-mask region API when\n mask_data_len does not match the region geometry. (medium)\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Peter Korsgaard <peter@korsgaard.com>"
619
},
@@ -363,9 +376,6 @@
363376
"CVE-2026-54876": {
364377
"198317785a89ed7fd398fda7ab8ede7dfb4871c7": "package/libopenssl: security bump to version 3.6.4\n\nhttps://github.com/openssl/openssl/releases/tag/openssl-3.6.4\n\nThis release incorporates the following bug fixes and mitigations:\n\nFixed QUIC server being able to trigger double free when processing\nINITIAL packet.\n(CVE-2026-18798)\n\nFixed heap buffer overflow in CMS key unwrapping.\n(CVE-2026-63072)\n\nFixed invalid pointer dereference in CMP server via crafted protectionAlg.\n(CVE-2026-63076)\n\nFixed unbounded memory growth in QUIC server incoming channel queue.\n(CVE-2026-14456)\n\nFixed RPK server signature algorithm selection being able to dereference\na missing certificate.\n(CVE-2026-14457)\n\nFixed excessive memory use buffering DTLS records for a future epoch.\n(CVE-2026-54874)\n\nFixed client-side memory leak in OCSP response checking.\n(CVE-2026-54876)\n\nFixed untrusted Sender DN being used as a format string in CMP response\nvalidation.\n(CVE-2026-63073)\n\nFixed CMP indefinite cache growth of extraCerts.\n(CVE-2026-63074)\n\nFixed QUIC ACK-only packet retention being able to cause memory exhaustion.\n(CVE-2026-63075)\n\nFixed possibility of AEAD forgeries with empty ciphertext when using\nEVP_Cipher().\n(CVE-2026-75803)\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
365378
},
366-
"CVE-2026-19542": {
367-
"58f31377389dd2f5090e4dd69deb4d5f994f88c0": "package/{glibc, localedef}: security bump version to 2.44-27-gae9225d55\n\nFixes CVE-2026-19542:\nhttps://gitlab.com/gnutools/glibc/-/commit/d6ff274313d79feb864cc10eb775b91c817a67e9\nhttps://sourceware.org/bugzilla/show_bug.cgi?id=34506\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Peter Korsgaard <peter@korsgaard.com>"
368-
},
369379
"CVE-2026-62356": {
370380
"fab3c4eb92877284f39ba59289affc8fcbccf1a7": "package/redis: security bump to v8.10.1\n\nSee the release notes:\nhttps://github.com/redis/redis/blob/8.10.1/00-RELEASENOTES\n\nNotably, this fixes CVE-2026-62356: miscalculated buffer size in\n`CMSketch` RDB loading may lead to heap OOB write, as well as other\nsecurity fixes without CVE number\n\nSigned-off-by: Titouan Christophe <titouan.christophe@mind.be>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
371381
},

0 commit comments

Comments
 (0)