|
1 | 1 | { |
2 | 2 | "vcs_url": "https://github.com/buildroot/buildroot", |
3 | 3 | "vulnerabilities": { |
| 4 | + "CVE-2026-6472": { |
| 5 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 6 | + }, |
| 7 | + "CVE-2026-6473": { |
| 8 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 9 | + }, |
| 10 | + "CVE-2026-6474": { |
| 11 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 12 | + }, |
| 13 | + "CVE-2026-6475": { |
| 14 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 15 | + }, |
| 16 | + "CVE-2026-6476": { |
| 17 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 18 | + }, |
| 19 | + "CVE-2026-6477": { |
| 20 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 21 | + }, |
| 22 | + "CVE-2026-6478": { |
| 23 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 24 | + }, |
| 25 | + "CVE-2026-6479": { |
| 26 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 27 | + }, |
| 28 | + "CVE-2026-6575": { |
| 29 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 30 | + }, |
| 31 | + "CVE-2026-6637": { |
| 32 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 33 | + }, |
| 34 | + "CVE-2026-6638": { |
| 35 | + "9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>" |
| 36 | + }, |
4 | 37 | "CVE-2026-41163": { |
5 | 38 | "9ca78cc11c904f3e6a4e4e3fa0a7049f2506219c": "package/bubblewrap: security bump to version 0.11.2\n\nFixes CVE-2026-41163, which affects any system using bubblewrap 0.11.x\nusing a setuid bubblewrap.\n\nRelease notes:\n\n https://github.com/containers/bubblewrap/releases/tag/v0.11.2\n\nSigned-off-by: Adrian Perez de Castro <aperez@igalia.com>\nSigned-off-by: Julien Olivain <ju.o@free.fr>\n(cherry picked from commit 108f51c1b35479a8c1c3c3d9ab58589ef26217f3)\nSigned-off-by: Thomas Perale <thomas.perale@mind.be>", |
6 | 39 | "7e18e312205347656e1e1e2c17bf6529a6275174": "package/bubblewrap: security bump to version 0.11.2\n\nFixes CVE-2026-41163, which affects any system using bubblewrap 0.11.x\nusing a setuid bubblewrap.\n\nRelease notes:\n\n https://github.com/containers/bubblewrap/releases/tag/v0.11.2\n\nSigned-off-by: Adrian Perez de Castro <aperez@igalia.com>\nSigned-off-by: Julien Olivain <ju.o@free.fr>\n(cherry picked from commit 108f51c1b35479a8c1c3c3d9ab58589ef26217f3)\nSigned-off-by: Thomas Perale <thomas.perale@mind.be>", |
|
0 commit comments