Skip to content

Commit 0583f17

Browse files
Sync Collecting Fix Commits: Sun May 17 23:28:34 UTC 2026
Signed-off-by: AboutCode Automation <automation@aboutcode.org>
1 parent 930b998 commit 0583f17

3 files changed

Lines changed: 45 additions & 0 deletions

File tree

data/fix-commits/advisory-database-b78f1d41.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://github.com/github/advisory-database",
33
"vulnerabilities": {
4+
"GHSA-3QMJ-QW66-FWX8": {
5+
"9a5cc253f1c0953f7ad1e27a65d55e829580e693": "Publish Advisories\n\nGHSA-3qmj-qw66-fwx8\nGHSA-hh8h-hxcj-2pm7"
6+
},
7+
"GHSA-HH8H-HXCJ-2PM7": {
8+
"9a5cc253f1c0953f7ad1e27a65d55e829580e693": "Publish Advisories\n\nGHSA-3qmj-qw66-fwx8\nGHSA-hh8h-hxcj-2pm7"
9+
},
410
"GHSA-79P2-24V8-GP9V": {
511
"9e11038b74a415cb258e4480af9958fa0437c439": "Publish Advisories\n\nGHSA-79p2-24v8-gp9v\nGHSA-rvhx-c29r-93j7\nGHSA-263p-9rp6-x92j\nGHSA-7848-x3wq-cg7m\nGHSA-rvm4-4vv7-vq58\nGHSA-9w55-r5pp-5hfx\nGHSA-2chr-7vph-93pf\nGHSA-5r72-p4cv-h344\nGHSA-2pvh-447j-v7m6\nGHSA-mgj5-5f6h-8742\nGHSA-q648-4769-6m83\nGHSA-rq43-8p3g-5cc4\nGHSA-w853-9vqg-wx8h\nGHSA-wg67-7cxp-7wp8\nGHSA-24c9-h3qq-j27f\nGHSA-463m-22hh-chvm\nGHSA-59cp-8v32-7335\nGHSA-5pg7-fr46-jx8j\nGHSA-8hp2-qmc6-f97h\nGHSA-8p2w-g92w-f4x3\nGHSA-v974-2cjf-22q5\nGHSA-vqfg-jwcg-58ww"
612
},

data/fix-commits/buildroot-0b809119.json

Lines changed: 33 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,39 @@
11
{
22
"vcs_url": "https://github.com/buildroot/buildroot",
33
"vulnerabilities": {
4+
"CVE-2026-6472": {
5+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
6+
},
7+
"CVE-2026-6473": {
8+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
9+
},
10+
"CVE-2026-6474": {
11+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
12+
},
13+
"CVE-2026-6475": {
14+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
15+
},
16+
"CVE-2026-6476": {
17+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
18+
},
19+
"CVE-2026-6477": {
20+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
21+
},
22+
"CVE-2026-6478": {
23+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
24+
},
25+
"CVE-2026-6479": {
26+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
27+
},
28+
"CVE-2026-6575": {
29+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
30+
},
31+
"CVE-2026-6637": {
32+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
33+
},
34+
"CVE-2026-6638": {
35+
"9fb64dfc2411bace5a0e1e55ac17963ba4bca6d1": "package/postgresql: security bump version to 18.4\n\nhttps://www.postgresql.org/about/news/postgresql-184-1710-1614-1518-and-1423-released-3297/\n\nFixes CVE-2026-6472, CVE-2026-6473, CVE-2026-6474, CVE-2026-6475,\nCVE-2026-6476, CVE-2026-6477, CVE-2026-6478, CVE-2026-6479,\nCVE-2026-6575, CVE-2026-6637, CVE-2026-6638.\n\nSigned-off-by: Bernd Kuhls <bernd@kuhls.net>\nSigned-off-by: Julien Olivain <ju.o@free.fr>"
36+
},
437
"CVE-2026-41163": {
538
"9ca78cc11c904f3e6a4e4e3fa0a7049f2506219c": "package/bubblewrap: security bump to version 0.11.2\n\nFixes CVE-2026-41163, which affects any system using bubblewrap 0.11.x\nusing a setuid bubblewrap.\n\nRelease notes:\n\n https://github.com/containers/bubblewrap/releases/tag/v0.11.2\n\nSigned-off-by: Adrian Perez de Castro <aperez@igalia.com>\nSigned-off-by: Julien Olivain <ju.o@free.fr>\n(cherry picked from commit 108f51c1b35479a8c1c3c3d9ab58589ef26217f3)\nSigned-off-by: Thomas Perale <thomas.perale@mind.be>",
639
"7e18e312205347656e1e1e2c17bf6529a6275174": "package/bubblewrap: security bump to version 0.11.2\n\nFixes CVE-2026-41163, which affects any system using bubblewrap 0.11.x\nusing a setuid bubblewrap.\n\nRelease notes:\n\n https://github.com/containers/bubblewrap/releases/tag/v0.11.2\n\nSigned-off-by: Adrian Perez de Castro <aperez@igalia.com>\nSigned-off-by: Julien Olivain <ju.o@free.fr>\n(cherry picked from commit 108f51c1b35479a8c1c3c3d9ab58589ef26217f3)\nSigned-off-by: Thomas Perale <thomas.perale@mind.be>",

data/fix-commits/vim-8422b30e.json

Lines changed: 6 additions & 0 deletions
Original file line numberDiff line numberDiff line change
@@ -1,6 +1,12 @@
11
{
22
"vcs_url": "https://github.com/vim/vim",
33
"vulnerabilities": {
4+
"GHSA-4473-94JM-W5X9": {
5+
"a65a52d684bc58535ad28a4ae824d22e76399934": "patch 9.2.0496: [security]: Code Injection in cucumber filetype plugin\n\nProblem: [security]: Code Injection in cucumber filetype plugin\n (Christopher Lusk)\nSolution: Use rubys Regexp.new() with the untrusted pattern\n\nGithub Security Advisory:\nhttps://github.com/vim/vim/security/advisories/GHSA-4473-94jm-w5x9\n\nSigned-off-by: Christian Brabandt <cb@256bit.org>"
6+
},
7+
"GHSA-CRM5-RH6J-2C7C": {
8+
"f08ab2f4d7d2947c8dd6c179ae08ee6146a2694b": "patch 9.2.0495: [security]: runtime(netrw): code injection via NetrwBookHistSave()\n\nProblem: [security]: runtime(netrw): code injection via\n NetrwBookHistSave()\nSolution: Properly quote the directory name using string() function\n (Srinivas Piskala Ganesh Babu)\n\nGithub Security Advisory:\nhttps://github.com/vim/vim/security/advisories/GHSA-crm5-rh6j-2c7c\n\nSigned-off-by: Christian Brabandt <cb@256bit.org>"
9+
},
410
"GHSA-66HR-7P6X-X5J3": {
511
"8af0f098c3a42a28661d0295364e6e0fd7dbc92c": "patch 9.2.0480: [security]: runtime(netrw): code injection via mf command\n\nProblem: [security]: runtime(netrw): code injection via mf command\n (Christopher Lusk, Zdenek Dohnal)\nSolution: Do not use string concatenation inside the filter() commands\n (Zdenek Dohnal)\n\nGithub Security Advisory:\nhttps://github.com/vim/vim/security/advisories/GHSA-66hr-7p6x-x5j3\n\nSigned-off-by: Christian Brabandt <cb@256bit.org>"
612
},

0 commit comments

Comments
 (0)